Menu

Monthly Archives: October 2018

Google chose not to go public about bug that exposed Google Plus users’ data
Assassin’s Creed Odyssey suffers DDoS attack at launch
Department of Homeland Security and GCHQ back Apple and Amazon’s denials they were hacked by China
Unpatched routers bad, doubly unpatched routers worse – much, much worse!
Remember that lost memory stick from Heathrow Airport? The terrorist’s wet dream? So does the ICO
Most routers full of firmware flaws that leave users at risk

If you own a Wi-Fi router, it may well be riddled with security holes that expose you to a host of threats The post Most routers full of firmware flaws that leave users at risk appeared first on WeLiveSecurity

The Leading Linux Desktop Platform Issues Of 2018
Amazon employee shared email addresses with third-party seller
Which? That smart home camera? The one with the vulns? Really?
Attackers use voicemail hack to steal WhatsApp accounts
Phantom Secure CEO sold encrypted phones to drug cartels
Seven Russian cyberspies indicted for hacking, wire fraud, ID theft

LinuxSecurity.com: An update for rh-haproxy18-haproxy is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Fitbit data leads to arrest of 90-year-old in stepdaughter’s murder

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Intel’s commitment to making its stuff secure is called into question
PoC Attack Escalates MikroTik Router Bug to ‘As Bad As It Gets’

LinuxSecurity.com: Due to multiple vulnerabilities in various coders used by ImageMagick, Gentoo Linux now installs a policy.xml file which will restrict coder usage by default. [More…]

LinuxSecurity.com: A vulnerability in OpenSSH might allow remote attackers to determine valid usernames.

LinuxSecurity.com: Multiple vulnerabilities have been found in SoX, the worst of which may lead to a Denial of Service condition.

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 20 vulnerabilities is now available.

Why Facebook Loves Open-Source Firmware
Russia’s elite hacking unit has been silent, but busy
US Indicts 7 Russian Intel Officers for Hacking Anti-Doping Organizations

security update

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

Silk Road Admin Pleads Guilty- Might Receive 20 Years Jail Time
SAP bug beatdowns, Apple gets nasty with Mac repairs, Struts woe, and more from infosec
Sony Smart TV Bug Allows Remote Access, Root Privileges

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
What could be more embarrassing for a Russian spy: Their info splashed online – or that they drive a Lada?

LinuxSecurity.com: joernchen of Phenoelit discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability via a specially crafted .gitmodules file in a project cloned with –recurse-submodules.

LinuxSecurity.com: joernchen of Phenoelit discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability via a specially crafted .gitmodules file in a project cloned with –recurse-submodules.

D-Link Patches RCE Bugs in Wireless Access Point Gear

LinuxSecurity.com: Security fix for CVE-2018-17336

LinuxSecurity.com: Security fix for CVE-2018-16435

LinuxSecurity.com: Security fix for CVE-2018-10897

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Threatpost New Wrap Podcast For Oct. 5
Virus Bulletin 2018: Exposing the Social Media Fraud Ecosystem
BEC-as-a-service offers hacked business accounts for as little as $150
Hackers exploit Bitcoin bug to print 235 million Pigeoncoins
Don’t ever use a VPN without paying attention to these five things
Virus Bulletin 2018: Supply chain hacking grows up

Striking the balance between supply, demand and safety is a major concern The post Virus Bulletin 2018: Supply chain hacking grows up appeared first on WeLiveSecurity

LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.

Prison smuggler busted by his own drone camera

LinuxSecurity.com: An update that fixes 10 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

Chinese tech titans’ share prices slump after THAT Super Micro story
Wi-Fi versions to get names people can actually understand
Malware Outbreak Causes Disruptions, Closures at Canadian Restaurant Chain
This dark web market is dedicated to compromising your emails
The State Of LinuxBoot For Replacing Proprietary UEFI Firmware With The Linux Kernel
Burgerville customer credit card info stolen in data breach laid at Fin7’s feet
Facebook doubles cooling off period to cash in on your FOMO
Man the harpoons: The KRACK-en reawakens in updated WPA2 attack
Google’s Intra app secures older Androids with encrypted DNS
Make it a cyber-habit: Five simple steps to staying safe online

What are some essential steps you can take to increase your online safety – now and in the long run? The post Make it a cyber-habit: Five simple steps to staying safe online appeared first on WeLiveSecurity

Cloud misconfiguration: The security threat too often overlooked

Reading Time: ~2 min.Brazilian Bank Traffic Rerouted by Massive Botnet A botnet containing more than 100,000 routers and other devices was recently spotted hijacking traffic destined for several Brazilian banks. The hijacking victims are then sent to one of at least 50 confirmed phishing sites that will attempt to steal any information the user will […]

The weekend starts here… right after you’ve installed these critical Cisco bug patches
The fur is not gonna fly: Uncle Sam charges seven Russians with Fancy Bear hack sprees
China accused of sabotaging thousands of servers at major US companies with tiny microchips hidden on motherboards

LinuxSecurity.com: Use a more restrictive blacklist in several policy abstractions.

LinuxSecurity.com: Several security issues were fixed in ImageMagick.

Decoding the Chinese Super Micro super spy-chip super-scandal: What do we know – and who is telling the truth?
Dutch cheesed off with Russians, expel four suspects over chemical weapons Wi-Fi spying
Smashing Security #098: A Facebook omnishambles

security update

ThreatList: 83% of Routers Contain Vulnerable Code

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Virus Bulletin 2018: Turla APT Changes Shape with New Code and Targets
Whose line of attack is it anyway? Cyber-assault whodunnits harder than ever to solve
Chinese surveillance chips found in servers used by US technology giants: Report

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

Apple, Amazon Strongly Refute Server Infiltration Report
UK pins ‘reckless campaign of cyber attacks’ on Russian military intelligence
Why ask the public about cybercrime and cybersecurity?

Answers could help raise awareness of situations that people fear The post Why ask the public about cybercrime and cybersecurity? appeared first on WeLiveSecurity

LinuxSecurity.com: dnsmasq, a DNS forwarder and DHCP server, ships the DNS Root Zone Key Signing Key (KSK), used as the DNSSEC trust anchor. ICANN will rollover the KSK in 11 October 2018, and DNS resolvers will need the new key

Sendgrid blurts out OWN customers’ email addresses with no help from hackers
Virus Bulletin 2018: Attack velocity ramps up

Some tips for helping to keep your data more secure from the floor of VB 2018 The post Virus Bulletin 2018: Attack velocity ramps up appeared first on WeLiveSecurity

Setting up a Mac for young children
Big Data and Cybersecurity: Opportunity or Threat?
Cop charged with selling phone tracking service on dark web
Facebook finds “no evidence” attackers accessed third-party apps

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Virus Bulletin 2018: macOS Flaw Allows Attackers to Hijack Installed Apps
Apple forgot to lock Intel Management Engine in laptops, so get patching

LinuxSecurity.com: The package python-django before version 2.1.2-1 is vulnerable to information disclosure.

Cloud, Containers, Orchestration Big Factors in BSIMM9

LinuxSecurity.com: Several security issues were fixed in the Apache HTTP Server.