Menu

Monthly Archives: April 2018

PyRoMine Uses NSA Exploit for Monero Mining and Backdoors
Know what Instagram knows – here’s how you download your data
iPhone crackers GrayShift become victim of extortion after code Leak

Reading Time: ~2 min.Take Our Daughters And Sons To Work Day is today, and while your initial reaction may be to make a note to call in sick that day (heck, that was my gut instinct), resist the urge. It’s one day that is a great reminder for the entire year. We all need to […]

20 years ago today! What we can learn from the CIH virus…
Access denied! World’s largest denial of service site busted
Master Key Hack Exploits Flaw in Key System to Unlock Hotel Rooms
Yahoo fined $35m for staying quiet about mega breach
Gmail users, here’s how (and why) you should set up prompt-based 2FA
Researchers reveal how hotel key cards can be hacked – what you need to know
WEI Mortgage uncovers email phishing scheme and data breach
Is “Malware of Mass Disruption” the WMD of the future? Insights from the stage at RSA 2018

ESET’s Global Security Evangelist Tony Anscombe expands on his theory The post Is “Malware of Mass Disruption” the WMD of the future? Insights from the stage at RSA 2018 appeared first on WeLiveSecurity

LinuxSecurity.com: An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Hyperoptic’s ZTE-made 1Gbps routers had hyper-hardcoded hyper-root hyper-password
Power spike leads Chinese police to 600-machine mining rig
Win 7, Server 2008 ‘Total Meltdown’ exploit lands, pops admin shells

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Smashing Security #075: Quitting Facebook

LinuxSecurity.com: CVE-2017-17833 An issue has been found in openslp that is related to heap memory

LinuxSecurity.com: An update that solves 18 vulnerabilities and has 29 fixes is now available.

Western Digital My Cloud EX2 NAS Device Leaks Files

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: A remote code execution vulnerability has been found in Drupal, a fully-featured content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2018-004

LinuxSecurity.com: Updated packages that provide Red Hat JBoss Enterprise Application Platform 7.1.2, fixes several bugs, and adds various enhancements are now available for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact

ISO blocks NSA’s latest IoT encryption systems amid murky tales of backdoors and bullying

LinuxSecurity.com: An update for eap7-jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 7.1.2 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.1.2 for Red Hat Enterprise Linux 7.

LinuxSecurity.com: Updated packages that provide Red Hat JBoss Enterprise Application Platform 7.1.2 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Updated packages that provide Red Hat JBoss Enterprise Application Platform 7.1.2 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.

LinuxSecurity.com: This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.

LinuxSecurity.com: **Version 1.6.4** – 2018-04-13 * Security fixes in some edge case scenarios, recommended update for all users * Fixed regression in version guessing of path repositories * Fixed removing aliased packages from the repository, which might resolve some odd update bugs * Fixed updating of package URLs for GitLab * Fixed run-script –list failing […]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

Thousands of Android apps for kids are secretly tracking their activities
Hotel, motel, Holiday Inn? Doesn’t matter – they may need to update their room key software
Metamorfo Targets Brazilian Users with Banking Trojans
World’s biggest DDoS-for-hire souk shuttered, masterminds cuffed
Europol Smacks Down World’s Largest DDoS-for-Hire Market
Researchers Hacked Amazon’s Alexa to Spy On Users, Again
Website down! DDoS-for-hire site Webstresser shut by crime agencies
Bezop Cryptocurrency Server Spills 25K in Private Investor, Promoter Data
Podcast: Why Manufacturers Struggle To Secure IoT

LinuxSecurity.com: Several security issues were fixed in MySQL.

