Menu

Monthly Archives: October 2018

Decoding the Google Titan, Titan, and Titan M – that last one is the Pixel 3’s security chip

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has four fixes is now available.

Smashing Security #100: One flippin’ hundred
Tumblr turns stumblr, left humblr: Blogging biz blogs bloggers’ private info to world+dog
Naked celebrity photo hacker used to be a high school teacher

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Someone’s in hot water: Tea party super PAC group ‘spilled 500,000+ voters’ info’ all over web
Authorities search & seize properties of GTA V’s “Infamous” cheat developers

security update

security update

LinuxSecurity.com: An update is now available for Red Hat Fuse Integration Services. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LuminosityLink spyware mastermind gets 30 months in the clink, forfeits $725k in Bitcoin
Oracle Fixes 301 Flaws in October Critical Patch Update

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2921

LinuxSecurity.com: An update is now available for Red Hat JBoss Operations Network. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: It was discovered that there was a denial-of-service vulnerability in libpdfbox-java, a PDF library for Java. A malicious PDF file could have triggered an extremely long running

LinuxSecurity.com: An update is now available for Red Hat Satellite 6.4 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

GreyEnergy: New malware targeting energy sector with espionage
libssh Authentication Bypass Makes it Trivial to Pwn Rafts of Servers
Weirdo Twitter messages were a glitch, not a hack
Podcast: A Utility Ransomware Attack, Post-Hurricane
Serious SSH bug lets crooks log in just by asking nicely…
Multiple D-Link Routers Open to Complete Takeover with Simple Attack
On Heels of Criticism, Newly-Released Google Chrome 70 Prioritizes Privacy
Text Bomb Causing PS4 to Crash
Malicious Platform Independent Trojan GPlayed Disguised as Google Play Store
New iPhone lock screen bypass exposes your photos
Is this the simple solution to password re-use?
35 million US voter records up for sale on the dark web

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

UK’s MoD Exposed in 37 Security Breaches: Report
The Biggest Features Of Linux 4.19: Intel/AMD, CoC, 802.11ax, EROFS, GPS & GASKET
Linux’s LoRa Is Ready To Deliver Long-Range, Low-Power Wireless
Remote Code Implantation Flaw Found in Medtronic Cardiac Programmers
Donald Daters app for pro-Trump singles exposes users’ data at launch
GreyEnergy: Updated arsenal of one of the most dangerous threat actors

ESET research reveals a successor to the infamous BlackEnergy APT group targeting critical infrastructure, quite possibly in preparation for damaging attacks The post GreyEnergy: Updated arsenal of one of the most dangerous threat actors appeared first on WeLiveSecurity

Last year, D-Link flubbed a router bug-fix, so it’s back with total pwnage

Reading Time: ~3 min.For the past 20 years, Webroot’s technology has been driven by our dedication to protecting users from malware, viruses, and other online threats. The release of Webroot® WiFi Security—a new virtual private network (VPN) app for phones, computers, and tablets—is the next step in fulfilling our commitment to protect everyone’s right to […]

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Party like it’s 1989… SVGA code bug haunts VMware’s house, lets guests flee to host OS

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Thought Patch Tuesday was a load? You gotta check out this Oracle mega-advisory, then

LinuxSecurity.com: Several vulnerabilities have been discovered in GraphicsMagick, a set of command-line applications to manipulate image files, which could result in denial of service or the execution of arbitrary code if malformed image files are processed.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Asterisk, an open source PBX and telephony toolkit, which may result in denial of service or information disclosure.

As End of Life Nears, More Than Half of Websites Still Use PHP V5

security update

security update

Insult to injury: Malware menace soaks water-logged utility ravaged by Hurricane Florence
Alphabet in the soup for keeping quiet about Google+ data leak bug

LinuxSecurity.com: ClamAV could be made to crash if it opened a specially crafted file.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Anthem, Apple and the Pentagon: A Data-Breach Cornucopia
Penta-gone! Personal records of 30,000 US Dept of Defense workers swiped by miscreants

LinuxSecurity.com: Nitin Venkatesh discovered a cross-site scripting vulnerability in moin, a Python clone of WikiWiki. A remote attacker can conduct cross-site scripting attacks via the GUI editor’s link dialogue. This only affects installations which have set up fckeditor (not enabled by default).

Risk Level: Very Low. Type: Trojan, Virus, Worm.

In County Crippled by Hurricane, Water Utility Targeted in Ransomware Attack
Bug in Newly Released iOS 12.0.1 Gives Access To Your Photos
ThreatList: Half of Execs Feel Unprepared to Respond to a Cyber-Incident
Facebook Expands Efforts to Squash Voter Suppression
Privacy Regulation Could Be a Test for States’ Rights
UK’s National Cyber Security Centre gives itself big ol’ pat on the back in annual review
US embassy accidentally emails invitation to ‘cat pyjama-jam’ meeting
How Chrome and Firefox could ruin your online business this month

LinuxSecurity.com: Net-SNMP could be made to crash if it received specially crafted network traffic.

Phishers are after something unusual in ploy targeting book publishers

In a new twist on the theme, the scammers have their sights set on book manuscripts, among other things The post Phishers are after something unusual in ploy targeting book publishers appeared first on WeLiveSecurity

Google using lock screen passwords to encrypt Android Cloud backups
Considering Electronic Document Signing? Try OneSpan Sign Free For 30 Days
How to secure your Azure network
How to buy (and set up) a safe and secure baby monitor

LinuxSecurity.com: An update for tomcat is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Pentagon data breach puts personal details of 30,000 staff at risk
Web browsers sharpen knives for TLS 1.0, 1.1, tell protocols to dig their own graves for 2019

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing

LinuxSecurity.com: Several security issues were fixed in Thunderbird.

Hunt for Red Bugtober: US military’s weapon systems riddled with security holes – auditors

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2918

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2916

security update

Up to 35 Million 2018 Voter Records For Sale on Hacking Forum

LinuxSecurity.com: Frediano Ziglio reported a missing check in the script to generate demarshalling code in the SPICE protocol client and server library. The generated demarshalling code is prone to multiple buffer overflows. An authenticated attacker can take advantage of this flaw to cause a denial

Talking DerbyCon, spy chip whispers and Google’s data breach | Salted Hash Ep 47

LinuxSecurity.com: Net-SNMP could be made to crash if it received specially crafted network traffic.

Did Jamal Khashoggi’s Apple Watch record his murder at Saudi consulate? Probably not
NotPetya Linked to Industroyer Attack on Ukraine Energy Grid
Facebook downgrades victim count, details data accessed in breach

While the number of victims is lower than previously thought, the data accessed for millions of them is more sensitive than originally believed The post Facebook downgrades victim count, details data accessed in breach appeared first on WeLiveSecurity

Facebook Offers Details on ‘View As’ Breach, Revises Numbers
Google Maps: Hubby divorces wife after finding her on Street View with another man
Facebook opens up about data breach details
The Occasional Orator Part 3

Proper preparation can make all the difference when it comes to speaking at conferences The post The Occasional Orator Part 3 appeared first on WeLiveSecurity

Fake Adobe update really *does* update Flash (while also installing cryptominer)

LinuxSecurity.com: Requests could be made to expose sensitive information if it received a specially crafted HTTP header.

Beware sextortionists spoofing your own email address
Literary-minded phishers are trying to pilfer publishers’ manuscripts
AMD Posts Latest Open-Source Linux Patches For FreeSync / Adaptive-Sync / VRR