Menu

Monthly Archives: October 2018

Adult websites shuttered after 1.2 million user details exposed
Why is Elon Musk promoting this Bitcoin scam? (He’s not)
Morrisons supermarket: We’re taking payroll leak liability fight to UK Supreme Court
‘The inmates have taken over the asylum’: DNS godfather blasts DNS over HTTPS adoption
Pirates! Don’t blame your illegal file sharing on family members

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

If Facebook buys a security company, how will it retain the staff who absolutely hate Facebook?
jQuery? More like preyQuery: File upload tool can be exploited to hijack at-risk websites
Watch how a Tesla Model S was stolen with just a tablet
Patch me, if you can: Grave TCP/IP flaws in FreeRTOS leave IoT gear open to mass hijacking
Forgotten that Chinese spy chip story? We haven’t – it’s still wrong, Super Micro tells SEC

LinuxSecurity.com: Paramiko could allow unintended access to network services.

LinuxSecurity.com: Net-SNMP could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: libssh could allow unintended access to network services.

LinuxSecurity.com: Requests could be made to expose sensitive information if it received a specially crafted HTTP header.

The Danger and Opportunity in 5G Connectivity and IoT
Obamacare Sign-Up Channel Breach Affects 75K Consumers
Personal data of 75,000 individuals exposed after HealthCare.gov system hack
Critical Bug Impacts Live555 Media Streaming Libraries
Take this short Recorded Future survey to assess your organization’s threat intelligence maturity
Popular website plugin harboured a serious 0-day for years
Strict password policy could prevent credential reuse, paper suggests

The solution to password recycling may be easier to implement than previously thought, according to a recent paper The post Strict password policy could prevent credential reuse, paper suggests appeared first on WeLiveSecurity

Alleged robber busted after Facebook-friending victim to apologize
Vendors confirm products affected by libssh bug as PoC code pops up on GitHub
A Twitter employee groomed by the Saudi government prompted 2015 state-sponsored hacking warning
Up to 9.5 million net neutrality comments were fake
Maker of LuminosityLink RAT gets 30 months in the clink

LinuxSecurity.com: Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file (CVE-2016-5319). In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function

Bad to the Bot Bone

LinuxSecurity.com: A vulnerability has been discovered in exiv2 (CVE-2018-16336), a C++ library and a command line utility to manage image metadata, resulting in remote denial of service (heap-based buffer over-read/overflow) via

Watch out: MPlayer and VLC media player hit by critical vulnerability

LinuxSecurity.com: The package thunderbird before version 60.2.1-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

Two Critical RCE Bugs Patched in Drupal 7 and 8
Apache Access Vulnerability Could Affect Thousands of Applications
Hackers breach Healthcare.gov system, taking files on 75,000 people
Password and credit card-stealing Azorult malware adds new tricks
North Korean hacker crew steals $571M in cryptocurrency across 5 attacks
Apple boss demands Bloomberg Super Micro U-turn, Russian troll charged, NSA hands out cash, and more
Facebook Portal isn’t designed to be as private as you might hope
Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

LinuxSecurity.com: Updated ghostscript packages fix many bugs and security vulnerabilities: Bypassing executeonly to escape -dSAFER sandbox. (CVE-2018-17961) Saved execution stacks can leak operator arrays. (CVE-2018-18073)

security update

LinuxSecurity.com: The updated clamav packages fix a security vulnerability: Vulnerability in ClamAV’s MEW unpacking feature that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition on an affected device (CVE-2018-15378).

LinuxSecurity.com: Updated rust packages fix security vulnerability The Rust Programming Language Standard Library before version 1.29.1 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in the standard library that can result in buffer overflow. This attack

LinuxSecurity.com: The updated glib2.0 packages fix security vulnerabilities: In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference (CVE-2018-16428).

LinuxSecurity.com: Updated 389-ds-base package fixes security vulnerabilities: a race condition on reference counter leads to DoS using persistent search (CVE-2018-10850)

LinuxSecurity.com: This update provides vlc 3.0.4 and fixes atleast the following security issue: A use-after-free was discovered in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media

LinuxSecurity.com: Updated mgetty packages fix security vulnerabilities: The function do_activate() did not properly sanitize shell metacharacters to prevent command injection (CVE-2018-16741).