The firms that piggyback on ransomware attacks for profit
Ethereum cryptocurrency wallets raided after Amazon’s internet domain service hijacked
Mysterious “double kill” IE zero-day allegedly in the wild
PyRoMine malware disables security & mines Monero using NSA exploits
One month to GDPR. Are you ready?
Ride-hailing service Careem lost 14 million users’ data… in January
UK Financial Sector Must Improve Collaboration: Report
Email security in 2018
Apple debugs debugger, nukes pesky vulns in iOS, WebKit, macOS
Bitcoin Ransomware Hits Ukraine’s Ministry of Energy website

LinuxSecurity.com: It was discovered that psensor, a server for monitoring hardware sensors remotely, was prone to a directory traversal vulnerability because the create_response function in server/server.c lacks a check for whether a file is under the webserver directory.

LinuxSecurity.com: librelp: Stack-based buffer overflow in relpTcpChkPeerName function in src/tcp.c (CVE-2018-1000140) SL6 x86_64 librelp-1.2.7-3.el6_9.1.x86_64.rpm librelp-debuginfo-1.2.7-3.el6_9.1.x86_64.rpm librelp-1.2.7-3.el6_9.1.i686.rpm librelp-debuginfo-1.2.7-3.el6_9.1.i686.rpm librelp-devel-1.2.7-3.el6_9.1.i686.rpm librelp-devel-1.2.7-3.el6_9.1.x86_64.rpm i386 librelp-1.2 [More…]

Exploit Targets Nvidia Tegra-Based Nintendo Systems
Yahoo! fined! $35m! for! covering! up! massive! IT! security! screwup!
Orangeworm Mounts Espionage Campaign Against Healthcare
AWS DNS network hijack turns MyEtherWallet into ThievesEtherWallet

LinuxSecurity.com: It was discovered that there was an XML external entity expansion (XXE) vulnerability in lucene-solr, a search engine library for Java. It could be exploited to read arbitrary local files from the Solr server

LinuxSecurity.com: An update for librelp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Ransomware Attack Hits Ukrainian Energy Ministry, Exploiting Drupalgeddon2

LinuxSecurity.com: An update for PackageKit is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for librelp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

All Nintendo Switch Consoles Contain Unpatchable Chip-Level Flaw
Critical infrastructure needs more 21qs6Q#S$, less P@ssw0rd, UK.gov security committee told
Now Amazon wants the keys to your car
Police try (and fail) to unlock phone with a dead man’s finger
Medic! Orangeworm malware targets hospitals worldwide
Ex-Reddit mogul apologizes for making the world ‘a worse place’

LinuxSecurity.com: This update doesn’t fix a vulnerability in linux-tools, but provides support for building Linux kernel modules with the “retpoline” mitigation for CVE-2017-5715 (Spectre variant 2).

Sednit update: Analysis of Zebrocy

Zebrocy heavily used by the Sednit group over last two years The post Sednit update: Analysis of Zebrocy appeared first on WeLiveSecurity

Can a commercial VPN really keep you anonymous? [VIDEO]
Ransomware runs rampant in 2017, Verizon report finds

Social engineering attacks that involve pretexting nearly tripled on an annual basis while phishing simulations show that curiosity gets the better of 4% of people. The post Ransomware runs rampant in 2017, Verizon report finds appeared first on WeLiveSecurity

Google Project Zero pulls the rug out from under Microsoft (again)
Hackers find life-threatening vulnerabilities in Austrian ski lift control unit
Mingis on Tech: The lowdown on Android security

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Ansible Engine 2.4 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The system could be made to crash or run programs as an administrator.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Massive cyber attack targets mid-Atlantic nation ‘Berylia’

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

security update

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Muhstik Botnet Exploits Highly Critical Drupal Bug
I got 99 secure devices but a Nintendo Switch ain’t one: If you’re using Nvidia’s Tegra boot ROM I feel bad for you, son

Reading Time: ~4 min.According to the Identity Theft Research Center, in 2017 alone, nearly 158 million social security numbers were stolen as a result of 1579 data breaches. Once a cybercriminal has access to your personal info, they can open credit cards, take out loans that quickly ruin your credit, or leave you with a […]

Trustjacking: iTunes’ Wi-Fi Sync Feature Vulnerable to Exploitation
Science fiction becomes science fact – Our brains can be hacked