Menu

Monthly Archives: July 2018

Reading Time: ~3 min.While one-click shopping on Amazon (or Webroot.com, for that matter) seems super easy when you’re the consumer, there are a lot of complex strategies and processes going on behind the scenes. We chat with Cathy Ondrak, product owner for Webroot.com, to get a glimpse behind the curtain. In her role, Cathy works […]

Twitter shutters accounts linked to US election hacking

LinuxSecurity.com: The package thunderbird before version 52.9.1-1 is vulnerable to multiple issues including arbitrary code execution, cross-site request forgery and information disclosure.

‘007’ code helps stop Spectre exploits before they exist
21-year-old woman charged with hacking Selena Gomez
Revealed in detail: World powers stuff spyware kit, how-to guides in dodgy nations’ pockets

LinuxSecurity.com: A timing attack was discovered in the function for CSRF token validation of the “Ruby rack protection” framework. For the stable distribution (stretch), this problem has been fixed in

Irish fella accused of being Silk Road admin ‘Libertas’ hauled to US
No Evidence of GandCrab Leveraging SMB Exploit – Yet

security update

security update

Sad Nav: How a cheap GPS spoofer gizmo can tell drivers to get lost

LinuxSecurity.com: The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo

LinuxSecurity.com: – Security fix for CVE-2017-9258, CVE-2017-9259, CVE-2017-9260

Newsmaker Interview: Bruce Schneier on ‘Going Dark’ and the Crypto Arms Race
Kremlin hacking crew went on a ‘Roman Holiday’ – researchers
New sextortion scheme uses victims’ real password for blackmailing
DanaBot Trojan Targets Bank Customers In Phishing Scam
IoT search engine exposes passwords of over 30,000 vulnerable DVRs
Road navigation systems can be spoofed using $223 equipment
Who is the weakest link in software security?
A highly targeted malware campaign is spying on 13 iPhones in India
Facebook refuses to remove fake news, but will demote it
Twitter pops a lot of famous people’s follower bubbles
Free eBook: If your friend was put in charge of a cyber budget, what advice would you give them?
Irishman extradited to the US to face charges relating to Silk Road

Gary Davis accused of working as an administrator for the notorious dark web marketplace appears in a federal court in New York The post Irishman extradited to the US to face charges relating to Silk Road appeared first on WeLiveSecurity

Major International Airport System Access Sold for $10 on Dark Web
Western E-Tailers Set to Lose Nearly $19bn to Fraud
GandCrab Ransomware Continues to Evolve But Can’t Spread Via SMB Shares Yet
USB Restricted Mode in iOS 11.4.1 now available to all iPhone users
Ex-Apple engineer charged with stealing self-driving car secrets
GitHub to Pythonistas: Let us save you from vulnerable code

LinuxSecurity.com: CVE-2015-1854 A flaw was found while doing authorization of modrdn operations. An unauthenticated attacker able to issue an ldapmodrdn call to

LinuxSecurity.com: It was discovered that there were two issues in znc, a modular IRC bouncer: * There was insufficient validation of lines coming from the network

Australia’s Airport Security Threatened by Hack
FBI: Email Account Compromise Losses Reach $12B
Russian intelligence officers indicted in DNC hacking

LinuxSecurity.com: Security fix for CVE-2018-8009 —- Version update to 2.7.6. Fixes many open CVEs and bugs.

LinuxSecurity.com: Update to 4.9.7 security release. https://wordpress.org/news/2018/07/wordpress-4-9-7-security-and-maintenance- release/

LinuxSecurity.com: Update to Sprockets 3.7.2. Fixes CVE-2018-3760: https://access.redhat.com/security/cve/cve-2018-3760

security update

LinuxSecurity.com: Several vulnerabilities were discovered in CUPS, the Common UNIX Printing System. These issues have been identified with the following CVE ids: CVE-2018-4180

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.

