Menu

Monthly Archives: June 2018

Hundreds Report WannaCry Phishing Campaign
School facial recognition system sparks privacy concerns
Facebook sends weekly app emails to wrong people
Dob in naughty data slurps to top EU court, privacy groups urge
On Kaspersky’s ‘transparency tour’ the truth was clear as mud
‘No questions asked’ Windows code cert slingers ‘fuel trade’ in digitally signed malware
Oracle gets busy with Lazy FPU fix, adds more CPU Spectre-protectors
In non-startling news, EFF says STARTTLS email crypto is mostly done wrong

Risk Level: Very Low. Type: Trojan.

Intel finds a cure for its software security pain: Window Snyder
The Pirate Bay stays down – Here’s how to access its Dark Web domain

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

WannaCry Extortion Fraud Reemerges
‘Black hat’ extortionist thrown back in the clink after Yelp-slamming biz
Meet MyloBot malware turning Windows devices into Botnet
UK Tax Agency Collects 5.1M Biometric Voice IDs, May Violate GDPR
Terrible passwords outlawed in Microsoft’s new Azure tool
Misconfiguration of Java web server component Jolokia puts orgs at risk
GDPR and the REAL impact on business

Reading Time: ~4 min.We’ve seen some tricky techniques used by cybercriminals to distribute malware through social media. One common threat begins with a previously compromised Facebook account sending deceptive messages that contain SVG image attachments via Facebook Messenger. (The SVG extention is an XML-based vector image format for two-dimensional graphics with support for interactivity and […]

Nintendo Switch hackers show hacking for mischief is alive and well
Brave browser starts feeding ads to willing guinea pigs
UK taxman has amassed voice profiles of 5.1 million taxpayers
Internet shut down in Algeria to stop exam cheats
China Escalates Hacks Against the US as Trade Tensions Rise
Tesla Employee Steals, Sabotages Company Data

LinuxSecurity.com: Backport security fixes for: CVE-2017-7380, CVE-2017-7381, CVE-2017-7382, CVE-2017-7383, CVE-2017-5852, CVE-2017-5853, CVE-2017-6844, CVE-2017-5854, CVE-2017-5855, CVE-2017-5886, CVE-2018-8000, CVE-2017-6840, CVE-2017-6842, CVE-2017-6843, CVE-2017-6845, CVE-2017-6847, CVE-2017-6848, CVE-2017-7378, CVE-2017-7379, CVE-2017-7994, CVE-2017-8054, CVE-2017-8378, CVE-2017-8787,

LinuxSecurity.com: This update fixes multiple security vulnerabilities: CVE-2017-7380, CVE-2017-7381, CVE-2017-7382, CVE-2017-7383, CVE-2017-5852, CVE-2017-5853, CVE-2017-6844, CVE-2017-5854, CVE-2017-5855, CVE-2017-5886, CVE-2018-8000, CVE-2017-6840, CVE-2017-6842, CVE-2017-6843, CVE-2017-6845, CVE-2017-6847, CVE-2017-6848, CVE-2017-7378, CVE-2017-7379, CVE-2017-7994, CVE-2017-8054,

LinuxSecurity.com: Backport security fixes for: CVE-2017-7380, CVE-2017-7381, CVE-2017-7382, CVE-2017-7383, CVE-2017-5852, CVE-2017-5853, CVE-2017-6844, CVE-2017-5854, CVE-2017-5855, CVE-2017-5886, CVE-2018-8000, CVE-2017-6840, CVE-2017-6842, CVE-2017-6843, CVE-2017-6845, CVE-2017-6847, CVE-2017-6848, CVE-2017-7378, CVE-2017-7379, CVE-2017-7994, CVE-2017-8054, CVE-2017-8378, CVE-2017-8787,

LinuxSecurity.com: This update fixes multiple security vulnerabilities: CVE-2017-7380, CVE-2017-7381, CVE-2017-7382, CVE-2017-7383, CVE-2017-5852, CVE-2017-5853, CVE-2017-6844, CVE-2017-5854, CVE-2017-5855, CVE-2017-5886, CVE-2018-8000, CVE-2017-6840, CVE-2017-6842, CVE-2017-6843, CVE-2017-6845, CVE-2017-6847, CVE-2017-6848, CVE-2017-7378, CVE-2017-7379, CVE-2017-7994, CVE-2017-8054,

Beware malicious software updates for legitimate apps
A volt out of the blue: Phone batteries reveal what you typed and read
India tells its banks to get Windows XP off ATMs – in 2019!

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Update to 2.5.5 bugfix/security release See https://github.com/ansible/ansible/blob/stable-2.5/changelogs/CHANGELOG-v2.5.rst for full changes. Fixes CVE-2018-10855 —- Update to 2.5.3 with bugfixes. https://github.com/ansible/ansible/blob/stable-2.5/changelogs/CHANGELOG-v2.5.rst

security update

LinuxSecurity.com: A vulnerability in PNP4Nagios which may allow local attackers to gain root privileges.

LinuxSecurity.com: A vulnerability in file could lead to a Denial of Service condition.

