Menu

Monthly Archives: April 2018

LinuxSecurity.com: – spec cleanup, silent rpmlint – remove upstreamed patches, fixes rhbz #1507577 – update to 1.2.2

LinuxSecurity.com: rebase and fixed CVE-2018-1000140

LinuxSecurity.com: https://nodejs.org/en/blog/release/v8.11.0/

ATMJackpot Malware Stealing Cash From ATMs
T-Mobile Austria stores passwords as plain text, Outlook gets message crypto, and more
Engineering Group and Open Source Initiative Partner for Enhanced Leadership in Open Source
OPEN SOURCE WON. SO, NOW WHAT?

LinuxSecurity.com: Lilith of Cisco Talos discovered several buffer overflow vulnerabilities in the SDL Image library which can be leveraged by attackers to execute arbitrary code via specially crafted image files.

LinuxSecurity.com: New patch packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Multiple invalid frees and buffer-overflow vulnerabilities were discovered in sam2p, a utility to convert raster images and other image formats, that may lead to a denial-of-service (application crash) or unspecified other impact.

US government seizes classified advertising website Backpage

security update

Mirai Variant Targets Financial Sector With IoT DDoS Attacks
Intel removes remote keyboard app for Android rather than fixing its flaws
Facebook’s secret plan to access hospital patient records
Privacy Advocates Blast Facebook After Data Scraping Scandal
Botched upgrade at Belgian bank Argenta sparks phishing frenzy
Hackers compromise AOL advertising platform to mine cryptocurrency
Is it a bird? Is it a plane? No, it’s a terrible breach of drone buyers’ data
Study: White House email domains at risk of being misused for phishing scams

Most of the White House’s email domains have yet to deploy an email authentication protocol known as DMARC that is designed to reduce the risk of attackers impersonating legitimate email addresses for distributing spam or phishing messages. The post Study: White House email domains at risk of being misused for phishing scams appeared first on […]

Lawmakers press Linux on security of open-source software
Facebook’s new fake news strategy is… decide for yourself!
Facebook knew for years scammers were harvesting users’ details with phone number searches. Did nothing
Intel won’t fix Spectre flaws in older chips
Washington DC “awash” with fake cell towers
Email Fraud is a Top Business Risk for 2018
Iran ‘the New China’ as a Pervasive Nation-State Hacking Threat

LinuxSecurity.com: Fixes for CVE-2018-1002150.

LinuxSecurity.com: Update to the latest upstream release, which fixes CVE-2017-14062.

LinuxSecurity.com: Update to 3.6.5

LinuxSecurity.com: – spec cleanup, silent rpmlint – remove upstreamed patches, fixes rhbz #1507577 – update to 1.2.2

NUC, NUC! Who’s there? Intel, warning you to kill a buggy keyboard app
Buggy Verge crypto-cash gets hacked, devs go fork themselves, hard

LinuxSecurity.com: This update includes the latest upstream release of the Apache HTTP Server, version 2.4.33. A number of security vulnerabilities are fixed in this release: * *Low*: Possible out of bound read in mod_cache_socache (CVE-2018-1303) * *Low*: Possible out of bound access after failure in reading the HTTP request (CVE-2018-1301) * *Low*: Weak Digest auth […]

LinuxSecurity.com: This update includes the latest upstream release of mod_http2, version 1.10.16. This includes a security fix (CVE-2018-1302): When an HTTP/2 stream was destroyed after being handled, mod_http2 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerabilty hard to trigger in usual […]

WhatsApp phishing – how it works, and what to do [VIDEO]
New macOS malware aims at infecting devices with malicious macros
Delta, Sears Breaches Blamed on Malware Attack Against a Third-Party Chat Service
Sears Holdings, Delta and others leak credit cards in “multibreach”

LinuxSecurity.com: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) (CVE-2018-5146) SL6 x86_64 libvorbis-1.2.3-5.el6_9.1.i686.rpm libvorbis-1.2.3-5.el6_9.1.x86_64.rpm libvorbis-debuginfo-1.2.3-5.el6_9.1.i686.rpm libvorbis-debuginfo-1.2.3-5.el6_9.1.x86_64.rpm libvorbis-devel-1.2.3-5.el6_9.1.i686.rpm libvorbis-devel-1.2.3-5.el6_9.1.x86_64.rpm i386 libvorbis-1.2.3 [More…]

