Menu

Monthly Archives: May 2018

LinuxSecurity.com: The Qualys Research Labs discovered multiple vulnerabilities in procps, a set of command line and full screen utilities for browsing procfs. The Common Vulnerabilities and Exposures project identifies the following problems:

ICANN Launches GDPR Lawsuit to Clarify the Future of WHOIS

LinuxSecurity.com: Several security issues were fixed in libytnef.

LinuxSecurity.com: An update for xmlrpc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Nocturnal Stealer Lets Low-Skilled Cybercrooks Harvest Sensitive Info
Paris Police Arrests Alleged Vevo Hackers
Huawei Patches Four Server Bugs Rated High Severity

LinuxSecurity.com: xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003) SL6 noarch xmlrpc3-client-3.0-4.17.el6_9.noarch.rpm xmlrpc3-common-3.0-4.17.el6_9.noarch.rpm xmlrpc3-client-devel-3.0-4.17.el6_9.noarch.rpm xmlrpc3-common-devel-3.0-4.17.el6_9.noarch.rpm xmlrpc3-javadoc-3.0-4.17.el6_9.noarch.rpm xmlrpc3-server-3.0-4.17.el6_9.noarch.rpm [More…]

We found 1 good reason to get the iOS 11.4 update – rogue message handling
Podcast: How Cities Can Be Security Smart
How to set up 2FA on eBay – go do it now!
These Chrome extensions & Android apps collect your Facebook data
European Commission “doesn’t plan to comply with GDPR” – well, sort of

LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Hoax alert! Starbucks is NOT inviting you to test its shatterproof windows
Apple’s iOS 11.4 security update arrives in an iCloud of silence
Acoustic attacks can blue-screen computers
Nuisance call bosses, get your wallets ready!
Smashing Security #080: Country bans Facebook, eavesdropping Alexa, and PornHub VPN
Court says ‘nyet’ to Kaspersky’s US govt computer ban appeal
Forget VPNfilter – here’s BACKLASH, a networking hack from way, way back
Yahoo hacker involved in 500 million accounts breach jailed for 5 years
Law forcing Feds to get warrants for email slurping is sneaked into US military budget

security update

security update

Bug In Git Opens Developer Systems Up to Attack
Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans
Inmates pirated movies from computers they build with spare parts
Yahoo! merc! hacker! Karim! Baratov! gets! five! years! in! the! clink!

LinuxSecurity.com: Several security issues were fixed in the kernel.

Yahoo Hacker Sentenced; Coke Opens Up a Can of Data Breach
SpamCannibal blacklist service reanimated by squatters, claims every IP address is spammy
Git security vulnerability could lead to an attack of the (repo) clones
Google Patches 34 Browser Bugs in Chrome 67, Adds Spectre Fixes
Multiple Internet-Connected BMW vehicles vulnerable to getting hacked
Hidden Cobra Strikes Again with Custom RAT, SMB Malware

LinuxSecurity.com: Several vulnerabilities have been found in the Apache HTTPD server. CVE-2017-15710

An acoustic attack can blue screen your Windows computer
Jail for the man who helped Russia hack Yahoo’s email accounts
California tests digital license plates. Is tracking cars next?
Despacito YouTube video hack – teenagers charged
An Industry In Transition: Key Tech Trends In 2018
FBI to all router users: Reboot now to neuter Russia’s VPNFilter malware
Facebook to be blocked in Papua New Guinea for one month
Tor exit node admin acquitted of aiding terrorism
Facebook battles tiny startup over privacy accusations
See me speak at the Cloud Security Summit in London
Have you heard about ransomware? Now’s the time to ask: Are you covered?

LinuxSecurity.com: Git contains multiple vulnerabilities that allow for the remote execution of arbitrary code.

FBI fingers North Korea for two malware strains

LinuxSecurity.com: The package strongswan before version 5.6.2-2 is vulnerable to denial of service.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: The package wireshark-cli before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package wireshark-common before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package wireshark-qt before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package wireshark-gtk before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several vulnerabilities were discovered in qemu, a fast processor emulator. CVE-2017-15038

Fraudsters Claim To Hack Two Canadian Banks

LinuxSecurity.com: Etienne Stalmans discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability exploitable via specially crafted submodule names in a .gitmodules file.

SEVered Attack Extracts the Memory of AMD-Encrypted VMs

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1726

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1669

Sonic Tone Attacks Damage Hard Disk Drives, Crashes OS

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Google Patches reCAPTCHA Bypass
GCHQ bod tells privacy advocates: Most of our work is making sure we operate within the law
Brazilian Banking Trojan Communicates Via Microsoft SQL Server
Hackers demand $1m ransom after stealing data from 2 Canadian banks
Despite Ringeader’s Arrest, Cobalt Group Still Active
BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts

LinuxSecurity.com: Batik could be made to expose sensitive information if it received a specially crafted XML.

UNICEF now using cryptocurrency mining for fundraising

So far in 2018, the NGO has launched two charity campaigns with the aim of raising funds through cryptocurrency mining. The post UNICEF now using cryptocurrency mining for fundraising appeared first on WeLiveSecurity

Are your Android apps sending unencrypted data?
Wayback Machine ‘unarchives’ spying website
Watch thieves steal keyless Mercedes within 23 seconds
Your Firefox account can now be secured with 2FA
Papua New Guinea to ban Facebook for a month
Inside Microsoft’s Azure Sphere hardware for secure IoT
Ex-staffer of UK.gov dept bags payout after boss blabbed medical info to colleagues
Two Canadian banks warn attackers may have stolen customer data

Simplii Financial and Bank of Montreal are believed to have suffered a twin attack that was soon followed by blackmail threats The post Two Canadian banks warn attackers may have stolen customer data appeared first on WeLiveSecurity

ISP popped router ports, saving customers the trouble of making themselves hackable
Softbank’s ‘Pepper’ robot is a security joke
10 years prison for man who hacked 200 firms & sold data on Dark Web

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Scammers raid man’s bank account while he waits on hold to fraud hotline

Criminals have set their sights on customers of a bank that has been struggling with a switchover to a new computer platform The post Scammers raid man’s bank account while he waits on hold to fraud hotline appeared first on WeLiveSecurity

Singapore ISP Leaves 1,000 Routers Open to Attack
This Chrome extension reveals if your password has been breached
Man arrested for possession of 58 terabytes of child sexual abuse material

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

Privacy International Launches GDPR Probe into Data Companies
Clear Linux Exploring Support For Windows WSL
GDPR latest: Fraudsters posing as banks in data protection emails phishing scam
One in Three HCOs Hit by Cyber-Attack