Menu

Monthly Archives: August 2018

Cyber Criminals selling Bitcoin ATM Malware on Dark Web
Snap code snatched, Pentagon bans bands, pacemakers cracked, etc
Blue Team village, Deffcon 2018 | Salted Hash Ep. 43

LinuxSecurity.com: New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

PGA Golf Championship hit with Bitcoin ransomware
The off-brand ‘military-grade’ x86 processors, in the library, with the root-granting ‘backdoor’
Chris Valasek and Charlie Miller: How to Secure Autonomous Vehicles
Sensitive data on 31,000 GoDaddy servers exposed online

LinuxSecurity.com: Two vulnerabilities have been found in the PostgreSQL database system: CVE-2018-10915

LinuxSecurity.com: It was discovered that the PatternSyntaxException class in the Concurrency component of OpenJDK, an implementation of the Oracle Java platform could result in denial of service via excessive memory consumption.

LinuxSecurity.com: Various vulnerabilities leading to denial of service or possible unspecified other impacts were discovered in sam2p, an utility to convert raster images to EPS, PDF, and other formats.

Hackers phish Butlin’s holiday camp chain, access customers’ personal data
Black Hat 2018: Voice Authentication is Broken, Researchers Say
Hi-de-Hack! Redcoats red-faced as Butlin’s holiday camp admits data breach hit 34,000
Congresscritters want answers on Tillerson’s rm -rf /opt/gov/infosec
How one man could have hacked every Mac developer (73% of them, anyway)
Comcast Xfinity web flaws exposed customer data
15,000-strong army of Twitter robots found spreading cryptocurrency spam

LinuxSecurity.com: Several security issues were fixed in the kernel.

Over 20 Flaws Discovered in Popular Healthcare Software
#BHUSA: Politics and Cyber-Defense Are Colliding
Off-colour tweet earns Google’s Spectre whizz a midnight eviction from Caesars and DEF CON

Reading Time: ~2 min.Chipmaker Production Halts After WannaCry Attack A recent WannaCry attack at a Taiwanese chip manufacturerhas brought production to a standstill and threatens delays for new Apple products yet to be released. The manufacturer has announced that after two days their systems are clear and production is able to continue, blaming their own […]

Black Hat 2018: With Healthcare Security Flaws, Safety’s Increasingly at Stake
Facebook ‘regrets’ balloons and confetti triggered by earthquake posts
Hackers can cook people alive using sat-comms ‘microwave oven’ death rays – claim
Encryption doesn’t stop him or her or you… from working out what Thing 1 is up to
Spec-exec CPU bugs sweep hacking Oscars – and John McAfee’s in there like a bullet
Can we talk about the little backdoors in data center servers, please?
Say what you will about self-driving cars – the security is looking ‘OK’

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: Java applications could be made to use excessive memory.

LinuxSecurity.com: Java applications could be made to use excessive memory.

You can’t always trust those mobile payment gadgets as far as you can throw them – bugs found by infosec duo
Kaspersky VPN blabbed domain names of visited websites – and gave me a $0 reward, says chap
Understanding TRITON and the Missing Final Stage of the Attack

security update

Crims hacked accounts, got phones, resold them – and the Feds reckon they’ve nabbed ’em
Oh, fore putt’s sake: Golf org PGA bunkered up by ransomware attack just days before tournament
Black Hat 2018: Widespread Critical Flaws Found in Smart-City Gear
Black Hat 2018: Stealthy Kernel Attack Flies Under Windows Mitigation Radar
Hacking For Sport: A Journey in Reverse Engineering a Toshiba Wireless SD Card
New WhatsApp flaws let attackers hack chats to spread fake news
New Actor DarkHydrus Targets Middle East with Open-Source Phishing
Discover which dangers lurk ahead – at Sophos’ ‘See the Future’ event
Google to warn companies targeted in government-backed attacks
Black Hat 2018: Cortana Flaw Allowed Takeover of Locked Windows 10 Device
Attackers grab hold of PGA of America files, demand ransom

The golf association is said to have had little success with restoring access to its files so far The post Attackers grab hold of PGA of America files, demand ransom appeared first on WeLiveSecurity

Hacker leaks Snapchat’s source code on Github
Anonymous hackers vow to expose Q-Anon
How SELinux helps mitigate risk while facilitating compliance
“Attack” on FCC over net neutrality was legitimate traffic, report says

LinuxSecurity.com: The following vulnerability was discovered in wpa_supplicant. CVE-2018-14526: | An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0

DARPA takes aim at deepfake forgeries
Google Bug Hunter Urges Apple to Change its iOS Security Culture
Fortnite for Android goes “off market” – is that good or bad? [VIDEO]
IT Leaders Believe AI is a ‘Silver Bullet’ for Threats
Healthcare Firm Exposes Data on 2m+ Mexicans
26.5 million Comcast Xfinity customers had their partial home addresses and SSNs exposed by sloppy security
How evil JavaScript helps attackers tag possible victims – and gives away their intent
WhatsApp security snafu ‘could allow message manipulation’
Should I infect this PC, wonders malware. Let me ask my neural net…
Revealed: El Reg blew lid off Meltdown CPU bug before Intel told US govt – and how bitter tech rivals teamed up
If for some reason you’re still using TKIP crypto on your Wi-Fi, ditch it – Linux, Android world bug collides with it
Microsoft to hackers: Finding Hyper-V bugs is hard. Change my mind. PS: Here’s a head start…

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

Stress, bad workplace cultures are still driving security folk to drink
Smashing Security #090: Fortnite for Android, and the FCC’s DDoS BS
Google Project Zero boss: Blockchain won’t solve your security woes – but partying just might
Black Hat 2018: Mixed Signal Microcontrollers Open to Side-Channel Attacks
Black Hat 2018: Google’s Tabriz Talks Complex Security Landscapes

LinuxSecurity.com: The package linux-hardened before version 4.17.11.a-1 is vulnerable to denial of service.

LinuxSecurity.com: The package linux-zen before version 4.17.11-1 is vulnerable to denial of service.

LinuxSecurity.com: The package linux-lts before version 4.14.59-1 is vulnerable to denial of service.

LinuxSecurity.com: The package linux before version 4.17.11-1 is vulnerable to denial of service.

LinuxSecurity.com: Henning Westerholt discovered a flaw related to the To header processing in kamailio, a very fast, dynamic and configurable SIP server. Missing input validation in the build_res_buf_from_sip_req function could result in denial of service and potentially the execution of arbitrary code.

My Little Pony animator jailed for possessing 60k child abuse images
‘Chaff Bug’ Defense Rolls Out Shiny Objects for Attackers to Find

LinuxSecurity.com: New upstream version 0.7alpha. Fixes CVE-2018-14679 libmspack: off-by-one error in the CHM PMGI/PMGL chunk number validity checks

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Threatlist: Manufacturing, a Top Target for Espionage
Japanese dark-web drug dealers are so polite, they’ll offer ‘a refund’ if you’re not satisfied
Interviewing ESET’s experts about the Web’s journey so far – part 3

All good things come to an end, and we’re rounding off our series of interviews to mark the 27th anniversary since computer scientist Tim Berners-Lee publicly announced the World Wide Web project The post Interviewing ESET’s experts about the Web’s journey so far – part 3 appeared first on WeLiveSecurity

Facebook wants to be the future of online banking
5 Ways the Cloud is Beneficial to Businesses
iPhone Chip Maker Firm Attacked with Computer Virus