Menu

Monthly Archives: August 2018

security update

Hackers manage – just – to turn Amazon Echoes into snooping devices
Intel CPUs Undermined By Fresh Speculative Execution Flaws
Oracle: Run, don’t walk, to patch this critical Database takeover bug

LinuxSecurity.com: Several security issues were fixed in libarchive.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan.

Microsoft Flaw Allows Full Multi-Factor Authentication Bypass
Google Services Track User Movements In Privacy Faux Pas
Three more data-leaking security holes found in Intel chips as designers swap security for speed
Millions of Android Devices At Risk of Man-in-the-disk Attack
Researchers Break IPsec VPN Connections with 20-Year-Old Protocol Flaw
Managing risk in the modern world
CVE? Nope. NVD? Nope. Serious must-patch type flaws skipping mainstream vuln lists – report
Faxploit: Hackers can use Fax machines to inject malware into a targeted network
Adobe Patch Tuesday: Fixes for Critical Acrobat and Reader Flaws
Apple Mac “zero day” hack lets you sneakily click [OK]
Black Hat 2018: AI was supposed to fix security – what happened?

Heralded as the answer to many cybersecurity issues, machine learning hasn’t always delivered The post Black Hat 2018: AI was supposed to fix security – what happened? appeared first on WeLiveSecurity

Black Hat Exclusive Video: The IoT Security Threat Looms for Enterprises
ThreatList: Almost All Security Pros Believe Election Systems Are at Risk
Pacemaker controllers still vulnerable 18 months after flaws reported
#DEFCON Vote Hacking Village Refute NASS ‘Unfair’ Claims
Butlin’s Customers Face Anxious Holiday After Breach Alert
Podcast: Black Hat and DEF CON 2018 Wrap
Police body cameras open to attack
Pausing ‘Location history’ doesn’t stop Google tracking your location. Here’s how to stop it

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

11-year-old hacker changes election results
Facebook news feed changes – it’s a hoax!
May the May update be with you: OpenSSL key sniffed from radio signal
Faxploit: Retro hacking of fax machines can spread malware
Cisco patches IOS in response to boffins’ IKE-busting breakthrough
Intel finally emits Puma 1Gbps modem fixes – just as new ping-of-death bug emerges

security update

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

It’s official: TLS 1.3 approved as standard while spies weep

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: The package thunderbird before version 60.0-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

LinuxSecurity.com: Chris Coulson discovered a use-after-free flaw in the GNOME Display Manager, triggerable by an unprivileged user via a specially crafted sequence of D-Bus method calls, leading to denial of service or potentially the execution of arbitrary code.

New Variant of KeyPass Ransomware Discovered
Blue Team Village, DEF CON 2018 | Salted Hash Ep 43
Black Hat 2018: IoT Security Issues Will Lead to Legal ‘Feeding Frenzy’
GoDaddy Leaks ‘Map of the Internet’ via Amazon S3 Cloud Bucket Misconfig

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

DEF CON 2018: ‘Man in the Disk’ Attack Surface Affects All Android Phones
How a cryptocurrency-destroying bug almost didn’t get reported
Black Hat Video Exclusive: Mobile APTs Redefining Phishing Attacks
US voting systems: Full of holes, loaded with pop music, and hacked by an 11-year-old
DEF CON 2018: Voting Hacks Prompt Push Back from Election Officials, Vendors

LinuxSecurity.com: Multiple vulnerabilities have been discovered in various parsers of Blender, a 3D modeller/ renderer. Malformed .blend model files and malformed multimedia files (AVI, BMP, HDR, CIN, IRIS, PNG, TIFF) may result in the execution of arbitrary code.

Can cramming code with bugs make it more secure? Some think so

Unbeknownst to exploit writers, the seemingly mouth-watering bugs would be bogus and non-exploitable The post Can cramming code with bugs make it more secure? Some think so appeared first on WeLiveSecurity

Siri is listening to you, but she’s NOT spying, says Apple
Feds indict 12 for allegedly buying iPhones on other people’s dimes
In-flight satellite comms vulnerable to remote attack, researcher finds

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 9 fixes is now available.

Security breach in the White House’s Situation Room
PGA of America Struck By Ransomware
#DEFCON DHS Says Collaboration Needed for Secure Infrastructure and Elections
#DEFCON Government Attacks and Surveillance Continue to Increase
Criminal justice software code could send you to jail and there’s nothing you can do about it
Hackers can manipulate Police body cam footages
Prank ‘Give me a raise!’ email nearly lands sysadmin with dismissal
Former NSA top hacker names the filthy four of nation-state hacking
Black Hat: Protecting Industrial Control System

Aiming to protect critical infrastructure against attacks The post Black Hat: Protecting Industrial Control System appeared first on WeLiveSecurity

UK cyber cops: Infosec pros could help us divert teens from ‘dark side’
DEF CON 2018: Critical Bug Opens Millions of HP OfficeJet Printers to Attack
DEF CON 2018: Apple 0-Day (Re)Opens Door to ‘Synthetic’ Mouse-Click Attack
The Enigma of AI & Cybersecurity
NSA Brings Nation-State Details to DEF CON
#DEFCON L0pht Reunite to Find Security Unimproved
DEF CON 2018: Hacking Medical Protocols to Change Vital Signs

security update

security update

LinuxSecurity.com: rebase to 8.37.0 ———————- – few fixes and enhancements handling journal input – now requires librelp at least 1.2.16, adding support for setting address to bind – various other rsyslog core bugfixes and stability fixes

LinuxSecurity.com: – update to 2.56.x

LinuxSecurity.com: – update to 2.56.x

DEF CON 2018: Telltale URLs Leak PII to Dozens of Third Parties

LinuxSecurity.com: New upstream version 0.7alpha. Fixes CVE-2018-14679 libmspack: off-by-one error in the CHM PMGI/PMGL chunk number validity checks