Menu

Monthly Archives: August 2018

LinuxSecurity.com: The 4.17.11 stable update contains a number of important fixes across the tree. Also of note, starting with this release, kernel-headers is built from a different srpm. The contents should be the same, but there were some benefits to breaking it from the kernel build. —- The 4.17.10 stable kernel update contains a number […]

LinuxSecurity.com: Update Python 2 dependency declarations to new packaging standards

Consumer DNA Testing Takes a Step Towards Privacy, Transparency
Ever seen printer malware in action? Install this HP Ink patch – or you may find out

LinuxSecurity.com: Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to open redirects, cross-site request forgery, information disclosure, session fixation or denial of service.

LinuxSecurity.com: Enrico Zini discovered a vulnerability in Syntastic, an addon module for the Vim editor that runs a file through external checkers and displays any resulting errors. Config files were looked up in the current working directory which could result in arbitrary

LinuxSecurity.com: Update to 2.26, fixes CVE-2018-9275

LinuxSecurity.com: Update to 2.26, fixes CVE-2018-9275

LinuxSecurity.com: Several security issues were fixed in ClamAV.

Salesforce.com Warns Marketing Customers of Data Leakage SNAFU
Threatlist: SMB Security Challenges Grow with the Cloud
Web doc iCliniq plugs leaky S3 bucket stuffed full of medical records

LinuxSecurity.com: It was found that the security update of busybox announced as DLA-1445-1 to prevent the exploitation of CVE-2011-5325, a symlinking attack, was too strict in case of cpio archives. This update restores the old behavior.

Routers turned into zombie cryptojackers – is yours one of them?
Alleged “high-ranking” members of the Fin7 cybercrime group arrested
DHS Launches Cyber-Risk Management Center
Reddit Breached After SMS 2FA Fail
How safe is your DNA data?
Alaskan borough dusts off the typewriters after ransomware crims pwn entire network
Amnesty International spearphished with government spyware

Reading Time: ~2 min.Cryptojacking “Game” Found on Steam Store Valve has taken recent action against an indie-developed game available on Steam, the company’s game/app store, and removed their listing after many customers had complained about cryptomining slowing their systems, once launched. Additionally, the developers have been caught selling in-game items on third-party sites, that were […]

LinuxSecurity.com: Various vulnerabilities were discovered in graphicsmagick, a collection of image processing tools and associated libraries, resulting in denial of service, information disclosure, and a variety of buffer overflows and overreads.

MikroTik routers grab their pickaxes, descend into the crypto mines

security update

Dear alt-right morons and other miscreants: Disrupt DEF CON, and the goons will ‘ave you
Porn parking, livid lockers and botched blenders: The nightmare IoT world come true
Putting the ass in Atlassian: Helpdesk email server passwords blabbed to strangers

LinuxSecurity.com: New lftp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Several vulnerabilities were discovered in libsmpack, a library used to handle Microsoft compression formats. A remote attacker could craft malicious CAB, CHM or KWAJ files and use these flaws to cause a denial of service via application crash, or potentially execute arbitrary code.

LinuxSecurity.com: openslp: Heap memory corruption in slpd/slpd_process.c allows denial of service or potentially code execution (CVE-2017-17833) SL6 x86_64 openslp-2.0.0-3.el6.i686.rpm openslp-2.0.0-3.el6.x86_64.rpm openslp-debuginfo-2.0.0-3.el6.i686.rpm openslp-debuginfo-2.0.0-3.el6.x86_64.rpm openslp-devel-2.0.0-3.el6.i686.rpm openslp-devel-2.0.0-3.el6.x86_64.rpm openslp-server- [More…]

DEF CON plans to show US election hacking is so easy kids can do it
Did you know: Lawyers can certify web domain ownership? Well, not no more they ain’t
ThreatList: Spam’s Revival is Tied to Adobe Flash’s Demise
Castaway hacker guilty of sedating children’s hospital computers

LinuxSecurity.com: New version 2.6.2. Security fix for CVE-2018-14339, CVE-2018-14340, CVE-2018-14341, CVE-2018-14342, CVE-2018-14343, CVE-2018-14344, CVE-2018-14367, CVE-2018-14368, CVE-2018-14369, CVE-2018-14370.

LinuxSecurity.com: Update to 6.6. —- Version 6.5 – address CVE-2018-10773, CVE-2018-10774, CVE-2018-10775 – fix injection of Fedora LDFLAGS

LinuxSecurity.com: Update to 6.6. —- Version 6.5 – address CVE-2018-10773, CVE-2018-10774, CVE-2018-10775 – fix injection of Fedora LDFLAGS

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

Phishing Campaign Steals Money From Industrial Companies
Cisco drops a cool $2.3 billion on SaaSy outfit Duo Security
Podcast: Breaking Down the COSCO Ransomware Attack
Reddit’s serious “security incident” – what you need to know

Reading Time: ~6 min.Cybercriminals are constantly experimenting with new ways to take money from their victims. Their tactics evolve quickly to maximize returns and minimize risk. The emergence of cryptocurrency has opened up new opportunities to do just that. To better understand today’s threat landscape, it’s worth exploring the origins of cryptocurrencies and the progress […]

Reddit hacked – but don’t give up on 2FA just yet
How to defend yourself against SamSam ransomware
Facebook bans midterm-meddling accounts and pages

LinuxSecurity.com: Several security issues were fixed in ClamAV.

