Menu

Monthly Archives: June 2018

Dixons Carphone ‘fesses to mega-breach: Probes ‘attempt to compromise’ 5.9m payment cards
Microsoft reveals which Windows bugs it might decide not to fix

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

June 2018, and Windows Server can be pwned with a DNS request
June Patch Tuesday: Microsoft Issues Fixes for DNS, Cortana

LinuxSecurity.com: Danny Grander discovered a directory traversal flaw in plexus-archiver, an Archiver plugin for the Plexus compiler system, allowing an attacker to overwrite any file writable by the extracting user via a specially crafted Zip archive.

Android Devices With Misconfigured ADB, a Ripe Target for Cryptojacking Malware
Amazon Fire TV & Fire TV Stick hit by crypto mining Android malware

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Reading Time: ~3 min.Cyberattacks are on the rise, with UK firms being hit, on average, by over 230,000 attacksin 2017. Managed service providers (MSPs) need to make security a priority in 2018, or they will risk souring their relationships with clients. By following 3 simple MSP best practices consisting of user education, backup and recovery, […]

Type: Vulnerability. Adobe Flash Player is prone to multiple security vulnerabilities; fixes are available.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Bypass Glitch Allows Malware to Masquerade as Legit Apple Files
Spain’s La Liga app uses fans’ phones to detect illegal soccer broadcasts

La Liga says that the functionality requires the user’s express consent and that it is only intended to detect unauthorized broadcasts of soccer games. The post Spain’s La Liga app uses fans’ phones to detect illegal soccer broadcasts appeared first on WeLiveSecurity

Florida skips gun background checks for a year after employee forgets login
Bitcoin value tumbles as hackers loot CoinRail cryptocurrency exchange
The Google Pixelbook power button is now a 2FA token
FBI’s BEC Crackdown Leads To 74 Arrests Globally

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Hello, ‘Apple’ here, and this dodgy third-party code is A-OK with us
UK! watchdog! slaps! Yahoo! with! £250k! fine! for! 2014! data! breach!
Ericsson’s Chris Price on the need for collaboration between open source communities and projects
Over 301,000 Open Jobs in Cybersecurity

LinuxSecurity.com: An update for Red Hat JBoss Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

OnePlus 6 smartphone flash override demoed
AWS Best Practices webinar series: Building security into your environment
How to get the most cloud security
How the Spanish cybercriminal underground operates | Salted Hash Ep 30
74 people arrested in US-led crackdown on email scams

The international effort to disrupt Business Email Compromise (BEC) schemes also resulted in the seizure of nearly $2.4 million and the recovery of around $14 million in fraudulent wire transfers. The post 74 people arrested in US-led crackdown on email scams appeared first on WeLiveSecurity

GnuPG patched to thwart ‘fake filename’

LinuxSecurity.com: Jakub Wilk discovered a directory traversal flaw in the Archive::Tar module, allowing an attacker to overwrite any file writable by the extracting user via a specially crafted tar archive.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Youth crime falls as kids stay inside to play Grand Theft Auto instead of going out to steal cars
VMware’s remote management agent allows remote execution

security update

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a privilege-escalation vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Several security issues were fixed in GnuPG.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Meet Summit, world’s fastest AI-powered supercomputer
Tens of thousands of Android devices are leaving their debug port exposed
Foscam Issues Patches For Vulnerabilities in IP Cameras

security update

Scammers ahoy! International police operation harpoons 74 email whaling suspects
InvisiMole Burrows into Targets with Rich Espionage Tools
Report: Chinese Hackers Siphon Off ‘Massive’ Amounts of Undersea Military Data
Unprotected Server Exposes Weight Watchers Internal IT Infrastructure
Hackers target payment transfer system at Chile’s biggest bank
Check your router – list of routers affected by VPNFilter just got bigger
When Ducks collide – an #Infosec18 retrospective [VIDEO]
Android users: Beware these popularity-faking tricks on Google Play

Tricksters have been misleading users about the functionality of apps by displaying bogus download numbers The post Android users: Beware these popularity-faking tricks on Google Play appeared first on WeLiveSecurity

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Bitcoin price takes a dive after another cryptocurrency exchange hack

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Bootloader vulnerability in OnePlus 6 lets an attacker take control of the device
FBI Slaps New Charges Against Researcher Who Stopped WannaCry
GDPR will increase reported breaches and trigger a flood of ‘Right to be Forgotten’ requests
Google: We won’t cause “overall harm” with our AI
US Government’s biometric database worries privacy advocates
Welcome to the non-neutral net: Day one
Security execs must prep for post-Brexit cyber challenges – report

LinuxSecurity.com: An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for RHEL-7. Red Hat Product Security has rated this update as having a security impact

Bitcoin falls after Korean exchange loses $40M following hack attack

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, execution of arbitrary code or bypass of JAR signature validation.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

8 Google Maps hidden places You are not allowed to see

LinuxSecurity.com: The package flashplugin before version 30.0.0.113-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

LinuxSecurity.com: The package p7zip before version 16.02-5 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package firefox before version 60.0.2-1 is vulnerable to arbitrary code execution.

Chinese hackers stole undersea warfare data from US Navy contractor
How NATO Defends Against the Dark Side of the Web