Menu

Monthly Archives: September 2018

Cyber-Attack Inevitable, Businesses Not Prepared
Operator of VirusTotal Like Malware-Scanning Service Jailed for 14 Years

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via a malformed fax message.

Hacker gets 14 years jail time for operating Scan4You malware scanning service
The curious sudden rise of free US election ‘net security guardians
Woman Pleads Guilty to DC CCTV Ransomware Blitz
SingHealth data breach reveals several ‘inadequate’ security measures
Virus screener goes down, Intel patches more chips, Pegasus government spying code spreads across globe

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

Hackers steal $60 million from Japan’s Zaif cryptocurrency exchange
Critical Vulnerability Found in Cisco Video Surveillance Manager
Twitter: Don’t panic, but we may have leaked your DMs to rando devs
Couldn’t give a fsck about patching? Well, that’s your WordPress website pwned, then

security update

Twitter Flaw Exposed Direct Messages To External Developers
Delphi Packer Looks for Human Behavior Before Deploying Payload
Apple’s dropping Back To My Mac Remote Access. Here’s an Alternative, Currently Discounted.
Unpatched Microsoft Zero-Day in JET Allows Remote Code-Execution
Enigma message crack honours pioneering Polish codebreakers
Hackers target Newegg with “sophisticated malware”; steal credit card data
California man may get 6 months in prison for uploading Deadpool on Facebook
Scottish brewery recovers from ransomware attack
Bitcoin flaw could have allowed dreaded 51% takeover
Top 3 benefits of company open source programs
Attackers crack Newegg’s defenses, slurp customers’ credit card data

The skimmer, injected into the store’s payment page, harvested credit-card details from the store’s online customers for more than a month The post Attackers crack Newegg’s defenses, slurp customers’ credit card data appeared first on WeLiveSecurity

Australian encryption Bill raises bar for outrageous legislation: Comms Alliance
Security Vulnerability in ESS ExpressVote Touchscreen Voting Computer
Equifax faces ?500,000 fine in the UK over massive data breach
Warning issued as Netflix subscribers hit by phishing attack
Never mind Brexit. UK must fling more £billions at nuke subs, say MPs

LinuxSecurity.com: 3.6.9

Reading Time: ~2 min.Newegg Breach Lasts Nearly a Month Newegg finally addressed a recent breach after unknowingly hosting malicious code within a payment page for the last month. While the company is still unclear about how many customers were affected, the injected code does appear to have targeted both desktop and mobile visitors to the […]

LinuxSecurity.com: This is a security update for `CVE-2018-16802`. It also fixes a printing problem discovered in one of the previous CVE fixes. NOTE: *Please, be advised that there’s a separate issue related to printing problems, which is connected to CUPS itself, meaning this update might not completely resolve your printing issues.* —- This is a […]

LinuxSecurity.com: 3.6.9

LinuxSecurity.com: Security fix for CVE-2018-1000801

LinuxSecurity.com: Fixes CVE-2018-16515

LinuxSecurity.com: 8u181 update

LinuxSecurity.com: – New upstream Firefox version (62.0) – More info at https://www.mozilla.org/en- US/firefox/62.0/releasenotes/

LinuxSecurity.com: Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes

LinuxSecurity.com: Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes

LinuxSecurity.com: Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes

LinuxSecurity.com: Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes

LinuxSecurity.com: Update to devscripts-2.18.4, see http://metadata.ftp- master.debian.org/changelogs//main/d/devscripts/devscripts_2.18.4_changelog for details.

Dead retailer’s ‘customer data’ turns up on seized kit, unencrypted and very much for sale
Guilty: The Romanian ransomware mastermind who infected Trump inauguration CCTV cams

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Microsoft’s Jet crash: Zero-day flaw drops after deadline passes
Developer goes rogue, shoots four colleagues at ERP code maker
Lucy Gang Debuts with Unusual Android MaaS Package
NSS Labs fires off anti-malware-testing lawsuit at infosec toolmakers
Cisco Issues New Warning for 6-Month-Old Critical Bug in IOS XE
No, Sunspot Solar Observatory didn’t see aliens
Hackers behind Mirai botnet to avoid jail for working with the FBI
Securing industrial IoT passwords: For Pete’s sake, engineers, don’t all jump in at once
Magecart Strikes Again, Siphoning Payment Info from Newegg
Mirai’s architects avoid prison thanks to work for FBI

Instead, the three men will cooperate with law enforcement and the broader research community – an area in which, it turns out, they already have quite some experience The post Mirai’s architects avoid prison thanks to work for FBI appeared first on WeLiveSecurity

Sealed with an XSS: Lloyds Group should avoid cross talk, say IT pros
Man who shared Deadpool movie on Facebook faces 6 months in jail
Thousands of Breached Websites Turn Up On MagBo Black Market

LinuxSecurity.com: Several security issues were fixed in Little CMS.

LinuxSecurity.com: Multiple security vulnerabilities were discovered in GlusterFS, a clustered file system. Buffer overflows and path traversal issues may lead to information disclosure, denial-of-service or the execution of arbitrary code.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

US military given the power to hack back/defend forward

LinuxSecurity.com: An update is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Bind could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: Several security issues were fixed in Little CMS.

FBI wants to keep “helpful” Mirai botnet authors around
Western Digital goes quiet on unpatched MyCloud flaw
Congrats on keeping out the hackers. Now, you’ve taken care of rogue insiders, right? Hello?
No, the Mirai botnet masters aren’t going to jail. Why? ‘Cos they help Feds nab cyber-crims
What’s that smell? Oh, it’s Newegg cracked open by card slurpers

LinuxSecurity.com: A vulnerability has been discovered in php5, a server-side, HTML-embedded scripting language. The Apache2 component allows XSS via the body of a “Transfer-Encoding: chunked” request because of a defect

Oi, you. Equifax. Cough up half a million quid for fumbling 15 million Brits’ personal info to hackers

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that contains security fixes can now be installed.

Smashing Security #096: Bribing Amazon staff, and blinking deepfakes

LinuxSecurity.com: CVE-2016-10728 If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it can lead to missed TCP/UDP detection

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Patch for EE’s 4G Wi-Fi mini modem nails local privilege escalation flaw
Mirai Masterminds Helping FBI Snuff Out Cybercrime
Heads up: Get ready to tune in live and watch us probe insider threats menacing today’s IT
Critical Out-of-Band Patch Issued for Adobe Acrobat Reader
Security Embargos at Red Hat
National Museum of Computing to hold live Enigma code-breaking demo with a Bombe
URL spoofing – what it is and what to do about it [VIDEO]
Hackers disrupt UK’s Bristol Airport flight info screens after ransomware attack