Menu

Monthly Archives: July 2018

Google Patches Critical Remote Code Execution Bugs in Android OS
Keeping False Positives in Check
Japanese Coinhive JS injector slapped with suspended sentence
The Pirate Bay is cryptomining for Monero with your CPU again
Attackers could use heat traces left on keyboard to steal passwords

The attack, called “Thermanator”, could use your body heat against you in order to steal your credentials or any other short string of text that you have typed on a computer keyboard The post Attackers could use heat traces left on keyboard to steal passwords appeared first on WeLiveSecurity

Linux experts are crap at passwords!
Chrome and Firefox pull history-stealing browser extension
Welsh firm fined £60k for pummelling phones with 270k pay-day loan texts
Employee allegedly stole government spyware and hid it under his bed
Disgruntled programmer accused of trying to sell his firm’s iPhone spyware for $50 million

LinuxSecurity.com: It was discovered that the Soup HTTP library performed insuffient validation of cookie requests which could result in an out-of-bounds memory read.

The Pirate Bay is plundering your CPU for cryptocash, again
Are cybercrooks watching you copy and paste? [VIDEO]
Fortnum & Mason: 23,000 Affected by Data Hack
Machine Learning, Cloud, Compliance and Business Awareness Drive Cybersecurity

LinuxSecurity.com: Several vulnerabilities were found in phpMyAdmin, the web-based MySQL administration interface, including SQL injection attacks, denial of service, arbitrary code execution, cross-site scripting, server-side request forgery, authentication bypass, and file system traversal.

SIM card in bird’s GPS tracker used to rack up $2,700 phone bill
Newsmaker Interview: VDOO CEO Talks Top IoT Threats

Reading Time: ~2 min.Canadian college breach targets thousands Last Friday, Algonquin College officials announced that an earlier data breachpotentially affected thousands of current and former students, as well as employees. While it is still unclear exactly what systems were affected, the officials have been working to contact all potential victims and inform them of the […]

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

NSO Group bloke charged with $50m theft of government malware

LinuxSecurity.com: It was discovered that the Soup HTTP library performed insuffient validation of cookie requests which could result in an out-of-bounds memory read.

LinuxSecurity.com: The system could be made to expose sensitive information.

Don’t fear 1337 exploits. Sloppy mobile, phishing defenses a much bigger corp IT security threat

LinuxSecurity.com: Some security vulnerabilities were found in Mercurial which allow authenticated users to trigger arbitrary code execution and unauthorized data access in certain server configuration. Malformed patches and repositories can also lead to crashes and arbitrary code

Google admits third-party app developers read your Gmail emails
Windows 10’s defences are pretty robust these days, so of course folk are trying to break them

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

Year-Old Critical Vulnerabilities Patched in ISP Broadband Gear

LinuxSecurity.com: Archive Zip module could be made to expose sensitive information if it received a specially crafted input.

LinuxSecurity.com: Archive Zip module could be made to expose sensitive information if it received a specially crafted input.

ThreatList: Biggest Cybercrime Developments in 2018, So Far

Risk Level: Very Low. Type: Trojan.

Android Apps Are Sharing Screenshots, Video Recordings to Third Parties, Report Finds
Ex-employee stole secrets of Israeli spyware firm for dark web deals
Your smartphone can watch you if it wants to, study finds
Cyberboffins drill into World Cup cyber honeypot used to lure Israeli soldiers
Serious Security: How to cut-and-paste your way to Bitcoin riches
Five tips for pentesters in iOS

Recommendations for pentesters looking for security flaws in iOS applications made by developers The post Five tips for pentesters in iOS appeared first on WeLiveSecurity

California’s New Privacy Law Gives GDPR-Compliant Orgs Little to Fear
Iranian Attackers Spoof Security Site for Phishing Lure
Tor-linked nonprofit raided by police
7-year-old’s avatar sexually assaulted on “family-friendly” Roblox
UK.gov: New London courthouse will focus on crimes of a cyber nature
Things that make you go hmmm: Do crypto key servers violate GDPR?
Gentoo hack caused by three rookie mistakes
Thunderbird gets its EFAIL patch
Chrome, Firefox pull invasive browser extension
Smashing Security #085: Doctor Who, Facebook patents, and Bob’s Burgers
Top 7 Most Popular and Best Cyber Forensics Tools

security update

security update

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in Exiv2.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Carole Cadwalladr takes us behind the scenes of the Cambridge Analytica investigation
The Pirate Bay is silently mining cryptocurrency without user consent
Welcome to a New Look for Threatpost
Navigating an Uncharted Future, Bug Bounty Hunters Seek Safe Harbors
ThreatList: Exploit Kits Still a Top Web-based Threat
ThreatList: Top Summer DDoS Trends
Newsmaker Interview: Marten Mickos on the Future of Bug Bounty

LinuxSecurity.com: The package git-annex before version 6.20180626-1 is vulnerable to multiple issues including arbitrary filesystem access and information disclosure.

LinuxSecurity.com: The package gitlab before version 11.0.1-1 is vulnerable to multiple issues including cross-site scripting and insufficient validation.

Want to beat facial recognition? Join the Insane Clown Posse
Elderly scam victims are too embarrassed to speak up
Samsung phones sending photos to contacts without permission
Going on vacation? Five things to do before you leave

You’ve set up an out-of-office auto-responder and packed your stuff, but have you done all of your “homework” before you rush out the front door for that well-deserved time off? The post Going on vacation? Five things to do before you leave appeared first on WeLiveSecurity

Facebook accidentally unblocks people
Someone else is reading your Gmails
Bill Clinton’s cyber-attack novel: The airport haxploit-blockbuster you knew it would be
NHS Developer Error Leads to Data Leak
Ransomware: Not dead, just getting a lot sneakier
‘Plane Hacker’ Roberts: I put a network sniffer on my truck to see what it was sharing. Holy crap!
Huawei enterprise comms kit has a TLS crypto bug
Hands up if you didn’t lose data in the Typeform breach

LinuxSecurity.com: Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program. For the stable distribution (stretch), this problem has been fixed in

LinuxSecurity.com: Several vulnerabilites have been discovered in Exiv2, a C++ library and a command line utility to manage image metadata which could result in denial of service or the execution of arbitrary code if a malformed file is parsed.

Samsung Investigates Claims of Spontaneous Texting of Images to Contacts

LinuxSecurity.com: libsoup could be made to crash if it received a specially crafted input.

LinuxSecurity.com: Two vulnerabilities affecting the cups printing server were found which can lead to arbitrary IPP command execution and denial of service.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2001

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1997

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1979

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1965

Four US govt agencies poke probe in Facebook following more ‘oops, we spilled your data’ shocks
More Federal Agencies Wrapped Up in Facebook Data Privacy Probe
Google Chrome update to label HTTP-only sites insecure within WEEKS
Typeform data breach exposes users of many websites
Tool scrubs hidden tracking data from printed documents
Immigrant identity thief and ICE lawyer gets four years
Britain’s tax authority reports takedown of record 20,000 fake sites

Her Majesty’s Revenue & Customs (HMRC) is “consistently the most abused government brand”, according to the National Cyber Security Centre (NCSC) The post Britain’s tax authority reports takedown of record 20,000 fake sites appeared first on WeLiveSecurity

HMRC: 29% Increase in Malicious Site Deactivations
Two-Fifths of UK CEOs See Cyber-Attacks as Inevitable
The difference between red team engagements and vulnerability assessments | Salted Hash Ep 34