Menu

Monthly Archives: August 2018

Boffins trying to build a open source secure enclave on RISC-V

LinuxSecurity.com: Updated squirrelmail packages fix XSS-security vulnerability: It was discovered that some special tags have not been filtered accordingly which can be used for an XSS-attack.

LinuxSecurity.com: Updated libxcursor packages fix security vulnerability _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow. (CVE-2015-9262)

LinuxSecurity.com: OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c (CVE-2018-15473).

LinuxSecurity.com: This update provides the virtualbox 5.1.18 maintenance release that fixes atleast the following security issues: Fixed an easily exploitable vulnerability that allowed unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox

LinuxSecurity.com: Updated quazip packages fix security vulnerability: A vulnerability has been found in the way developers have implemented the archive extraction of files. An arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other

LinuxSecurity.com: Updated mariadb packages fix security vulnerabilities: Vulnerability in the MariaDB Server component of MariaDB (subcomponent: MyISAM). Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MariaDB Server.

LinuxSecurity.com: This update provides libraw 0.18.13 fixing atleast the following security issues: LibRaw versions prior to 0.18.12 are vulnerable to an integer overflow in the internal/dcraw_common.cpp:parse_qt() function. An attacker could

LinuxSecurity.com: The updated packages fix security vulnerabilities: An out-of-bounds read flaw exists in parse_file_info in archive_read_support_format_iso9660.c in libarchive 3.3.2 when extracting a specially crafted iso9660 iso file, related to

LinuxSecurity.com: The updated packages fix a security vulnerability: Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial

LinuxSecurity.com: This update provides mercurial version 4.6.2 and fixes the following security issues: Fix the mpatch_apply function in mpatch.c that incorrectly proceeds in cases where the fragment start is past the end of the original data

Apple Watch saves one more life by notifying user about his unusual heart rate
DraftKings rides to court, asks to unmask 10 DDoS suspects
VirusTotal Intelligence, a search engine for malware | Salted Hash Ep 45

Reading Time: ~2 min.Texas Voters’ Data Leaked A security researcher just discovered a publicly-available file containing sensitive voting informationfor nearly 99% of all registered voters in the state of Texas. The file was compiled by a data firm that was trying to gauge political opinion for the 2016 elections, as well as more localized campaigns. […]

LinuxSecurity.com: It was discovered that there were a number of Cross Site Scripting (XSS) vulnerabilities in the squirrelmail webmail client. For Debian 8 “Jessie”, these issues has been fixed in squirrelmail

John McAfee backed Bitfi wallet pwned again
MagentoCore Card Skimmer Found on Mass Numbers of E-Commerce Sites
Threatpost News Wrap Podcast For Aug. 31
C’mon, if you say your device is ‘unhackable’, you’re just asking for it: Bitfi retracts edgy claim
Bucking the Norm, Mozilla to Block Tracking Cookies in Firefox
DDoS attack from Anonymous Catalonia cripples Bank of Spain website
Air Canada admits app data breach included customers’ passport details
Spies still butthurt they can’t get at encrypted comms data
Fourth ‘Fappening’ celeb nude snap thief treated to 8 months in the clink

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

Proposed US law would require President to act against overseas hackers
Passport Numbers Exposed in Air Canada Data Breach
‘Celebgate’ Hacker Heading to Prison
What is WannaCry ransomware, how does it infect, and who was responsible?
ThreatList: Security Pros Confident They Could Compromise Their Own Orgs
How to retrofit the cloud for security: 2 essential steps
Jennifer Lawrence nude photo thief is going to the slammer
Cobalt cybercrooks phry up phishing campaign to phling at phinance orgs
Forcing iPhone unlock violates Fifth Amendment, says Court of Appeals
Security bods: Android system broadcasts enable user tracking

LinuxSecurity.com: CVE-2018-5740 The “deny-answer-aliases” feature in BIND has a flaw which can cause named to exit with an assertion failure.

LinuxSecurity.com: CVE-2018-10871 By default nsslapd-unhashed-pw-switch was set to ‘on’. So a copy of

New Threat Actor ‘Rocke’: A Rising Monero Cryptomining Menace
Cryptojacking isn’t a path to riches – payout is a lousy $5.80 a day

Type: Vulnerability. The Microsoft Windows LSASS service is prone to a remotely exploitable buffer overrun vulnerability; may allow arbitrary code execution.

