Menu

Monthly Archives: July 2018

LinuxSecurity.com: Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may result in incorrect processing of HTTP/FTP, directory traversal, command injection, unintended socket creation or information disclosure.

Facebook Removes 17 Profiles Involved in Political Meddling
ThreatList: Business Email Compromises Way Up for Q2

LinuxSecurity.com: Security fix for CVE-2018-13988.

LinuxSecurity.com: Update zziplib to 0.13.69 version, fixes all known CVEs for the package.

Complex Malvertising Scheme Impacts Multiple Levels of Web Economy
HP Offers Up to $10,000 Rewards for Printer Bugs
Podcast: Why Bitcoin Miners Target Critical Infrastructure Networks
Please forgive me, I can’t stop robbing you: SamSam ransomware earns handlers $5.9m

LinuxSecurity.com: Denis Andzakovic discovered that network-manager-vpnc, a plugin to provide VPNC support for NetworkManager, is prone to a privilege escalation vulnerability. A newline character can be used to inject a

SamSam: The (almost) $6 million ransomware
NSA hasn’t closed security windows Snowden climbed through
Football team in trouble over unauthorized access to rivals’ videos
Leaky radio devices broadcast chipset data, discover researchers
Spectre chip weakness can be used to steal data remotely
OneDrive app for Android updated with fingerprint authentication

With this update, Microsoft is bringing a feature for Android users that has been available on iOS devices for quite a while now The post OneDrive app for Android updated with fingerprint authentication appeared first on WeLiveSecurity

UK CNP Fraud Drops as Banks Fight Back
Idaho Inmates Hack Tablets for Extra Credits
Automating Kernel Exploitation for Better Flaw Remediation
Steam game Abstractism pulled after cryptomining accusations
Cryptojacking for beginners – what you need to know
Dixons Carphone: Yeah, so, about that hack we said hit 1.2m records? Multiply that by 8.3
Dixons Carphone admits hack far bigger than originally thought
Inmates hack tablets for free credits prison

The nature of the vulnerability hasn’t been disclosed, but is said to have already been identified and fixed The post Inmates hack tablets for free credits prison appeared first on WeLiveSecurity

LinuxSecurity.com: New file packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New seamonkey packages are available for Slackware 14.2 and -current to fix security issues.

Australians almost immune from ransomware, topping lists for data safety
Pentagon ‘do not buy’ list says нет to Russia, 不要 to Chinese code
Updated AZORult Spyware Comes with Sophisticated New Techniques

security update

LinuxSecurity.com: Several security issues were fixed in MySQL.

LinuxSecurity.com: yum-utils: reposync: improper path validation may lead to directory traversal (CVE-2018-10897) SL6 noarch yum-plugin-aliases-1.1.30-42.el6_10.noarch.rpm yum-plugin-changelog-1.1.30-42.el6_10.noarch.rpm yum-plugin-ovl-1.1.30-42.el6_10.noarch.rpm yum-plugin-security-1.1.30-42.el6_10.noarch.rpm yum-plugin-tmprepo-1.1.30-42.el6_10.noarch.rpm yum-plugin-verify-1.1.30-42.e [More…]

LinuxSecurity.com: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) (CVE-2018-2952) SL6 x86_64 java-1.7.0-openjdk-1.7.0.191-2.6.15.4.el6_10.x86_64.rpm java-1.7.0-openjdk-debuginfo-1.7.0.191-2.6.15.4.el6_10.x86_64.rpm java-1.7.0-openjdk-devel-1.7.0.191-2.6.15.4.el6_10.x86_64.rpm java-1.7.0-openjdk-demo-1.7.0.191-2.6.15.4.el6_10.x86_64.rpm [More…]

Connected Car Apps Open Privacy Hole For Used Car Owners

LinuxSecurity.com: yum-utils: reposync: improper path validation may lead to directory traversal (CVE-2018-10897) SL7 noarch yum-plugin-aliases-1.1.31-46.el7_5.noarch.rpm yum-plugin-changelog-1.1.31-46.el7_5.noarch.rpm yum-plugin-ovl-1.1.31-46.el7_5.noarch.rpm yum-plugin-tmprepo-1.1.31-46.el7_5.noarch.rpm yum-plugin-verify-1.1.31-46.el7_5.noarch.rpm yum-plugin-versionlock-1.1.31-46.el7 [More…]

LinuxSecurity.com: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) (CVE-2018-2952) SL7 x86_64 java-1.7.0-openjdk-1.7.0.191-2.6.15.4.el7_5.x86_64.rpm java-1.7.0-openjdk-debuginfo-1.7.0.191-2.6.15.4.el7_5.x86_64.rpm java-1.7.0-openjdk-headless-1.7.0.191-2.6.15.4.el7_5.x86_64.rpm java-1.7.0-openjdk-accessibility-1.7.0.191-2.6.15.4.el7_5.x86_64. [More…]

LinuxSecurity.com: CVE-2018-14339 CVE-2018-14340 CVE-2018-14341

Jailhouse Tablets Allow Inmates to Steal Thousands of Dollars in Credits
DMARC Compliance Lacking in 28 Percent of .Gov Agencies
New York Times profiles one of its own security experts
How hack on 10,000 WordPress sites was used to launch an epic malvertising campaign
Prison inmates hacked tablets to earn $225,000 in credits
Parasite HTTP RAT loaded with advanced detection evasion capability
1.4 million online fashion shoppers exposed after data breach at UK ecommerce provider
Prisoners exploit tablet vulnerability to steal nearly $225K
Social media rumors lead to PepsiCo lawsuit
Google bans Android miners from Play Store
Russian Hacking Campaign Targeted US Utilities
‘Fancy Bear’ Targets Democratic Sen. Claire McCaskill
Phishing problems: 3.2M emails blocked in a month | Salted Hash Ep 37

LinuxSecurity.com: The host name verification in Tomcat when using TLS with the WebSocket client was missing. It is now enabled by default. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: Two vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following issues.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.

