Menu

Monthly Archives: June 2018

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

ClipboardWalletHijacker malware replaces address to steal cryptocurrency
Bank of Chile Suffers $10m Loss
Trump-Kim Meeting Was a Magnet For Russian Cyberattacks

security update

security update

security update

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2018-4190](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4190), [CVE-2018-4199](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4199), [CVE-2018-4218](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4218), [CVE-2018-4222](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4222),

LinuxSecurity.com: Update to latest nodejs-uri-js for CVE fix

LinuxSecurity.com: Update to latest nodejs-uri-js for CVE fix

LinuxSecurity.com: This rebases singularity from 2.2.1 to 2.5.1, which should include all corresponding updates (n.b. a request for rebase permission has been put into FESCo; hence auto-push has been disabled until they approve). Please test for functionality and backward compatibility issues, particularly around the runtime components.

LinuxSecurity.com: This rebases singularity from 2.2.1 to 2.5.1, which should include all corresponding updates (n.b. a request for rebase permission has been put into FESCo; hence auto-push has been disabled until they approve). Please test for functionality and backward compatibility issues, particularly around the runtime components.

Silk road adviser caught, Kaspersky sues Dutch paper, and Vietnam’s tech clampdown
DDoS Amped Up: DNS, Memcached Attacks Rise
23,000 Compromised in HealthEquity Data Breach

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1852

Paul Manafort accused of ‘foldering’ to hide communications
Boffins offer to make speculative execution great again with Spectre-Meltdown CPU fix

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Chinese hackers attack National Data Center using watering hole attack
Vermont Librarian Wins Small-Claims Suit Against Equifax

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

security update

74 arrested after FBI disrupts International gang of BEC scammers
WannaCry Kill Switch Hero Faces New Charges, But Code Evals Say Little
New Banking Trojan Can Launch Overlay Attacks on Latest Android Versions
SHOCK! HORROR! SURPRISE! Bitcoin priceplosion may have been market manipulation
Apple iPhone’s USB Restricted Mode gives Feds a cracking headache

Reading Time: ~2 min.Apple Bans All Cryptocurrency Mining Apps from App Store Apple has made several policy changes over the last few days that will effectively ban all cryptocurrency mining features from apps in the App Store. This change comes not long after Apple removed an app called Calender 2, which silently began background mining […]

Sir, you’ve been using Kaspersky Lab antivirus. Please come with us, sir
Former FBI boss Comey used private email for official business – DoJ
U.S. Intelligence Cautions World Cup Travelers on Mobile Use
Football app tracks illegal broadcasts using your microphone and GPS

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Stop Cyberbullying Day: Advice for victims and witnesses

A comprehensive list of some of the online resources available to victims, their families and friends The post Stop Cyberbullying Day: Advice for victims and witnesses appeared first on WeLiveSecurity

Xen Project patches Intel’s Lazy FPU flaw

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: GnuPG 2 could be made to present validity information incorrectly.

LinuxSecurity.com: Kernel: FPU state information leakage via lazy FPU restore (CVE-2018-3665) SL7 x86_64 kernel-3.10.0-862.3.3.el7.x86_64.rpm kernel-debug-3.10.0-862.3.3.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-862.3.3.el7.x86_64.rpm kernel-debug-devel-3.10.0-862.3.3.el7.x86_64.rpm kernel-debuginfo-3.10.0-862.3.3.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-862.3.3.el7.x86_ [More…]

Quantum cryptography demo shows no need for ritzy new infrastructure

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Apple Removes iPhone USB Access Feature, Blocking Out Hackers, Law Enforcement

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

The $99 digital padlock that kept crooks out… for 2 whole seconds
Cops fined £80,000 for revealing childhood abuse victims’ names
Dixons Carphone Cyberattack Targets 5.9M Bank Cards

LinuxSecurity.com: Several security issues were fixed in Ruby.

