Menu

Monthly Archives: April 2018

Steve Wozniak explains why he deactivated his Facebook account
Congress grills Zuckerberg, day one: How does this online stuff work?

LinuxSecurity.com: C?dric Buissart from Red Hat discovered an information disclosure bug in pcs, a pacemaker command line interface and GUI. The REST interface normally doesn’t allow passing –debug parameter to prevent information leak, but the check wasn’t sufficient.

Breach at UK’s Great Western Railway: Commuters told to reset passwords
Imagine you’re having a CT scan and malware alters the radiation levels – it’s doable
While Zuck squirmed, Reddit revealed it found and killed 944 Russian troll factory accounts
No password? No worries! Two new standards aim to make logins an API experience
SAP’s Business Client can own entire apps, DDOS them into dust
Want to terrify a city with an emergency broadcast? All you need is a laptop and $30

security update

Microsoft Fixes 66 Bugs in April Patch Tuesday Release
How to know if your Facebook data was shared with Cambridge Analytica?
It’s April 2018 – and Patch Tuesday shows Windows security is still foiled by fiendish fonts

security update

LinuxSecurity.com: – https://www.drupal.org/SA-CORE-2018-002 – https://www.drupal.org/SA- CORE-2018-001

Vulnerability in San Francisco’s Public Safety Warning Sirens Fixed

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: – https://www.drupal.org/SA-CORE-2018-002 – https://www.drupal.org/SA- CORE-2018-001

Ransomware Dominates Verizon DBIR
Students fell prey to phishing attacks conducted by their universities

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Worm.

How ODNS keeps your browsing habits secret
Adobe Patches Four Critical Bugs in Flash, InDesign
Fraudsters intercept corporate debit cards and swap out chips in new scam

Criminals have devised a new scheme that aims to drain the bank accounts of large corporations. The post Fraudsters intercept corporate debit cards and swap out chips in new scam appeared first on WeLiveSecurity

Quant Loader Trojan Spreads Via Microsoft URL Shortcut Files
Mind-Reader Headset Transfers Your Thoughts On Screen with 90% Accuracy
China forces spyware onto Muslim’s Android phones, complete with security holes
The world’s most popular YouTube video has been hacked

Hackers have managed to deface an array of popular YouTube music videos, changing titles and thumbnail images. The post The world’s most popular YouTube video has been hacked appeared first on WeLiveSecurity

How to check if your Facebook data was shared with Cambridge Analytica
YouTube illegally collects data from kids, group claims
Another company’s been harvesting Facebook user data
Looking ahead to RSA 2018: An interview with ESET Security Evangelist Tony Anscombe

ESET sat down with Tony Anscombe, Global Security Evangelist and Industry Ambassador, to talk about RSA 2018, his talk at the conference, and what to expect. The post Looking ahead to RSA 2018: An interview with ESET Security Evangelist Tony Anscombe appeared first on WeLiveSecurity

Vevo YouTube account hacked; popular celebs affected – Despacito video deleted
What are the advantages of open source software?
Red Hat looks beyond Linux
Jail for white collar pirates who stole from Oracle

LinuxSecurity.com: Kubernetes and its dependencies have been deprecated in the Red Hat Enterprise Linux 7 Extras channel. 2. Description: The kubernetes packages provide utilities for container cluster management.

LinuxSecurity.com: Ansible and its dependencies have been deprecated in the Red Hat Enterprise Linux 7 Extras channel. 2. Description: Ansible and its dependencies will no longer be updated through the Extras

Death in paradise: ‘Cyber attack’ takes out national government’s IT

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for pcs is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libvorbis is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libvncserver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for krb5 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for xdg-user-dirs is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for openssh is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for glibc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for policycoreutils is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Company insiders behind 1 in 4 data breaches – study
Gmail is secure. Netflix is secure. Together they’re a phishing threat

Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Panera Ignores Security Flaw for Months This week it was revealed that Panera failed […]

Sorry spooks: Princeton boffins reckon they can hide DNS queries

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Visual Studio is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Wireless Keyboard is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

You. FCC. Get out there and do something about these mystery bogus cell towers, huff bigwigs

security update

Patch or ditch Adobe Flash: Exploit on sale, booby-trapped Office docs spotted in the wild
Word Attachment Delivers FormBook Malware, No Macros Required
Two Latest Cyber Security Threats & How To Protect Against Them

Risk Level: Very Low. Type: Trojan.

Hackers leave US flag after targeting Cisco switches in Russia & Iran
Hacker who broke into NFL’s Twitter account to spread death hoax learns his punishment

The 2016 compromise of the league’s Twitter account is one of a number of high-profile social media hijackings. The post Hacker who broke into NFL’s Twitter account to spread death hoax learns his punishment appeared first on WeLiveSecurity

Impact Of Chat Service Breach Expands To Best Buy, Kmart
How to Delete Your Facebook Account Permanently – 2018 Guide

LinuxSecurity.com: Minor security update from upstream fixing CVE-2018-0739

LinuxSecurity.com: New version 2.1.26 (#1370156, #1304360)

LinuxSecurity.com: https://nodejs.org/en/blog/release/v8.11.0/

LinuxSecurity.com: Update to latest upstream version.

LinuxSecurity.com: Python Crypto could expose sensitive information.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Ming: CVE-2018-6358

5 Facebook facepalms (just last week)
Cinema voucher-pusher tells customers: Cancel your credit cards, we’ve been ‘attacked’
Hacker mines up to $1 million in Verge after exploiting major bug
Thousands of Google employees call for company to cancel Pentagon work
The Linux Foundation launches a deep learning foundation
There’s security – then there’s barbed wire-laced pains in the arse
Cisco mess from 2017 becomes tool for state-sponsored infrastructure attacks and defacements

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

Linux Beep bug joke backfires as branded fix falls short

LinuxSecurity.com: A vulnerability in SPICE VDAgent could allow local attackers to execute arbitrary commands.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which may allow an attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in libvirt, the worst of which may result in the execution of arbitrary commands.

LinuxSecurity.com: Multiple vulnerabilities were discovered in mailx, the worst of which may allow a remote attacker to execute arbitrary commands.

LinuxSecurity.com: This update fixes assorted CVEs in LibOFX.

LinuxSecurity.com: Fixes for CVE-2018-1002150.

LinuxSecurity.com: Update to the latest upstream release, which fixes CVE-2017-14062.

LinuxSecurity.com: **PHP version 7.1.16** (29 Mar 2018) **Core:** * Fixed bug php#76025 (Segfault while throwing exception in error_handler). (Dmitry, Laruence) * Fixed bug php#76044 (‘date: illegal option — -‘ in ./configure on FreeBSD). (Anatol) **FPM:** * Fixed bug php#75605 (Dumpable FPM child processes allow bypassing opcache access controls). (Jakub Zelenka) **GD:** * Fixed bug php#73957