Menu

Monthly Archives: April 2018

LinuxSecurity.com: Security fix for CVE-2018-1086 and CVE-2018-1079

LinuxSecurity.com: It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities that could result in infinite loops in different dissectors. Other issues are related to crash in dissectors that are

LinuxSecurity.com: Two vulnerabilities were found in OpenCV, the “Open Computer Vision Library”. CVE-2018-5268

How’s your Wednesday? Things going well? OK, your iPhone, iPad can be pwned via Wi-Fi sync
Surprise! Wireless brain implants are not secure, and can be hijacked to kill you or steal thoughts
iOS Sync Glitch Lets Attackers Control Devices
Millions of apps are exposing sensitive & unencrypted user data
Gold Galleon Hacking Group Plunders Shipping Industry
Vlogger loses $2M in cryptocurrency during YouTube live stream
German Government Chooses Open Source For Its Federal Cloud Solution
50,000 Minecraft users infected with hard drive wiping malware
Microsoft built its own custom Linux kernel for its new IoT service
Researcher Billy Rios, Talks Medical Device Security at RSA Conference 2018
Facebook pushes ahead with controversial facial recognition feature in Europe
ID theft in UK hits record high as crooks shift to more vulnerable targets
RSA 2018: Untangling the enterprise security mess

Securely keeping track of data and security applications The post RSA 2018: Untangling the enterprise security mess appeared first on WeLiveSecurity

Nate Cardozo, Attorney with EFF Talks Encryption at RSA Conference 2018
Why ‘remote detonator’ is a bad name for your Wi-Fi network
Russia’s Grizzly Steppe gunning for vulnerable routers

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

Facebook: 3 reasons we’re tracking non-users
Hackers are using botnets to take the hard work out of breaking into networks
Detailing The Idle Loop Ordering Problem & The Power Improvement In Linux 4.17
Casino Gets Hacked Through Its Internet-Connected Fish Tank Thermometer
My letter urging Georgia governor to veto anti-hacking bill
Trends 2018: Democracy hack

Can the electoral processes be protected? The post Trends 2018: Democracy hack appeared first on WeLiveSecurity

NHS given a lashing for lack of action plan one year since WannaCry
Cisco, Microsoft and 32 big vendor pals join ‘Accord’ to improve security by doing … security stuff
Hop to it, bunnies: TaskRabbit breach means new passwords

LinuxSecurity.com: Wojciech Regula discovered an XML External Entity vulnerability in the XML Parser of the mindmap loader in freeplane, a Java program for working with mind maps, resulting in potential information disclosure if a malicious mind map file is opened.

You’re a govt official. You accidentally slap personal info on the web. Quick, blame a kid!

LinuxSecurity.com: Version 2.1.3 (March 5th, 2018) ——————————- **Security fixes** * Attributes that have URI values weren’t properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized. This security issue was introduced in Bleach 2.1. […]

Hey, govt hacker bod. Made some really nasty malware? Don’t be upset if it returns to bite you

security update

Millions of Apps Leak Private User Data Via Leaky Ad SDKs
Woman who hacked airline network busted through VPN logs

security update

Signal app guru Moxie: Facebook is like Exxon. Everyone needs it, everyone despises it
RSAC 2018: Tech Giants Form Cybersecurity Tech Accord
Android malware on Play Store targeting Palestinians on Facebook

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Worm.

US, UK, and Australian governments accuse Russia of targeting networking infrastructure
We ‘could’ send troubled Watchkeeper drones to war, insists UK minister
Over 20 million Chrome users have installed fake malicious Ad Blockers
Traditional firewalls fall short in protecting organizations, says survey
Cryptominer Malware Threats Overtake Ransomware, Report Warns
Automated Bots Growing Tool For Hackers
5 simple tips for better computer security
WhatsApp image showing drug dealer’s fingerprints leads to arrest
Fake or not fake – that is the question

An interview with ESET’s Lukáš Štefanko on the thin line between what deserves the name “security app” and what can be called fake. The post Fake or not fake – that is the question appeared first on WeLiveSecurity

Gmail’s new ‘Confidential Mode’ won’t be completely private
“Privacy is not for sale,” says Telegram founder
Could an Intel chip flaw put your whole computer at risk?
Build up your security credentials at SANS London June 2018
Security Trends to Watch Out for in 2018
Quarterly cybercrime digest: Extraditions and more

As Internet crime knows no borders, mutual legal assistance involving various nations and, by extension, requests for extraditing suspected cyber-offenders are sometimes part and parcel of prosecution efforts. The post Quarterly cybercrime digest: Extraditions and more appeared first on WeLiveSecurity

LinuxSecurity.com: The Citrix Security Response Team discovered that corosync, a cluster engine implementation, allowed an unauthenticated user to cause a denial-of-service by application crash.