Timehop Reveals More Personal Data Was Breached
WordPress Sites Targeted in World Cup-Themed Spam Scam
Hope for Hutchins, Navy sinks contractor, there’s another Russian hacking scandal, and more

LinuxSecurity.com: Multiple vulnerabilities were found in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes 15 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Thought two-factor auth completely locks down Office 365? Not quite
US drug cops snared crooks with pre-cracked BlackBerry mobes – and that’s just the start
Scam alert: No, hackers don’t have webcam vids of you enjoying p0rno. Don’t give them any $$s

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.

You are not alone; Instagram is down for many

Reading Time: ~2 min.Ticketmaster Snafu Only Tip of the Iceberg After last month’s Ticketmaster breach, a follow-up investigation found it to be part of a larger payment card compromising campaign affecting more than 800 online retail sites worldwide. The cause of the breach appears to stem from the third-party breaches of several Ticketmaster suppliers, which […]

Indictment bombshell: ‘Kremlin intel agents’ hacked, leaked Hillary’s emails same day Trump asked Russia for help
Justice Department Indicts 12 Russian Nationals Tied to 2016 Election Hacking

LinuxSecurity.com: gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification (CVE-2018-12020) SL6 x86_64 gnupg2-2.0.14-9.el6_10.x86_64.rpm gnupg2-debuginfo-2.0.14-9.el6_10.x86_64.rpm gnupg2-smime-2.0.14-9.el6_10.x86_64.rpm i386 gnupg2-2.0.14-9.el6_10.i686.rpm gnupg2-debuginfo-2.0.14-9.el6_10.i686.rpm gnupg2-smim [More…]

LinuxSecurity.com: Red Hat JBoss Core Services Pack Apache Server 2.4.29 packages are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Red Hat JBoss Core Services Pack Apache Server 2.4.29 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Red Hat JBoss Core Services Pack Apache Server 2.4.29 packages are now available. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

Indian iPhone Spy Campaign Used Fake MDM Platform

Risk Level: Very Low. Type: Trojan.

ThreatList: Bug Bounty Payouts Increase Six Percent for Critical Vulnerabilities
Sextortionists Shift Scare Tactics to Include Legit Passwords
It pays to know your enemies: Sophos webinar gives you the cybercrime lowdown
Unsanctioned Apps Invite Fox into Cybersecurity Hen House
Spectre bug protection forcing Chrome to use 10 to 13% more RAM
Bogus Mobile Device Management system used to hack iPhones in India
Sextortion scam knows your password, but don’t fall for it
Ukraine claims it blocked VPNFilter attack at chemical plant
Facebook ordered to let grieving mother in to dead daughter’s account
Linux, malware and data breaches – what can we learn? [VIDEO]

LinuxSecurity.com: It was discovered that there was a symlink attack in the Cinnamon desktop environment. An attacker could overwrite an arbitrary file on the filesystem via

Risk Level: Very Low. Type: Trojan.

Google’s ghost busters: We can scare off Spectre haunting Chrome tabs

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2112

Now Pushing Malware: NPM package dev logins slurped by hacked tool popular with coders
Hacker Compromises Air Force Captain to Steal Sensitive Drone Info
“Bitcoins for cash in bags” trader gets 12 months in prison
Dark web marketplace found selling access to airport’s security system
Cisco Patches High-Severity Bug in VoIP Phones
ThreatList: 6-Year-Old Dorkbot Banking Malware Resurfaces as Big Threat
Chrome Now Features Site Isolation to Defend Against Spectre
Timehop data breach is worse than they initially said
Average cost of a data breach exceeds $3.8 million, claims report
Ransomware is so 2017, it’s all cryptomining now among the script kiddies

LinuxSecurity.com: Update to upstream version 9.4.11. Fixes CVE-2017-7656, CVE-2017-7657, CVE-2017-7658, CVE-2018-12538.

Palo Alto Networks rattles tin, wants $1.5bn for, er, stuff and things
Insights Security Hardening Rules

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Facebook fined over data privacy scandal

Social media giant fined in the UK for failing to protect users’ personal information and for a lack of transparency The post Facebook fined over data privacy scandal appeared first on WeLiveSecurity

Not All Hacks Are Created Equal
This Is How Much a ‘Mega Breach’ Really Costs
Hacker Exploits 2-Year Old Router Issue To Steal Sensitive US Military Data