Menu

Monthly Archives: May 2018

400 popular Drupal based websites hacked to mine cryptocurrency
Bad guys have something new to play with! Microsoft Excel adds support for JavaScript
Pentagon orders military exchanges to pull Chinese smartphones over security risks
Most Industrial Networks Vulnerable to Attack
Budget Android manufacturer Blu settles with FTC over privacy fiasco

LinuxSecurity.com: Harry Sintonen discovered that wget, a network utility to retrieve files from the web, does not properly handle ‘rn’ from continuation lines while parsing the Set-Cookie HTTP header. A malicious web server could use this flaw to inject arbitrary cookies to the cookie jar file, adding

The Man on the Train: Caught with his phishing loot
Cloud security: The skills gap is delaying cloud migration
Countdown to the GDPR deadline: Are you ready? | Salted Hash Ep 28
Tuesday review – the hot 21 stories of the week
Equifax reveals full horror of that monstrous cyber-heist of its servers
Android P to improve users’ network privacy

security update

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Hacking charge dropped against Nova Scotia teen who slurped public records from the web
Download Kali Linux 2018.2 with new security features

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

That Drupal bug you were told to patch weeks ago? Cryptominers hope you haven’t bothered
Romanian Hackers Extradited to U.S. over $18M Vishing Scam
Variant of SynAck Malware Adopts Doppelgänging Technique

LinuxSecurity.com: Several security issues were fixed in the kernel.

Reading Time: ~3 min.As the EU’s General Data Protection Regulation (GDPR) edges closer, we’re looking back on the five most significant stories during the lead up to its implementation. Read about GDPR’s impact on data security and find out how to get prepared with five steps to compliance. What aspect of GDPR will have the […]

Asylo Open-Source Framework Tackles TEEs for Cloud
Cryptojacking Campaign Exploits Drupal Bug, Over 400 Websites Attacked
Cyberwar: Greek & Turkish hackers target each other’s media outlets
Lenovo Patches Arbitrary Code Execution Flaw
Tech support scams and the call of the void

The importance of providing the best possible after-sales service to customers The post Tech support scams and the call of the void appeared first on WeLiveSecurity

Report: China’s Intelligence Apparatus Linked to Previously Unconnected Threat Groups
Linux Kernel Hardens Sound Drivers Against Spectre V1 Vulnerability
Password re-use is dangerous, right? So what about stopping it with password-sharing?
Russia blocks 50 VPNs & Anonymizers amid Telegram crack down

security update

LinuxSecurity.com: An XML external entity expansion vulnerability was discovered in the DataImportHandler of Solr, a search server based on Lucene, which could result in information disclosure.

Abbott to fix critical vulnerabilities in 350,000 ICDs & Pacemakers
Vulnerabilities on the Rise?
A GEORGIA HACKING BILL GETS CYBERSECURITY ALL WRONG
Man hacked 200 firms & sold data of millions of users on dark web

LinuxSecurity.com: – fix stack-based buffer overflow in utils.c:checkmailpath() (CVE-2018-1100) – fix stack-based buffer overflow in gen_matches_files() (CVE-2018-1083) – fix stack-based buffer overflow in exec.c:hashcmd() (CVE-2018-1071)

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions or unsafe redirects. More information can be found in the upstream advisory at

security update

LinuxSecurity.com: – https://www.drupal.org/project/drupal/releases/7.59 – https://www.drupal.org/SA-CORE-2018-004

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Red Hat Single Sign-On 7.2.2 is now available for download from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: It was found that the Quassel IRC client was vulnerable to a remote code execution vulnerability due to insufficient checks in the deserializer code.

Android users hit by ZooPark malware stealing data & recording calls
Security Holes Make Home Routers Vulnerable
Hackers Leverage GDPR to Target Airbnb Customers

LinuxSecurity.com: This update includes the changes in tzdata 2018e for the Perl bindings. For the list of changes, see DLA-1371-1. For Debian 7 “Wheezy”, these problems have been fixed in version

LinuxSecurity.com: This update includes the changes in tzdata 2018e. Notable changes are: – North Korea switches back to +09 on 2018-05-05.

Serious Security: The GLitch “row hammering” attack
Cookie code compromise caper caught and crumbled

LinuxSecurity.com: Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Report: Intel Facing New Spectre-Like Security Flaws
Pr0nbot is Back – and Evading Twitter Censors
Abbott Addresses Life-Threatening Flaw in a Half-Million Pacemakers
Breakthrough pushes Quantum Key Distribution beyond 500km
Anti-theft software LoJack hijacked by Russian Fancy Bear group
The Pentagon bans Huawei and ZTE smartphone sales at military bases worldwide
A bug stored Twitter passwords in plain text so change your password
Twitter advises all users to change passwords after glitch

A bug exposed the passwords of an undisclosed number of users in plain text within Twitter’s internal systems The post Twitter advises all users to change passwords after glitch appeared first on WeLiveSecurity

Tech companies resist government hacking back and backdoors
What to do after a data breach: 5 steps to minimize risk
UK Phisher Pleads Guilty to Just Eat Scam
Yes, you should change your Twitter password – but don’t panic
Half a million pacemakers need a security patch
How to secure SaaS: Understanding the cloud’s security layers
Google rolls out .app domains with built-in HTTPS

The move is part of the company’s HTTPS-everywhere vision for the internet The post Google rolls out .app domains with built-in HTTPS appeared first on WeLiveSecurity

Penetrate the mind of the cyber criminal at SANS London July 2018

Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Cyberattack Shuts Down Mexico Central Bank Within the past week, several payment systems associated […]

Twitter admits to password storage blunder – change your password now!

Reading Time: ~1 min.Our most recent release of the DNS Protection agent provided customers with added features and enhancements designed to improve the overall product experience and its capabilities delivered to end users. We revamped the network detection functionality to improve accuracy and speed for roaming and off-site clients who frequently change networks. We also […]

Fresh fright of data-spilling Spectre CPU design flaws haunt Intel
It’s World (Terrible) Password (Advice) Day!
4chan hackers tried changing voting results of NASA student challenge
Twitter Urges Users to Change Passwords Due to Glitch
European Space Agency wants in on quantum comms satellites
Twitter: No big deal, but everyone needs to change their password

security update

Hurry up patching those Oracle bugs: Attackers aren’t waiting