The Pirate Bay alternatives (2018) in wake of Cryptomining scandal

LinuxSecurity.com: A heap-based buffer overflow in cURL might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ZNC, the worst of which could result in privilege escalation.

LinuxSecurity.com: Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine.

LinuxSecurity.com: Fixes **CVE-2017-11332**, **CVE-2017-11358**, and **CVE-2017-11359**. —- **Prevents division by zero in `src/ao.c`** This bug is hard to reproduce, depending on the HW configuration or installed OS parts. For me, it can be reproduced only in `mock`. In this update, error message should be displayed instead of SIGFPE.

LinuxSecurity.com: Security critical patch update for OpenJDK (July CPU). See http://www.oracle.com/technetwork/security- advisory/cpujul2018-4258247.html#AppendixJAVA

LinuxSecurity.com: upstream security fix release

LinuxSecurity.com: **PHP version 7.2.8** (19 Jul 2018) **Core:** * Fixed bug php#76534 (PHP hangs on ‘illegal string offset on string references with an error handler). (Laruence) * Fixed bug php#76520 (Object creation leaks memory when executed over HTTP). (Nikita) * Fixed bug php#76502 (Chain of mixed exceptions and errors does not serialize properly). (Nikita) **Date:** […]

Flaw in Swann smart security cameras allows access to user’s live stream
364 inmates hacked prison tablets to steal almost $225,000
5 Ways Small Security Teams Can Defend Like Fortune 500 Companies
This new cryptomining malware targets business PCs and servers
FBI boss: We went to the moon, why can’t we have crypto backdoors? – and more this week

LinuxSecurity.com: It was discovered that there was a denial of service vulnerability in policykit-1, a framework for managing administrative policies and privileges.

LinuxSecurity.com: The package libextractor before version 1.7-1 is vulnerable to denial of service.

LinuxSecurity.com: The package wesnoth before version 1.14.4-1 is vulnerable to arbitrary code execution.

security update

ICO hacked: Hackers steal $8 million from KICKICO Blockchain network

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to fix security issues.

FELIXROOT Backdoor Resurfaces in Environmental Spam Campaign

security update

Security Glitch in IoT Camera Enabled Remote Monitoring

LinuxSecurity.com: The fix for arbitrary code execution documented in CVE-2017-17458 was incomplete in the previous upload. A more exhaustive change was implemented upstream and completely disables non-Mercurial subrepositories unless users changed the subrepos.allowed setting.

LinuxSecurity.com: USN-3722-1 introduced a regression in ClamAV.

LinuxSecurity.com: A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: A security update is now available for Red Hat Single Sign-On 7.2 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low. Type: Trojan.

Spectre attack variant can be remotely mounted to extract sensitive data
Font of pwnage: Crims poison well with crypto-jacking code, trickles into PDF editor app
“Simple trick” floors home security camera, gives anyone access
Your essential guide to what sysadmins really mean
Google takes on Yubico with its own security key, Titan
Help us bring a smile to a sysadmin’s dial…
Threatpost News Wrap Podcast For July 27
Google wants you to beef up your account security with its own hardware token

The company credits hardware-based two-factor authentication with practically eliminating the problem of phishing attacks that have targeted its own employees of late The post Google wants you to beef up your account security with its own hardware token appeared first on WeLiveSecurity

Our FREE #SysAdminDay gift means you need NEVER code in Python again!
Nerves jangled by new ransomware attack on shipping giant
Shock Land Rover Discovery: Sellers could meddle with connected cars if not unbound
Virginian Bank Robbed Twice in Eight Months
COSCO Hit by Suspected Ransomware
Wyden urges government agencies to ditch Flash
How to Find Trustworthy Tools and Software for Your Business

LinuxSecurity.com: The security update of mailman announced as DLA-1442-1 introduced a regression due to an incomplete fix for CVE-2018-13796 that broke the admin and listinfo overview pages.

LinuxSecurity.com: Security researchers identified two software analysis methods that, if used for malicious purposes, have the potential to improperly gather sensitive data from multiple types of computing devices with different vendors’ processors and operating systems.

Well, well, well. Crime does pay: Ransomware creeps let off with community service

Reading Time: ~2 min.Paired Bluetooth Devices Vulnerable to Man-in-the-Middle Attacks A new vulnerability has been discovered that would allow an attacker to easily view the traffic sent between two Bluetooth-paired devices. The core of the vulnerability relies on the attacker’s device being within wireless range of both devices in the process of being paired. Signals […]