Menu

Monthly Archives: September 2018

LinuxSecurity.com: Michael Kaczmarczik discovered a vulnerability in the web interface template editing function of Sympa, a mailing list manager. Owner and listmasters could use this flaw to create or modify arbitrary files in the server with privileges of sympa user or owner view list config files

LinuxSecurity.com: The git-annex package was found to have multiple vulnerabilities when operating on untrusted data that could lead to arbitrary command execution and encrypted data exfiltration.

Misconfigured Tor sites using SSL certificates exposing public IP addresses
Google Rolls Out 40 Fixes with Chrome 69

LinuxSecurity.com: The daemon in GDM does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rhvm-appliance is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Active Campaign Exploits Critical Apache Struts 2 Flaw in the Wild
MEGA secure upload service gets its Chrome extension hacked
The Vulnerability Disclosure Process: Still Broken
Ran Levi interviews Graham Cluley on the Malicious Life podcast
IDG Contributor Network: How enterprise knowledge graphs can proactively reduce risk
IDG Contributor Network: Replication isn’t data protection. Here’s why
MEGA Chrome extension hacked with cryptocurrency malware
Linus Torvalds: Changes in hardware change Linux development
You are not alone; Facebook, Instagram and WhatsApp are down for many (Updated)
Don’t Fall for Webcam Blackmail: Here’s How to Protect Yourself
PowerPool malware exploits ALPC LPE zero-day vulnerability

Malware from newly uncovered group PowerPool exploits zero-day vulnerability in the wild, only two days after its disclosure The post PowerPool malware exploits ALPC LPE zero-day vulnerability appeared first on WeLiveSecurity

Everything DM gets direct message slap: Marketing biz cops £60k ICO fine
Silence! Cybercrime’s Pinky and the Brain have nicked $800k off banks
Serious Fraud Office trialling AI for data-heavy cases
Knock, knock: Digital key flaw unlocks door control systems
Department of Labour denies server compromise in recent cyberattack
This malware disguises itself as bank security to raid your account
ICO Breach Reports Jump 75% as Human Error Dominates
If an extension goes rogue, everything you do in your browser is compromised
Tiny Island Atoll’s Domain Used in Widespread Ad Fraud
Can ‘sonar’ sniff out your Android’s lock code?
Google releases free AI tool to stamp out child sexual abuse material
Brit teen pleads guilty to Minecraft-linked bomb and airline hoaxes
Cybercrooks home in on infosec’s weakest link – you poor gullible people
Premera Blue Cross victims accuse insurer of deliberately destroying hacking evidence
Uncle Sam wants tech toolkit to snoop social media stock scammers

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: Quang Nguyen discovered an integer overflow in the Little CMS 2 colour management library, which could in denial of service and potentially the execution of arbitrary code if a malformed IT8 calibration file is processed.

Mikrotik routers pwned en masse, send network data to mysterious box
Multiple Remote Code-Execution Flaws Patched in Opsview Monitor
Google and MasterCard will track your retail spending under a secret deal
Thousands of MikroTik Routers Hijacked for Eavesdropping

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

ThreatList: 60% of BEC Attacks Fly Under the Radar
Credit card gobbling malware found piggybacking on ecommerce sites
CamuBot Malware Camouflaged as Bank Security App to Steal Credentials
India’s ISPs show they have good MANRS, sign up to Internet Society’s routing security scheme
Cock-ups, rather than conspiracies, top self-reported data breaches

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

How refusing to give police your Facebook password can lead to prison
Of ML and malware: What’s in store?

All things labeled Artificial Intelligence (AI) or Machine Learning (ML) are making waves, but talk of them in cybersecurity contexts often muddies the waters. A new ESET white paper sets out to bring some clarity to a subject where confusion often reigns supreme The post Of ML and malware: What’s in store? appeared first on […]

Governments demand companies allow access to data, or else
Hollywood accuses itself of piracy
Thousands of misconfigured 3D printers on interwebz run risk of sabotage
Five steps that raise your security defences to the next level
‘CamuBot’ Banking Malware Ups the Trojan Game with Biometric Bypass
Google Ads cracks down on tech support scammers
Excuse me, but your website’s source code appears to be showing

LinuxSecurity.com: An update for collectd is now available for Red Hat Gluster Storage 3.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Updated samba packages that fix several security issues and provide several bug fixes and an enhancement are now available for Red Hat Gluster Storage 3.4 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Updated samba packages that fix several security issues and provide several bug fixes and an enhancement are now available for Red Hat Gluster Storage 3.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Updated glusterfs packages that fix multiple security issues and bugs, and add various enhancements are now available for Red Hat Gluster Storage 3.4 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Updated glusterfs packages that fix multiple security issues, several bugs, and adds various enhancements are now available for Red Hat Gluster Storage 3.4 on Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

Cryptominers killing cryptominers to squeeze more out of your CPU
Parental control spyware app Family Orbit hacked; 281 GB of data exposed

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Hackers selling data of 130 million Chinese hotel clients on Dark Web for 8 BTC
Majority of the world’s top million websites use HTTPS

The adoption of the protocol’s secure variant has continued its growth spurt in recent months, crossing the 50-percent milestone for the first time ever The post Majority of the world’s top million websites use HTTPS appeared first on WeLiveSecurity

Google cracks down on dodgy tech support ads
APT10 Under Close Scrutiny as Potentially Linked to Chinese Ministry of State Security
Twitter testing new feature that reveals when you’re online
Can you “see” someone’s screen by listening to it? [VIDEO]
Machine Identity Failings Expose Firms
Orgs Still Feel Vulnerable Despite Cyber Standards
Firefox to start blocking ad-tracking by default
‘Sick sadist’ admits to trolling dead people on social media
Chrome: Flash is almost, almost, almost dead
Possible Satori botnet hacker indicted by Feds
Google quietly bought Mastercard credit and debit card records
Read OneSpan’s 8-page report on the top six e-Signature use cases in banking

LinuxSecurity.com: It was discovered that there was a string injection vulnerability in the “dojo” Javascript library. For Debian 8 “Jessie”, this issue has been fixed in dojo version

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: The updated packages fix security vulnerabilities: gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a

LinuxSecurity.com: Updated java-1.8.0-openjdk packages fixes atleast the following security vulnerability: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (CVE-2018-2952)

LinuxSecurity.com: Updated openssl packages fix security vulnerabilities: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a

LinuxSecurity.com: Two security issues have been discovered in the Tomcat servlet and JSP engine. CVE-2018-1336

Hearing Date Set in Georgia Election Security Case
How One Company’s Cybersecurity Problem Becomes Another’s Fraud Problem

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

security update

security update