Menu

Monthly Archives: October 2018

General Motors collected location & radio listening habits data of 90,000 drivers
23-year-old woman charged with stealing $320,000 worth of cryptocurrency
Apple and Samsung punished for slowing down old smartphones
Facebook fined £500K for Cambridge Analytica saga
Former Facebook security chief calls out Apple for privacy hypocrisy
IoT: A roomful of conundrums

How can you stay safe in a world where “smart” is the new default? The post IoT: A roomful of conundrums appeared first on WeLiveSecurity

Facebook stopped 8.7m nude images of children in 3 months
How the cloud has made you more secure
Sorry friends, I’m afraid I just can’t quite afford the Bitcoin to stop that vid from leaking everywhere
Belgium: Oi, Brits, explain why Belgacom hack IPs pointed at you and your GCHQ
Cathay Pacific breach exposes data of 9.4 million passengers

The data breach at the Hong Kong flag carrier is the third such incident to hit the aviation industry in two months The post Cathay Pacific breach exposes data of 9.4 million passengers appeared first on WeLiveSecurity

LinuxSecurity.com: The package firefox before version 63.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, privilege escalation, content spoofing, denial of service and information disclosure.

We asked 100 people to name a backdoored router. You said ‘EE’s 4GEE HH70’. Our survey says… Top answer!

LinuxSecurity.com: An update that fixes 10 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 40 vulnerabilities is now available.

British Airways: If you’re feeling left out of our 380,000 passenger hack, then you may be one of another 185,000 victims
This two-year-old X.org give-me-root hole is so trivial to exploit, you can fit it in a single tweet

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3005

LinuxSecurity.com: Narendra Shinde discovered that incorrect command-line parameter validation in the Xorg X server may result in arbitary file overwrite, which can result in privilege escalation.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3006

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, incomplete TLS identity verification, information disclosure or the execution of arbitrary code.

LinuxSecurity.com: A regression was found in the recent security update for 389-ds-base (the 389 Directory Server), announced as DLA-1554-2, caused by an incomplete fix for CVE-2018-14648. The regression caused the server to crash when processing requests with empty attributes.

Word up: Embedded vids in Office docs can hide embedded nasties, infosec bods warn

security update

What a crane in the ass: Bug leaves construction machinery vulnerable to evil command injection

Reading Time: ~3 min.By now, you likely know that a Virtual Private Network (VPN) is essential to remaining safe when working remotely. But, once set up, how can you optimize your VPN to work well with your devices and meet your security needs? Here are our top five tips for maximizing your VPN experience. Pair […]

TimpDoor Android malware turning devices into hidden proxies
UK Slaps Facebook with $645K Fine Over Cambridge Analytica Scandal
Pentagon Expands Bug-Bounty Program to Include Physical Systems
Debunking AI’s Impact on the Cybersecurity Skills Gap
Third-Party Apps May Read Your Email: Learn How to Protect
Hackers deface Saudi ‘Davos in the Desert’ site against Khashoggi’s death

LinuxSecurity.com: It was discovered that 389-ds-base (the 389 Directory Server) is vulnerable to search queries with malformed values in the do_search() function (servers/slapd/search.c). Attackers could leverage this vulnerability by sending crafted queries in a loop to cause DoS.

Firefox 63 gets tough with trackers
Yahoo agrees to pay $50 million to settle data breach lawsuit
EU Laws Could Spell Double Trouble for Firms
Google and Facebook accused of secretly tracking users’ locations
Cathay Pacific hack: Personal data of up to 9.4 million airline passengers laid bare
Hackers steal personal data of up to 9.4 million Cathay Pacific passengers
Could TLS session resumption be another ‘super cookie’?
ESET releases new decryptor for Syrian victims of GandCrab ransomware

ESET experts have created a new decryption tool that can be used by Syrian victims of the GandCrab ransomware. It is based on a set of keys recently released by the malware operators The post ESET releases new decryptor for Syrian victims of GandCrab ransomware appeared first on WeLiveSecurity

Smashing Security #101: Rule 34, Twitter scams, and Facebook fails

LinuxSecurity.com: It was discovered that mosquitto, an MQTT broker, was vulnerable to remote denial-of-service attacks that could be mounted using various vectors.

From ‘WebEx’ to ‘WebExec’ to ‘WTF, my PC!’ Cisco rapped in chat app security flap

security update

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.6.0-sun is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.6.0-sun is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Teacher linked to Celebgate hacking scandal facing 7 years in prison
Ex spy bosses: Cyber-warfare needs rules of engagement for nations to promptly ignore

LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could result in the execution of arbitrary code, privilege escalation or information disclosure.

Magecart Cybergang Targets 0days in Third-Party Magento Extensions
Worrying Windows 10 wrecking-ball weapon weirdly wanders wildly on worldwide web
Windows ‘Deletebug’ Zero-Day Allows Privilege Escalation, Destruction
Supermarket told it must compensate 100,000 workers after payroll data deliberately leaked by rogue employee

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves 25 vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

sLoad Banking Trojan Downloader Displays Sophisticated Recon and Targeting
ThreatList: Ransomware, EKs and Trojans lead the Way in Q3 Malware Trends
Russia launched Triton malware to sabotage Saudi petrochemical plant
Vesta control panel servers infected with DDoS malware after supply chain attack
Are your jilted apps stalking you?
Banking Trojans continue to surface on Google Play

The malicious apps have all been removed from the official Android store but not before the apps were installed by almost 30,000 users The post Banking Trojans continue to surface on Google Play appeared first on WeLiveSecurity

WordPress takes aim at ancient versions of its software
Poorly secured SSH servers targeted by Chalubo botnet
Morrisons Loses Insider Breach Liability Appeal
Former high school teacher pleads guilty to hacking celebrities
Are you Cyber Aware? How about your friends and family?
Twitter thought Elon Musk’s bizarre tweets were evidence he’d been hacked
LuminosityLink RAT author sentenced to 2.5 years in jail

As part of his plea agreement, the author of the malware also forfeited the proceeds from his crimes – 114 Bitcoin worth $725,000 The post LuminosityLink RAT author sentenced to 2.5 years in jail appeared first on WeLiveSecurity

That Saudi oil and gas plant that got hacked. You’ll never guess who could… OK, it’s Russia

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

You patch my back(up) and I’ll patch yours… Arcserve bugs burrow remotely exploited holes in UDP storage systems
City Pays $2K in Ransomware, Stirs ‘Never Pay’ Debate

LinuxSecurity.com: Several security issues were fixed in MySQL.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2942

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2943

StrongPity APT Changes Tactics to Stay Stealthy
ProtonVPN Subscriptions Now Available on Firefox for $10
ThreatList: 3 Out of 4 Employees Pose a Security Risk to Businesses
Adult Website Hack Exposes 1.2M ‘Wife Lover’ Fans
How to Choose the Most Secure Software for your Business
Patch now! Multiple serious flaws found in Drupal
Phishing is still the most commonly used attack on organizations, survey says
Thousands of Applications Vulnerable to RCE via jQuery File Upload

LinuxSecurity.com: Several security issues were fixed in Tex Live.

Get Essential Security Information from Linux Security Summit Videos