Menu

Monthly Archives: August 2018

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Wickr gets slicker with fresh network tricker: Privacy-protecting domain fronting alternative emerges
Nork hackers Lazarus brought back to life by AppleJeus to infect Macs for the first time
Cheddar’s Restaurants Bitten By Credit-Card Breach
ThreatList: $1.1M is Lost to Cybercrime Every Minute of Every Day

security update

AdvisorsBot Downloader Emerges in Raft of Malware Campaigns
Winner, Winner, prison dinner: Five years in the clink for NSA leaker
Intel rips up microcode security fix license that banned benchmarking

LinuxSecurity.com: An update for openstack-keystone is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Pango could be made to crash if it opened a specially crafted file.

LinuxSecurity.com: Several security issues were fixed in Spidermonkey.

LinuxSecurity.com: An update that solves two vulnerabilities and has 21 fixes is now available.

Apache Struts 2 Flaw Uncovered: ‘More Critical Than Equifax Bug’
Recent App Issues Reveal Facebook’s Struggles to Temper Data Privacy Woes
Facebook pulls its VPN from the iOS App Store after data-harvesting accusations
Vulnerability in OpenSSH “for two decades” (no, the sky isn’t falling!)
Facebook pulls ‘snoopy’ Onavo VPN from Apple’s App Store after falling foul of rules
Security and Artificial Intelligence: Hype vs. Reality
Google warns businesses of government-backed phishing attacks
Augusta University Health data breach: Private data of over 417,000 individuals exposed
DNC: Highly Publicized ‘Phishing Attempt’ Was Only a Security Test
Patch time! Adobe issues unexpected ‘critical’ fix for Photoshop CC
US Democrats call in Feds: There’s something phishy going on with our voter database
Superdrug targeted by miscreants who claim to have stolen customer data

The retailer says that whatever data the crooks have obtained, they weren’t stolen through a breach of its systems The post Superdrug targeted by miscreants who claim to have stolen customer data appeared first on WeLiveSecurity

Hacker holds the data of 20,000 Superdrug customers to ransom
Hackers Use Public Cloud Features to Breach, Persist In Business Networks
Facebook’s rating you on how trustworthy you are
Babysitting app suffers ‘temporary data breach’ of 93,000 users
Smashing Security #092: Hacky sack hack hack
Detecting bot attacks | Salted Hash Ep 44
Using smart meter data constitutes a search, but court allows them anyway
Unencrypted laptop exposes personal details of 37,000 Eir customers, faulty security update blamed
Deepfakes porn service: Don’t worry, we’ll only use “consenting adults”
If it doesn’t need to be connected, don’t: Nurse prescribes meds for sickly hospital infosec
Whoa, is it Patch Tuesday already? No, just an unexpected critical Photoshop fix
When something’s weird in your ImageMagick upload, who ya gonna call? Ghostbusters!
How an uploaded image could take over your website, and how to stop it

Risk Level: Very Low.

Everyone screams patch ASAP – but it takes most organizations a month to update their networks
Apache’s latest SNAFU – Struts normal, all fscked up: Web app framework needs urgent patching
DNC Becomes Latest Target in Series of Election-Season Attacks

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

One-in-two JavaScript project audits by NPM tools sniff out at least one vulnerability…
Unpatched Ghostscript Flaws Allow Remote Takeover of Systems

LinuxSecurity.com: The security update announced as DSA 4279-1 caused regressions on the ARM architectures (boot failures on some systems). Updated packages are now available to correct this issue.

LinuxSecurity.com: An update for openstack-keystone is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: mutt: Remote code injection vulnerability to an IMAP mailbox (CVE-2018-14354) * mutt: Remote Code Execution via backquote characters (CVE-2018-14357) * mutt: POP body caching path traversal vulnerability (CVE-2018-14362) SL6 x86_64 mutt-1.5.20-9.20091214hg736b6a.el6.x86_64.rpm mutt-debuginfo-1.5.20-9.20091214hg736b6a.el6.x86_64.rpm i386 mutt-1.5.20-9.20091214hg736b6a.el6.i68 [More…]

LinuxSecurity.com: base-files could be made to hang or overwrite files as the administrator.

