Menu

Monthly Archives: August 2018

Windows 10 May Not Be Free for Businesses Anymore
iKeyMonitor: A parental control app ensuring safety of your child
Safe as houses: 5 security measures adopted by cryptocurrency exchanges
HP Bug Bounty Program: Hack HP Printers & Earn Up To $10,000
Snapchat’s source code leaked out, and was published on GitHub
Patrick Wardle on Breaking and Bypassing MacOS Firewalls
Software bugs put nearly 100 million health records at risk of exposure

The slew of vulnerabilities – since patched – were found without the use of automated testing tools The post Software bugs put nearly 100 million health records at risk of exposure appeared first on WeLiveSecurity

Could deliberately adding security bugs make software more secure?

LinuxSecurity.com: The security update for slurm-llnl introduced a regression in the fix for CVE-2018-10995 which broke accounting. For Debian 8 “Jessie”, this problem has been fixed in version

Profit-strapped Symantec pulls employee share scheme
SingHealth Attack Potentially State-Linked
Linux kernel bug: TCP flaw lets remote attackers stall devices with tiny DoS attack
Update Mechanism Flaws Allow Remote Attacks on UEFI Firmware
Twitter CEO says they’re taking no action against InfoWars and Alex Jones
Podcast: enSilo CEO on Black Hat USA 2018 Top Trends
An inside look at hybrid Office 365 phishing attacks | Salted Hash Ep 41
Hey, you know what a popular medical record system doesn’t need? 23 security vulnerabilities
Funnily enough, no, infosec bods aren’t mad keen on W. Virginia’s vote-by-phone-app plan
Fresh Approach to WiFi Cracking Uses Packet-Sniffing

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

security update

Cybersecurity Certifications: Why They Matter and How to Know Which Ones To Pursue
Cracking the passwords of some WPA2 Wi-Fi networks just got easier
Microsoft Adds Direct Trust for Let’s Encrypt
Pentagon Bans Soldiers from Using GPS Apps and Devices
Batten down the ports: Linux networking bug SegmentSmack could remotely crash systems
Update MikroTik routers – 170,000 devices hit by cryptocurrency malware
Interviewing ESET’s experts about the Web’s journey so far – part 2

Today, we continue with our series of conversations with ESET’s security pros to hear what they have to say about the evolution of the World Wide Web since it was publicly announced 27 years ago The post Interviewing ESET’s experts about the Web’s journey so far – part 2 appeared first on WeLiveSecurity

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Apple chip supplier blames WannaCryptor variant for plant shutdowns

The malware outbreak has even prompted concerns of delays in the shipments of the next wave of iPhones The post Apple chip supplier blames WannaCryptor variant for plant shutdowns appeared first on WeLiveSecurity

Threatlist: Financial Services Firms Lag in Patching Habits
How Bitcoin and the Dark Web hide SamSam in plain sight
iPhone chipmaker blames ransomware for factory shutdowns
Rights groups challenge UK cops over refusal to hand over info on IMSI catchers
Mozilla faces resistance over DNS privacy test
Fortnite ditches Google Play – will it undermine Android security?
Bank on it: It’s either legal to port-scan someone without consent or it’s not, fumes researcher
Chipmaker TSMC Hit by Virus Outbreak
Privacy International Takes Police Phone ‘Hacking’ Case to IPC
Podcast: Black Hat USA 2018 Preview
No, Michael J Fox isn’t dead
What is a phishing kit? Watch this in-depth explainer | Salted Hash Ep 39
Top tip? Sprinkle bugs into your code to throw off robo-vuln scanners
Battle lines drawn over US mass surveillance as senators probe NSA’s bonfire of phone records
IBM, ATMs – WTF? Big Blue to probe cash machines, IoT, vehicles, etc in new security labs

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

BlackBerry claims it can do to ransomware what Apple did to its phones
Cracking the passwords of some WPA/WPA2 W-Fi networks just got easier
Fortnite Skips Google Play For Android Apps, Irking Security Experts
Ramnit Changes Shape with Widespread Black Botnet
Chip flinger TSMC warns ‘WannaCry’ outbreak will sting biz for $250m
Facebook cracks opens its bottle of Fizz – a carbonated TLS 1.3 lib

