Menu

Monthly Archives: June 2018

The Zip Slip vulnerability – what you need to know
Auth0 Glitch Allows Attackers to Launch Phishing Attacks
Federal Agencies Face an Uphill Battle in Cyber-Preparedness
Cloudflare Gets Transparent on DNS Resolver Outage
Facebook Defends Against Device-Integrated APIs Policy, But Concerns Remain
Scammers hacked webcams to secretly record videos & post on YouTube
Apple says no to Facebook’s tracking

LinuxSecurity.com: Some more efail fixes, https://enigmail.net/index.php/en/download/changelog

LinuxSecurity.com: **Version 4.0.11** (2018-05-25) * bug #27364 [DI] Fix bad exception on uninitialized references to non-shared services (nicolas-grekas) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas- grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user

LinuxSecurity.com: **Version 2.8.41** (2018-05-25) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas-grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user is logged out * security #cve-2018-11385 Adding session authentication strategy to Guard

Syndicate Wallet hacked; $10 million dollars stolen
Blocking facial recognition surveillance using AI
Crappy IoT on the high seas: Holes punched in hull of maritime security
You have NOT won! A look at fake FIFA World Cup-themed lotteries and giveaways

With the 2018 FIFA World Cup in Russia just days away, fraudsters are increasingly using all things soccer as bait to reel in unsuspecting fans so that they get more than they bargained for The post You have NOT won! A look at fake FIFA World Cup-themed lotteries and giveaways appeared first on WeLiveSecurity

Microsoft faces wrath of developers after GitHub acquisition
WeLiveSecurity named Best Corporate Security Blog!

Thanks to everyone who reads us and voted for us! The post WeLiveSecurity named Best Corporate Security Blog! appeared first on WeLiveSecurity

In World Cup Russia, our Wi-Fi networks will log on to you!
SaaSy HR outfit PageUp reports ‘unauthorised activity’ and data breach
Pwn goal: Hackers used the username root, password root for botnet control database login

security update

LinuxSecurity.com: Several security issues were fixed in Git.

DNA Testing Service MyHeritage Leaks User Data of 92 Million Customers
WARDroid Uncovers Mobile Threats to Millions of Users Worldwide
DNA testing website MyHeritage hacked; 92 million user accounts stolen
Here’s a transaction Transamerica regrets: Transgressors swipe retirees’ personal info
Drupalgeddon 2.0 Still Haunting 115K+ Sites
Loose .zips sink chips: How poisoned archives can hack your computer
Google Patches 11 Critical Android Bugs in June Update
Facebook partnered with 60+ device makers & shared users’ private data
Continental: We, er, tire of Whatsapp, Snapchat on work phones. GDPR, innit?
UK’s first transatlantic F-35 delivery flight delayed by weather
Ex-CEO on TalkTalk mega breach: It woz ‘old shed’ legacy tech wot done it
The cyberattack on banks in Mexico: The challenges posed to cybersecurity

Following the massive cyberattack on banks in Mexico, we consider what can cybersecurity can do to help the industry The post The cyberattack on banks in Mexico: The challenges posed to cybersecurity appeared first on WeLiveSecurity

Social Media Privacy Dominates Apple iOS 12, macOS Launches
Misconfigured Google Groups Settings Leaking Sensitive Data

LinuxSecurity.com: **Version 3.4.11** (2018-05-25) * bug #27364 [DI] Fix bad exception on uninitialized references to non-shared services (nicolas-grekas) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas- grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user

Just a third of Brit cops are equipped to fight crime that is ‘cyber’
Bizarre Chrome and Firefox flaw exposed Facebook details
Facebook defends practice of giving deep data access to device makers
Learn what the ‘zero trust’ security model really means | Salted Hash Ep 29
Google says fix for ‘weird’ 1975 text message bug is on the way
End-to-end encryption doesn’t stop the FBI reading your messages. Just ask Paul Manafort
Microsoft to buy GitHub for $7.5 billion

security update

security update

LinuxSecurity.com: Several security issues were fixed in Liblouis.

Malicious Chrome & Edge extension drops backdoor and spy on users

Reading Time: ~4 min.Nearly 50% of Americans don’t use antivirus software That’s right; something as basic as installing internet security software (which we all know we’re supposed to use) is completely ignored by about half the US. You’d be amazed how common this and other risky online behaviors are. We did a survey of people’s […]

Router reboot: How to, why to, and what not to do

The FBI say yes but should you follow this advice? And if you do follow it, do you know how to do so safely? The post Router reboot: How to, why to, and what not to do appeared first on WeLiveSecurity

LinuxSecurity.com: CVE-2016-9396

Personal data of over 50,000 Honda Connect App leaked

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Apple lifts two-month ban on Telegram updates in iOS store
Cloudflare mistakes own 1.1.1.1 DNS for DDoS attack

LinuxSecurity.com: An update for rh-java-common-xmlrpc is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Facebook faces furious shareholders at annual meeting
‘Tesco probably knows more about me than GCHQ’: Infosec boffins on surveillance capitalism
Going to Infosec Europe? Grab yourself a goody bag
False contest to win jersey of the Brazilian team found on WhatsApp

The scam circulated through WhatsApp aimed at users in Brazil claiming that Nike will give away the jersey that the team will wear at Russia 2018. The post False contest to win jersey of the Brazilian team found on WhatsApp appeared first on WeLiveSecurity

‘Moore’s Revenge’ is upon us and will make the world weird
G Suite admins need to RTFM – thousands expose internal emails

security update

security update

LinuxSecurity.com: It was discovered that Wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for PCP, ADB, NBAP, UMTS MAC, IEEE 802.11, SIGCOMP, LDSS, GSM A DTAP and Q.931, which result in denial of service or the execution of arbitrary code.