Facebook admits it does track non-users, for their own good
Intel’s security light bulb moment: Chips to recruit GPUs to scan memory for software nasties
Microsoft has designed an Arm Linux IoT cloud chip. Repeat, an Arm Linux IoT cloud chip

LinuxSecurity.com: – update to the latest upstream release (fixes CVE-2018-1000168)

LinuxSecurity.com: Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use python send2trash module from system * use correct shebang for python2 * upstream changelog: https://apps.ankiweb.net/docs/changes.html

LinuxSecurity.com: New upstream release with security fix for CVE-2018-1084

LinuxSecurity.com: Update to latest upstream version.

LinuxSecurity.com: update to latest upstream release, which fixes the following vulnerabilities: – CVE-2018-1100 – stack-based buffer overflow in utils.c:checkmailpath() – CVE-2018-1083 – stack-based buffer overflow in compctl.c:gen_matches_files() – CVE-2018-1071 – stack-based buffer overflow in exec.c:hashcmd()

LinuxSecurity.com: Removing dependency on wireshark metapackage from wireshark-cli —- Added wireshark-qt to wireshark metapackage —- – New version 2.4.5 – Contains fixes for CVE-2018-7419, CVE-2018-7418, CVE-2018-7417, CVE-2018-7420, CVE-2018-7320, CVE-2018-7336, CVE-2018-7337, CVE-2018-7334, CVE-2018-7335, CVE-2018-6836, CVE-2018-5335, CVE-2018-5334, CVE-2017-6014, CVE-2017-9616,

security update

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: This update doesn’t fix a vulnerability in linux-tools, but provides support for building Linux kernel modules with the “retpoline” mitigation for CVE-2017-5715 (Spectre variant 2).

Threatpost RSA Conference 2018 Preview
Police bust drug dealers using fingerprint from a WhatsApp photo
US, UK cyber cops warn Russians are rooting around in your routers

LinuxSecurity.com: Marcin Noga discovered multiple vulnerabilities in readxl, a GNU R package to read Excel files (via the integrated libxls library), which could result in the execution of arbitrary code if a malformed spreadsheet is processed.

Google to add extra Gmail security … by building a walled garden
Security? We’ve heard of it, say web-app devs. 31 in 33 codebases have at least one big bad vuln

LinuxSecurity.com: Several security issues were fixed in Ruby.

LinuxSecurity.com: Minor update from upstream with fix for CVE-2018-9234 and other bug fixes.

Police locate suspect from a crowd of 50,000 using Facial Recognition
Google Play Boots Three Malicious Apps From Marketplace Tied to APTs
UK spy agency warns Brit telcos to flee from ZTE gear
Hackers attack Casino’s fish tank thermometer to obtain sensitive data

LinuxSecurity.com: Several security issues were fixed in Patch.

How to protect your Facebook data [UPDATED]
Quarterly cybercrime digest: Sentencing

The long arm of the law caught up with a number of cybercriminals in the first three months of this year. The post Quarterly cybercrime digest: Sentencing appeared first on WeLiveSecurity

LinuxSecurity.com: It was discovered that there was an input validation vulnerability in the patch(1) utility where an ed(1) script embedded in a regular input file could result in arbitrary code execution. This was reported by Rachel Kroll [0] et al.

Nation-State Attacks Take 500% Longer to Find
Allscripts: Ransomware, recovery, and frustrated customers
Tracking protection in Firefox for iOS now on by default – why this matters
Facial recognition cameras on lamp posts to be tested in Singapore
Cisco backs test to help classical crypto outlive quantum computers
Security bods liberate EITest malware slaves

LinuxSecurity.com: A NULL Pointer Dereference was discovered in the TIFFPrintDirectory function (tif_print.c) when using the tiffinfo tool to print crafted TIFF information. This vulnerability could be leveraged by remote attackers to cause a crash of the application.

LinuxSecurity.com: A NULL Pointer Dereference was discovered in the TIFFPrintDirectory function (tif_print.c) when using the tiffinfo tool to print crafted TIFF information. This vulnerability could be leveraged by remote attackers to cause a crash of the application.

Android apps prove a goldmine for dodgy password practices
Australian Feds cuff woman who used BTC to buy drugs on dark web

LinuxSecurity.com: A vulnerability in Go allows remote attackers to execute arbitrary commands.