Menu

Monthly Archives: July 2018

LinuxSecurity.com: Busybox, utility programs for small and embedded systems, was affected by several security vulnerabilities. The Common Vulnerabilities and Exposures project identifies the following issues.

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2018-4117

Boffins: Mixed-signal silicon can SCREAM your secrets to all

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

How to (slowly) steal secrets over the network from chip security holes: NetSpectre summoned
Identity theft protection firm LifeLock may have exposed user email addresses

LinuxSecurity.com: CVE-2018-11319 The improper handling of search for configuration files might be exploited for arbitrary code execution via a malicious gcc plugin.

Highly Sophisticated Parasite RAT Emerges on the Dark Web
Oh no, what a rough blow: Cosco at a lossco over ransomware tossco
Bugs in Samsung IoT Hub Leave Smart Home Open To Attack

LinuxSecurity.com: An update for ceph is now available for Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2241

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2252

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2242

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2240

COSCO’s American Operations Hit With Crippling Ransomware Attack
Sen. Wyden Urges Government Ban on Adobe Flash
Chrome now flags HTTP sites as “not secure”

This is bad news for many websites that have yet to embrace encrypted connections The post Chrome now flags HTTP sites as “not secure” appeared first on WeLiveSecurity

LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

Fake banking apps on Google Play leak stolen credit card data

Fraudsters are using bogus apps to convince users of three Indian banks to divulge their personal data The post Fake banking apps on Google Play leak stolen credit card data appeared first on WeLiveSecurity

Senator calls on US Government to start killing Flash now
Malware targeting cash machines fetches top dollar on dark web

LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

HTTP versus HTTPS – what’s all the fuss? [VIDEO]
8 types of malware and how to recognize them
DHS Officials: Hundreds of US Utility Victims Infiltrated by Russian Hackers
Regional Virginia Bank Falls Victim to Coordinated $2.4M ATM Heist
More browser extensions and apps caught spying on users
Man accused of tricking men into involuntary porn
Twitter boots 143K bad apps, throttles developer access to API
Would a bill banning bots do more harm than good?
Bigamists have no right to privacy on Facebook

LinuxSecurity.com: The package jenkins before version 2.133-1 is vulnerable to multiple issues including access restriction bypass, arbitrary filesystem access, cross-site scripting and information disclosure.

I saw what you did…or did I?

It might seem legit but there are several reasons why you should not always hit the panic button when someone claims to have your email password The post I saw what you did…or did I? appeared first on WeLiveSecurity

Popular Android/iOS Apps & Extensions Collecting “Highly Personal” User data
Sen. Ron Wyden: Adobe Flash is doomed, why is Uncle Sam still using it?

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Smashing Security #088: PayPal’s Venmo app even makes your drug purchases public
Skills That a ‘Next-Level’ Pentester Should Have

security update

security update

LinuxSecurity.com: This update includes the latest upstream release, **httpd 2.4.34**, with multiple bug fixes and enhancements. See http://www.apache.org/dist/httpd/CHANGES_2.4.34 for more information on the changes in this version. A security vulnerability is addressed in this update: * `mod_md`: DoS via Coredumps on specially crafted requests (CVE-2018-8011)

New variant of Kronos banking trojan spotted using Tor network
Pinterest Browser Extension Injects Unwanted Code into 5K Websites
US Homeland Security warns of latest hacker craze – ERP pwnage
Hey you smart, well-paid devs. Stop clicking on those phishing links and bringing in malware muck on your shoes
Facebook Security Exec Calls for Tightened Data Privacy

LinuxSecurity.com: New version of dcraw is available 9.28.0 Security fix for CVE-2018-5801

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2251

Risk Level: Very Low. Type: Trojan, Worm.

Intel Smart Sound Tech Vulnerable to Three High-Severity Bugs
Podcast: The Industrial World is Facing a Security Crisis
Mind your company’s old Twitter accounts, rather than allowing them to be hijacked by hackers
Security Technologies: ExecShield
2FA? We’ve heard of it: White hats weirded out by lack of account security in enterprise
How one hacker could have changed automotive history
Hook, line, and sinker: How to avoid looking ‘phish-y’

Top tips to help you avoid being caught receiving or sending phishing-looking emails The post Hook, line, and sinker: How to avoid looking ‘phish-y’ appeared first on WeLiveSecurity

Reading Time: ~4 min.According to the Identity Theft Research Center, 2017 saw 1,579 data breaches—a record high, and an almost 45 percent increase from the previous year. Like many IT service providers, you’re probably getting desensitized to statistics like this. But you still have to face facts: organizations will experience a security incident sooner or […]

Hidden camera Uber driver fired after live streaming passenger journeys
Crimson Hexagon banned by Facebook over user data concern
Endpoint Concerns Blight IIoT Security
Two-Thirds of Organizations Hit in Supply-Chain Attacks
London Calling with New Strategies to Stop Ransomware
Scammers pwn verified Fox Twitter account to scam cryptocurrency
Criminal mastermind injects malicious script into Ethereum tracker. Their message? ‘1337’
Russian hackers are ready to disrupt US energy utilities, says DHS
Here’s why Twitter will lock your account if you change your display name to Elon Musk
Safeguard your code: 17 tips to develop more-secure code
The risks associated with global Internationalized Domain Names | Salted Hash Ep 36
Intel Xeon workhorses boot evil maids out of the hotel: USB-based spying thwarted by fix
Want a $200k TIP? ZDI sticks bounties on bugs in big-name server code

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: A vulnerability has been discovered in Sympa, a modern mailing list manager, that allows write access to files on the server filesystem. This flaw allows to create or modify any file writable by the Sympa user, located on the server filesystem, using the function of Sympa

Update your devices: New Bluetooth flaw lets attackers monitor traffic

LinuxSecurity.com: The libarchive-zip-perl package is vulnerable to a directory traversal attack in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use

LinuxSecurity.com: CVE-2018-12584 A flaw in function ConnectionBase::preparseNewBytes of resip/stack/ConnectionBase.cxx has been detected, that

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Kronos Banking Trojan Resurfaces After Years of Silence
Google Starts Labeling All HTTP Sites as ‘Not Secure’

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

security update

LinuxSecurity.com: Danny Grander reported that the unzip and untar tasks in ant, a Java based build tool like make, allow the extraction of files outside a target directory. An attacker can take advantage of this flaw by submitting a specially crafted Zip or Tar archive to an ant build to

Emotet Malware Evolves Beyond Banking to Threat Delivery Service
Apache, IBM Patch Critical Cloud Vulnerability

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Bluetooth Bug Allows Man-in-the-Middle Attacks on Phones, Laptops

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Worm.