LinuxSecurity.com: The 4.17.2 kernel rebase contains new drivers, new features, and a number of important fixes across the tree.

security update

Ransomhack; a new attack blackmailing business owners using GDPR

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1957

Hackers Steal $31m+ From South Korean Crypto-Exchange
Destructive Nation-State Cyber Attacks Will Rise, Say European Infosec Pros
Hardened Azure, softened containers, force unlocking iOS 12, 11 iPhones – and more

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

iPhone pwned? Researcher says he can unlock iOS without running out of tries
Meet TLBleed: A crypto-key-leaking CPU attack that Intel reckons we shouldn’t worry about
WannaCry ransomware scam tries to extort money without actually infecting your computer

LinuxSecurity.com: Two vulnerabilities were discovered in LAVA, a continuous integration system for deploying operating systems for running tests, which could result in information disclosure of files readable by the lavaserver system user or the execution of arbitrary code via a XMLRPC call.

LinuxSecurity.com: It was discovered that the low-level interface to the RSA key pair generator of Bouncy Castle (a Java implementation of cryptographic algorithms) could perform less Miller-Rabin primality tests than expected.

Fortnite Fraudsters Infest the Web with Fake Apps, Scams
Malicious App Infects 60,000 Android Devices – But Still Saves Their Batteries

LinuxSecurity.com: git: arbitrary code execution when recursively cloning a malicious repository (CVE-2018-11235) SL7 x86_64 git-1.8.3.1-14.el7_5.x86_64.rpm git-daemon-1.8.3.1-14.el7_5.x86_64.rpm git-debuginfo-1.8.3.1-14.el7_5.x86_64.rpm git-svn-1.8.3.1-14.el7_5.x86_64.rpm noarch emacs-git-1.8.3.1-14.el7_5.noarch.rpm emacs-git-el-1.8.3.1-14.el7_5.noarch.rpm git-all-1.8.3.1-14.el7 [More…]

Supreme Court Bolsters Mobile-Phone Privacy Rights
DDoS-Happy ‘Bitcoin Baron’ Sentenced to Almost 2 Years in Jail
Flight tracking service Flightradar24 hacked; 230,000 accounts affected
Roku TV, Sonos Speaker Devices Open to Takeover
“WannaCrypt” ransomware scam demands payment in advance!

Reading Time: ~4 min.I had the privilege of giving a keynote on one of my favorite topics, busting myths around artificial intelligence (AI) and machine learning (ML), during DattoCon 2018 this week. Webroot has been doing machine learning for more than a decade and consider this aspect one of our key differentiators for our solutions. […]

Microsoft Edge bug could be exploited to spill your emails to malicious sites

Since a patch for the flaw has already been released, users are well advised to make sure that they’re running the browser’s most recent version The post Microsoft Edge bug could be exploited to spill your emails to malicious sites appeared first on WeLiveSecurity

In Russia for World Cup? Beware of fake WiFi hotspots stealing user data
Holy Potatoes! Popular games remove “spyware” after gamers revolt

LinuxSecurity.com: It was discovered that there were two remote code execution vulnerabilities in php-horde-image, the image processing library for the Horde groupware tool:

Olympic Destroyer Malware is Back to Wreak Havoc
‘Hidden Tunnels’ Help Hackers Launch Financial Services Attacks
ICE staff doxxed on Twitter, GitHub, Medium amid child separation furore
Schneier warns of ‘perfect storm’: Tech is becoming autonomous, and security is garbage
Don’t panic, but your baby monitor can be hacked into a spycam
Malware infected Battery saver app on Play Store infects 60,000 users
Sneaky Web Tracking Technique Under Heavy Scrutiny by GDPR
MOS-SAD: Israeli govt weighs in on Facebook privacy, promises action
Want to know what all that Fortnite hype is about? Whoa, Android fans – mind how you go
Financial Services Sector Rife with Hidden Tunnels

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

LinuxSecurity.com: – Security fix for [CVE-2017-11546, CVE-2017-11547] – Fix the .desktop files so that opening a .mid file from a GUI filemanager works

LinuxSecurity.com: http://www.simplesystems.org/libtiff/v4.0.9.html

LinuxSecurity.com: Update to 2.8.3 – Fix security issue

Don’t download it! Fake Fortnite app ends in malware…
60,000 Android devices hit by battery-saving app attack
The Pirate Bay is down – Here are its alternatives & Dark Web domain
WannaCry is back! (Psych. It’s just phisher folk doing what they do)
Bithumb Crypto Exchange Hacked Again; $31 Million Stolen
Why you may want to update your browser in the next 9 days
So long! ‘The internet’s most inept criminal’ goes to jail
Offline Android apps get new security check
Elderly victims conned out of millions by tech support scammer
Apple to share location data during emergency calls in iOS 12
Ham-fisted hacker gets jail time for serial DDoS attacks

The tale of “Bitcoin Baron” reveals a worrying picture and illustrates how easy it has become to wreak havoc on the internet The post Ham-fisted hacker gets jail time for serial DDoS attacks appeared first on WeLiveSecurity

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

Most Websites and Web Apps No Match for Attack Barrage
Mylobot Malware Brings New Sophistication to Botnets
Ex-Tesla employee sued for hacking and stealing company data
Smashing Security #083: Fake email derails clarinetist’s dream
Sorry, but blockchain databases are just not that secure
Israel cyberczar drops hints about country’s new security initiative
South Korea’s largest cryptocurrency exchange hacked

Bithumb has claimed that $31.5 million worth of virtual coins were stolen by hackers The post South Korea’s largest cryptocurrency exchange hacked appeared first on WeLiveSecurity

Please tighten your passwords and assume the brace position, says plane-tracking site