Menu

Monthly Archives: June 2018

Are your IoT gizmos, music boxes, smart home kit vulnerable to DNS rebinding attacks? Here’s how to check

Risk Level: Very Low. Type: Trojan.

Traffic sign near ICE headquarters hacked with “Abolish ICE” message
IBM’s McAfee-as-a-service cloudy antivirus wobbled for nearly a day

LinuxSecurity.com: An update for git is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: The system could be made to expose sensitive information.

Script kiddie goes from ‘Bitcoin Baron’ to ‘Lockup Lodger’ after DDoSing 911 systems
Microsoft Edge bug odyssey shows why we can’t have nice things

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Tesla fingers former Gigafactory hand as alleged blueprint-leaking sabotage mastermind
Private sector needs a little sumthin’ sumthin’ to get it sharing threat intel – US security chap
New Phishing Scam Reels in Netflix Users to TLS-Certified Sites
Tesla sues ex-employee for hacking & sharing GBs of data with 3rd parties
Mylobot Botnet Emerges with Rare Level of Complexity
At last, a use for Intel’s SGX – locking AI and blockchain, says Intel
Bitcoin Baron Gets 20 Months in Prison for DDoS Attacks
Google Chromecast and Home Speaker can leak location data to websites
16 arrested for hacking Internet cafes to mine cryptocurrency
Who owns your iPhone? [VIDEO]

LinuxSecurity.com: – Security fix for [CVE-2017-11546, CVE-2017-11547] – Fix the .desktop files so that opening a .mid file from a GUI filemanager works

LinuxSecurity.com: Secunia Advisory SA83507, credits Kasper Leigh Haabb, Secunia Research at Flexera parse_qt: possible integer overflow reject broken/crafted NOKIARAW files Backported 0.19-patch to recover read position if TIFF/EXIF tag is too long

LinuxSecurity.com: Update to Chromium 67. Security fix for CVE-2018-6123 CVE-2018-6124 CVE-2018-6125 CVE-2018-6126 CVE-2018-6127 CVE-2018-6128 CVE-2018-6129 CVE-2018-6130 CVE-2018-6131 CVE-2018-6132 CVE-2018-6133 CVE-2018-6134 CVE-2018-6135 CVE-2018-6136 CVE-2018-6137 CVE-2018-6148

LinuxSecurity.com: Update to 2.8.3 – Fix security issue

Alleged Vault 7 leaker was busted because of basic security blunders
11 ‘teammates’ to help you win your own cybersecurity game

Our lineup may seem heavy on the defensive side, but such is the nature of game plans for warding off a range of threats lurking in cyberspace The post 11 ‘teammates’ to help you win your own cybersecurity game appeared first on WeLiveSecurity

The girls who used WhatsApp to learn under the noses of IS
US Fraudster Pleads Guilty to Using OPM Breach Data
‘Wallchart’ Phishing Campaign Exploits World Cup Watchers
Shared, not stirred: GCHQ chief says Europe needs British spies

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: This update provides mitigations for the “lazy FPU” vulnerability affecting a range of Intel CPUs, which could result in leaking CPU register states belonging to another vCPU previously scheduled on the same CPU. For additional information please refer to

Hot new application for blockchain: How does botnet control sound?
OpenBSD disables Intel’s hyper-threading over CPU data leak fears
(Cryptographically) sign me up! Android to take bad app checks offline
PayPal reminds users: TLS 1.2 and HTTP/1.1 are no longer optional

security update

Flaw in Google Home and Chromecast devices reveals user location
APT15 Pokes Its Head Out With Upgraded MirageFox RAT
When It Comes To IoT Security, Liability Is Muddled
Stop downloading fake malicious Fortnite Android apps
Olympic Destroyer Returns to Target Biochemical Labs

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Domain transfer #FAIL – man gets 20 years for gunpoint domain hijack
Axis Cameras Riddled With Vulnerabilities Enabling “Full Control”
How a Nigerian Prince scam victim got his money back after 10 years
Rex Mundi hacking extortion gang busted by Europol

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Researchers claim Chrome bug bounty paid to the wrong people
Cryptography is the Bombe: Britain’s Enigma-cracker on display in new home

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Tesla saboteur caused extensive damage and leaked highly sensitive data, claims Elon Musk
Why open source is good for business, and people
Europol Disrupts Rex Mundi Cybercrime Group
Um, excuse me. Do you have clearance to patch that MRI scanner?
Getting hands-on with industrial control system setups at RSA | Salted Hash Ep 31
Europol and partners dismantle prolific cyber-extortion gang

The arrest of a 25-year-old French man in Thailand apparently seals the fate of Rex Mundi, a hack-and-extort collective that operated since at least 2012 The post Europol and partners dismantle prolific cyber-extortion gang appeared first on WeLiveSecurity

Pass gets a fail: Simple Password Store suffers GnuPG spoofing bug

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for zsh is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for glibc is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for pcs is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for sssd and ding-libs is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for samba is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

It’s time for TLS 1.0 and 1.1 to die (die, die)
Fraudster admits she was OPM dealer: Leaked US govt staff files used to bag cash, car loans
Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke
Not so private eye: Got an Axis network cam? You’ll need to patch it, unless you like hackers
“Unbreakable” Smart Lock Tapplock Issues Critical Security Patch
Google Home, Chromecast Leak Location Information
Zacinlo malware spams Windows 10 PCs with ads and takes screenshots

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are avalable.

LinuxSecurity.com: Multiple vulnerabilities were discovered in the Lua subsystem of Redis, a persistent key-value database, which could result in denial of service. For the stable distribution (stretch), these problems have been fixed in

macOS QuickLook Feature Leaks Data Despite Encrypted Drive
22K Open, Vulnerable Containers Found Exposed on the Net
Firefox fixes critical buffer overflow
Strip Capita of defence IT contract unless things improve – Brit MPs
Apple code signing flaw could have made Mac malware look legit
The “world’s worst” smart padlock – it’s EVEN WORSE than we thought
New Telegram-abusing Android RAT discovered in the wild

Entirely new malware family discovered by ESET researchers The post New Telegram-abusing Android RAT discovered in the wild appeared first on WeLiveSecurity

Convicted! Anonymous Twitter troll not as anonymous as they thought
13 Ways Cyber Criminals Spread Malware
Dark Web drug dealer betrayed by his beard, pleads guilty
US government finds new malware from North Korea
Dixons Carphone Breach Hits 5.9 Million Cards
’90s hacker collective man turned infosec VIP: Internet security hasn’t improved in 20 years
US Government warns of more North Korean malware attacks
Pwned with ‘4 lines of code’: Researchers warn SCADA systems are still hopelessly insecure
US-CERT warns of more North Korean malware
Authorities shut down Dark Web marketplace “Black Hand”

LinuxSecurity.com: Update to latest nodejs-uri-js for CVE fix

LinuxSecurity.com: Update to latest nodejs-uri-js for CVE fix

LinuxSecurity.com: It was discovered that Libgcrypt is prone to a local side-channel attack allowing recovery of ECDSA private keys. For the stable distribution (stretch), this problem has been fixed in

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.