Reading Time: ~4 min.This week, I’ll be at Black Hat USA 2018 in Las Vegas. If you’ve ever been to Black Hat, then you know all about the flood of information and how hard it can be to take it all in. This year’s presentations will range from the newest trends in browser exploits, bots, […]

Top iPhone Supplier Battles WannaCry Infection
Making millions out of prisoners’ email
Interviewing ESET’s experts about the Web’s journey so far – part 1

What has the journey of the World Wide Web been like so far, as seen and experienced by ESET’s security folk? ESET Senior Research Fellow David Harley provides his take in the first installment of our series of interviews marking the Web’s 27th birthday. The post Interviewing ESET’s experts about the Web’s journey so far […]

Windows 10 updates under fire from unhappy security admins
Man arrested for blackmailing women with porn fakes
‘Unhackable’ Bitfi hardware rooted within a week
Guilty! Court sinks children’s hospital attacker found stranded on a boat
You’ll have to disable a recommended Android security setting to install Fortnite

LinuxSecurity.com: It was discovered that there were several vulnerabilities in libsmpack, a library used to handle Microsoft compression formats. A remote attacker could craft malicious .CAB, .CHM or .KWAJ files

An introduction to Kit Hunter, a phishing kit detector | Salted Hash Ep 40

LinuxSecurity.com: It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data.

LinuxSecurity.com: It was discovered that there was a directory traversal vulnerability in cgit, a web frontend for Git repositories. For Debian 8 “Jessie”, this issue has been fixed in cgit version

LinuxSecurity.com: An update for openslp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for rhvm-setup-plugins is now available for Red Hat Virtualization Engine 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for xmlrpc is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The fix for CVE-2018-10886 was incomplete in the previous upload. New changes was implemented upstream which check and resolve symlinks before expanding the archives.

LinuxSecurity.com: It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data.

LinuxSecurity.com: Andreas Hug discovered an open redirect in Django, a Python web development framework, which is exploitable if django.middleware.common.CommonMiddleware is used and the APPEND_SLASH setting is enabled.

security update

security update

LinuxSecurity.com: Backport fix for CVE 2017-11548

LinuxSecurity.com: Update to 3.2.1 (CVE-2017-12627)

LinuxSecurity.com: Update to 3.2.1 (CVE-2017-12627)

security update

LinuxSecurity.com: The package python2-django before version 1.11.15-1 is vulnerable to open redirect.

LinuxSecurity.com: The package cgit before version 1.2.1-1 is vulnerable to directory traversal.

Hacking tools & ready-made phishing pages being sold on dark web for $2
ZombieBoy cryptomining malware exploits CVEs to evade detection
Industrial Sector Targeted in Highly Personalized Spear-Phishing Campaign
GDPR: What’s really changed so far?

LinuxSecurity.com: Jann Horn discovered a directory traversal vulnerability in cgit, a fast web frontend for git repositories written in C. A remote attacker can take advantage of this flaw to retrieve arbitrary files via a specially crafted request, when ‘enable-http-clone=1’ (default) is not turned off.

TSMC chip fab tools hit by virus, payment biz BGP hijacked, CCleaner gets weird – and more
Security world to hit Las Vegas for a week of hacking, cracking, fun

security update

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 10 vulnerabilities is now available.

Massive ransomware attack forcing authorities to move to typewriters

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: Sync with git (CVE-2017-14160, CVE-2018-10392, CVE-2018-10393, bz#1516379)

LinuxSecurity.com: The 4.17.11 stable update contains a number of important fixes across the tree. Also of note, starting with this release, kernel-headers is built from a different srpm. The contents should be the same, but there were some benefits to breaking it from the kernel build. —- The 4.17.10 stable kernel update contains a number […]

LinuxSecurity.com: Update Python 2 dependency declarations to new packaging standards

security update