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

security update

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libvorbis is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Bot-ched security: Chat system hacked to slurp hundreds of thousands of Delta Air Lines, Sears customers’ bank cards

Reading Time: ~3 min.When WannaCry ransomware spread throughout the world last year by exploiting vulnerabilities for which there were patches, we security “pundits” stepped up the call to patch, as we always do. In a post on LinkedIn Greg Thompson, Vice President of Global Operational Risk & Governance at Scotiabank expressed his frustration with the […]

You are not alone; The Pirate Bay is down once again

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Mark Zuckerberg admits Facebook scans user private messages
Hooray! Facebook ditches searching for people by phone number or email
Rarog Trojan ‘Easy Entry’ For New Cryptomining Crooks, Report Warns
1.5 BEEELLION sensitive files found exposed online dwarf Panama Papers leak
Don’t want to alarm you, but defence bods think North Korea could nuke UK ‘within a few years’
Saks and Lord & Taylor stores suffer data breach exposing five million bank cards

Cybercriminals are believed to have stolen information for more than five million credit and debit cards that shoppers had used at dozens of Saks Fifth Avenue, Saks Off 5th and Lord & Taylor stores mainly in the United States between May 2017 and March 2018. The post Saks and Lord & Taylor stores suffer data […]

Beware ad slingers thinly disguised as security apps

ESET researchers have analyzed a newly discovered set of apps on Google Play, Google’s official Android app store, that pose as security applications. Instead of security, all they provide is unwanted ads and ineffective pseudo-security. The post Beware ad slingers thinly disguised as security apps appeared first on WeLiveSecurity

Find out who is leaking your secrets, with help from invisible zero-width characters
Gosh, these ‘hacker’ nerds are only getting more sophisticated
Facebook and Twitter may be forced to identify bots
Cloudflare’s 1.1.1.1 promises to make DNS more secure
YouTube employee’s Twitter account hijacked during shooting
Smashing Security #072: Why are firms so cr*p with our private data?
US spanks EU businesses in race to detect p0wned servers
Brain monitor had remote code execution and DoS flaw

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

They forked this one up: Microsoft modifies open-source code, blows hole in Windows Defender
Facebook Bolsters Privacy Measures With New Data Access Restrictions

LinuxSecurity.com: The package drupal before version 8.5.1-1 is vulnerable to arbitrary code execution.

security update

security update

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Intel Tells Remote Keyboard Users to Delete App After Critical Bug Found
Cyber security developments: Keeping safe and up to date

LinuxSecurity.com: An update that fixes one vulnerability is now available.

White House Lags Far Behind on Email Security Benchmark
No, Panera Bread Doesn’t Take Security Seriously
Intel Halts Spectre Fixes On Older Chips, Citing Limited Ecosystem Support
Mainstream Live Chat widgets leaking personal details of employees
Insecure SCADA Systems Blamed in Rash of Pipeline Data Network Attacks
Why you might want to tell Facebook you now live in Europe
Don’t blame Panera Bread’s security guy just because he used to work at Equifax
Google banishes cryptocurrency mining extensions from Chrome Web Store

The tech giant is taking the measure after a rise in malicious browser extensions that mine digital money by hijacking the processing power of users’ computers. The clampdown follows Google’s recent move to stop serving any and all adverts promoting virtual currencies and initial coin offerings. The post Google banishes cryptocurrency mining extensions from Chrome […]

Free Virgin Atlantic tickets? No, it’s a WhatsApp scam
Magento sites hacked with cryptominers & credential stealing malware
Hand over your social media history before you enter the US
Grindr was sharing HIV status of users, but now it’s not
The 5 IT security actions to take now based on 2018 Trends

Implementing the five actions described in this article can help reduce your organization’s cyber risk and bolster its security defenses The post The 5 IT security actions to take now based on 2018 Trends appeared first on WeLiveSecurity

Facebook Expands Bug Bounty Amid Spiraling Privacy Scandal
Saks, Lord & Taylor Payment Card Breach Affects 5 Million
GoScanSSH Malware Avoids US Military, South Korea Targets
Those Facebook videos you thought were deleted were not deleted

LinuxSecurity.com: Multiple vulnerabilities have been found in glibc, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were discovered in libxslt, the worst of which may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: Michal Kedzior found two vulnerabilities in LDAP Account Manager, a web front-end for LDAP directories. CVE-2018-8763