Huge Cryptomining Attack on ISP-Grade Routers Spreads Globally
Hundreds of Android apps on Play Store infected with Windows malware
Reddit reveals breach as attacker circumvents staff’s 2FA

The company has learned the hard way that there are better ways to deliver two-factor authentication than via text messages The post Reddit reveals breach as attacker circumvents staff’s 2FA appeared first on WeLiveSecurity

Facebook’s security boss is offski. Not to worry, it has ’embedded security’ in all divisions
Notorious hacking group Fin7’s 3 main hackers arrested by the FBI
Microsoft Edge adds WebAuthn as passwords near the end
A single ransomware creator made almost $6 million
Yale University discloses old school data breach
Spam is getting smarter and we’re still falling for it

LinuxSecurity.com: Several vulnerabilities have been discovered in mutt, a sophisticated text-based Mail User Agent, resulting in denial of service, stack-based buffer overflow, arbitrary command execution, and directory traversal

Facebook shuts off user data access for hundreds of thousands of apps
Smashing Security #089: Data breaches, ransomware, Bitcoin robberies, and typewriters
UK.gov ploughs cash into creaky police technology

LinuxSecurity.com: The security update of busybox announced as DLA-1445-1 introduced a regression due to an incomplete fix for CVE-2015-9261. It was no longer possible to decompress gzip archives which exceeded a certain file size.

Do you work in a regulated industry?
Cache of the Titans: Let’s take a closer look at Google’s own two-factor security keys
Drink this potion, Linux kernel, and tomorrow you’ll wake up with a WireGuard VPN driver
New Zealand school on naughty step after ransomware failure
Reddit hacked: Hackers steal complete copy of old database backup

LinuxSecurity.com: New blueman packages are available for Slackware 14.2 and -current to fix a security issue.

‘Unhackable’ Bitfi crypto-currency wallet maker will be shocked to find fingernails exist
DOJ Nabs Three FIN7 Cybercrime Suspects in Europe

security update

Bevy of Android Apps Harbor Hidden Malicious Windows Executables

LinuxSecurity.com: Several security issues were fixed in libmspack.

The End for Fin7: Feds cuff suspected super-crooks after $$$m stolen from 15m+ credit cards
SMS 2FA gave us sweet FA security, says Reddit: Hackers stole database backup of user account info, posts, messages
Reddit Breach Stems from SMS Two-Factor Authentication Breakdown

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Security critical patch update for OpenJDK (July CPU). See http://www.oracle.com/technetwork/security- advisory/cpujul2018-4258247.html#AppendixJAVA

LinuxSecurity.com: Security critical patch update for OpenJDK (July CPU). See http://www.oracle.com/technetwork/security- advisory/cpujul2018-4258247.html#AppendixJAVA

LinuxSecurity.com: # New upstream release 2.3 Fixes possible tag truncation security bug in AEAD API, see RHBZ#1602752 ## 2.3 – 2018-07-18 * SECURITY ISSUE: finalize_with_tag() allowed tag truncation by default which can allow tag forgery in some cases. The method now enforces the min_tag_length provided to the GCM constructor. * Added support for Python 3.7. […]

Risk Level: Very Low.

How a man hacked his victims’ SIM cards to steal millions of dollars
Amnesty International Targeted by Nation-State Spyware
Holy ship! UK’s Clarksons blames megahack on single point of pwnage
Android apps infected with umm… *Windows* malware
Alleged SIM-swap scammer nabbed for stealing $5m in Bitcoin
Staff dust off their typewriters after malware attack
Phone scam exploits Russian hacking fears
Steam Bans Developer After Outcry Over Cryptomining, Scam Items
High-schoolers’ data put up for sale after being scraped from surveys
HP offers rewards for hacking its printers

But don’t get too excited just yet: the first-of-its-kind bug bounty program for printers is invite-only for now The post HP offers rewards for hacking its printers appeared first on WeLiveSecurity

Mozilla still working on Firefox’s site isolation security revamp
New Spectre Variant Hits the Network
Clarksons says single user account to blame for data breach
Conversation hijacking attacks | Salted Hash Ep 38
Oooooh! Fashion! Yes, breach did contain 1 million+ records
UK cyber security boffins dispense Ubuntu 18.04 wisdom
Porn-warning security scam hooks you up to “Apple Care”