Menu

Monthly Archives: October 2018

LinuxSecurity.com: Various security issues were discovered in the poppler PDF rendering shared library.

This one weird trick turns your Google Home Hub into a doorstop
Nice work if you can get it: GandCrab ransomware nets millions even though it has been broken
US government charges two Chinese spies over jet engine blueprint theft

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for xorg-x11-server is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: This is the One-Month notification for the retirement of Red Hat Enterprise Linux 7.3 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.3.

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

Spooky miasmic gas bricks hospital iPhones (mwah ha ha ha)
Apple Fixes Multiple macOS, iOS Bugs Including a Quirky FaceTime Vulnerability
Kraken Ransomware Upgrades Distribution with RaaS Model
Post-breach, Cathay Pacific hit by group action by UK law firm
How one man could have taken over any business on Facebook

LinuxSecurity.com: Several security issues were fixed in curl.

Growing pains: Skills gap meets expanding threat surface

The need to defend a growing threat surface highlights the widening cybersecurity skills gap The post Growing pains: Skills gap meets expanding threat surface appeared first on WeLiveSecurity

Yes, you should update your iPhone to iOS 12.1, but its lock screen is *still* unsafe
Google’s stealthy reCAPTCHA v3 detects humans – no questions asked
Crypto exchange collapses, victims accuse it of exit scam
Five ways to make Halloween less cyber-scary for kids

How can we help kids avoid security horrors and stay safe from rogue online “neighbors” at Halloween and thereafter? The post Five ways to make Halloween less cyber-scary for kids appeared first on WeLiveSecurity

LinuxSecurity.com: The package gitlab before version 11.4.3-1 is vulnerable to multiple issues including arbitrary code execution, cross-site request forgery, cross-site scripting and information disclosure.

Check this out: Radisson Hotel Group ‘fesses up to ‘security incident’
Mirai author fined $8.6million, gets 6 months house arrest

LinuxSecurity.com: Updated glusterfs packages that fix multiple security issues and bugs are now available for Red Hat Gluster Storage 3.4 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Updated glusterfs packages that fix multiple security issues and bugs are now available for Red Hat Gluster Storage 3.4 on Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

Apple emits its much-anticipated updates to Mac, AppleTV, and iOS
Square, PayPal POS Hardware Open to Multiple Attack Vectors
Employee infects US govt network with malware after visiting 9,000 porn sites

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

Google Updates reCAPTCHA: No More Boxes to Check
Signal App’s New Privacy Feature Conceals Sender ID from Metadata
ThreatList: Dead Web Apps Haunt 70 Percent of FT 500 Firms
Alleged SWATter will plead guilty to dozens of serious new federal charges
Gov worker visits 9k porn sites without protection, spreads infection

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Snakes in the grass! Malicious code slithers into Python PyPI repository

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

China hijacking internet traffic using BGP, claim researchers

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for glibc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for jasper is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for xerces-c is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for fuse is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Videos and MS Office documents – ingredients for a malware attack
IoT Flaw Allows Hijacking of Connected Construction Cranes

security update

Pain in the brain! Kaspersky warns of hackable brain implants
‘Recommendations To Enable PSD2-Compliant Transaction Monitoring’ white paper. Get your copy for free!
IBM acquiring Red Hat for a whopping $34 billion
Girl Scouts Issues Data Breach Warning to 2,800 Members

LinuxSecurity.com: CVE-2018-17100 An int32 overflow can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted

Nation-State Phishing: A Country-Sized Catch
X.Org Flaw Allows Privilege Escalation in Linux Systems
Search for Chrome on Bing, and you might get a nasty surprise
Self-driving cars learn (from us) about who to sacrifice in a crash
“Right to repair” gets a boost from new DMCA software rules
Call of Duty players caught up in cryptocurrency theft racket
Researchers exploit Microsoft Word through embedded video
Ransomware and the enterprise: A new white paper

Ransomware remains a serious threat and this new white paper explains what enterprises need to know, and do, to reduce risk The post Ransomware and the enterprise: A new white paper appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in MySQL.

Nothing exceeds like excess; or, a lack of privacy in the digital age

What has the internet brought us? And how does privacy stay anchored in the data deluge of the digital age? Here’s a brief reflection to celebrate today’s Internet Day The post Nothing exceeds like excess; or, a lack of privacy in the digital age appeared first on WeLiveSecurity

LinuxSecurity.com: CVE-2018-16395 Fix for OpenSSL::X509::Name equality check.

LinuxSecurity.com: It was discovered that incorrect connection setup in the server for Teeworlds, an online multi-player platform 2D shooter, could result in denial of service via forged connection packets (rendering all game server slots occupied).

LinuxSecurity.com: The update of Graphicsmagick in DSA-4321-1 introduced a change in the handling of case-sensitivity in an internal API function which could affect some code built against the GraphicsMagick libraries. This update restores the previous behaviour.

LinuxSecurity.com: CVE-2018-1000805 Fix to prevent malicious clients to trick the Paramiko server into thinking an unauthenticated client is authenticated.

Now use Internet anonymously through Tor-enabled SIM card Onion3G
Cathay Pacific hit by massive data breach; 10 million passengers affected
Site security & user friendliness: Top E-commerce qualities for 2018
Yahoo! $50m! hack! damages! bill!, Russian trolls menaced by Uncle Sam inaction, computer voting-machine UI confusion, and more

LinuxSecurity.com: An update that solves one vulnerability and has 5 fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges (CVE-2018-14665).

LinuxSecurity.com: This kernel update is based on the upstream 4.14.78 and fixes atleast the following security issues: An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy

LinuxSecurity.com: Updated firefox packages fix security vulnerabilities: Mozilla: Memory safety bugs fixed in Firefox ESR 60.3 (CVE-2018-12389). Mozilla: Memory safety bugs fixed in Firefox 63 and Firefox ESR 60.3

LinuxSecurity.com: This kernel-tmb update is based on the upstream 4.14.78 and adds additional fixes for the L1TF security issues. It also fixes atleast the following security issues: Linux kernel from versions 3.9 and up, is vulnerable to a denial of

LinuxSecurity.com: This kernel-linus update is based on the upstream 4.14.78 and adds additional fixes for the L1TF security issues. It also fixes atleast the following security issues: Linux kernel from versions 3.9 and up, is vulnerable to a denial of

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Apple and Samsung fined millions for intentionally slowing down old smartphones
ThreatList: 1 Out of 5 Would Ditch a Business After a Data Breach
The D in Systemd stands for ‘Dammmmit!’ A nasty DHCPv6 packet can pwn a vulnerable Linux box

security update

security update

security update

PoC Attack Leverages Microsoft Office and YouTube to Deliver Malware
How to build your own IT infosec holodeck: A blueprint for crafting a virtual enterprise to prod, test and hack

Reading Time: ~2 min.Data Breach Affects Centers for Medicare & Medicaid Services The Centers for Medicare & Medicaid Services (CMS) announced last week they had discovered malicious activity within their direct enrollment pathway, which connects patients and healthcare brokers. At least 75,000 individuals were affected. The pathway has since been disabled to prevent further exposure. […]

British Airways hack is worse than originally thought
British Airways Data Breach Takes Off Again with 185K More Victims
DemonBot Fans DDoS Flames with Hadoop Enslavement