Menu

Monthly Archives: August 2018

Crashing Mobile Apps Capture Screens, Leak Private Data
Brazilian Crypto exchange hacked; private data of over 264,000 users exposed

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Facebook Flaw Allowed Remote Commands

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Multiple researchers have discovered a vulnerability in the way the Intel processor designs have implemented speculative execution of instructions in combination with handling of page-faults. This flaw could allow an attacker controlling an unprivileged process to read

LinuxSecurity.com: bind: processing of certain records when “deny-answer-aliases” is in use may trigger an assert leading to a denial of service (CVE-2018-5740) SL6 x86_64 bind-debuginfo-9.8.2-0.68.rc1.el6_10.1.i686.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.1.x86_64.rpm bind-libs-9.8.2-0.68.rc1.el6_10.1.i686.rpm bind-libs-9.8.2-0.68.rc1.el6_10.1.x86_64.rpm bind-utils-9.8.2-0.68.rc1.el6_10.1 [More…]

LinuxSecurity.com: bind: processing of certain records when “deny-answer-aliases” is in use may trigger an assert leading to a denial of service (CVE-2018-5740) SL7 x86_64 bind-debuginfo-9.9.4-61.el7_5.1.i686.rpm bind-debuginfo-9.9.4-61.el7_5.1.x86_64.rpm bind-libs-9.9.4-61.el7_5.1.i686.rpm bind-libs-9.9.4-61.el7_5.1.x86_64.rpm bind-libs-lite-9.9.4-61.el7_5.1.i686.rpm bind-libs-lite-9. [More…]

LinuxSecurity.com: Several security issues were fixed in GD.

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low. Type: Trojan.

OCR software firm ABBYY leaks 203,000 customer documents in MongoDB server snafu
6 Tips to Protect Your Online Business from Cyber Attacks
Microsoft Windows Zero-Day Found in Task Scheduler
No, eight characters, some capital letters and numbers is not a good password policy
Footie fans calling for a red card over West Ham United CC email blunder
PoC targeting critical Apache Struts bug found online

The discovery was made barely two days after the release of a patch that fixes the critical flaw in the web application framework The post PoC targeting critical Apache Struts bug found online appeared first on WeLiveSecurity

LinuxSecurity.com: This is the Six-Month notification for the retirement of Red Hat Enterprise Linux 6.4 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.4.

ThreatList: Ransomware Attacks Down, Fileless Malware Up in 2018
Give yourselves a pat on the back, top million websites, half of you now use HTTPS
Adobe Pushes Out Unscheduled Creative Cloud Application Fix
Lukáš Štefanko: I hope other app developers don’t follow Epic‘s example

After Epic Games shunned Google Play, debates about threats faced by Android users have taken on a whole new tenor. Joining us to add his voice to the mix is ESET Malware Researcher Lukáš Štefanko The post Lukáš Štefanko: I hope other app developers don’t follow Epic‘s example appeared first on WeLiveSecurity

Black hats are baddie hackers, white hats are goodies, grey hats will sell IP to kids in hoodies
EU may fine political groups misusing personal data to skew elections
How hackers managed to steal $13.5 million in Cosmos bank heist
NSA leaker Reality Winner gets 63 months in jail
None too chuffed with your A levels? Hey, why not bludgeon the exam boards with GDPR?
Facebook helps woman track down her brother’s killer after 37 years
Event management kit can take a hammering these days: Use it well and it’ll save your ass
Woman sues US border patrol over data copied from seized iPhone
Tuesday review – the hot 23 stories of the week
Boffins bork motion control gear with the power of applied sound
Windows 0-day pops up out of nowhere Twitter

LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 10 fixes is now available.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Lawyers sued for impersonating rival firm online to steal clients
Side-Channel Attack Allows Remote Listener to ‘Hear’ On-Screen Images

LinuxSecurity.com: Several vulnerabilities were discovered in Ruby 2.1. CVE-2016-2337

AT Command Hitch Leaves Android Phones Open to Attack

LinuxSecurity.com: The Bootstrap framework was found to have cross-site scripting vulnerabilities in the “collapse” plugin. For Debian 8 “Jessie”, this problem has been fixed in version

Ah, um, let’s see. Yup… Fortnite CEO is still mad at Google for revealing security hole early

LinuxSecurity.com: The system could be made to expose sensitive information.

