Menu

Monthly Archives: October 2018

How OpenStack Barbican deployment options secure your cloud

LinuxSecurity.com: Three vulnerabilities were discovered in the Open Ticket Request System which could result in privilege escalation or denial of service. For the stable distribution (stretch), these problems have been fixed in

Top cybersecurity facts, figures and statistics for 2018
30 Million Facebook Accounts Were Hacked: Check If You’re One of Them

LinuxSecurity.com: Updated texlive packages fix security vulnerability: A buffer overflow in the handling of Type 1 fonts allowed arbitrary code execution when a malicious font is loaded by one of the vulnerable tools: pdflatex, pdftex, dvips, or luatex (CVE-2018-17407).

LinuxSecurity.com: Updated firefox packages fix security vulnerabilities: A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered

LinuxSecurity.com: joernchen of Phenoelit discovered that git is prone to an arbitrary code execution vulnerability due to insufficient validation of submodule url and path via a specially crafted .gitmodules file in a project cloned with –recurse-submodules (CVE-2018-17456).

LinuxSecurity.com: Nextcloud has been updated to 13.0.6 and fixes atleast the following security issue: A missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization

security update

security update

LinuxSecurity.com: spamassassin: Certain unclosed tags in crafted emails allow for scan timeouts and result in denial of service (CVE-2017-15705) * spamassassin: Local user code injection in the meta rule syntax (CVE-2018-11781) SL7 x86_64 spamassassin-3.4.0-4.el7_5.x86_64.rpm spamassassin-debuginfo-3.4.0-4.el7_5.x86_64.rpm – Scientific Linux Development Team

Fake Adobe updates installing cryptomining malware while updating Flash
Azure goes quiet, Huawei Canada ban urged, US Senators are after Google, and more
It’s the real Heart Bleed: Medtronic locks out vulnerable pacemaker programmer kit
30M Facebook breach; includes users phone numbers and location data
ICS Security Plagued with Basic, Avoidable Mistakes

LinuxSecurity.com: This update fixes several vulnerabilities in Imagemagick, a graphical software suite. Various memory handling problems or incomplete input sanitising have been found in the coders for BMP, DIB, PICT, DCM, CUT and PSD.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer which could result in denial of service or the execution of arbitrary code.

security update

Now this might be going out on a limb, but here’s how a branch.io bug left ‘685 million’ netizens open to website hacks

LinuxSecurity.com: The package wireshark-cli before version 2.6.4-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Threatpost News Wrap Podcast For Oct. 12
Facebook mass hack last month was so totally overblown – only 30 million people affected

Risk Level: Very Low. Type: Trojan.

Microsoft Zero-Day Patch for JET Bug Incomplete, Claims Firm

Reading Time: ~2 min.Latest Windows 10 Update Removes User Files Microsoft recently pulled its latest update, version 1809, after several users complained about personal files being deleted. While some users were able to use third-party software to retrieve deleted files, users whose files wnet missing from the Documents folder are having a much trickier time […]

Baby Got Bots
Shining a Light on a New Technique for Stealth Persistence
Facebook Bans More Than 800 Accounts in Disinformation Purge
Shocking: Hackers using Googlebots in cryptomining malware attacks
What Kanye West can teach us about passcodes
It is 2018 and the NHS is still counting the cost of WannaCry. Carry the 2, + aftermath… um… £92m
35 state attorney generals tell FCC to pull the plug on robocalls
Experian credit-freeze PINs could be revealed by a simple trick

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

Payment skimmers sneaking on to websites via third party code
This is how much the WannaCry ransomware attack cost the NHS
Threat Hunters & Security Analysts: A Dynamic Duo
Tips for minding the digital skills gap

The times they are a-changin‘, so how do you build and sharpen the skills that you need to avoid being left behind by the digital revolution? The post Tips for minding the digital skills gap appeared first on WeLiveSecurity

AMD Stages A Number Of Fixes Ahead Of Linux 4.20~5.0 – Plus Vega 20 “MGPU Fan Boost”
Arrest of top Chinese intelligence officer sparks fears of new Chinese hacking efforts

LinuxSecurity.com: Git could be made to run programs as your login if it recursivelyopened a malicious git repository.

