Menu

Monthly Archives: July 2018

Oracle Re-Patches Decade-Old Solaris Bug
Dust yourself off and try again: Ancient Solaris patch missed the mark
IBM fixes flaw that let hackers replace its serverless code with their own
Bluetooth bug could expose devices to snoopers

Patches have already been released or are expected to see the light of day soon The post Bluetooth bug could expose devices to snoopers appeared first on WeLiveSecurity

The Bluetooth “device snooping bug” – what you need to know
Insecure web still too prevalent: Boffins unveil HSTS wall of shame
Names and photos of Venmo ‘drug buyers’ published on Twitter
Supplier Error Leaks Decade of Data from Carmakers
Campaign’s Election Data Exposed in Virginia
UK university domains spoofed in massive fraud campaign targeting suppliers
Google hasn’t suffered an employee phishing compromise in over a year
Privacy Questions Raised as Tech Giants Join Forces on Data Portability

LinuxSecurity.com: An update for rhev-hypervisor7 is now available for RHEV 3.X Hypervisor and Agents for Red Hat Enterprise Linux 6 and RHEV 3.X Hypervisor and Agents Extended Lifecycle Support for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

Why your website is officially ‘not secure’ from today
Mega medical tester pester: It smacked a big one, that malware scam, if indeed it was SamSam

LinuxSecurity.com: An update for rh-ror42-rubygem-sprockets is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ror50-rubygem-sprockets is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

No big deal… Kremlin hackers ‘jumped air-gapped networks’ to pwn US power utilities
Big bad Bluetooth blunder bug battered – check for security fixes
Robo-drop: Factory bot biz ‘leaks’ automakers’ secrets onto the web
If at first you, er, make things worse, you’re probably Microsoft: Bug patch needed patching

LinuxSecurity.com: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) (CVE-2018-2952) SL6 x86_64 java-1.8.0-openjdk-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8.0-openjdk-debug-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8 [More…]

LinuxSecurity.com: Update to 1.2.6 to fix a local authenticated privilege escalation bug (CVE-2018-10900). The issue has been discovered and responsibly disclosed by Denis Andzakovic: https://pulsesecurity.co.nz/advisories/NM-VPNC-Privesc

Spectre rises from the dead to bite Intel in the return stack buffer
IT biz embezzlement brouhaha leaves bloke with $456k migraine
Google Chrome users met with ‘Not secure’ warnings when visiting HTTP sites
Uber driver recorded passengers & live-streamed videos on Twitch
New Spectre-Level Flaw Targets Return Stack Buffer
Spectre Will Haunt Us For a Long Time

LinuxSecurity.com: A regression that caused boot failures was fixed in the Linux kernel.

LinuxSecurity.com: A regression that caused boot failures was fixed in the Linux kernel.

Leaky Backup Spills 157 GB of Automaker Secrets
Who watches Sony’s watcher? Boffins poke holes in surveillance kit
Facebook Suspends Analytics Firm Over Surveillance Concerns
ThreatList: Supply-Chain Defenses Need Improvement
Robotics supplier’s sloppy security leaks ten years’ worth of data from major car manufacturers
Major sites still largely lax on prompting users towards safer password choices, study finds

A study assessed whether or not the most popular English-language websites help users strengthen their security by providing them with guidance on creating safer passwords during account sign-up or password-change processes The post Major sites still largely lax on prompting users towards safer password choices, study finds appeared first on WeLiveSecurity

Google Chrome: HTTPS or bust. Insecure HTTP D-Day is tomorrow, folks
WhatsApp limits message forwarding in response to lynchings
Facebook, Google, Microsoft and Twitter make leaving easier
Has GDPR Impacted Insider Threats?
UK Gov Launches Consultation to Speed-Up Cybersecurity Strategy
Attention Airline Passengers, Your Data Is at Risk
DOJ to publicly disclose election tampering schemes
Don’t ignore application security | Salted Hash Ep 35

LinuxSecurity.com: Multiple vulnerabilities have been found in Passenger, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: CVE-2018-7033 Fix for issue in accounting_storage/mysql plugin by always escaping strings within the slurmdbd.

