Menu

Monthly Archives: July 2018

Smashing Security #086: Elon Musk submarine scams and 2FA bypass
What can $10 stretch to these days? Lunch… or access to international airport security systems
Trends 2018: Doing time for cybercrime

Law enforcement and malware research join forces to take down cybercriminals The post Trends 2018: Doing time for cybercrime appeared first on WeLiveSecurity

Who’s Reading Your Gmail Messages?
Stolen Taiwanese Certs Used in Malware Campaign
Asian Countries Frequent Targets of APT Attacks
Cost of UK Data Breaches Rises to ?2.7m
Your Google phone will soon screen nuisance calls
Facebook doesn’t want to eradicate fake news. If it did they’d kick out InfoWars
Hackers break into newswire services, trade on what they find
Default router password leads to spilled military secrets

LinuxSecurity.com: It was discovered that there was a discovered a path traversal flaw in ruby-sprockets, a Rack-based asset packaging system. A remote attacker could take advantage of this flaw to read arbitrary files outside an application’s root directory via “file://” requests.

Snakes on a plane! (Stuffed inside a hard drive)

LinuxSecurity.com: New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Ticketmaster breach ‘part of massive card-skimming campaign’
Tim? Larry? We need to talk about smartphones and privacy
Timehop admits to more data leakage, details GDPR danger
FBI for the Apple guy: Bloke accused of stealing car kit collared

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2113

Like my new wheels? All I did was squash a bug, and they gave me $72k

LinuxSecurity.com: An update for gnupg2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for gnupg2 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Ticketmaster Breach: Just One Part of a Wide-Ranging Campaign

Type: Vulnerability. Microsoft Access is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Skype for Business and Lync are prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Skype for Business and Lync are prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows PowerShell is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a remote code-execution vulnerability; fixes are available.

Multiple Bugs Found in QNAP Q’Center Web Console
Deceased Patient Data Being Sold on Dark Web
Thomas Cook website spills personal info – and it’s fine with that
Newsmaker Interview: Scott Helme on Securing the Web

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Updated kernel-rt packages that fix two security issues and add one enhancement are now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Xapian-core could be made to execute arbitrary code if it received a specially crafted file.

Fresh Spectre Variants Come to Light
Hola VPN’s Chrome extension hacked to target MyEtherWallet users
Hacker selling classified information on MQ-9 Reaper Drone on dark web
US military manuals hawked on dark web after files left rattling in insecure FTP server
Another Linux distro poisoned with malware
Facebook fined a paltry £500,000 (8 minutes’ revenue) over Cambridge Analytica scandal
Update Flash (and Adobe Acrobat) now!
Creating a Defensible Security Architecture
Ticketmaster breach was part of a larger credit card skimming effort, analysis shows
Apple and Google questioned by Congress over user tracking
Infosec bootcamp, tools, exploit code, forensics and more: Get trained at SANS London Sept 2018
Infosec defenders’ supply chain is inferior to black hats, says Carbon Black CEO

LinuxSecurity.com: Updates for rh-dotnet20-dotnet, rh-dotnet21-dotnet, rh-dotnetcore10-dotnetcore, and rh-dotnetcore11-dotnetcore are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact

A curious tale of the priest, the broker, the hacked newswires, and $100m of insider trades
Arch Linux PDF reader package poisoned
China-based hackers take an interest in Cambodia’s elections
Facebook stares down barrel of $660,000 fine over data slurping
Intel, Microsoft, Adobe release a swarm of bug fixes to ruin your week

security update

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix bugs and security issues.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of Load & Store instructions (a commonly used performance optimization). It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory read from address to which a recent […]

LinuxSecurity.com: An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of Load & Store instructions (a commonly used performance optimization). It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory read from address to which a recent […]

The Pirate Bay: We mine Monero from your CPU, install Adblocker or leave