Menu

Monthly Archives: August 2018

LinuxSecurity.com: QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams (CVE-2018-11806) * QEMU: i386: multiboot OOB access while loading kernel image (CVE-2018-7550) Bug Fix(es): * Previously, live migrating a Windows guest in some cases caused the guest to become unresponsive. This update ensures that Real-time Clock (RTC) interrupts are not missed, which prevents the problem […]

Highly Flexible Marap Malware Enters the Financial Scene
Juno this ain’t right! Chinese hackers target Alaska

Type: Vulnerability. Adobe Flash Player is prone to multiple information-disclosure vulnerabilities; fixes are available.

New Trickbot Variant Touts Stealthy Code-Injection Trick
‘China’s MIT’ Linked to Espionage Campaign Against Alaska, Economic Partners
Google Expands Bug-Bounty Program to Battle Abuse Methods
Open MQTT Servers Raise Physical Threats in Smart Homes
Hackers steal $13.5 million from Indian bank in global attack
Some 2.6 billion data records exposed in first half of 2018

The newly-released report provides an overview of the data breach landscape in the first half of this year The post Some 2.6 billion data records exposed in first half of 2018 appeared first on WeLiveSecurity

ThreatList: Telecom Sector Plagued with Advanced Malware
Ex-NSA hacker proves how easily macOS user warnings can be bypassed by malware

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Google Chrome Bug Opens Access to Private Facebook Information
Australians who won’t unlock their phones could face 10 years in jail
Hackers Target Instagram, Users Blame Russia
Washington Man Sentenced in Ransomware Conspiracy
Election Websites, Backend Systems Most at Risk of Cyberattack in Midterms
Sacramento admits to tracking welfare recipients’ license plates
Silk Road founder Ross Ulbricht is dictating tweets from prison
Smashing Security #091: Sextortion, Las Vegas hotels, and Alex Jones
Bogus journals being used to publish fake science

LinuxSecurity.com: fix for CVE-2018-14526

Risk Level: Very Low. Type: Trojan.

Mozilla-endorsed security plug-in accused of tracking users
Making money mining Coinhive? Yeah, you and nine other people
Microsoft Cortana Flaw Allows Web Browsing on Locked PCs
BlackIoT Botnet: Can Water Heaters, Washers Bring Down the Power Grid?

security update

New Intel chip flaw “Foreshadow” attacks SGX technology to extract sensitive data
India’s Cosmos bank raided for $13m by hackers
Support for ageing key exchange crypto leaves VPNs open to attack

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft PowerPoint is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. The Microsoft .NET Framework is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft COM for Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft SQL Server is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Bitcoin backer sues AT&T for $240m over stolen cryptocurrency
Google is tracking your location, even when the setting is turned off
The sextortionists are back, this time with your phone number as “proof”
Office 365 Phishing Campaign Hides Malicious URLs in SharePoint Files
Defcon: 11-year-old modifies Florida Presidential voting results
ThreatList: Financial-Themed Phishing Hooks Targets in Q2
Sex extortion emails now quoting part of their victim’s phone number
Instagram users locked out of accounts en masse

If you’re an Instagrammer, you may want to take some basic precautions, such as picking a strong and unique password and signing up for two-factor authentication sooner rather than later The post Instagram users locked out of accounts en masse appeared first on WeLiveSecurity

Are your Android apps listening to you?
Your smart air conditioner could contribute to mass power outages
Baddies of the internet: It’s all about dodgy mobile apps, they’re so hot right now
NHS Patient Data at Risk from Historic Breach: Report
FBI warns of choreographed ATM drainage
Podcast: Bugcrowd Founder on Printer Bugs, IoT Bounty Hunting, and New VDP Project
Foreshadow and Intel SGX software attestation: ‘The whole trust model collapses’
Criminals a bit less interested in nicking Brits’ identities this year
Florida Man laundered money for Reveton ransomware. Then Microsoft hired him
Patch Tuesday heats up with pair of exploited zero-days squashed – plus 58 other vulns fixed
IDG Contributor Network: How hybrid IT impacts identity management
Patch Tuesday: Microsoft Addresses Two Zero-Days in 60-Flaw Roundup
Bad news conspiracy theorists. QAnon codes are just a guy mashing his keyboard
Victims Lose Access to Thousands of Photos as Instagram Hack Spreads