Menu

Monthly Archives: July 2018

Stealthy Malware Hidden in Images Takes to GoogleUserContent
IoT Robot Vacuum Vulnerabilities Let Hackers Spy on Victims
Declassified files reveal how pre-WW2 Brits smashed Russian crypto

LinuxSecurity.com: Update to 0.26.5 (CVE-2018-10887, CVE-2018-10888)

LinuxSecurity.com: This release fixes a directory and symbolic link traversal vulnerability in Archive::Zip::Archive Perl module that allows an attacker to writite into an arbitrary file accesible by a local user.

LinuxSecurity.com: – Fix Side Channel Based ECDSA Key Extraction (CVE-2018-12437) (PR #408) – Fix potential stack overflow when DER flexi-decoding (CVE-2018-0739) (PR #373) – Fix two-key 3DES (PR #390) – Fix accelerated CTR mode (PR #359) – Fix Fortuna PRNG (PR #363) – Fix compilation on platforms where cc doesn’t point to gcc (PR #382) […]

LinuxSecurity.com: Fix heap memory corruption, CVE-2017-17833

LinuxSecurity.com: Linux 4.9 has been packaged for Debian 8 as linux-4.9. This provides a supported upgrade path for systems that currently use kernel packages from the “jessie-backports” suite.

LinuxSecurity.com: Linux 4.9 has been packaged for Debian 8 as linux-4.9. This provides a supported upgrade path for systems that currently use kernel packages from the “jessie-backports” suite.

GangWang GPS Navigation Attack Leads Unsuspecting Drivers Astray
How Cyber Insurance Changes the Conversation Around Risk
Brit tech forges alliance to improve cyber security as MPs moan over ‘acute scarcity’ of experts
Hackers automate the laundering of money via Clash of Clans
Adobe on internal systems security hole: Panic not. It isn’t critical
Ubisoft Games Hit by Massive DDoS Attacks
America’s largest diagnostics service LabCorp suffers massive data breach

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Google slapped with €4.34bn fine by EU over antitrust violations

Tech giant has 90 days to comply with ruling or faces further penalties over ‘anti-competitive’ practices The post Google slapped with €4.34bn fine by EU over antitrust violations appeared first on WeLiveSecurity

LinuxSecurity.com: An update for fluentd is now available for Red Hat OpenStack Platform 13.0 Operational Tools for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Critical Authentication Flaws in Cisco Policy Suite Patched
Venmo users: time to hide your drug deals and excessive pizza consumption

LinuxSecurity.com: This is the Six-Month notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.

Cloud Security: Lessons Learned from Intrusion Prevention Systems
US Vote-Counting Computers Had Flaw, Allowed Hackers Access
US Orgs Overly Optimistic About Cyber-Readiness
Google hit with $5.1b fine in EU’s Android antitrust case
Privacy Advocates Say Kelsey Smith Act Gives Police Too Much Power

LinuxSecurity.com: unzip and untar target tasks in ant allows the extraction of files outside the target directory. A crafted zip or tar file submitted to an Ant build could create or overwrite arbitrary files with the

Microsoft offers up to $100,000 to identity bug finders
Automated money-laundering scheme found in free-to-play games
British Airways cancelled flights at Heathrow after ‘IT system issue’

Thousands of British Airways passengers left stranded at Heathrow airport following incident The post British Airways cancelled flights at Heathrow after ‘IT system issue’ appeared first on WeLiveSecurity

Smashing Security #087: How Russia hacked the US election
Airbus UK infosec gros fromage: Yep, we work with arch-rivals Boeing

LinuxSecurity.com: Jeriko One discovered two vulnerabilities in the ZNC IRC bouncer which could result in privilege escalation or denial of service. For the stable distribution (stretch), these problems have been fixed in

LinuxSecurity.com: A use-after-free was discovered in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played.