Researchers Blame ‘Monolithic’ Linux Code Base for Critical Vulnerabilities
Cisco smells a RAT in Breaking Security’s Remcos PC wrangler
Triout Malware Carries Out Extensive, Targeted Android Surveillance
Misconfigured backup leads to exposure of 50.5 million GOMO Mobile customers
Podcast: Bad Packets Report Founder on Rising Cryptojacking Attacks
New Red Hat Product Security OpenPGP key
Turla: In and out of its unique Outlook backdoor

The latest ESET research offers a rare glimpse into the mechanics of a particularly stealthy and resilient backdoor that the Turla cyberespionage group can fully control via PDF files attached to emails The post Turla: In and out of its unique Outlook backdoor appeared first on WeLiveSecurity

Scot.gov wins pals with pledge not to keep hold of innocents’ mugshots and biometric data
Adobe Patches Critical Photoshop Flaws in Unscheduled Update
Netflix, HBO GO, Hulu passwords found for sale on the Dark Web
Extortionist lawyer pleads guilty to creating porn honeypot
Get serious about consumer data protection
Ohio Man Sentenced to 15 Years for BEC Scam
Augusta Health Center Reveals Historic Breach
Elders of internet hash out standards to grant encrypted message security for world+dog
Microsoft disrupts Fancy Bear election meddlers
ETSI crypto-based access control standards land

LinuxSecurity.com: Dariusz Tytko, Michal Sajdak and Qualys Security discovered that OpenSSH, an implementation of the SSH protocol suite, was prone to a user enumeration vulnerability. This would allow a remote attacker to check whether a specific user account existed on the target server.

Ryuk Ransomware Emerges in Highly Targeted, Highly Lucrative Campaign
Super-mugs: Hackers claim to have snatched 20k customer records from Brit biz Superdrug
Security MadLibs: Your IoT electrical outlet can now pwn your smart TV
Dark Tequila: A Distilled Threat for Mexican Targets

LinuxSecurity.com: New libX11 packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Airmail 3 Exploit Instantly Steals Info from Apple Users
Use Debian? Want Intel’s latest CPU patch? Small print sparks big problem

Type: Vulnerability. Microsoft Internet Explorer is prone to an unspecified arbitrary code-execution vulnerability; fixes are available.

Serious Security: How to stop dodgy HTTP headers clogging your website

LinuxSecurity.com: An update for mutt is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: wpa_supplicant and hostapd could be made to expose sensitiveinformation if it received a crafted message.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Belkin IoT Smart Plug Flaw Allows Remote Code Execution in Smart Homes
Republican & Conservative leaders are the new targets of Russian hackers —Microsoft
Microsoft: We busted Russian Fancy Bear disinfo websites
IoT botnet of heaters & ovens can cause massive widespread power outages
Fake Android Fortnite version circulating on the web to spread malware
Video: Bishop Fox on Device Threats and Layered Security
Google Faces Legal Turmoil After Location Tracking Debacle
MadIoT: How an IoT botnet could launch a major attack on the power grid
Twitch admits exposing user messages after archiving error
Social networks to be fined for hosting terrorist content
Smart irrigation systems vulnerable to attacks, warn researchers

Internet-connected irrigation systems suffer from security gaps that could be exploited by attackers aiming, for example, to deplete a city’s water reserves, researchers warn The post Smart irrigation systems vulnerable to attacks, warn researchers appeared first on WeLiveSecurity

The security changes you can expect in iOS 12
Corporate pre-crime: The ethics of using AI to identify future insider threats
UK hacking prosecutions plummet with only 47 charges recorded last year
TLS developers should ditch ‘pseudo constant time’ crypto processing