Menu

Monthly Archives: September 2018

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

Canadian town forced to pay Bitcoin after nasty ransomware attack
Cloud data management firm exposes database with over 440M emails & IP addresses
Russian Cybercriminal Pleads Guilty to Operating Kelihos Botnet
Apple removes top anti-malware apps from its store for “stealing data”
Pakistani hacker reports address bar spoofing flaws in Edge & Safari browser
Air-conditioned apocalypse: A blackout scenario involving smart climate control devices
Potential Hurricane Florence Phishing Scams
New GandCrab variant attacks Florida School District

LinuxSecurity.com: zutils version prior to version 1.8-pre2 contains a buffer overflow vulnerability in zcat which happened with some input files when the ‘-v, –show-nonprinting’ option was

security update

Official mobile version of Tor Browser released for Android – Download now
ICO Swamped with GDPR Breach Over-Reporting
DDoS attacks: Students blamed for many university cyber attacks
Kronos crims go retro, Apple builds cop portal, Swiss cheesed over Russian hack bid, etc

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Docker fave Alpine Linux suffers bug miscreants can exploit to poison containers
Researchers Heat Up Cold-Boot Attack That Works on All Laptops
E.U.: Tech Giants Face Big Fines, 1 Hour Limit to Remove Extremist Content

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2692

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2693

Security procedures are good – follow them and you get to keep your job
Five Weakest Links in Cybersecurity That Target the Supply Chain

Reading Time: ~2 min.Massive Customer Database Left Exposed by Data Management Firm A security researcher recently found a database containing customer information for nearly half a billion users of Veeam software on an unsecured AWS server. Most of the data was contact information spanning from 2013 to 2017 and was likely used by the Veeam […]

Magecart Threat Group Racks Up More Hack Victims
Veeam holds its hands up, admits database leak was plain ‘complacency’
Blockchain hustler beats the house with smart contract hack
Major US mobile carriers want to be your password
Kernel sanders: Webroot vuln creates route to root Macs
Review that! Fake TripAdvisor review peddler sent to jail
You didn’t buy ‘your’ iTunes movies; Apple can delete them anytime
You’ll never guess what you can do once you steal a laptop, reflash the BIOS, and reboot it
Browser security hole on Macs and iPhones – just how bad is it?

LinuxSecurity.com: Updated flash-player-plugin packages fix security vulnerability: Successful exploitation of the currently un-disclosed vulerability could lead to information disclosure (CVE-2018-15967).

LinuxSecurity.com: Updated ntp packages fix security vulnerability: Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6

LinuxSecurity.com: New ghostscript packages are available for Slackware 14.2 and -current to fix security issues.

OilRig APT Continues Its Ongoing Malware Evolution
Princely five years in US big house for Nigerian biz email scammer
Former Detroit IT boss sent down 20 months for bathroom bung bonanza
ThreatList: Microsoft Macros Remain Top Vector for Malware Delivery

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Programmer’s Day: Resources to audit your code

Taking advantage of the celebration of the Day of the Programmer, we share some audit tools to evaluate the security of your code The post Programmer’s Day: Resources to audit your code appeared first on WeLiveSecurity

Veeam leaves MongoDB database wide open, exposes 445m records
Street gang members indicted for stealing POS terminals
Experts Bemoan Shortcomings with IoT Security Bill
Prison for man who assisted scareware scheme that targeted newspaper website
The Reg takes the US government’s insider threat training course
Kodi add-ons launch cryptomining campaign

ESET researchers have discovered several third-party add-ons for the popular open-source media player Kodi being used to distribute Linux and Windows cryptocurrency-mining malware The post Kodi add-ons launch cryptomining campaign appeared first on WeLiveSecurity

California bill regulates IoT for first time in US
Update now! Microsoft’s September 2018 Patch Tuesday is here
Solid password practice on Capital One’s site? Don’t bank on it
Smashing Security #095: British Airways hack, Mac apps steal browser history, and one person has 285,000 texts leaked

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: USN-3747-1 introduced a regression in OpenJDK 10.

Card-stealing code that pwned British Airways, Ticketmaster pops up on more sites via hacked JS

security update

security update

PowerShell Obfuscation Ups the Ante on Antivirus

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.

Whisky business: Uni of Edinburgh servers Irn-Scru’d by cyber-attack
Apple Yet to Patch Safari Browser Address Bar Spoofing Flaw
Osiris Banking Trojan Displays Modern Malware Innovation
TV License website said it was secure. It wasn’t
Back up a minute: Veeam database config snafu exposed millions of customer records
Researchers demonstrate how to unlock Tesla wireless key fobs in 2 seconds
Patch Tuesday: Microsoft plugs zero-day hole exploited by PowerPool

Microsoft and Adobe have each shipped out their scheduled batches of patches to address security flaws in their respective software The post Patch Tuesday: Microsoft plugs zero-day hole exploited by PowerPool appeared first on WeLiveSecurity

Microsoft purges 3,000 tech support scams hiding on TechNet
Beware: WhatsApp scammers target children with ‘Olivia’ porn message

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has four fixes is now available.

Younger Facebook users 4 times more likely to delete app, study shows

LinuxSecurity.com: Two input sanitization failures have been found in the faxrunq and faxq binaries in mgetty. An attacker could leverage them to insert commands via shell metacharacters in jobs id and have them executed with the

LinuxSecurity.com: It was discovered that there was a denial of service and a potential arbitrary code execution vulnerability in the kamailio SIP server. A specially-crafted SIP message with an invalid “Via” header could cause a

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Vizio to send class notices through the TVs that spied on viewers
Explore the threat landscape at Sophos ‘See the Future’ event
2-bit punks’ weak 40-bit crypto didn’t help Tesla keyless fobs one bit
Brit armed forces still don’t have enough techies, thunder MPs
Generally Disclosing Pretty Rapidly: GDPR strapped a jet engine on hacked British Airways

LinuxSecurity.com: Updates for rh-dotnet21 and rh-dotnet21-dotnet are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Low.

Risk Level: Very Low. Type: Trojan.

It’s September 2018, and Windows VMs can pwn their host servers by launching an evil app
Threatlist: Email Attacks Surge, Targeting Execs

LinuxSecurity.com: Two input sanitization failures have been found in the faxrunq and faxq binaries in mgetty, a smart modem getty replacement. An attacker could leverage them to insert commands via shell metacharacters in jobs id and have them executed with the privilege of the faxrunq/faxq user.

Security firm uses Twitter to disclose critical zero-day flaw in Tor Browser
Microsoft Patches Three Actively Exploited Bugs as Part of Patch Tuesday