Menu

Monthly Archives: April 2018

USB Sticks Can Trigger BSOD – Even on a Locked Device
KRACK Vulnerability Puts Medical Devices At Risk
Failbreak: Bloke gets seven years in the clink for trying to hack his friend out of jail
Someone hacked this highway sign & defaced it with “Hail Hitler” text
Updated GravityRAT Malware Adds Advanced AV Detection
Brit healthcare system inks Windows 10 install pact with Microsoft
Firewalls: What They Are & Why You Need Them
NIST Updates Cybersecurity Framework to Tackle Supply Chain Threats, Vulnerability Disclosure and More
Online poker site bombarded by DDoS attacks, pauses tournaments
Twitter Sold Data To Cambridge Analytica-Linked Company
Man jailed for hacking County jail’s records to get friend released early
This test will tell you how likely you are to fall for fraud

The questionnaire measures a range of personality traits to distinguish people who are more prone to taking the bait than others. The post This test will tell you how likely you are to fall for fraud appeared first on WeLiveSecurity

Hacker who almost sprung a prisoner out of jail is himself imprisoned for seven years
Google adds SSO verification check to G Suite
YouTube snags millions of bad videos, but is it getting the right ones?

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

DNA in genealogy database leads to arrest of suspected serial killer
No, Mark Zuckerberg isn’t messaging you about winning a Facebook lottery
Cloud Misconceptions Are Pervasive Across Enterprises
Why Hackers Love Healthcare
GDPR may well kill enterprise blockchain databases

LinuxSecurity.com: An update for openvswitch is now available for Fast Datapath for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Thailand seizes server linked to North Korean attack gang

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.4. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Umm, Oracle – about that patch? It might not be very sticky …

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Serious vulnerabilities were found in the libvorbis library, commonly used to encode and decode audio in OGG containers. 2017-14633

LinuxSecurity.com: Security fix for [CVE-2018-10194](https://access.redhat.com/security/cve/cve-2018-10194).

LinuxSecurity.com: Updated Boost libraries are available that fix compatibility with CUDA 9.x compilers and fix a possible integer overflow in Boost.Regex.

LinuxSecurity.com: Information leak via crafted user-supplied CDROM [XSA-258] (#1571867) x86: PV guest may crash Xen with XPTI [XSA-259] (#1571878)

LinuxSecurity.com: Security fix for CVE-2018-1088 (Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled)

security update

security update

security update

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.1. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

How to Transfer Data from Android to iPhone
Should we open source election software?
Despite Risks, Nearly Half of IT Execs Don’t Rethink Cybersecurity after an Attack

LinuxSecurity.com: This is an update to the latest upstream release, which disables the UDP port by default (CVE-2018-1000115).

LinuxSecurity.com: It was discovered that gunicorn, an event-based HTTP/WSGI server was susceptible to HTTP Response splitting. For the oldstable distribution (jessie), this problem has been fixed

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, execution of arbitrary code or bypass of JAR signature validation.

LinuxSecurity.com: CVE-2018-7033 An issue that could be used for SQL Injection attacks against SlurmDBD has been fixed.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the image loading library for Simple DirectMedia Layer 1.2, which could result in denial of service or the execution of arbitrary code if malformed image files are opened.

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

New Phishing Attack Targets 550M Email Users Worldwide
Most federal IT contractors don’t protect emails from fraud
Windows USB-stick-of-death, router bugs resurrected, and more

LinuxSecurity.com: It has been discovered that Tor, a connection-based low-latency anonymous communication system, contains a protocol-list handling bug that could be used to remotely crash directory authorities with a null-pointer exception (TROVE-2018-001).

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2018-6056

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

security update

LinuxSecurity.com: This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. — https://www.genivia.com/advisory.html

LinuxSecurity.com: The v4.16.4 update contains fixes across the tree

LinuxSecurity.com: Update to newer release of Tika including security fixes for CVE-2016-4434 and CVE-2016-6809.

LinuxSecurity.com: New upstream release – This release fixes CVE-2018-1106 which is a moderate security issue.

LinuxSecurity.com: Security fix for [CVE-2018-10194](https://access.redhat.com/security/cve/cve-2018-10194).