“Hey, Cortana, did Patch Tuesday fix a serious lock screen bug?”
Phishing anniversary: Here’s a free $50/month subscription

Adidas “prize” used as bait in attempt to lure people into biting The post Phishing anniversary: Here’s a free $50/month subscription appeared first on WeLiveSecurity

Apple will throw forensics cops off the iPhone Lightning port every hour
Trial of two men accused of $20m hacked press release fraud begins

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

World Cup dream team: ESET vs. Malware

An all-star line-up to go head-to-head with malware The post World Cup dream team: ESET vs. Malware appeared first on WeLiveSecurity

Modern Cybersecurity Demands a Different Corporate Mindset
Major breach at British retailer Dixons Carphone affects nearly six million bank cards

Intruders also accessed 1.2 million personal data records, such as names, addresses or email addresses, in what is shaping up to be one of Britain’s biggest data breaches involving a single company The post Major breach at British retailer Dixons Carphone affects nearly six million bank cards appeared first on WeLiveSecurity

Google locks out extensions that don’t come from its Chrome Web Store

LinuxSecurity.com: The package chromium before version 67.0.3396.87-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package gnupg before version 2.2.8-1 is vulnerable to content spoofing.

Apple confirms it’s closing security loophole that police were using to crack iPhones
Podcast: The Growing Social Media Threat Landscape
Chile to revolutionize cybersecurity after the recent cyberattack

The country’s financial authorities met to establish a new cybersecurity plan following attack on the Bank of Chile The post Chile to revolutionize cybersecurity after the recent cyberattack appeared first on WeLiveSecurity

Smashing Security #082: World Cup cybersecurity, crypto crashes, and a bang of a password fail

LinuxSecurity.com: Several vulnerabilities were found in SPIP, a website engine for publishing, resulting in cross-site scripting and PHP injection. For the oldstable distribution (jessie), this problem has been fixed

LinuxSecurity.com: Multiple vulnerabilities have been found in Quassel, the worst of which could allow remote attackers to execute arbitrary code.

Da rude sand storm seizes the Opportunity, threatens to KO rover
Malicious Docker Containers Earn Cryptomining Criminals $90K
Microsoft Reveals Which Bugs It Won’t Patch
Intel chip flaw: Math unit may spill crypto secrets to apps – modern Linux, Windows, BSDs immune
Two Bugs in WordPress Tooltipy Plugin Patched

security update

US senators get digging to find out the truth about FCC DDoS attack
Japanese police to charge scammers with crypto mining without consent

LinuxSecurity.com: plexus-archiver: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file (CVE-2018-1002200) SL7 noarch plexus-archiver-2.4.2-5.el7_5.noarch.rpm plexus-archiver-javadoc-2.4.2-5.el7_5.noarch.rpm – Scientific Linux Development Team

LinuxSecurity.com: An update for rh-maven33-plexus-archiver and rh-maven35-plexus-archiver is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for plexus-archiver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Citation needed: The EU claims Kaspersky wares ‘confirmed as malicious’

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Banco de Chile Wiper Attack Just a Cover for $10M SWIFT Heist
Tech pioneers: new copyright law a step towards an internet of surveillance and control
Dixons Carphone breach: Millions of card and user data compromised
World Cup watching: The common threats found when using streaming sites

On the eve of the 2018 FIFA World Cup in Russia, we take a closer look at the possible cybersecurity risks that exist on sports streaming websites The post World Cup watching: The common threats found when using streaming sites appeared first on WeLiveSecurity

FBI arrests 74 in global Business Email Compromise takedown
MP gets 600 rape threats in a night, wants an end to online anonymity
Dixons Carphone data breach – millions put at risk of fraud

LinuxSecurity.com: An update is now available for Red Hat JBoss Core Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Serious Security: How three minor bugs make one major exploit
6 million cards compromised in Dixons Carphone breach – act now!
74 Arrested in International Email Scam Schemes
UK watchdog issues $330k fine for Yahoo’s 2014 data breach
US government report highlights gaps in battle against botnets

The report also identifies goals that are intended to help mitigate risks associated with botnets and to increase the resilience of the internet ecosystem The post US government report highlights gaps in battle against botnets appeared first on WeLiveSecurity

What’s new in PHP 7.3