LinuxSecurity.com: Several security issues were fixed in libx11.

LinuxSecurity.com: Several security issues were fixed in libx11.

LinuxSecurity.com: An update for OpenDaylight is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for ansible is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: poppler could be made to crash if it received specially crafted PDF file.

Android OS API-Breaking Flaw Offers Useful WiFi Data to Bad Actors
Cobalt Group Targets Banks in Eastern Europe with Double-Threat Tactic
How one man could have pwned all your PHP programs
Hackers latch onto new Apache Struts megavuln to mine cryptocurrency
Won’t patch systems? Never run malware scans? Welcome to the US State Department!
Critical Flaws in Syringe Pump, Device Gateways Threaten Patient Safety
Air Canada resets 1.7 million accounts after app breach
Why Yahoo scanning user email is no cause for panic
Travel Breaches Hit Air Canada and Asia-Pac Hotelier
Chinese hotel chain’s customer data on Dark Web – 500M records for $50K
Instagram expands 2FA and account verification

The move is part of a three-pronged plan that is intended to bolster user trust and safety on the photo-sharing platform The post Instagram expands 2FA and account verification appeared first on WeLiveSecurity

A DDoS Knocked Spain’s Central Bank Offline
A False Sense of Security
Hacked stalking app reveals victims’ photos, texts and location info
Football team drops the privacy ball with email Cc blunder
Instagram fights misinformation and account hijackings with new tools
Welcome! Mimecast finds interesting door policies on email filters

LinuxSecurity.com: Several issues were discovered in libx11, the client interface to the X Windows System. The functions XGetFontPath, XListExtensions, and XListFonts are vulnerable to an off-by-one override on malicious server responses. A malicious server could also send a reply in which

Chinese hotel chain warns of massive customer data theft
Smashing Security #093: Abandoned domains and dating app dangers
BusyGasper Malware Packs a Simple but Potent Punch
Company that Sells Spyware to Domestic Abusers Hacked
Yahoo Persists in Scanning Emails for In-Depth Ad-Targeting
Error Canada: Airline tells customers to reset mobile app after attack

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2570

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2557

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2571

High-Severity Flaws Patched in Schneider Electric Products
The 4 Critical Building Blocks for Digital Threat Hunting
Podcast: Plugging Leaky Data in the Cloud
Hackers faked Cosmos backend to hoodwink bank out of $13.5m
And you you thought you were safe behind your laptop screen…
Hackers Publish PoC of Zero-day Vulnerability in Windows on Twitter
Lazarus Group’s AppleJeus MacOS malware targeting cryptocurrency exchanges
ABBYY woes: Doc-reading software firm leaves thousands of scans blowing in wind
Researchers Shine Light on Smart-Bulb Data Theft
Facebook: It’s too tough to find personal data in our huge warehouse
Semi-annual balance of mobile security

For Android, malware detections were down 27.48% compared to the first half of 2017; for iOS, they decreased 15% compared to the same period last year The post Semi-annual balance of mobile security appeared first on WeLiveSecurity

Tumblr outlaws creepshots and deepfake porn
Google created “unnecessary risk” for Fortnite users, claims Epic boss
ICO Breach Complaints Jump 160% in a Year
The Difference Between Sandboxing, Honeypots & Security Deception
Fiserv Flaw Exposed Customer Data at Hundreds of Banks
Listening Watch sounds out security idea with websites that listen
We’re all sick of Fortnite, but the flaw found in its downloader is the latest way to attack Android
If you have to simulate a phishing attack on your org, at least try to get something useful from it

LinuxSecurity.com: Several issues were discovered in the Tomcat servlet and JSP engine. They could lead to unauthorized access to protected resources, denial-of-service, or information leak.

Intel Management Engine JTAG flaw proof-of-concept published

security update

Instagram finally supports third-party 2FA apps for greater account security

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to mitigate security issues.

Voting machine maker claims vote machine hack-fests a ‘green light’ for foreign hackers