LinuxSecurity.com: The redmine security update announced as DSA-4191-1 caused regressions with multi-value fields while doing queries on project issues due to an bug in the patch to address CVE-2017-15569. Updated packages are now available to correct this issue.

Steam fixes 10-year-old critical remote code execution vulnerability

LinuxSecurity.com: CVE-2016-9396

LinuxSecurity.com: Security fix for CVE-2016-5003, CVE-2016-5002

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1780

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1779

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1777

Ticketfly, Major Concert Venues Still Offline After Hack

LinuxSecurity.com: Man Yue Mo, Lars Krapf and Pierre Ernst discovered that Batik, a toolkit for processing SVG images, did not properly validate its input. This would allow an attacker to cause a denial-of-service, mount cross-site scripting attacks, or access restricted files on the

A Spectre flaw solution, Cloudflare blips, a bank cyber-heist in Canada, and more in infosec land

LinuxSecurity.com: It was discovered that Zookeeper, a service for maintaining configuration information, enforced no authentication/authorisation when a server attempts to join a Zookeeper quorum.

LinuxSecurity.com: New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

Researchers Warn of Microsoft Zero-Day RCE Bug
Browser Side-Channel Flaw De-Anonymizes Facebook Data
Stingray phone stalker tech used near White House, SS7 abused to steal US citizens’ data – just Friday things
Visa card payment network goes down across Europe
Public Google Groups Leaking Sensitive Data at Thousands of Orgs
Sonic & Ultra signals can be used to crash Windows, Linux & hard drives
An acoustic attack can bluescreen your Windows computer

Security researchers have demonstrated how attackers could cause physical damage to hard drives, and cause PCs to crash, just by playing sounds through a computer’s speaker. The post An acoustic attack can bluescreen your Windows computer appeared first on WeLiveSecurity

Trends 2018: Critical infrastructure attacks on the rise

Healthcare sectors, critical manufacturing, food production and transportation also said to be targets for cybercriminals The post Trends 2018: Critical infrastructure attacks on the rise appeared first on WeLiveSecurity

OMG, that’s downright Wicked: Botnet authors twist corpse of Mirai into new threats
Brit bank TSB facepalms at critical mass as users report receiving letters meant for other people
Ticketfly website hacked & offline after hacker leaks customer data
Honda, Universal Music Group Expose Sensitive Data in Misconfig Blunders

LinuxSecurity.com: xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003) SL7 noarch xmlrpc-client-3.1.3-9.el7_5.noarch.rpm xmlrpc-common-3.1.3-9.el7_5.noarch.rpm xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm xmlrpc-server-3.1.3-9.el7_5.noarch.rpm – Scientific Linux Development Team

Your F-35s need spare bits? Computer says we’ll have you sorted in… a couple of years

LinuxSecurity.com: Upstream security fixes related to .gitmodules handling. From the [upstream announcement](https://public-inbox.org/git/xmqqy3g2flb6.fsf@gitster- ct.c.googlers.com/): “` * Submodule “names” come from the untrusted .gitmodules file, but we blindly append them to $GIT_DIR/modules to create our on-disk repo paths. This means you can do bad things by putting “../” into the

Artist rigs up Google Assistant to (sometimes) fire a gun on command

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service. CVE-2018-1093

LinuxSecurity.com: Upstream security fixes related to .gitmodules handling. From the [upstream announcement](https://public-inbox.org/git/xmqqy3g2flb6.fsf@gitster- ct.c.googlers.com/): “` * Submodule “names” come from the untrusted .gitmodules file, but we blindly append them to $GIT_DIR/modules to create our on-disk repo paths. This means you can do bad things by putting “../” into the

Doctor sues patient for $1m over bad online reviews
World Cup scams: how to avoid an own goal

Whether travelling to enjoy the matches in person, or watching from home, fans should be on the lookout for foul play The post World Cup scams: how to avoid an own goal appeared first on WeLiveSecurity

SpamCannibal comes back to life, starts spam-blocking everyone
Europol sets up EU-wide team to fight dark web crime

Embedded within the agency’s European Cybercrime Centre (EC3), the new team will also work together with law enforcement globally in an effort to reduce the size of the underground illegal economy The post Europol sets up EU-wide team to fight dark web crime appeared first on WeLiveSecurity

More curious, less cautious: Protecting kids online

How we can help protect a generation for which digital is the way of the world? The post More curious, less cautious: Protecting kids online appeared first on WeLiveSecurity

An advert against online privacy