Menu

Monthly Archives: May 2018

2018: Scariest Year of Evil Things on the Internet
California Teen Arrested for Phishing Teachers to Change Grades

LinuxSecurity.com: Security update for CVE-2017-17723, CVE-2017-17725, CVE-2018-5772

LinuxSecurity.com: Security update for CVE-2017-17723, CVE-2017-17725, CVE-2018-5772

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Misconfigured Reverse Proxy Servers Spill Credentials
RedDawn Espionage Campaign Shows Mobile APTs on the Rise
BYOD Threats Exposed: 61% of UK SMEs Suffer Cyber-Attacks
New Research Seeks to Shorten Attack Dwell Time
Signal bugs, car hack antics, the Adobe flaw you may have missed, and much more

security update

Threatpost News Wrap Podcast for May 18

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Updated collectd packages are now available for Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of

LinuxSecurity.com: An update for sensu is now available for Red Hat OpenStack Platform 10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Hans Jerry Illikainen discovered a type conversion vulnerability in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played.

Tracking firm caught leaking realtime location data of US Mobile users
TeleGrab Malware Steals Telegram Desktop Messaging Sessions, Steam Credentials
Critical Linux Flaw Opens the Door to Full Root Access
WinstarNssmMiner Monero mining malware crashes PC upon detection
Suspected Syrian Electronic Army hackers indicted for conspiracy and identity theft
Senate votes to restore net neutrality… but don’t get your hopes up
Open source code is ubiquitous and so are many vulnerabilities

One-third of audited codebases that contain Apache Struts suffer from the same vulnerability that facilitated the Equifax hack a year ago The post Open source code is ubiquitous and so are many vulnerabilities appeared first on WeLiveSecurity

ZipperDown catches 170,000 iOS apps with their pants down
DHS Unveils National Cybersecurity Risk Strategy
IT Pros Worried About IoT But Not Prepared to Secure It
Tech Talk: Prepping for GDPR
Don’t invest! The ICO scam that doesn’t want your money

LinuxSecurity.com: The package curl before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.

Man faces up to 35 years in prison for helping hackers evade detection by anti-virus software

Reading Time: ~2 min.Chili’s Restaurant Reveals Payment Card Breach In the last week, officials have discovered a data breach that affects an unknown number of the chain’s 1,600 restaurants across the country. It is believed that the breach could affect customers who visited the restaurant between March and April of this year, and likely includes […]

LocationDumb: Phone tracker foul-up exposes world+dog to tracking
Meet MEWKit, a tricky phishing attack draining Ethereum wallets

security update

LinuxSecurity.com: The package zathura-pdf-mupdf before version 0.3.3-3 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Fake Fortnite Apps for Android Spread Spyware, Cryptominers
‘Voice-Squatting’ Turns Alexa, Google Home into Silent Spies

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5 and Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5 and Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The package runc before version 1.0.0rc5+19+g69663f0b-1 is vulnerable to privilege escalation.

LinuxSecurity.com: An update is now available for Red Hat JBoss Data Grid. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Securus firm that lets US Cops track cellphone users has been hacked
Cisco Warns of Three Critical Bugs in Digital Network Architecture Platform
One Year After WannaCry: A Fundamentally Changed Threat Landscape
The Dark Overlord: Suspected hacking group member arrested in Serbia
Podcast: The Evolution of Deception Technology
RIG EK Still Makes Waves, This Time with a Stealthy Backdoor
Phishing Spy Campaign Targets Top Mideast Officials
Mexico’s Banking System Sees $18M Siphoned Off in Phantom Transactions
Biometrics: Better than your mother’s maiden name. Good luck changing your body if your info is stolen

LinuxSecurity.com: New upstream bugfix release, includes security fix for CVE-2017-18266

Suspected member of The Dark Overlord arrested in Serbia

The Dark Overlord, known for a number of breaches and cyber-extortion campaigns in the last two years, is believed to have made US$275,000 from various schemes The post Suspected member of The Dark Overlord arrested in Serbia appeared first on WeLiveSecurity

Facebook crushes 583 million fake accounts in 3 months

LinuxSecurity.com: New upstream bugfix release, includes security fix for CVE-2017-18266

Alexa, Siri and Google can be tricked by commands you can’t hear
StalinLocker ransomware: Put unlock code or say goodbye to your data
Last call for GDPR

With the deadline fast approaching SMBs are reminded of what is required to become compliant The post Last call for GDPR appeared first on WeLiveSecurity

CIA’s “Vault 7” mega-leak was an inside job, claims FBI
Hackers siphon hundreds of millions of pesos out of Mexican banks through shadow transactions
US Government Cybersecurity at a Crossroads
Airports Ill-Equipped to Deal with Major Cyber-Attacks
Blighty’s super-duper F-35B fighter jets are due to arrive in a few weeks
Rail Europe data breach lasted almost three months
Russian malware harvesting Telegram Desktop creds, chats

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues.

LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Oh, great, now there’s a SECOND remote Rowhammer exploit
DOJ convicts second bloke for helping malware go undetected

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Suspected member of The Dark Overlord hacking group arrested
Smashing Security #078: Hounds hunt hackers, too-human Google AI, and ethnic recognition tech – WTF?
Running Cisco DNA Center? Update right now to get rid of the static admin credential

LinuxSecurity.com: OSS-fuzz, assisted by Max Dymond, discovered that cURL, an URL transfer library, could be tricked into reading data beyond the end of a heap based buffer when parsing invalid headers in an RTSP response.

LinuxSecurity.com: It was discovered that there was an issue in the curl a command-line tool for downloading (eg.) data over HTTP. curl could have be tricked into reading data beyond the end of a heap

security update

Lawyers for Marcus Hutchins: His ‘I made malware’ jail phone call isn’t proper evidence
New Cryptominer Distributes XMRig in Aggressive Attacks

LinuxSecurity.com: Several security issues were fixed in PHP.

Former CIA engineer allegedly leaked Vault 7 documents to WikiLeaks
RedHat admins, patch now – don’t let your servers get pwned!
EFAIL Opens Up Encrypted Email to Prying Eyes
Chili’s Doesn’t Leave Data Breach on the Back Burner
Securus lets cops perform real-time cellphone tracking of US Mobile Users
Google to require Android device-makers to roll out OS security patches regularly

The move is intended to help address the mobile platform’s perennial problem – that many manufacturers of Android-powered devices are slow to get software updates out the door The post Google to require Android device-makers to roll out OS security patches regularly appeared first on WeLiveSecurity

WannaCry hero charged with creating Kronos banking malware
Seven out of ten see criminal hacking as big risk to health, safety, prosperity

Recent survey shows that adults in the US view computer hacking as a major threat to their quality of life The post Seven out of ten see criminal hacking as big risk to health, safety, prosperity appeared first on WeLiveSecurity

Chili’s PoS breach: Want some credit card theft with your baby back ribs?
Mexican Banks Lose Millions in SWIFT-like Attacks
Chili’s Suffers Data Breach
Major #eFail Vulnerability Exposes PGP Encrypted Email — UPDATED
What an Apple phishing attack looks like | Salted Hash Ep 32
Four-million Facebook users’ data wide open for anyone to download for years
Facebook can’t wiggle out of facial recognition lawsuit, judge says