Menu

Monthly Archives: May 2018

MassMiner Takes a Kitchen-Sink Approach to Cryptomining
Phone Maker BLU Settles with FTC Over Unauthorized User Data Extraction
A Look Inside: Bug Bounties and Pen Testing

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Kitty Cryptomining Malware Cashes in on Drupalgeddon 2.0
Scammers bought Twitter ads to run verified badge phishing scam
Facebook’s getting a clear history button
Critical Cisco WebEx Bug Allows Remote Code Execution
Google and Amazon put an end to censorship-dodging domain fronting
Kitty malware gets its claws into Drupal websites to mine Monero
Poker tournaments disrupted after DDoS attacks on Americas Cardroom

LinuxSecurity.com: It was discovered that jackson-databind, a Java library used to parse JSON and other data formats, improperly validated user input prior to deserializing because of an incomplete fix for CVE-2017-7525.

Using Docker and Windows Server Containers? There’s a patch for that
Firms running Cisco WebEx are told to update their software… again!

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

Recycling is a must, but why would you reuse your password?

World Password Day, celebrated on the first Thursday of every May, is a timely reminder of the fact that our passwords are the key to a wealth of personal information about us. The post Recycling is a must, but why would you reuse your password? appeared first on WeLiveSecurity

Free Speech Advocates Blast Amazon Over Threats Against Signal
Facebook fires engineer accused of stalking women
Fedora 28 “Cutting Edge” Linux Distro Released With New Features
A critical security flaw in popular industrial software put power plants at risk
Boutique Shops Offering Rewards Points Pop Up on the Dark Web

LinuxSecurity.com: An update for rh-php70-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for go-toolset-7 and go-toolset-7-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Quit WebEx now if you want to live! (Bad bugs, not killer slideware)
Goodbye Cambridge Analytica, hello Emerdata?
Oracle Access Manager is a terrible doorman: Get patching this bug

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: A buffer overflow in Python might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability was discovered in hesiod which may allow remote attackers to gain root privileges.

LinuxSecurity.com: Two vulnerabilities were found in the Quassel IRC client, which could result in the execution of arbitrary code or denial of service. Note that you need to restart the ‘quasselcore’ service after upgrading

Smashing Security #076: Spying phones, hacked ski lifts, and World Password Day

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

security update

security update

Hacktivists, Tech Giants Protest Georgia’s ‘Hack-Back’ Bill
Fancy that, Fancy Bear: LoJack anti-laptop theft tool caught phoning home to the Kremlin

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

What’s so special about the SamSam ransomware? [VIDEO]
Medical devices vulnerable to KRACK Wi-Fi attacks
FacexWorm malware steals cryptocurrency & Facebook credentials
Facebook Introduces ‘Clear History’ Option Amid Data Scandal
Vlad that’s over: Remote code flaws in Schneider Electric apps whacked
Schneider Electric Patches Critical RCE Vulnerability
Hands off! Arm pitches tamper-resistant Cortex-M35-P CPU cores

LinuxSecurity.com: An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

Volkswagen and Audi car infotainment systems hacked remotely

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Virtualization 4 Management Agent for RHEL 7 and Red Hat Virtualization Manager 4.1. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

WiFi or Ethernet: Which is faster and which is safer?

There is a lot of debate about WiFi speeds and whether they can offer higher potential speeds than a cable connection, but in practice Ethernet connections turn out to be not only faster but also safer. The post WiFi or Ethernet: Which is faster and which is safer? appeared first on WeLiveSecurity

City of London Police Takes Cybercrime Fight to Businesses
A Quarter of UK CNI Firms Have Suffered Cyber-Attack Outages
Firefox isn’t adding ads, it’s ‘sponsored content’

LinuxSecurity.com: Update to 1.8.8

North Korea’s antivirus software whitelisted mystery malware

LinuxSecurity.com: Red Hat Mobile Application Platform 4.6.0 Release – Container Images 2. Description: Red Hat Mobile Application Platform (RHMAP) 4.6.0 consists of three main components:

AWS sends noise to Signal: You can’t use our servers to beat censors
Scammers using Google Maps to skirt link-shortener crackdown
A cryptocurrency platform exposed sensitive data of 25,000 users
Millions of Home Fiber Routers Vulnerable to Complete Takeover
Samples of SiliVaccine Offer Rare Peek Inside North Korea’s Antivirus Software
Volkswagen Cars Open To Remote Hacking, Researchers Warn

Risk Level: Very Low. Type: Trojan, Worm.

Google Maps open redirect flaw abused by scammers
Twitter sold user data to Cambridge Analytica’s Aleksandr Kogan
Surveillance watchdog learns that old domains never die
Tens of Thousands of Malicious Apps Using Facebook APIs
Researchers find critical security flaws in popular car models
The hacker who broke into jail and had to stay for 7 years
GravityRAT malware evades detection and targets users in India
Controlling children’s use of technology: a preventive measure or an invasion of privacy?

How to use parental control apps to protect children and the fine line that exists between controlling the use of technology and invasion of privacy The post Controlling children’s use of technology: a preventive measure or an invasion of privacy? appeared first on WeLiveSecurity

Cyber Security Breaches Survey 2018
North Korea Ramps Up ‘Operation GhostSecret’ Cyber Espionage Campaign
Defending against mobile technology threats | Salted Hash Ep 24

Reading Time: ~3 min.Text messages are now a common way for people to engage with brands and services, with many now preferring texts over email. But today’s scammers have taken a liking to text messages or smishing, too, and are now targeting victims with text message scams sent via shortcodes instead of traditional email-based phishing […]

Bitcoin hijackers found at least one sucker for scam Chrome extension