Menu

Monthly Archives: April 2018

So you’ve got a zero-day – do you sell to black, grey or white markets?

LinuxSecurity.com: The package lib32-openssl before version 1:1.1.0.h-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package zsh before version 5.5-1 is vulnerable to arbitrary code execution.

security update

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Multiple vulnerabilities were discovered in the implementation of the Perl programming language. The Common Vulnerabilities and Exposures project identifies the following problems:

How Netflix Deploys Open Source AI to Reveal Your Favorites

LinuxSecurity.com: Minor update from upstream with fix for CVE-2018-9234 and other bug fixes.

LinuxSecurity.com: * Rebase to Ruby 2.5.1. * Several CVE fixes. * Conflict requirement needs to generate dependency. * Stop using –with-setjmp-type=setjmp on aarch64.

LinuxSecurity.com: harden the binaries (rhbz#1548670)

LinuxSecurity.com: Security fix for CVE-2018-1086 and CVE-2018-1079 Rebased to latest upstream sources

LinuxSecurity.com: Fix CVE-2017-11550 and CVE-2004-2779

LinuxSecurity.com: Fixes several heap-buffer-overflows, see related Bugzilla tickets!

LinuxSecurity.com: GwanYeong Kim reported that ‘pack()’ could cause a heap buffer write overflow with a large item count. For Debian 7 “Wheezy”, these problems have been fixed in version

security update

UK health service boss in the guts of WannaCry outbreak warns of more nasty code infections
Tried checking under the sofa? Indian BTC exchange Coinsecure finds itself $3.5m lighter

LinuxSecurity.com: python-paramiko: Authentication bypass in transport.py (CVE-2018-7750) SL6 noarch python-paramiko-1.7.5-4.el6_9.noarch.rpm – Scientific Linux Development Team

New malware mine cryptocurrency without open browser session
Critical Vulnerability in Drupal CMS Used for Cryptomining
Router ravaging, crippling code, and why not to p*ss off IT staff
Q1 Cyber-Attacks on UK Firms Jump 27%
USING OPEN SOURCE DESIGNS TO CREATE MORE SPECIALIZED CHIPS
Exposed: Lazy Android mobe makers couldn’t care less about security
Don’t Trust Android OEM Patching, Claims Researcher
Website security firm Sucuri hit by large scale volumetric DDoS attacks
NHS boss at the centre of WannaCry outbreak warns of more attacks

LinuxSecurity.com: USN-3621-1 caused a regression in Ruby.

$3.5 beeeellion Bitcoin falls out of Indian BTC exchange’s wallet

LinuxSecurity.com: The package apache before version 2.4.33-1 is vulnerable to multiple issues including session hijacking, access restriction bypass, content spoofing and denial of service.

Someone stole $3 million from Coinsecure Bitcoin exchange
The ransomware that says, “I don’t want money” – play a violent game instead!
This ransomware wants you to play, not pay

Unlike its much more malicious counterparts, this ransomware has a rather benign demand. It also provides two curious ways of recovering one’s files. The post This ransomware wants you to play, not pay appeared first on WeLiveSecurity

Instagram bends to GDPR – a “download everything” tool is coming
Interview: Sarah Jamie Lewis, Executive Director of the Open Privacy Research Society
Anti-Malware testing needs standards, and testers need to adopt them

A closer look at Anti-Malware tests and the somewhat unreliable nature of the process. The post Anti-Malware testing needs standards, and testers need to adopt them appeared first on WeLiveSecurity

Fake Hillary porn just the tip of Russia’s Reddit penetration
Story of a ransomware victim
Facebook shines a little light on ‘shadow profiles’
From Bangkok to Phuket, they cry out: Oh, Bucket! Thai mobile operator spills 46k people’s data
What Facebook and the CLOUD Act mean for cloud privacy
Quarterly cybercrime digest: Part 1

In Part 1, our roundup of some of the most notable law enforcement actions against computer crime in the first quarter of 2018 will focus on arrests and charges involving suspected cyber-crooks. The post Quarterly cybercrime digest: Part 1 appeared first on WeLiveSecurity

Thousands of compromised websites spreading malware via fake updates

Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Music-Oriented YouTube Channels Hacked Within the last week, hackers have defaced multiple YouTube music […]

Cloudflare promises to tend not two, but 65,535 ports in a storm

LinuxSecurity.com: An update that solves three vulnerabilities and has 7 fixes is now available.