Bloke accused of netting $5m on inside info about Lattice Semiconductor

LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: CVE-2018-11439 Fix for a heap-based buffer over-read via a crafted audio file.

security update

security update

Who’s leaving Amazon S3 buckets open online now? Cybercroooks, US election autodialers
Will this biz be poutine up the cash? Hackers demand dosh to not leak stolen patient records
ThreatList: Popular Apps Get Enterprise Blacklisted
Thousands of U.S. Voter Personal Records Leaked by Robocall Firm

LinuxSecurity.com: New release (1:12.2.6-1) Security fix for CVE-2018-1128 Security fix for CVE-2018-1129 Security fix for CVE-2018-10861

Mingis on Tech: The blockchain evolution, from services…to smartphones

LinuxSecurity.com: The package curl before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package libcurl-gnutls before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package libcurl-compat before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-libcurl-compat before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-curl before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: Several security issues were fixed in PolicyKit.

LabCorp Investigates a Potential Breach that Could Affect Millions
Woman charged for hacking & leaking private pictures of Selena Gomez
So long and thanks for all the fixes: ERPScan left out of credits on Oracle bug-bash list
Oracle Sets All-Time Record with July Critical Patch Update
Microsoft Bounty Program Offers Payouts for Identity Service Bugs
Smaller Nation State Attacks: A Growing Cyber Menace
Brit watchdog fines child sex abuse inquiry £200k over mass email blunder
Could semantic icons replace passwords and PINs?
SPECTRE Variant 1 scanning tool
21-year-old spy tool developer faces prison
£200,000 fine for exposing possible child abuse victims in classic Cc/Bcc email blunder
Elon Musk retracts vile Twitter accusation against cave rescuer
Call records breach let users feel like Movistars (with everyone watching who they’re talking to)
Time to Yank Cybercrime into the Light
Russian National Vulnerability Database Operation Raises Suspicions
“Astoundingly stupid” Kodak (not really) Bitcoin miner bites the dust
Business email compromise scams have netted $12.5 billion, says FBI

LinuxSecurity.com: A vulnerability was discovered in WordPress, a web blogging tool. It allowed remote attackers with specific roles to execute arbitrary code.

PayPal’s pal Venmo spaffs your pals’ payments – and yours
Microsoft to pay new bounties for identity services holes

LinuxSecurity.com: A vulnerability in tqdm could allow remote attackers to execute arbitrary code.

security update

Blood test biz LabCorp pulls plug on systems over hacker fears

LinuxSecurity.com: Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in various parsers of Blender, a 3D modeller/ renderer. Malformed .blend model files and malformed multimedia files (AVI, BMP, HDR, CIN, IRIS, PNG, TIFF) may result in the execution of arbitrary code.

Scumbag confesses in court: LuminosityLink creepware was my baby

LinuxSecurity.com: New mutt packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

800K Patient Records At Issue in ProCare Health Snafu
Peer-to-Peer Crypto-Exchanges: A Haven for Money Laundering

security update

US voting systems (in Oregon) potentially could be hacked (11 years ago) by anybody (in tech support)
Recent Andariel Group ActiveX Attacks Point to Future Targets
Millions of Telefonica customers’ data exposed after security breach

LinuxSecurity.com: gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification (CVE-2018-12020) SL7 x86_64 gnupg2-2.0.22-5.el7_5.x86_64.rpm gnupg2-debuginfo-2.0.22-5.el7_5.x86_64.rpm gnupg2-smime-2.0.22-5.el7_5.x86_64.rpm gnupg2-2.0.22-5.el7_5.src.rpm – Scientific Linux Development Team

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Look, what’s that over there? Sophos nips Windows DNS DLL false positive in the bud
Luminosity RAT author pleads guilty to creating & selling hacking tool
Russia’s national vulnerability database is a bit like the Soviet Union – sparse and slow
DDoS Attacks Get Bigger, Smarter and More Diverse
How to spoof someone’s GPS navigation to send them the wrong way
How to Teach Your Employees About Cybersecurity
Yar, thar she blows: Corp-cash-stealing email whaling attacks now a $12.5bn industry
A deep dive down the Vermin RAThole

ESET researchers have analyzed remote access tools cybercriminals have been using in an ongoing espionage campaign to systematically spy on Ukrainian government institutions and exfiltrate data from their systems The post A deep dive down the Vermin RAThole appeared first on WeLiveSecurity

Trump wants to work with Russia on infosec. Security experts: lol no
“Red Alert” Warning on US Cyber-Attacks, Now at “Critical Point”
Russia Fends Off 25 Million Cyber-Attacks During World Cup
Guy jailed for refusing to unlock phones