Newsmaker Interview: Derek Manky on ‘Self-Organizing Botnet Swarms’
Fortnite Android App Falls Victim to Man-in-the-Disk Flaw
Google finds flaw in Android Fortnite’ Installer leading to malware installation
You are not alone; The Pirate Bay is down for everyone
T-Mobile data breach: Personal data of 2 million users stolen
Fortnite fury over how Google handled its huge security hole
Why now could be a good time to fortify your Android defenses

Stop us if you’ve heard this before: avoid installing apps from outside Google Play. But what if you’re itching to battle it out in Fortnite? The post Why now could be a good time to fortify your Android defenses appeared first on WeLiveSecurity

US Election Hack Whistleblower Gets Five Years
Cheddar’s Scratch Kitchen Chain Suffers Data Breach
Voting machine maker vows to step up security, Fortnite bribes players to do 2FA – and more

LinuxSecurity.com: An update for rh-postgresql96-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 31 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

99% of Texas Voter Records Exposed
It’s The Season For A Lot Of Interesting Linux / Open-Source Conferences
T-Mobile, AT&T customer account PINs were exposed by website flaws

LinuxSecurity.com: CVE-2018-15501 A potential out-of-bounds read when processing a “ng” smart packet might lead to a Denial of Service.

You can now run Windows 95 on your Mac, Linux and Windows 10 devices
The GDPR Ripple Effect
T-Mobile Hacked – 2 Million Customers’ Personal Data Stolen

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

PoC Code Surfaces to Exploit Apache Struts 2 Vulnerability
Now that’s a fortune cookie! Facebook splats $5k command-injection bug in one of its servers
Following Facebook and Twitter, Google Targets Iranian Influence Operation
Mirai Variant Cross-Compiles Attack Code with Aboriginal Linux
Well, can’t get hacked if your PC doesn’t work… McAfee yanks BSoDing Endpoint Security patch

LinuxSecurity.com: Spice could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: postgresql: Certain host connection parameters defeat client-side security defenses (CVE-2018-10915) SL7 x86_64 postgresql-debuginfo-9.2.24-1.el7_5.i686.rpm postgresql-debuginfo-9.2.24-1.el7_5.x86_64.rpm postgresql-libs-9.2.24-1.el7_5.i686.rpm postgresql-libs-9.2.24-1.el7_5.x86_64.rpm postgresql-9.2.24-1.el7_5.i686.rpm postgresql-9.2.24-1.el7_5.x86_64.rpm postgre [More…]

LinuxSecurity.com: An update for postgresql is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

T-Mobile Alerts 2.3 Million Customers of Data Breach Tied to Leaky API
T-Mobile suffers data breach affecting 2.2 million customers
Uni credential-swiping hack campaign linked to Iranian government
Cross-Site Scripting Flaw in Apache ActiveMQ Threatens Web Visitors
Top dark web drug vendors nabbed by ‘Operation Darkness Falls’

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Facebook pulls its privacy-violating Onavo VPN from Apple’s App Store
Medical records of high school students leaked in ‘appalling’ data breach
DNC ‘spearphishing attack’ was actually a test
Breach exposed details of 2 million T-Mobile US customers – report
Hackers have stolen details of two million T-Mobile customers
Chap asks Facebook for data on his web activity, Facebook says no, now watchdog’s on the case

Reading Time: ~2 min.Dark Tequila Targets Mexican Financial Organizations Over the past 5 years, one malware campaign has been plaguing the financial industries of Mexico: Dark Tequila. While many researchers have been monitoring samples for most of that time, only recently has the entire campaign come into focus, with over 30,000 unique targets in 2018 […]

Back to school soon – for script kiddies as well as normal kids. Hackers peddle cybercrime e-classes via Telegram

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.