Menu

Monthly Archives: June 2018

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes is now available.

Gentoo Linux on Github hacked; repositories modified
Ticketmaster Breach Discovered in April, Says Bank
Cyber-Attacks Caused 18 Days of NHS Downtime
Rowhammer returns, Spectre fix unfixed, Wireguard makes a new friend, and much more

LinuxSecurity.com: CVE-2017-7651 fix to avoid extraordinary memory consumption by crafted CONNECT packet from unauthenticated client

LinuxSecurity.com: CVE-2017-12872 / CVE-2017-12868 The (1) Htpasswd authentication source in the authcrypt module and (2)

LinuxSecurity.com: An update that fixes one vulnerability is now available.

And that’s now all three LTE protocol layers with annoying security flaws
Worse than Equifax: Personal records of 340M people leaked online
EFF Sues to Repeal Controversial Online Sex Trafficking FOSTA Law
Rowhammer Variant ‘RAMpage’ Targets Android Devices All Over Again

Reading Time: ~2 min.Weaponized USB Drives Targeting Japan and South Korea In an effort to target air-gapped internal systems, a new wave of weaponized USB drives has been found throughout Japanese and South Korean organizations. While these attacks are relatively uncommon, that only heightens the threat as most companies are ill-prepared for such an attack […]

Reality Winner, N.S.A. Contractor, Sentenced to 5+ Years in Leak Case
WebAssembly Changes Could Ruin Meltdown and Spectre Browser Patches
Hundreds of Hotels Hit in FastBooking Breach
Cyber Risk at All-Time High for UK Financial Sector
Facebook and Google accused of manipulating us with “dark patterns”
Adidas US breach may have exposed millions of customers’ personal info
Linux distro hacked on GitHub, “all code considered compromised”
How (over)sharing on social media can trip you up

Profuse recounting of details from your life via social media may come at a price The post How (over)sharing on social media can trip you up appeared first on WeLiveSecurity

It’s a bad, bad web ad world, and some hosting biz like it that way
Brave Brave browser’s hamburger menu serves Tor onion routing
UK.gov’s long-awaited, lightweight biometrics strategy fails to impress
How polite: Fun-bucks coin miners graciously ease off CPU pounding
Et tu, Gentoo? Horrible gits meddle with Linux distro’s GitHub code
Startup bank Monzo: We warned Ticketmaster months ago of site fraud

security update

security update

Are Your Smartphones’ Batteries Spying on You?
Facebook shells out $8k bug bounty after quiz web app used by 120m people spews profiles
Norwegian Agency Dings Facebook, Google For “Unethical” Privacy Tactics
Rewards Points Targeted by Teens in Hack of 500K Accounts
Cyber nasties downed NHS systems for 1,300 hours over 36 months
The Ticketmaster breach – what happened and what to do
Hitherto unknown marketing firm exposed hundreds of millions of Americans’ data
Ticketmaster Chat Feature Leads to Credit-Card Breach
Windows 10 security can be bypassed by Settings page weakness
Ticketmaster breached for months, personal data stolen by hackers

LinuxSecurity.com: The 4.17.2 kernel rebase contains new drivers, new features, and a number of important fixes across the tree. —- The v4.16.17 update includes important fixes across the tree

LinuxSecurity.com: – fix out-of-bounds read via a crafted ELF file (CVE-2018-10360)

NSA Leaker Winner Pleads Guilty
IEEE Calls for Strong Encryption
Smashing Security #084: No! My voice is not my password
That’ll learn ya! Data watchdog spanks two Brit phone botherers
Twitter bots, disassemble

Social media giants announce new measures to tackle bots and abusers The post Twitter bots, disassemble appeared first on WeLiveSecurity

OMG! I just received someone else’s security camera footage!
Are you happy with this technology that Facebook’s developing?
US legislators put industrial control system security on the map
Twitter introduces another way for you to better secure your account

LinuxSecurity.com: Several vulnerabilities have been discovered in exiv2, a C++ library and a command line utility to manage image metadata, resulting in denial of service, heap-based buffer over-read/overflow, memory exhaustion, and

IEEE joins the ranks of non-backdoored strong cryptography defenders

LinuxSecurity.com: An update is now available for Red Hat OpenStack Platform 10.0 (Newton) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Various security issues were discovered in Graphicsmagick, a collection of image processing tools. Heap-based buffer overflows or overreads may lead to a denial of service or disclosure of in-memory information or other unspecified impact by processing a malformed image file.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor: CVE-2018-12891

Firefox Monitor tool informs users if they have been hacked
Infosec bod wagers web bookie BetVictor is lax on password protection

LinuxSecurity.com: Two flaws were discovered in ruby-passenger for Ruby Rails and Rack support that allowed attackers to spoof HTTP headers or exploit a race condition which made privilege escalation under certain conditions possible.

LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code, denial of service, cross-site request forgery or information disclosure.

LinuxSecurity.com: An update for patch is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for patch is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for patch is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for patch is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

Uncle Sam is shocked, SHOCKED to find dark-web bazaars trading drugs, weapons, etc
Ticketmaster gatecrash: Gig revelers’ personal, payment info glimpsed by support site malware
Voice records of millions of Brits stored by tax agency without consent
Reality Winner pleads guilty after being unmasked by microdots
WPA3 is here but how will it make Wi-Fi more secure?
Man travels across world to attack online friend, shot by girl’s mum
US authorities now need warrant for your cellphone location data
World Cup squads briefed on cybersecurity best practices

The football associations of countries competing at Russia 2018 are taking no chances when it comes to cyber-related issues The post World Cup squads briefed on cybersecurity best practices appeared first on WeLiveSecurity

A year after devastating NotPetya outbreak, what have we learnt? Er, not a lot, says BlackBerry bod
Woman ruined, sent death threats after #PermitPatty shaming video goes viral
Midsized Organizations More Secure Than Large Ones
Black Hat Survey: Enterprise Tech, US Government Unprepared for Cyberattacks
Twitter gets physical – with support for hardware security keys

LinuxSecurity.com: An update for org.ovirt.engine-root is now available for Red Hat Virtualization Manager 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Updated redhat-virtualization-host packages that fix several bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

EU summons a CYBER FORCE into existence
FireEye hacked off at claim it hacked Chinese military’s hackers
German researchers defeat printers’ doc-tracking dots
“Safer hops for email” – EFF’s plan to cut down on email snooping
Sophos SafeGuard anything but – thanks to 6 serious security bugs
Mozilla Announces Firefox Monitor Tool Testing, Firefox 61
PBot adware spams ads & installs cryptominer on Windows PCs
Reality Winner, liberty loser: NSA leaker faces 63 months in the cooler

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Mozilla tests new Firefox Privacy Monitor tool
WPA3 is the magic number? Protocol refresh promises tighter Wi-Fi security
Simple Security Flaws Could Steer Ships Off Course
Why Bitcoin’s about to give up one of its closely guarded secrets
UK Minister of Fun Matt Hancock opens London infosec upstart creche
Wi-Fi security gets a boost as WPA3 standard is launched

The new wireless security protocol is poised to make hacking Wi-Fi connections a whole lot harder The post Wi-Fi security gets a boost as WPA3 standard is launched appeared first on WeLiveSecurity

Israel cyber chief’s ‘pants’ analogy for password security deemed, well, ‘pants’
Money-eating cash machine RAT gobbles $17,500
Bill Could Give Californians Unprecedented Control Over Data