When SecureRandom()… isn’t: JavaScript fingered for poking cash-spilling holes in Bitcoin wallets

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, and Red Hat Enterprise

‘Well intentioned lawmakers could stifle IoT innovation’, warns bug bounty pioneer

Type: Vulnerability. Microsoft Jet Database Engine is prone to a buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Outlook Bug Allowed Hackers to Use .RTF Files To Steal Windows Passwords
Calls For Regulation Build After Facebook Privacy Fallout
Microsoft Outlook bug expose Windows credentials to hackers

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton), Red Hat OpenStack Platform 11.0 (Ocata), Red Hat OpenStack Platform 12.0 (Pike), Red Hat OpenStack Platform 8.0 (Liberty), and Red Hat OpenStack Platform 9.0 (Mitaka).

LinuxSecurity.com: An update for sensu is now available for Red Hat OpenStack Platform 11.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: This updates LibOFX to fix assorted CVEs.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Worm.

Risk Level: Very Low. Type: Worm.

Avoiding the Ransomware Mistakes that Crippled Atlanta
GCHQ boss calls out Russia for ‘industrial scale disinformation’
Hackers can takeover & control emergency alarm system with a $35 radio
New ‘Early Bird’ Code Injection Technique Helps APT33 Evade Detection

LinuxSecurity.com: It was discovered that the poppler upload for the oldstable distribution (jessie), released as DSA-4079-1, did not correctly address CVE-2017-9776 and additionally caused regressions when rendering PDFs embedding JBIG2 streams. Updated packages are now available to correct

Using Outlook? You should probably do some patching
Fake Chrome & Firefox browser update lead users to malware infection
Update now! Microsoft’s April 2018 Patch Tuesday – 65 vulns, 24 critical
Where’s my free monitoring service, One Plus? – hacked-off customers
How many Linux users are there anyway?
Top Ten Ways to Detect Phishing
Congress chews up Zuckerberg, day two: A far more thorough mastication
Death SWAT suspect tweets threats from jail using buggy inmate kiosk
UK defines Cyber DEFCON 1, 2 and 3, though of course doesn’t call it that
Kemi Badenoch MP, self-confessed website hacker
Data exfiltrators send info over PCs’ power supply cables
Smashing Security #073: Rick Astley: Never gonna hack you up

LinuxSecurity.com: This update upgrades Firefox to version 52.7.3 ESR. * firefox: Use-after-free in compositor potentially allows code execution (CVE-2018-5148) SL6 x86_64 firefox-52.7.3-1.el6_9.x86_64.rpm firefox-debuginfo-52.7.3-1.el6_9.x86_64.rpm firefox-52.7.3-1.el6_9.i686.rpm firefox-debuginfo-52.7.3-1.el6_9.i686.rpm i386 firefox-52.7.3-1.el6_9.i686.rpm firefox-debuginfo-52.7.3-1 [More…]

Boffins pull off quantum leap in true random number generation

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

Type: Vulnerability. Adobe Flash Player is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: Fixes for CVE-2018-1002150.

LinuxSecurity.com: This updates LibOFX to fix assorted CVEs.

17-year-old finds screen lock bypass vulnerability in Signal app for iOS

LinuxSecurity.com: Several security issues were fixed in Patch.

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update that solves 5 vulnerabilities and has one errata is now available.

Rudd-y hell, dark web! Amber alert! UK Home Sec is on the war path for stealthy cyber-crims
3 critical Flash vulnerabilities patched. Update now!
AMD Rolls Out Spectre Fixes
New ransomware locks files & asks victims to play PUBG game

LinuxSecurity.com: An update that solves three vulnerabilities and has 7 fixes is now available.

An apology to my Facebook followers
Ransomware, hackers, insider threats and human error featured in data breach report
As legal threats rise, this new report aims to guide ethical hackers
Cyber-Criminals Could Earn CEO-Level Salary: Report
Back to the future! 1990s Windows File Manager! NOW OPEN SOURCE!