000000 is Kanye West’s iPhone passcode
WebSphere and loathing in New York: IBM yanks buggy application server security fix from admins

LinuxSecurity.com: An update for spamassassin is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

FitMetrix Exposes Millions of Customer Details, Accessed by Criminals
New Drupalgeddon Attacks Enlist Shellbot to Open Backdoors
ThreatList: Credential Theft Spikes by Triple Digits in U.S.

LinuxSecurity.com: Magnus Klaaborg Stubman discovered a NULL pointer dereference bug in net-snmp, a suite of Simple Network Management Protocol applications, allowing a remote, authenticated attacker to crash the snmpd process (causing a denial of service).

Bloke gets six months for fixing up Russia’s US election trolls with bank accounts, fake identities

Type: Vulnerability. The Microsoft .NET Core is prone to an information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: Several security issues were fixed in Tex Live.

Major weapon systems developed by US DoD highly vulnerable to cyber attacks
Adaptable, All-in-One Android Trojan Shows the Future of Malware
UK.gov teams up with Five Eyes chums to release spotters’ guide for hacking tools
Dark web kingpin visiting US for beard competition gets 20 years in prison
Fake Adobe Flash Updates Hide Malicious Crypto Miners
Calif. Law Takes Aim at Weak IoT Passwords
Instagram tests sharing your location history with Facebook
Millions at risk from default webcam passwords
Jailbroken PS4 seller sued by Sony
In the two years since Dyn went dark, what have we learned? Not much, it appears

LinuxSecurity.com: An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

New TeleBots backdoor: First evidence linking Industroyer to NotPetya

ESET’s analysis of a recent backdoor used by TeleBots – the group behind the massive NotPetya ransomware outbreak – uncovers strong code similarities to the Industroyer main backdoor, revealing a rumored connection that was not previously proven The post New TeleBots backdoor: First evidence linking Industroyer to NotPetya appeared first on WeLiveSecurity

Mozilla grants distrusted Symantec certs a stay of execution, claims many sites yet to make switch
Update now! Microsoft fixes 49 bugs, 12 are critical
The Obama-era cyber détente with China was nice, wasn’t it? Yeah well it’s obviously over now
Mingis on Tech: Data breaches in a world of ‘surveillance capitalism’
Send in the clones: Facebook cloning revisited

As another confusing message spreads, we look at Facebook privacy, cloning, and hacking The post Send in the clones: Facebook cloning revisited appeared first on WeLiveSecurity

LinuxSecurity.com: dnsruby is a feature-complete DNS(SEC) client for Ruby. It ships the DNS Root Key Signing Key (KSK), used as trust anchor to validate the authenticity of DNS records. This update includes the latest KSK

LinuxSecurity.com: An update that contains security fixes can now be installed.

Now, watch this… Network time protocol bugs sting Juniper operating system
If you haven’t already patched your MikroTik router for vulns, then if you could go do that, that would be greeeeaat
Oh no, Xi didn’t! Chinese spymaster cuffed in Belgium, yoinked to US on aerospace snoop rap

LinuxSecurity.com: Ben Pfaff discovered that the convert_to_decimal function in the GNU Portability Library contains a heap-based buffer overflow because memory is not allocated for a trailing ‘’ character during %f processing.

Risk Level: Very Low. Type: Trojan.

Smashing Security #099: Passwords – A Smashing Security splinter (replay)
PINs and needled: Experian site blabbed codes to unlock credit accounts for fraudsters
FruityArmor APT Exploits Yet Another Windows Graphics Kernel Flaw
Who needs custom malware? ‘Govt-backed’ Gallmaker spy crew uses off-the-shelf wares

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.