Menu

Monthly Archives: November 2018

LinuxSecurity.com: Several security issues were fixed in WebKitGTK+.

Risk Level: Very Low. Type: Trojan, Worm.

Widespread Malvertising Campaign Hijacks 300 Million Sessions
Microsoft patches Patch Tuesday’s Outlook 2010 problem patch
More details on One Planet York app vulnerability doesn’t paint council in a good light
Google Maps scammers put their own phone numbers onto bank listings
When the FBI rather than the fraudsters make the fake FedEx website
LinkedIn rapped for targeting ads at 18 million Facebook users
German chat site faces fine under GDPR after data breach

The country’s first fine under GDPR is lower than might have been expected, however, as the company was acknowledged for its post-incident cooperation and enhanced security measures The post German chat site faces fine under GDPR after data breach appeared first on WeLiveSecurity

Baroness Trumpington, former Bletchley Park clerk, dies aged 96

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

Parents slam “weirdo” fraudsters for using child’s Facebook pic for cash
Uber fined £385k by ICO for THAT hack of 57m customers’ deets
Sacked NCC Group grad trainee emailed 300 coworkers about Kali Linux VM ‘playing up’

LinuxSecurity.com: An update for rh-nginx114-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-nginx112-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-dotnet21-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Oz opposition caves, offers encryption backdoor compromise

LinuxSecurity.com: A vulnerability in spice-gtk could allow an attacker to remotely execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Libav, the worst of which may allow a Denial of Service condition.

LinuxSecurity.com: A vulnerability in Tablib might allow remote attackers to execute arbitrary python commands.

LinuxSecurity.com: Multiple vulnerabilities have been found in Binutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for NetworkManager is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for sos-collector is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Risk Level: Very Low. Type: Trojan, Worm.

Did UK city council over-react to a vulnerability report in its recycling app or not?
Knuddels Flirt App Slapped with Hefty Fine After Data Breach
Check your repos… Crypto-coin-stealing code sneaks into fairly popular NPM lib (2m downloads per week)
Mobile Rotexy Malware Touts Ransomware, Banking Trojan Functions
USPS, Amazon Data Leaks Showcase API Weaknesses
User Confidence in Smartphone Security Abysmal

Reading Time: ~5 min.‘Tis the season of giving, which means scammers may try to take advantage of your good will. A surprising fact about American donation habits is that everyday folks like yourself are the single largest driver of charitable donations in the United States. Giving USA’s Annual Report on Philanthropy found that individuals gave […]

Bedroom design outfit slapped with £160k fine for 1.6 million spam calls
Bug Bounty: Earn $40,000 for hacking Facebook, Instagram or WhatsApp
Man arrested for stealing $1m from Silicon Valley Exec via SIM-swapping
L0rdix malware on dark web steals data, mines crypto & enslaves PCs as botnet
Adult video game website High Tail Hall hacked; user data stolen

LinuxSecurity.com: An update for rh-mysql57-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-nginx110-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

That Black Mirror episode with the social ratings? It’s happening IRL

LinuxSecurity.com: An update for rh-nginx18-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The phone went dark, then $1m was sucked out in SIM-swap crypto-heist
Spectre mitigation guts Linux 4.20 performance
The frustratingly simple techniques of ‘human hacking’ – and how to fight them
LinkedIn violated data protection by using 18M email addresses of non-members to buy targeted ads on
Smartphone shopping: Avoid the blues on Cyber Monday

As we increasingly make use of our smartphones to satisfy our shopping needs, let’s shine a light on how these hubs of our digital lives can be used to shop securely, on and around a day dedicated to online deals The post Smartphone shopping: Avoid the blues on Cyber Monday appeared first on WeLiveSecurity

Tighten up your security defences at SANS London 2019

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: gnuplot5, a command-line driven interactive plotting program, has been examined with fuzzing by Tim Blazytko, Cornelius Aschermann, Sergej Schumilo and Nils Bars.

security update

Hacker takeovers Drake’s Fortnite account to yell racial slurs
DoS Vulnerabilities Found in Linux Kernel, Unpatched
Security News This Week: Amazon Won’t Say How Many Customer Emails It

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: A vulnerability in xml-security-c, a library for the XML Digital Security specification, has been found. Different KeyInfo combinations, like signatures without public key, result in incomplete DSA structures that

LinuxSecurity.com: Multiple vulnerabilities have been found in Exiv2, the worst of which could result in a Denial of Service condition.

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Thunderbird, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in GPL Ghostscript, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Asterisk, the worst of which could result in a Denial of Service condition.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Spotify Phishers Hijack Music Fans’ Accounts
Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
Mirai Evolves From IoT Devices to Linux Servers
Threatpost News Wrap Podcast for Nov. 23

LinuxSecurity.com: USN-3801-1 caused some minor regressions in Firefox.

LinuxSecurity.com: Two security vulnerabilities were discovered in OTRS, a Ticket Request System, that may lead to privilege escalation or arbitrary file write. CVE-2018-19141

LinuxSecurity.com: It was discovered that a buffer overflow in liveMedia, a set of C++ libraries for multimedia streaming could result in the execution of arbitrary code when parsing a malformed RTSP stream.

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: CVE-2015-5297 Numerical overflow in pointer arithmetic.

LinuxSecurity.com: mod_perl could be made to run programs contrary to expectations.

Old Printer Vulnerabilities Die Hard
‘Cuddly’ German chat app slacking on hashing given a good whacking under GDPR: €20k fine
ThreatList: One-Third of Firms Say Their Container Security Lags
Cryptocurrency ‘minting’ flaw could have leached money from exchanges
Hacker says USPS ignored serious security flaw for over a year
Apache Hadoop spins cracking code injection vulnerability YARN

LinuxSecurity.com: The package webkit2gtk before version 2.22.4-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package flashplugin before version 31.0.0.153-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-libtiff before version 4.0.10-1 is vulnerable to multiple issues including arbitrary code execution, denial of service and information disclosure.

LinuxSecurity.com: It was discovered that there were two vulnerabilities libphp-phpmailer, an email library for the PHP programming language: * CVE-2017-5223: Local file disclosure vulnerability via relative path

LinuxSecurity.com: A critical vulnerability in Adobe Flash Player 31.0.0.148 and earlier versions. Successful exploitation could lead to arbitrary code execution in the context of the current user. (CVE-2018-15981) References:

LinuxSecurity.com: In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. (CVE-2018-16646) An issue was discovered in Poppler 0.71.0. There is a reachable abort in

LinuxSecurity.com: The ghostscript 9.26 update is focusing on security issues, including solving several (well publicised) real and potential exploits. For other fixes in this release, see the referenced News.

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, incomplete TLS identity verification, information disclosure or the execution of arbitrary code.

LinuxSecurity.com: mod_perl could be made to run programs contrary to expectations.

LinuxSecurity.com: Several security vulnerabilities were discovered in the JasPer JPEG-2000 library. CVE-2015-5203

LinuxSecurity.com: It was discovered that there was an XSS vulnerability in the ruby-rack web-server library. A malicious request could impact the HTTP/HTTPS scheme being returned

Laptop search unravels scheme to fake death for insurance cash
The passwordless web explained
Who needs passwords? Microsoft now lets you in with your face or security key

The software giant takes passwords one step closer to obsolescence as it now enables users to log into their Microsoft accounts with more modern forms of authentication The post Who needs passwords? Microsoft now lets you in with your face or security key appeared first on WeLiveSecurity