LinuxSecurity.com: Smarty 3.1.32 or below is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files (CVE-2018-13982).

LinuxSecurity.com: pdated tcpflow package fixes security vulnerability: An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handle_prism during caplen processing. If the caplen is less than 144, one can cause

LinuxSecurity.com: Updated calibre package fixes security vulnerability: gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that

LinuxSecurity.com: Updated docker packages fix security vulnerabilities: Lack of content verification in docker allowed a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing (CVE-2017-14992).

Risk Level: Very Low.

AWS FreeRTOS Bugs Allow Compromise of IoT Devices
Celebrating 100 episodes of the Smashing Security podcast
Manager who worked on Equifax’s breach website sentenced for insider trading

Reading Time: ~2 min.2018 Voter Records for Sale As the United States midterm elections draw closer, concern surrounding voter information is on the rise, and for good reason. Records for nearly 35 million registered voters from 19 different states were found for sale on a hacker forum, with prices ranging from $500 to $12,500, depending […]

Trivial Post-Intrusion Attack Exploits Windows RID
How to Make the Payment Process Easy for Online Customers
Serious D-Link router security flaws may never be patched
FBI Investigates Attack on Critical Water Utility
Pentagon Staff Hit by Major Data Breach
European Banks and Police Warn Consumers of Cyber Scams
Scams and flaws: Why we get duped

What are the emotional triggers and errors in judgment that make you fall for an online scam? The post Scams and flaws: Why we get duped appeared first on WeLiveSecurity

Apple privacy portal lets you see everything it knows about you
Swedish court tells ISP to block The Pirate Bay in the country
You like HTTPS. We like HTTPS. Except when a quirk of TLS can smash someone’s web privacy

LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata is now available.

LinuxSecurity.com: Two vulnerabilities were found in Drupal, a fully-featured content management framework, which could result in arbitrary code execution or an open redirect. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2018-006

security update

Talk about a curveball: Microsoft director of sports marketing fired, charged with fraud over ‘fake’ invoices
Equifax exec’s inside trade shame: Software boss sentenced for mega-hack stock profit
New APT Could Signal Reemergence of Notorious Comment Crew
Author of Luminosity RAT Gets 2.5 Years in Federal Prison
Tumblr Privacy Bug Could Have Exposed Sensitive Account Data
GreyEnergy Spy APT Mounts Sophisticated Effort Against Critical Infrastructure
400% increase in cryptomining malware attacks against iPhones

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.

The libssh “login with no password” bug – what you need to know [VIDEO]

Reading Time: ~3 min.There’s a reason major industry players have been discussing cybersecurity more and more: the stakes are at an all-time high for virtually every business today. Cybersecurity is not a matter businesses can afford to push off or misunderstand—especially small and medium-sized businesses (SMBs), which have emerged as prime targets for cyberattacks. The […]

RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
Is Google’s Android app unbundling good for security?
NCSC Tackles 10 Attacks on Government Per Week
LibSSH Flaw Allows Hackers to Take Over Servers Without Password
Tumblr patches bug that could have exposed user data

The microblogging platform is assuring its users that has found no evidence that any data was actually stolen The post Tumblr patches bug that could have exposed user data appeared first on WeLiveSecurity

You don’t have to sequence your DNA to be identifiable by your DNA

LinuxSecurity.com: An update for rh-nodejs8-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

How to use the Shodan search engine to secure an enterprise’s internet presence
Twitter publishes data on Iranian and Russian troll farms
VestaCP compromised in a new supply-chain attack

Customers see their admin credentials stolen and their servers infected with Linux/ChachaDDoS The post VestaCP compromised in a new supply-chain attack appeared first on WeLiveSecurity

LinuxSecurity.com: The package chromium before version 70.0.3538.67-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, sandbox escape, information disclosure and denial of service.

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for rh-nodejs6-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability