Menu

Monthly Archives: September 2018

Google Chrome will now generate unique passwords for you

LinuxSecurity.com: Several vulnerabilities have been found in OpenSSH, a free implementation of the SSH protocol suite:

‘Only paper ballots by 2020!’ call experts after election tampering
Cyber as a Business Enabler: Operationalizing Cyber Risk Analytics. Download free ebook sneak peek today

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

Teen arrested for DDoS attack on ProtonMail & making fake bomb threats
WannaCry ransomware fame North Korean hacker tracked down by the US

LinuxSecurity.com: Several heap-based buffer over-reads were found in discount, an implementation of the Markdown markup language in C, that allowed remote attackers to cause a denial-of-service via specially crafted files.

security update

security update

security update

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Schneider Electric Shipped USB Drives Loaded with Malware

LinuxSecurity.com: It was discovered that there was a an integer overflow vulnerability in curl, a command line tool for transferring data over HTTP, etc. For more information, please see:

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.

LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

The worst cyberattacks undertaken by nation-state hackers
UK Teen Hacker Arrested After DDoS-ing Own Email Provider
The Linux Foundation: Accelerating Open Source Innovation
Gits exposed, kinky app devs spanked, Feds spy on spyware buyers, etc

LinuxSecurity.com:

LinuxSecurity.com: Tavis Ormandy discovered multiple vulnerabilites in Ghostscript, an interpreter for the PostScript language, which could result in denial of service, the creation of files or the execution of arbitrary code if a malformed Postscript file is processed (despite the dSAFER sandbox being

LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and use-after-frees may lead to the execution of arbitrary code or denial of service.

‘Domestic Kitten’ Mobile Spyware Campaign Aims at Iranian Targets
Dear America: Want secure elections? Stick to pen and paper for ballots, experts urge
Top antivirus tool nuked from macOS App Store – after it phoned browser histories to China
Silicon Valley CEO admits $1.5m wire fraud: Bouxtie boss forged signatures to investors
Open .Git Directories Leave 390K Websites Vulnerable

LinuxSecurity.com: transfig could be made to execute arbitrary code if it received a specially crafted FIG file.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.

Revealed: British Airways was in talks with IBM on outsourcing security just before hack

Reading Time: ~2 min.Banking Trojans Still Appearing in Google Play Store Multiple security researchers recently discovered a handful of banking trojans that have still managed to make their way into the Google Play app store, despite Google having increased its security to detect such apps. Many of the apps are disguised as astrology/horoscope software, but […]

British Airways Website, Mobile App Breach Compromises 380k
British Airways hacked- Private & financial data of 380,000 customers stolen
Feel the shame: Email-scammed staffers aren’t telling bosses about it
Threatpost News Wrap Podcast For Sept. 7
Teen hacker admits to SWATting schools, airline flight
Former NASA contractor arrested on charges of sextorting seven women
Vodafone hounds Czech customers for bills after they were brute-forced with Voda-issued PINs
Threat Actors Eyeing IQY Files To Peddle Malspam

LinuxSecurity.com: Updated libxkbcommon packages fix security vulnerabilities: Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation

LinuxSecurity.com: Updated wireshark packages fix security vulnerabilities: Bluetooth Attribute Protocol dissector crash (CVE-2018-16056). Radiotap dissector crash (CVE-2018-16057).

LinuxSecurity.com: Updated sleuthkit packages fix security vulnerabilities: In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libtskfs.a, as demonstrated by fls (CVE-2017-13755).

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Top MacOS App Exfiltrates Browser Histories Behind Users’ Backs
Firefox finally casts Windows XP users adrift
Dark web sites could be exposed by routine slip-up
How a data request turned into a data breach
Russia ‘front of the queue’ when it comes to hacking, says security minister
ThreatList: Attacks on Industrial Control Systems on the Rise
Teenage hacker admits making hoax bomb threats against schools and airlines
M-M-M-MONSTER KILL: Cisco’s bug-wranglers swat 29 in single week
It looks like tech-savvy drivers will have to lead connected car data purge
Could you hack your bosses without hesitation, repetition or deviation? AI says: No
Supermicro wraps crypto-blanket around server firmware to hide it from malware injectors

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Bug bounty alert: Musk lets pro hackers torpedo Tesla firmware risk free
U.S. Ties Lazarus to North Korea and Major Hacking Conspiracy
Wannabe Supreme Brett Kavanaugh red-faced after leaked emails contradict spy testimony

LinuxSecurity.com: Firefox could be made to crash or run programs as your login if it opened a malicious website.

LinuxSecurity.com: Several vulnerabilities were found in qemu, a fast processor emulator: CVE-2015-8666

security update

security update

FBI fingers the Norks it wants to pinch for Sony hack, WannaCry attacks
‘World’s favorite airline’ favorite among hackers: British Airways site, app hacked for two weeks
British Airways hacked – customer data and details of 380,000 card payments stolen

LinuxSecurity.com: Several security issues were fixed in libtirpc.

LinuxSecurity.com: Several security issues were fixed in libtirpc.

Risk Level: Very Low. Type: Trojan.

Active Spy Campaign Exploits Unpatched Windows Zero-Day
Open Source Summit: Innovation, Allies, and Open Development
Mozilla Patches Critical Code Execution Bug in Firefox 62
Could home appliances knock down power grids?

Far-fetched though it may sound, the answer is yes, according to researchers, who show that electrical grids and smart home appliances could make for a dangerous mix The post Could home appliances knock down power grids? appeared first on WeLiveSecurity

Mobile spyware maker mSpy leaks millions of records – AGAIN
Social Security numbers exposed on US government transparency site
How to manipulate Apple’s podcast charts, and get yourself a top-rated show
HTTPS crypto-shame: TV Licensing website pulled offline
High-Severity Flaws in Cisco Secure Internet Gateway Service Patched
Thousands of MikroTik routers are snooping on user traffic
Thousands of unsecured 3D printers discovered online
Ungagged Google warns users about FBI accessing their accounts

LinuxSecurity.com: It was discovered that there was an integer overflow vulnerability in the “Little CMS 2” colour management library. A specially-crafted input file could lead to a heap-based buffer overflow.

Using just a laptop, boffins sniff, spoof and pry – without busting browser padlock
Nope, the NSA isn’t sitting in front of a supercomputer hooked up to a terrorist’s hard drive

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.2 to fix security issues.

LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New ghostscript packages are available for Slackware 14.2 and -current to fix security issues.

NASA ‘sextortionist’ allegedly tricked women into revealing their password reset answers, stole their nude selfies
Smashing Security #094: Rogue browser extensions, Twitter presence, and how to cheat in exams
Do you really think crims would do that? Just go on the ‘net and exploit a Windows zero-day?
Take a pinch of autofill, mix in HTTP, and bake on a Wi-Fi admin page: Quirky way to swipe a victim’s router password
Premera Blue Cross hacker victims claim insurer trashed server to hide data-slurp clues

Reading Time: ~4 min.If you saw a file called eicar.com on your computer, you might think it was malware. But, you would be wrong. Readers, if you haven’t yet met the EICAR test file, allow me to introduce you to it. If you have used the EICAR test file, let’s get a bit cozier with […]

LinuxSecurity.com: Zhaoyang Wu discovered that cURL, an URL transfer library, contains a buffer overflow in the NTLM authentication code triggered by passwords that exceed 2GB in length on 32bit systems.

OilRig Sends an OopsIE to Mideast Government Targets

security update