LinuxSecurity.com: Rebase to qpdf-7.1.1 because of CVEs

LinuxSecurity.com: Rebase to qpdf-7.1.1 because of CVEs

LinuxSecurity.com: This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. — https://www.genivia.com/advisory.html

Ozzie Ozzie Ozzie, oi oi oi! Tech zillionaire Ray’s backdoor crypto for the Feds is Clipper chip v2
SamSam Ransomware Evolves Its Tactics Towards Targeting Whole Companies
What is tar and why does OpenShift Container Application Platform use it?

LinuxSecurity.com: A remote code execution vulnerability has been found within multiple subsystems of Drupal. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised.

Uber Tightens Bug Bounty Extortion Policies
Man bought mail bomb from dark web (Alpha Bay market) to kill ex-wife
Ex-NSA staffer creates app to notify users of evil maid attack on MacBook
ThaiCERT Seizes Hidden Cobra Server Linked to GhostSecret, Sony Attacks
Flawed routers with hardcoded passwords were manufactured by firm that posed ‘national security risk’ to UK
High Court gives UK.gov six months to make the Snooper’s Charter lawful
“SamSam” ransomware – a mean old dog with a nasty new trick

Reading Time: ~2 min.Two big trends stood out at RSAC 2018. Many organizations that once thought all threat intelligence was created equal have gained appreciation for quality data feeds that deliver real-time information vs. crowdsourced or static lists. Endless alerts and flashy numbers are no longer enough. Companies want to know the “why?” and “what […]

Getting an Amazon Echo app to silently eavesdrop on you
Authorities bust world’s largest DDoS-for-hire service & seizes its domain
The NSA wants its algorithms to be a global IoT standard. But they’re simply not trusted
World’s biggest DDoS marketplace taken down, six suspected admins nabbed

For as little as $15 per month, anyone with a criminal bent could rent the services of webstresser.org to take down a targeted site. The post World’s biggest DDoS marketplace taken down, six suspected admins nabbed appeared first on WeLiveSecurity

Two-fifths of UK Firms Suffered Attack or Security Breach in 2017
Linux Launches Deep Learning Foundation For Open Source Growth In AI
Reports of tech support scams rocket, as fraudsters make a pretty penny
Infamous revenge porn site Anon-IB seized by police
RSA 2018: Behind the lines

ESET’s Senior Security Researcher Stephen Cobb reflects on RSA 2018 and the state of the cybersecurity industry The post RSA 2018: Behind the lines appeared first on WeLiveSecurity

Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Amazon IPs Rerouted for Several Hours Early Tuesday morning attackers compromised an ISP that […]

LinuxSecurity.com: New openvpn packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Upstream announcement: Welcome to **phpMyAdmin 4.8.0.1**, which fixes a security flaw found in phpMyAdmin. This version fixes a security flaw found in version 4.8.0 where an attacker can manipulate a user in to following a specially-crafted link, allowing the attacker to execute arbitrary SQL commands on the server. For more information, please see

LinuxSecurity.com: Update security update jdk8u171-b10

LinuxSecurity.com: Update to latest upstream release and security fix for CVE-2017-12626

LinuxSecurity.com: Security fix for CVE-2018-9918

LinuxSecurity.com: – don’t list nologin in /etc/shells (#1378893)

LinuxSecurity.com: **Version 1.6.4** – 2018-04-13 * Security fixes in some edge case scenarios, recommended update for all users * Fixed regression in version guessing of path repositories * Fixed removing aliased packages from the repository, which might resolve some odd update bugs * Fixed updating of package URLs for GitLab * Fixed run-script –list failing […]

LinuxSecurity.com: Upstream announcement: **Version 1.3.6** This is a security update to the stable version 1.3. It primarily fixes a recently discovered IMAP command injection vulnerability caused by insufficient input validation within the archive plugin. Details about the vulnerability are published under CVE-2018-9846. Additionally, we back-ported some minor fixes from the master

LinuxSecurity.com: Updated Boost libraries are available that fix compatibility with CUDA 9.x compilers and fix a possible integer overflow in Boost.Regex.

Apple’s latest updates are out – APFS password leakage bug squashed

LinuxSecurity.com: An update that solves 9 vulnerabilities and has one errata is now available.

Popular Chrome VPN extensions are leaking your DNS data

LinuxSecurity.com: An update for apr is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, Red Hat Enterprise

security update

Microsoft Issues More Spectre Updates For Intel CPUs
Rubella Crimeware Kit: Cheap, Easy and Gaining Traction