Menu

Monthly Archives: October 2018

CEO pleads guilty of conspiring with drug cartels to sell them stealthy Blackberrys

LinuxSecurity.com: Two security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code inside the sandboxed content process.

Virus Bulletin 2018: Microsoft’s Lambert on How Cloud is Changing Security

LinuxSecurity.com: Several security vulnerabilities were discovered in ImageMagick, an image manipulation program, that allow remote attackers to cause denial of service (application crash, excessive memory allocation, or other

Hackers are holding Instagram accounts of influencers for ransom
You dirty DRAC: IT bods uncover Dell server firmware security slip
Facebook Breach Sparks Concerns Around Third-Party Apps, Website Security
Fortnite players beware: New data stealing malware disguised as cheat tool

LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Artificial Intelligence: A Cybersecurity Tool for Good, and Sometimes Bad
Pumping the Brakes on Artificial Intelligence

LinuxSecurity.com: Several security issues were fixed in Liblouis.

Facebook: No evidence attackers used stolen access tokens on third-party sites

The social networking behemoth is expected to face a formal investigation by Ireland’s Data Protection Commission in what could be the “acid test” of GDPR since the law became effective in May The post Facebook: No evidence attackers used stolen access tokens on third-party sites appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in WebKitGTK+.

NSA staffer takes top-secret hacking tools home ‘to study’, gets 66 months
Update now: Adobe fixes 85 serious flaws in Acrobat and Reader
‘Desperate’ North Korea turns to APT hack attacks for cash
Hacked Fortnite accounts and rent-a-botnet being pushed on Instagram
Google’s new rules for developers make Chrome extensions safer for all
IT forensic tools: How to find the right one for each incident

Some online resources that will help you find the most suitable IT forensic tools for each case The post IT forensic tools: How to find the right one for each incident appeared first on WeLiveSecurity

Google is still chasing the self-driving engineer that jumped ship to Uber

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Foxit PDF Reader Fixes High-Severity Remote Code Execution Flaws

security update

LinuxSecurity.com: Security fix for CVE-2018-17294

LinuxSecurity.com: This is an update to Mozilla’s CA certificates list version 2.26, which has been published as part of Mozilla NSS 3.39. For additional details, please refer to the NSS 3.39 release notes: https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes

LinuxSecurity.com: – Update to bind-9.11.4-P2 – Add /dev/urandom to chroot (#1631515) – Fix multilib conflicts of devel package – Add support for OpenSSL provided random data

LinuxSecurity.com: Add few patches from Kurt Roeckx

LinuxSecurity.com: 4.1.5 GA —- 4.1.4 GA Security Fix for CVE-2018-10904 Security Fix for CVE-2018-10907 Security Fix for CVE-2018-10911 Security Fix for CVE-2018-10913 Security Fix for CVE-2018-10914 Security Fix for CVE-2018-10923 Security Fix for CVE-2018-10926 Security Fix for CVE-2018-10927 Security Fix for CVE-2018-10928 Security Fix for CVE-2018-10929 Security Fix for CVE-2018-10930 —- missing

LinuxSecurity.com: Update to 1.8.14, which includes fix for CVE-2018-14645.

NOKKI Malware Sports Mysterious Link to Reaper APT Group

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Google Patches Critical Vulnerabilities in Android OS
Keyloggers Turn to Zoho Office Suite in Droves for Data Exfiltration
Google Cracks Down on Malicious Chrome Extensions in Major Update
ThreatList: Password Hygiene Remains Lackluster in Global Businesses
Even with the latest iOS 12 update, your iPhone’s lockscreen is unsafe
Hackers demand ransom from hijacked Instagram influencers
Why keeping your cyber-wits about you matters

WeLiveSecurity is happy to support the European Cyber Security Month (ECSM) with its own “two cents”, split into four articles over the course of October that will be dedicated to promoting the campaign’s goals The post Why keeping your cyber-wits about you matters appeared first on WeLiveSecurity

LinuxSecurity.com: An update that solves 5 vulnerabilities and has four fixes is now available.

Lock screen bypass already discovered for Apple’s iOS 12
Linux 4.19-rc6 Kernel Released By Greg KH
Tesco Bank Fined ?16m After 2016 Cyber Heist
The Right Diagnosis: A Cybersecurity Perspective
Suspect forced to unlock iPhone with his face
MIMEsweeper maker loses UK High Court patent fight over 15-year-old bulletin board post
Students swap data for coffee at cashless cafe
Ever used an airport lounge printer? You probably don’t know how blabby they can be
100,000 home routers recruited to spread Brazilian hacking scam
Haven’t updated your Adobe PDF software lately? Here’s 85 new reasons to do it now
Boffin: Dump hardware number generators for encryption and instead look within
Adobe Patches 47 Critical Flaws in Acrobat and DC

LinuxSecurity.com: The package lib32-libxml2 before version 2.9.8-4 is vulnerable to denial of service.

LinuxSecurity.com: The package libxml2 before version 2.9.8-5 is vulnerable to denial of service.

LinuxSecurity.com: The package libxml2 before version 2.9.8-5 is vulnerable to denial of service.

LinuxSecurity.com: The package ntp before version 4.2.8.p12-1 is vulnerable to arbitrary code execution.

Desktop Telegram users showing off not only their silly selfies but also their IP addresses

LinuxSecurity.com: An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Nine NAS Bugs Open LenovoEMC, Iomega Devices to Attack
California, U.S. Government Battle Over Net Neutrality State Law
Telegram leaked IP addresses of its desktop app users
How to have that difficult “stay safe online” conversation with your kids
50 million Facebook users affected in breach

It has yet to be determined whether the accounts were misused or what information was accessed. In the meantime, you can improve your account security with a few easy steps The post 50 million Facebook users affected in breach appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in Ghostscript.

Financial Conduct Authority fines Tesco Bank £16.4m over 2016 security breach

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

Dark Web Azorult Generator Offers Free Binaries to Cybercrooks
You gave your number to Facebook for security and it used it for ads
Monero fixes major ‘burning bug’ flaw, preventing mass devaluation
Two reasons to reconsider your Facebook membership

LinuxSecurity.com: Firefox 60 is now the only supported version of the ESR series and it brings a completely new browser engine, designed to take full advantage of the processing power in modern devices. Firefox also now exclusively supports extensions built using the WebExtension API.

UK ruling party’s conference app editable by world+dog, blabs members’ digits
How to enforce SSL in ASP.Net Core
Top tips for protecting your Smart TV

The final few months of 2018 will likely be a busy time of year for people and cybercriminals will be no different as they continue to look for weak spots in networks The post Top tips for protecting your Smart TV appeared first on WeLiveSecurity

Free buyer’s guide to evaluating fraud detection & prevention tools
Location, location, location… technologies under the microscope
AI-powered IT security seems cool – until you clock miscreants wielding it too

security update