Menu

Monthly Archives: June 2018

LinuxSecurity.com: The package chromium before version 67.0.3396.79-1 is vulnerable to access restriction bypass.

LinuxSecurity.com: The package krb5 before version 1.16.1-1 is vulnerable to insufficient validation.

security update

security update

security update

security update

LinuxSecurity.com: This update fixes CVE-2016-10040, a stack overflow in QXmlSimpleReader due to a too lenient entityCharacterLimit in our version of the patch for CVE-2013-4549. (The limit was increased from the upstream 1024 to 65536 to address QTBUG-35459, an issue where the security fix was breaking existing real-world XML files. Unfortunately, that is too much to […]

LinuxSecurity.com: Security fix for CVE-2018-8013. Updated to upstream release 1.10.

Bug Bounty Payouts Up 73% Per Vulnerability: Bugcrowd
Survey Shows Florida at the Bottom for Consumer Cybersecurity
What got breached this week? Ticket portals, DNA sites, and Atlanta’s police cameras
Chinese hackers stole 614 gigabytes of US Navy’s anti-ship missile data

LinuxSecurity.com: Alexander Peslyak discovered that insufficient input sanitising of RFB packets in LibVNCServer could result in the disclosure of memory contents.

LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.

LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.

LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.

Lenovo Finally Patches Ancient BlueBorne Bugs in Tab and Yoga Tablets

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

LinuxSecurity.com: Ivan Fratric discovered a buffer overflow in the Skia graphics library used by Firefox, which could result in the execution of arbitrary code. For the oldstable distribution (jessie), this problem has been fixed

LinuxSecurity.com: New gnupg2 packages are available for Slackware 13.37, 14.0, 14.1, 14.2, and – -current to fix a security issue.

Creative Spam Thinks Outside the Macro with .IQY Attachments
Facebook bug exposed private posts of 14 million users to public

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Google Tackles AI Principles: Is It Enough?
WannaCry hero sinks deeper into trouble as new malware charges filed
Threatpost News Wrap Podcast for June 8
Facebook Software Bug Made Some Private Posts Public: 14 Million Affected
Facebook bug may have made 14m users’ posts public
Busted by a Facebook ‘friend’ who’s an undercover cop? It’s legal!

Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. 92 Million Genealogy Site Accounts Compromised Earlier this week, genealogy and DNA testing site […]

Deck the halls with HALs: AI steals the show at Infosec Europe
Adobe Patches Critical Flash Player Bug With Active Exploit

LinuxSecurity.com: DWARF5 and split dwarf, including GNU DebugFission, support.

LinuxSecurity.com: Remove essentially unused pre_release tagging in spec file Fixup Makefile patch to include LDFLAGS in all linking commands

Interred in the Internet of Everything

The security implications of devices connecting and sharing data The post Interred in the Internet of Everything appeared first on WeLiveSecurity

What is the New York Cybersecurity Regulation? What you need to do to comply
#Infosec18: Nation State Hacking is Biggest Change in Cyber-Threat Landscape
Atlanta ransomware attack destroyed years of police dashcam video
Russia appears to be ‘live testing’ cyber attacks – Former UK spy boss Robert Hannigan

LinuxSecurity.com: Several vulnerabilities were discovered in jruby, a Java implementation of the Ruby programming language. They would allow an attacker to use specially crafted gem files to mount cross-site scripting attacks, cause denial of service through an infinite loop,

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.

security update

LinuxSecurity.com: A security issue was fixed in Unbound.

Drupal drisputes dreport of widespread wide-open websites – whoa

LinuxSecurity.com: The package radare2 before version 2.6.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Creepy CloudPets pulled from stores over security fears

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

WhatsApp users targeted by homoglyph attack peddling free tickets to theme park
Zero-Day Flash Exploit Targeting Middle East
GDPR: A Compliance Quagmire, for Now
Targeted Spy Campaign Hits Russian Service Centers
Stop us if you’ve heard this one: Adobe Flash gets emergency patch for zero-day exploit
Shipping Industry Cybersecurity: A Shipwreck Waiting to Happen
Flash zero-day exploit. Act now!

Risk Level: Very Low.

Operation Prowli Profits On Weak IoT Devices, Servers
CloudPets May Be Out of Business, But Security Concerns Remain
Prowli malware takes over 40,000 devices worldwide for Monero mining
Baby Cam Creeper Actively Watched New Mom
Britain’s new F-35s arrive in UK as US.gov auditor sounds reliability warning klaxon
Atlanta’s ransomware attack: Police dashcam video archives lost forever

The city has spent $5 million to restore files, rebuild impacted systems, and harden its cyber-defenses The post Atlanta’s ransomware attack: Police dashcam video archives lost forever appeared first on WeLiveSecurity

World Cup, Vacation Scams Lead in Phishing Trips this Summer
WannaCry reverse-engineer Marcus Hutchins hit with fresh charges
InvisiMole: surprisingly equipped spyware, undercover since 2013

Hunting for secrets from high-profile targets while staying in the shadows The post InvisiMole: surprisingly equipped spyware, undercover since 2013 appeared first on WeLiveSecurity

VPNFilter malware caught infecting Asus, D-Link, Huawei, ZTE & others

LinuxSecurity.com: 8u171 update

We won! Smashing Security named Best Security Podcast

LinuxSecurity.com: Security fix for CVE-2017-13685 CVE-2017-15286

LinuxSecurity.com: 8u171 update

Dark web souks are so last year: Cybercrooks are switching to Telegram
MyHeritage Alerts Users to Data Breach
Open-source security: Zip Slip critical flaw hits thousands of projects. Update now
#Infosec18: Regulation is Top Driver of Cybersecurity, Now & in the Future
Phishing Scams Target FIFA World Cup Attendees
North Korean hacking group Covellite abandons US targets
Security fail? One in three companies think paying hackers is worth the risk
Customer Data Flies Away with Ticketfly Hacker
5 Tips for Protecting SOHO Routers Against the VPNFilter Malware
Cybercrime Is Skyrocketing as the World Goes Digital
Fitness app PumpUp left users’ personal data exposed on server
Queen’s University Belfast Launches Cyber-Testing Labs
Open Redis Servers Infected with Malware
Hackable CloudPets pulled from Target, Walmart, Amazon and more
VPNFilter update: More bad news for routers

New research into VPNFilter finds more devices hit by malware that’s nastier than first thought, making rebooting and remediating of routers more urgent. The post VPNFilter update: More bad news for routers appeared first on WeLiveSecurity

Oh the irony! When cybercriminals are rubbish at cybersecurity
Delete all your emails and acid wash your hard drives, says security expert Sean Hannity
Norman the AI bot reads Reddit, becomes “psychopath”
Smashing Security #081: Hacker no-hopers, Wessex Water has a word, and we win an award
VPNFilter router malware is a lot worse than everyone thought
‘Vigilance’ hacker charged over Minnesota government attacks
PageUp Malware Scare Sheds Light On Third-Party Risks
VPNFilter Malware Impact Larger Than Previously Thought
Zip Slip Flaw Affects Thousands of Open-Source Projects

LinuxSecurity.com: Several security issues were fixed in procps-ng.

HR software firm suffers massive data breach after malware attack

Reading Time: ~3 min.GDPR represents a massive paradigm shift for global businesses. Every organization that handles data belonging to European residents must now follow strict security guidelines and businesses are now subject to hefty fines if data breaches are not disclosed. Organizations around the world have been busy preparing to comply with these new regulations, […]

Tech giants! How do you know Jim in accounting isn’t Putin moves on you
Police Dept loses years worth of dashcam video to ransomware