Menu

Monthly Archives: August 2018

Connected car data handover headache: There’s no quick fix… and it’s NOT just Land Rovers
That’s the way the cookies crumble: Consent banners up 16% since GDPR

LinuxSecurity.com: Several security issues were fixed in OpenJDK 10.

LinuxSecurity.com: USN-3742-2 introduced regressions in the Linux Hardware Enablement(HWE) kernel for Ubuntu 12.04 ESM.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2462

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2439

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2526

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2526

LinuxSecurity.com: ClamAV, an anti-virus utility for Unix, has released the version 0.100.1. Installing this new version is required to make use of all current virus signatures and to avoid warnings.

Canadian Telcos Patch an APT-Ready Flaw in Disability Services
Side-Channel PoC Attack Lifts Private RSA Keys from Mobile Phones

security update

LinuxSecurity.com: An attacker could trick APT into installing altered packages.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Hackers can intercept and manipulate DNS queries, researchers warn
Darkhotel Exploits Microsoft Zero-Day VBScript Flaw
GandCrab’s Rotten EGGs Hatch Ransomware in South Korea
Cybercrime isn’t going away, but hacking prosecutions are falling
SuperProf gets schooled after assigning weak passwords to tutors
Security Technologies: Stack Smashing Protection (StackGuard)
Rotten EGGs spread ransomware in South Korea

LinuxSecurity.com: An update for openstack-keystone is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for openvswitch is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

So phar, so FUD: PHP flaw puts WordPress sites at risk of hacks
Discover the State of Authentication and the Evolving Threat Landscape in this White Paper by OneSpan. Get your copy!

LinuxSecurity.com: Multiple researchers have discovered a vulnerability in the way the Intel processor designs have implemented speculative execution of instructions in combination with handling of page-faults. This flaw could allow an attacker controlling an unprivileged process to read

The Rise of Bespoke Ransomware
Australian Teen Hacked Apple Network
Firefox axes add-ons, developer pushes back
Los Angeles to use body scanners on metro riders
A heated summer for cybersecurity in Canada

An overview of some of the cyberattacks that Canadian organizations faced in the summer months of 2018 The post A heated summer for cybersecurity in Canada appeared first on WeLiveSecurity

LinuxSecurity.com: An update for rh-postgresql95-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Google employees protest work on censored search engine for China
Adblocking and browser privacy can be bypassed, researchers find
How’s that encryption coming, buddy? DNS requests routinely spied on, boffins claim
Et tu, Brute? Then fail, Caesars: When it’s hotel staff, not the hackers, invading folks’ privacy

security update

LinuxSecurity.com: CVE-2018-14767 Fix for missing input validation, which could result in denial of service and potentially the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were discovered in Jetty, a Java servlet engine and webserver which could result in HTTP request smuggling. For the stable distribution (stretch), these problems have been fixed in

LinuxSecurity.com: New upstream release fixing YSA-2018-03 (#1613863)

LinuxSecurity.com: New upstream release fixing YSA-2018-03 (#1613863)

LinuxSecurity.com: New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Instagram acknowledges & addresses hacking spree against user accounts
The state of cybersecurity at small organizations
The 5 Challenges of Detecting Fileless Malware Attacks
AI in cybersecurity: what works and what doesn’t
Mastering email security with DMARC, SPF and DKIM
Facebook Messenger backdoor demand, bail in Bitcoin, and lots more
SentinelOne makes YouTube delete Bsides vid ‘cuz it didn’t like the way bugs were reported
‘Oh sh..’ – the moment an infosec bod realized he was tracking a cop car’s movements by its leaky cellular gateway

security update

security update

security update

16-year old compromised Apple networks to steal GBs of sensitive data
Philips Vulnerability Exposes Sensitive Cardiac Patient Information
Unique Malspam Campaign Uses MS Publisher to Drop a RAT on Banks

LinuxSecurity.com: Several vulnerabilities were discovered in Mutt, a text-based mailreader supporting MIME, GPG, PGP and threading, potentially leading to code execution, denial of service or information disclosure when connecting to a malicious mail/NNTP server.

Severe PHP Exploit Threatens WordPress Sites with Remote Code Execution

Risk Level: Very Low. Type: Trojan.

AT&T Faces $224M Legal Challenge Over SIM-Jacking Rings
Web cache poisoning just got real: How to fling evil code at victims
ThreatList: Almost Half of the World’s Top Websites Deemed ‘Risky’
Shiver me timbers: Symantec spots activist investor Starboard side
SuperProf private tutor site massively fails password test, makes accounts super easy to hack
Apple gets cored: 90GB of ‘secure files’ stolen by high schooler
‘Foreshadow’ flaw found in Intel CPUs – what to do

LinuxSecurity.com: An update that solves 12 vulnerabilities and has 60 fixes is now available.

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves 14 vulnerabilities and has 41 fixes is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

Most staffers expect bosses to snoop on them, say unions
US rolls back cyberwarfare rules
Australian schoolboy hacks into Apple’s network, steals files

His lawyer claims that the teen did the hacking because he admired Apple and dreamed of landing a job in the company The post Australian schoolboy hacks into Apple’s network, steals files appeared first on WeLiveSecurity

Apple hacked by 16-year-old who “dreamed” of working for firm
Indian Bank Loses $13.5m in Global Attack
UK Identity Fraud Falls but Online Scams Rise
Nigerian National Convicted for Phishing US Universities
ATM Heists Only Set to Accelerate After $13M Break-In
Week in security with Tony Anscombe

The first week in security video round-up from WeLiveSecurity The post Week in security with Tony Anscombe appeared first on WeLiveSecurity

What happens to your online accounts when you die?
Romance scam victim allegedly plotted to kill her mother for cash

LinuxSecurity.com: Fariskhi Vidyan and Thomas Jarosch discovered several vulnerabilities in php-horde-image, the image processing library for the Horde groupware suite. They would allow an attacker to cause a denial-of-service or execute arbitrary code.

Reading Time: ~2 min.Instagram Hack Baffles Users Hundreds of Instagram users have found themselves locked out of their accounts over the past week, with all methods of retrieving them having been removed as well. The episode began with many users noticing their accounts had been logged out and contact information changed, including email addresses with […]

Sextortion and what to do about it [VIDEO]

security update

security update

Risk Level: Very Low. Type: Trojan.

Who was it that hacked Apple? Ozzie Ozzie Ozzie, boy boy boy!

LinuxSecurity.com: mysql: Client programs unspecified vulnerability (CPU Jul 2017) (CVE-2017-3636) * mysql: Server: DML unspecified vulnerability (CPU Jul 2017) (CVE-2017-3641) * mysql: Client mysqldump unspecified vulnerability (CPU Jul 2017) (CVE-2017-3651) * mysql: Server: Replication unspecified vulnerability (CPU Oct 2017) (CVE-2017-10268) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 20 [More…]