Menu

Monthly Archives: July 2018

security update

Microsoft Fixes 17 Critical Bugs in July Patch Tuesday Release
AT&T abducts AlienVault to bolster business end of its security probing

Risk Level: Very Low.

Another Spectre CPU vulnerability among Intel’s dirty dozen of security bug alerts today
Adobe Issues Over 100 Patches for Flash, Acrobat and Reader
Insurers hurl sueball at Trustwave over 2008 Heartland megabreach
New iOS security feature can be defeated by a $39 adapter… sold by Apple
Think that bitcoins and a VPN keep you anonymous? Think again…

LinuxSecurity.com: libjpeg-turbo could be made to crash or run programs as your login if it opened a specially crafted file.

Researchers Reveal Workaround for Apple’s USB Restricted Mode
It’s mid-year report time, let’s see how secure corporate networks are. Spoiler alert: Not at all

Reading Time: ~3 min.With cybercrime damages set to cost the world $6 trillion annually by 2021, a new bar has been set for cybersecurity teams across industries to defend their assets. This rings especially true for IT service providers, who are entrusted to keep their clients’ systems and IT environments safe from cybercriminals. These clients […]

Red Hat’s disclosure process

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Ammyy Admin compromised with malware again; World Cup used as cover

Website altered to serve a malware-tainted version of otherwise legitimate software with the global event in Russia acting as a smokescreen The post Ammyy Admin compromised with malware again; World Cup used as cover appeared first on WeLiveSecurity

Why the airplane romance that went viral should worry everyone
Woman scams scammer, incriminates self in the process
Gas thieves remotely pwn pump with mysterious device

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

The Worst Cybersecurity Breaches of 2018 So Far
Timehop Breach Hits 21 Million Customers
Thai Cave rescue scammers pose as Elon Musk
Privates on parade: fitness tracker app reveals sensitive user details

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Evil third-party screens on smartphones are able to see all that you poke

LinuxSecurity.com: An update for rh-git29-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Brown pants moment for BlueJeans: Dozens of AV tools scream its vid chat code is malware
Malware-slinging scum copied D-Link’s code-signing certificates to dress up PC nasties
Timehop database hacked: Hackers steal data of 21 million users

Type: Vulnerability. Microsoft .NET Framework is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Macro Assembler is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Visual Studio is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Web Customization for ADFS is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft WordPad is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Wireless Display Adapter is prone to a command-injection vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft MSR JavaScript Cryptography Library is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local denial-of-service vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Polar fitness app exposed location data of users in military & airbases

LinuxSecurity.com: Orange Tsai discovered a path traversal flaw in ruby-sprockets, a Rack-based asset packaging system. A remote attacker can take advantage of this flaw to read arbitrary files outside an application’s root directory via specially crafted requests, when the Sprockets server is

Apple OS Update Lifts Curtain on iPhone USB Restricted Mode
How to Solve the Developer vs. Cybersecurity Team Battle
Polar Fitness App Exposes Location of ‘Spies’ and Military Personnel

Risk Level: Very Low. Type: Trojan.

Microsoft might not support Windows XP any more, but GandCrab v4.1 ransomware does
ThreatList: Virtualization-related Bug Reports Jump 275 Percent in 2018
Cops suspect Detroit fuel station was hacked before 10 drivers made off with 3k ‘free’ litres
Poor security at Thomas Cook airlines leads to simple extraction of fliers’ personal data
Your social media memories may have been compromised
Timehop Breach Impacts Personal Data of 21 Million Users
What sensitive data is lurking on your old SD card?
Newsmaker Interview: Patrick Wardle Talks Apple Malware Flubs and Successes
Copyright Directive legislation voted down by European Parliament
Smart TVs are spying on you through your phone
Leatherbound analogue password manager: For the hipster who doesn’t mind losing everything
State of the SOC? Depends on Who You Ask
New Malware Variant Hits With Ransomware or Cryptomining
Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign

D-Link and Changing Information Technologies code-signing certificates stolen and abused by highly skilled cyberespionage group focused on East Asia, particularly Taiwan The post Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign appeared first on WeLiveSecurity

‘Domain Factory’ confirms January 2018 data breach
Nostalgic social network ‘Timehop’ loses data from 21 million users
Fitness app Polar even better at revealing secrets than Strava

LinuxSecurity.com: Fix CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI

Looking for another great cyber podcast? CyberTangent is your new home with expert guests every episode

LinuxSecurity.com: Several security vulnerabilities were found in Bouncy Castle, a Java implementation of cryptographic algorithms. CVE-2016-1000338

Crooks hack gas station fuel pump to steal 600 gallons of gas

LinuxSecurity.com: New upstream version

LinuxSecurity.com: ## 3.3.17 (2018-05-25) * security #cve-2018-11407 [Ldap] cast to string when checking empty passwords * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user is logged out * security #cve-2018-11385 migrating session for UsernamePasswordJsonAuthenticationListener * security #cve-2018-11386

LinuxSecurity.com: Latest upstream release, omits some mounting code found to be insecure and not well tested.

LinuxSecurity.com: Latest upstream release, omits some mounting code found to be insecure and not well tested.

Snooping passwords from literally hot keys, China’s AK-47 laser, malware, and more
Digital India Susceptible to Security Breaches
UK Banks Must Produce Backup Plans for Cyberattacks

LinuxSecurity.com: There have been a number of updates to the set of Certificate Authority (CA) certificates that are considered “valid” or otherwise should be trusted.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

security update

security update

Old Malware Gives Criminals Tricky New Choice: Ransomware or Mining