Menu

Monthly Archives: May 2018

Serious XSS vulnerability discovered in Signal
Kaspersky Lab plays Swiss gambit in attempt to assuage Russian spying fears
Mining apps? We’re cool so long as they admit to it, says Canonical
UPnP joins the ‘just turn it off on consumer devices, already’ club
Red Hat admin? Get off Twitter and patch this DHCP client bug
Ex-CIA man named as suspect in Vault 7 leak

security update

Indian Cricket Board Exposes Personal Data of Thousands of Players
Julian Assange said to have racked up $5m security bill for Ecuador

Reading Time: ~2 min.Smartphone apps make life easier, more productive, and more entertaining. But can you trust every app you come across? Malicious mobile apps create easy access to your devices for Android and iOS malware to wreak havoc. And there are many untrusted and potentially dangerous apps lurking around in app stores determined to […]

Sensitive myPersonality App Data of Millions of Facebook Users Exposed
Attackers Use UPnP to Sidestep DDoS Defenses
Adobe Doles Out Second Round of Higher Priority Patches
Researchers reveal flaws that may expose encrypted emails to prying eyes

A team of academics says that, if exploited, the vulnerabilities can reveal the plain text of encrypted emails, including those sent years ago The post Researchers reveal flaws that may expose encrypted emails to prying eyes appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in PHP.

Kaspersky Lab’s move from Russia to Switzerland fails to save it from Dutch oven
Get a hands-on, inside look at the dark web | Salted Hash Ep 25
A tale of two zero-days

Double zero-day vulnerabilities fused into one. A mysterious sample enables attackers to execute arbitrary code with the highest privileges on intended targets The post A tale of two zero-days appeared first on WeLiveSecurity

Facebook app left 3 million users’ data exposed for four years
Police dog sniffs out USB drive to snare school hacker
The next Android version’s killer feature? Security patches
White Hat Spoofs 2FA, Sends User to Phishing Page
NCA: Organized Cybercrime Continues to Rise
The EFAIL vulnerability – why it’s OK to keep on using email
Prison phone service can expose the location of anyone with a phone
Zero arrests, 2 correct matches, no criminals: London cops’ facial recog tech slammed
Can AI help bridge the IT security skills gap? | Salted Hash Ep 27
Wanna break Microsoft’s Edge browser? Google’s explained how
How could the Facebook data slurping scandal get worse? Glad you asked

LinuxSecurity.com: A vulnerability has been found in mpv that may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: The package firefox before version 60.0-1 is vulnerable to multiple issues including arbitrary code execution, same-origin policy bypass, access restriction bypass, content spoofing, denial of service, information disclosure and sandbox escape.

LinuxSecurity.com: The package webkit2gtk before version 2.20.2-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package llpp before version 27-2 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: Fabian Vogt discovered that incorrect permission handling in the PAM module of the KDE Wallet could allow an unprivileged local user to gain ownership of arbitrary files.

S/MIME artists: EFAIL email app flaws menace PGP-encrypted chats
Bytecoin cryptocurrency mining malware found in Ubuntu Snap Store
GDPR Phishing Scam Targets Apple Accounts, Financial Data
How many ways can a PDF mess up your PC? 47 in this Adobe update alone

LinuxSecurity.com: Security fix for CVE-2018-10380

Samsung Patches Six Critical Bugs in Flagship Handsets

LinuxSecurity.com: Security fix for CVE-2018-10380

Despite Efail, the sky is not falling
Britain to slash F-35 orders? Erm, no, scoffs Lockheed UK boss
Uninstall PGP? PGP and S/MIME protected emails prone to exposure
Navy names new attack sub HMS Agincourt
Wah, encryption makes policing hard, cries UK’s National Crime Agency
Nest turns up the temperature on password reusers
Denmark’s largest train operator hit by service crippling DDoS attack
Is Google’s Duplex AI helpful or plain creepy?
Remote code execution bug found in GPON routers, but how bad is it really?
WannaCryptor: The curious tale of a ravenous cryptoworm

Do you still remember how WannaCryptor ran its – winding – course? It was a tale that revealed a number of intriguing plot lines amid the ransomworm’s numerous twists and turns. The post WannaCryptor: The curious tale of a ravenous cryptoworm appeared first on WeLiveSecurity

FBI: Reported Internet Crimes Topped $1.4 Billion Last Year
Open Source AI For Everyone: Three Projects to Know
2 million lines of source code left exposed by phone company EE
Critical vulnerabilities in PGP/GPG and S/MIME email encryption, warn researchers
PGP and S/MIME decryptors can leak plaintext from emails, says infosec Professor
Family Planning office warns customers private parts may be exposed
Ubuntu sends crypto-mining apps out of its store and into a tomb
Have you updated your Electron app? We hope so. There was a bad code-injection bug in it
Ransomware Attack Wipes Out Police and Fire Department Data

LinuxSecurity.com: https://www.libraw.org/news/libraw-0-18-11 —- CVE-2018-10529 fixed: out of bounds read in X3F parser CVE-2018-10528 fixed: possible stack overrun in X3F parser

Cyberattack shuts down Tennessee election website

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

Anonymous hacks Russian Govt website against ongoing censorship
Vega Stealer malware steals passwords & card data from Chrome & Firefox
Malicious Chrome extensions found stealing data with cryptomining malware
Rowhammer strikes networks, Bolton strikes security jobs, and Nigel Thornberry strikes Chrome, and more
Phishing Threats Move to Mobile Devices
Report: More Breaches Despite Increasing Security Budgets
Phishing Attack Bypasses Two-Factor Authentication

LinuxSecurity.com: An update that solves 6 vulnerabilities and has 6 fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Hacker access critical code of British cell operator EE
Google Project Zero Calls Windows 10 Edge Defense ‘ACG’ Flawed

security update

Vega Stealer Malware Takes Aim at Chrome, Firefox
CIO Leadership Live, with guest Jack Clare, CIO and chief strategy officer at Dunkin’ Brands
Panda Banking Trojan Diversifies into Cryptocurrency, Porn, Other Targets
Researcher shows how hackers can bypass Two-factor authentication
Hacking train Wi-Fi may expose passenger data and control systems
IBM bans USB drives – but will it work?

LinuxSecurity.com: Harry Sintonen have discovered a cookie injection vulnerability in wget caused by insufficient input validation, enabling an external attacker to inject arbitrary cookie values cookie jar file, adding new

Firefox support for WebAuthn shows passwords the door
Are firms and regulators prepared for GDPR?

The answer may hinge on if you’re a glass-half-full or glass-half-empty kind of person. While we’re at it, how about regulators’ level of preparedness, anyway? The post Are firms and regulators prepared for GDPR? appeared first on WeLiveSecurity

Apple boots out apps that abuse location data collection
Former Iranian Hacker Exposes Cyber-Efforts
Professionals ‘Lack Time’ or Ignore Critical Patch Application
iOS 11.4 to come with 7-day USB shutout
What your provider won’t tell you about cloud security
12 months on, what are the lessons learned from WannaCryptor?

Time does fly! It feels like only yesterday that a new strain of hitherto little-known malware achieved celebrity status among global ransomware campaigns The post 12 months on, what are the lessons learned from WannaCryptor? appeared first on WeLiveSecurity