Data breach: Millions of SingHealth users affected including Singapore’s PM

LinuxSecurity.com: Early versions of opencv have problems while reading data, which might result in either buffer overflows, out-of bounds errors or integer

Exposed: 157 GB of sensitive data from Tesla, GM, Toyota & others
US Intel Officials Share Their National Cybersecurity Concerns
Key takeaways from Singapore healthcare data breach

LinuxSecurity.com: The package networkmanager-vpnc before version 1.2.6-1 is vulnerable to privilege escalation.

LinuxSecurity.com: The package apache before version 2.4.34-1 is vulnerable to denial of service.

LinuxSecurity.com: The package znc before version 1.7.1-1 is vulnerable to multiple issues including privilege escalation and directory traversal.

DNS rebinding attack puts half a billion IoT devices at risk
The Fundamental Flaw in Security Awareness Programs
IoT hacker builds Huawei-based botnet, enslaves 18,000 devices in one day
LabCorp ransomed, 18k routers rooted, a new EXIF menace, and more

LinuxSecurity.com: Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program.

Microsoft: The Kremlin’s hackers are already sniffing, probing around America’s 2018 elections
Massive Malspam Campaign Finds a New Vector for FlawedAmmyy RAT
D-Link, Dasan Routers Under Attack In Yet Another Assault
Friday FYI: 9 out of 10 of website login attempts? Yeah, that’ll be hackers
Hackers attack Russian bank to steal $1m using an outdated router
Crypto gripes, election security, and mandatory cybersec school: Uncle Sam’s cyber task force emits todo list for govt
Newsmaker Interview: Troy Mursch on Why Cryptojacking Isn’t Going Away

LinuxSecurity.com: Update to 0.26.5 (CVE-2018-10887, CVE-2018-10888)

LinuxSecurity.com: This release fixes a directory and symbolic link traversal vulnerability in Archive::Zip::Archive Perl module that allows an attacker to writite into an arbitrary file accesible by a local user.

LinuxSecurity.com: An update for openstack-tripleo-heat-templates is now available for Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

GoogleUserContent CDN Hosting Images Infected with Malware
Doctor, doctor, I feel like my IoT-enabled vacuum cleaner is spying on me
ThreatList: A Ranking of Airports By Riskiest WiFi Networks
Chinese Hackers Mount Espionage Campaign During Trump-Putin Summit
Cybercrooks slurp nearly $1m from Russian bank after pwning router at regional branch
Top 10 vulnerable airports where your device can be hacked
Canada tackles malicious online advertising

Federal agency issues Notices of Violation to Datablocks and Sunlight Media for allegedly facilitating the installation of malware through online advertising The post Canada tackles malicious online advertising appeared first on WeLiveSecurity

UK’s Huawei handler dials back support for Chinese giant’s kit in critical infrastructure

LinuxSecurity.com: The dns-root-data update to 2017072601~deb8u2 broke dnsmasq’s init script, making dnsmasq no longer start when dns-root-data was installed.

Hackers hold 80,000 healthcare records to ransom
Roblox says hacker injected code that led to avatar’s gang rape
Millions of Health Records at Risk Following LabCorp Suspected Breach
Gov Slow to Address Urgent CNI Security Needs
White House Cybersecurity Strategy at a Crossroads
Basic email blunder exposed possible victims of child sexual abuse
Either my name, my password or my soul is invalid – but which?

Reading Time: ~2 min.Venmo’s Public Data Setting Shows All Researchers recently uncovered just how much data is available through the Venmo API, successfully tracking routines, high-volume transactions from vendors, and even monitoring relationships. Because Venmo’s privacy settings are set to public by default, many users have unknowingly contributed to the immense collection of user data […]

LinuxSecurity.com: The linux-base package has been updated to support the package of Linux 4.9 that was recently added to Debian 8. This resolves a dependency that was not satisfiable by the jessie and jessie-security suites.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: CVE-2015-1239 Fix for denial of service (process crash) via a crafted PDF.

ThreatList: Sizing Up The Scourge of Credential-Stuffing

security update

security update