Menu

Monthly Archives: April 2018

Join us in San Francisco at the 2018 Red Hat Summit
Uber Rival Careem Hacked, 14 million customer & driver data stolen
Prick up your ears! There’s a new biometric in town

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Yahoo mega-breach hacker faces nearly 8 years in prison
Firms using WebEx at risk of poisoned Flash attacks
LinkedIn patches serious leak in its AutoFill plugin
5 Tips to Make your Online Business Secure from Hackers

LinuxSecurity.com: Multiple vulnerabilities were found in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Multiple vulnerabilities were found in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following issues:

Is scraping files from a Freedom of Information website ‘hacking’?

LinuxSecurity.com: An update for rh-perl524-perl is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Single single-sign-on SNAFU threatens three Cisco products
Brains behind seL4 secure microkernel begin RISC-V chip port
Chinese web giant finds Windows zero-day, stays schtum on specifics

LinuxSecurity.com: A vulnerability has been found in librelp that may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in unADF that may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in mbed TLS, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Gentoo’s tenshi ebuild is vulnerable to privilege escalation due to the way pid files are handled.

LinuxSecurity.com: Multiple vulnerabilities have been found in Quagga, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ClamAV, the worst of which may allow remote attackers to execute arbitrary code.

Cybercrime Economy Generates $1.5 Trillion a Year
Email attacks continue to cause headaches for companies

LinuxSecurity.com: It was discovered that there was an issue in the gunicorn HTTP server for Python applicatons where CRLF sequences could result in an attacker tricking the server into returning arbitrary headers.

LinuxSecurity.com: Updated to securityupdate u171

LinuxSecurity.com: Security fix for CVE-2018-1000115, which disables the UDP port by default.

security update

security update

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

SquirtDanger malware steal passwords & take screenshots of user activity
Localblox exposes personal data of millions of Facebook & LinkedIn users
Cloud-surfing orgs under attack, Microsoft antivirus for Chrome, Windows 10 S bypass, non-RSA gigs, and more

LinuxSecurity.com: This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.

LinuxSecurity.com: This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.

LinuxSecurity.com: – update to the latest upstream release (fixes CVE-2018-1000168)

LinuxSecurity.com: Upstream announcement: **Version 1.3.6** This is a security update to the stable version 1.3. It primarily fixes a recently discovered IMAP command injection vulnerability caused by insufficient input validation within the archive plugin. Details about the vulnerability are published under CVE-2018-9846. Additionally, we back-ported some minor fixes from the master

LinuxSecurity.com: Security fix for CVE-2017-18197

LinuxSecurity.com: Upstream announcement: **Version 1.3.6** This is a security update to the stable version 1.3. It primarily fixes a recently discovered IMAP command injection vulnerability caused by insufficient input validation within the archive plugin. Details about the vulnerability are published under CVE-2018-9846. Additionally, we back-ported some minor fixes from the master

LinuxSecurity.com: Security fix for CVE-2017-18197

LinuxSecurity.com: An update that fixes 33 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

Oh, baby! Newborn-care website leaves database of medics wide open

LinuxSecurity.com: Two vulnerabilities were discovered in LibreOffice’s code to parse MS Word and Structured Storage files, which could result in denial of service and potentially the execution of arbitrary code if a malformed file is opened.

British teen who hacked CIA chief gets two years in prison

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the image loading library for Simple DirectMedia Layer 2, which could result in denial of service or the execution of arbitrary code if malformed image files are opened.

No way, RSA! Security conference’s mobile app embarrassingly insecure
Germany’s Deutsche Bank transfers €28 billion to an account by mistake
British Crackas With Attitude chief gets two years in the cooler for CIA spymaster hack

Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Russia Blocks Millions of IPs to Halt Use of Telegram Recently, Russia has been […]

Yahoo! webmail! hacker! faces! nearly! eight! years! in! the! cooler!

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: New upstream release with security fix for CVE-2018-1084

Akamai CSO Talks Cryptominers, IoT and the Reemergence of Old Threats
Podcast: How Millions of Apps Leak Private Data
Planned European death ray may not need Brit boffinry brain-picking
RSA 2018: IoT security comes of age

IoT security may have finally turned the corner towards a more secure future. The post RSA 2018: IoT security comes of age appeared first on WeLiveSecurity

Medicine pumps & Pacemaker threat as Dr’s simulate hacked overdose
HackerOne CEO Talks Bug Bounty Programs at RSA Conference
RSA Conference has a leaky app… again!
Kingpin who made 100 million robocalls loses his voice
Chrome anti-phishing protection… from Microsoft!
What’s the deal with session-replay scripts?

Some aspects of online tracking go beyond just website analytics The post What’s the deal with session-replay scripts? appeared first on WeLiveSecurity

LinkedIn Fixes User Data Leak Bug
How porn bots abuse government websites
GitHub: New copyright rules could strangle software development
Certificate Transparency and HTTPS
IBM introduces open-source library for protecting AI systems
Gold Galleon hackers target maritime shipping industry
Honeypots and the evolution of botnets | Salted Hash Ep 23

LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.60, which includes additional changes. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for

security update

LinuxSecurity.com: Fuzzing by the OSS-Fuzz project found two memory safety issues in LibreOffice, which could result in an application crash or possibly other unspecified impact.

Oracle whips out the swatter, squishes 254 security bugs in its gear

LinuxSecurity.com: OpenJDK: incorrect handling of Reference clones can lead to sandbox bypass (Hotspot, 8192025) (CVE-2018-2814) * OpenJDK: unrestricted deserialization of data from JCEKS key stores (Security, 8189997) (CVE-2018-2794) * OpenJDK: insufficient consistency checks in deserialization of multiple classes (Security, 8189977) (CVE-2018-2795) * OpenJDK: unbounded memory allocation during deserializati [More…]

LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.60, which includes additional changes. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for

Is it time to kill the pen test? | Salted Hash Ep 22
Yahoo! Hacker! Faces! Nearly! Eight! Years! In! Prison!

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

A Facebook malware has compromised thousands of accounts
IoT Security Concerns Peaking – With No End In Sight
Eight months after Equifax megahack, some Brits are only just being notified
Cloud Credentials: New Attack Surface for Old Problem
48 million personal profiles left exposed by data firm LocalBlox
Google in hot water over privacy of Android apps for kids
NSA reveals how it beats 0-days
Chris Vickery Discusses Data Leak of 48 Million Users by Private Intelligence Firm
Excel pivot table data leak leads to £120,000 fine for London council
Use of ‘StegWare’ Increases in Stealth Malware Attacks
Employee from hell busted by VPN logs
RSA 2018: Hacking the grid

The challenges facing critical infrastructure systems The post RSA 2018: Hacking the grid appeared first on WeLiveSecurity

Silence! Chrome hushes noisy autoplaying videos
Rough patch, or how to shut the window of (unpatched) opportunity

Simply throwing more staff at the patching problem won’t cut it, a study suggests. The post Rough patch, or how to shut the window of (unpatched) opportunity appeared first on WeLiveSecurity

Cutting custody snaps too costly for cash-strapped cops – UK.gov
PCI Council releases vastly expanded cards-in-clouds guidance
Facebook’s login-to-other-sites service lets scum slurp your stuff

LinuxSecurity.com: New gd packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New upstream release with security fix for CVE-2018-1084

Flash! Ah-ahhh! WebEx pwned for all of us!