Menu

Monthly Archives: November 2018

SIM swap! Man charged after million dollar cryptocurrency theft
Zero-Trust Frameworks: Securing the Digital Transformation
Facebook appeals ?500,000 penalty over Cambridge Analytica scandal
USPS finally fixes website flaw that exposed 60 million users’ data
Update now! Adobe Flash has another critical security vulnerability
Podcast: Breaking Down the Magecart Threat (Part One)
German e-government SDK patched against ID spoofing vulnerability
Reddit helps admin solve mystery of rogue Raspberry Pi
Dutton leans on encryption laws committee to hurry up
Real Identity of Hacker Who Sold LinkedIn, Dropbox Databases Revealed
As Black Friday Looms, IoT Gadgets Take the Risk Spotlight
Malware scum want to build a Linux botnet using Mirai
Smashing Security #105: Facebook, Nietzsche, Tesla, and Nicole

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: CVE-2018-0735 Samuel Weiser reported a timing vulnerability in the OpenSSL ECDSA signature generation, which might leak information to recover the

LinuxSecurity.com: The update for ceph issued as DSA-4339-1 caused a build regression for the i386 builds. Updated packages are now available to address this issue. For reference, the original advisory text follows.

Talk in Trump’s tweets tells whether tale is true: Code can mostly spot Prez lies from wording
Podcast: Why ‘Throwing Money’ at Threats Won’t Work
FCC Addresses Robocalling – But Questions Remain

LinuxSecurity.com: An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt. (CVE-2018-18751)

LinuxSecurity.com: This is a service release to update the stable version 1.3 of Roundcube Webmail. It contains fixes to several bugs backported from the master branch including a security fix for a reported XSS vulnerability (in handling invalid style tag content) plus updates to ensure compatibility with PHP 7.3 and recent versions of Courier-IMAP, Dovecot […]

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3409

Emotet’s Thanksgiving Campaign Delivers New Recipes for Compromise
Amazon warns customers it leaked their names and email addresses
3 is the magic number (of bits): Flip ’em at once and your ECC protection has been Rowhammer’d
High Tail Hall data breach exposes over 400,000 furry fans
Hackers target critical WordPress plugin flaw to install backdoors and create admin accounts
Microsoft’s MFA is so strong, it locked out users for 8 hours

Reading Time: ~4 min.As digital natives become more immersed in and dependent upon technology, they are likely to experience “cyber fatigue,” which can be thought of cybersecurity complacency. Paired with the invincible feeling that often accompanies being young, this can be a dangerous combination. It’s easy to mistakenly believe that hacked devices and identity theft […]

Technical foul: Amazon suffers data snafu days before Black Friday, emails world+dog

LinuxSecurity.com: Red Hat OpenShift Container Platform release 3.7.72 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Fancy Bear hacker crew Putin dirty RATs in Word documents emailed to govt orgs – report
Hackers erase 6,500 sites from the Dark Web in one attack
7 container security tools to lock down Docker and Kubernetes
Drone owner fined for putting police helicopter crew ‘in danger’
New era for Japan, familiar problems: Microsoft withdraws crash-tastic patches
Two Brits jailed for TalkTalk hack

The breach exposed the personal data of 160,000 people and cost the telecom company £77 million The post Two Brits jailed for TalkTalk hack appeared first on WeLiveSecurity

When selling security awareness training by email, probably a good shout not to hit ‘reply all’

LinuxSecurity.com: It was discovered that there was a remote denial-of-service vulnerability in ruby-i18n, a I18n and localization solution for Ruby. An application crash could be engineering a situation where `:some_key` is

Talk about a cache flow problem: This JavaScript can snoop on other browser tabs to work out what you’re visiting
If you’re using Dell EMC Avamar, even in VMware’s vSphere, you need to grab and install these security updates
Infosec’s Thanksgiving turkey triumvirate: Tesla, Tumblr, Trump (as in Ivanka)… and tons more
Australia’s ‘snoop minister’ wants crypto-busting law probe wound up, proposals back into parliament
Sofacy APT Takes Aim with Novel ‘Cannon’ Trojan

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 18 vulnerabilities is now available.

What the #!/%* is that rogue Raspberry Pi doing plugged into my company’s server room, sysadmin despairs

LinuxSecurity.com: A stack based buffer overflow vulnerability was found in liblivemedia, the LIVE555 RTSP server library. This issue might be leveraged by remote attackers to cause code execution, by sending a crafted packet.

LastPass? More like lost pass. Or where the fsck has it gone pass. Five-hour outage drives netizens bonkers

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.

Critical Adobe Flash Bug Impacts Windows, macOS, Linux and Chrome OS

security update

Did you hear? There’s a critical security hole that lets web pages hijack computers. Of course it’s Adobe Flash’s fault
Gmail Glitch Enables Anonymous Messages in Phishing Attacks
APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign

LinuxSecurity.com: The package grafana before version 5.3.4-1 is vulnerable to arbitrary filesystem access.

Sednit: What’s going on with Zebrocy?

In August 2018, Sednit’s operators deployed two new Zebrocy components, and since then we have seen an uptick in Zebrocy deployments, with targets in Central Asia, as well as countries in Central and Eastern Europe, notably embassies, ministries of foreign affairs, and diplomats. The post Sednit: What’s going on with Zebrocy? appeared first on WeLiveSecurity

OceanLotus: New watering hole attack in Southeast Asia

ESET researchers identified 21 distinct websites that had been compromised including some particularly notable government and media sites The post OceanLotus: New watering hole attack in Southeast Asia appeared first on WeLiveSecurity

Every day is Black Friday
Patch Skype for Business now or risk DoS via emoji kittens!
Update now! Dangerous AMP for WordPress plugin fixed
Two friends jailed for TalkTalk hack plot

LinuxSecurity.com: It was discovered that mishandled search requests in servers/slapd/search.c:do_search() in 389-ds-base allows for denial of service (CVE-2018-14648). References:

LinuxSecurity.com: mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user’s credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example,

LinuxSecurity.com: Assertion failure in BPMDetect class in BPMDetect.cpp (CVE-2018-17096). Out-of-bounds heap write in WavOutFile::write() (CVE-2018-17097). Heap corruption in WavFileBase class in WavFile.cpp (CVE-2018-17098). References:

Texas hospital becomes victim of Dharma ransomware
Russian hacker arrested in Bulgaria for ad fraud of over $7 million
Security warning: UK critical infrastructure still at risk from devastating cyber attack

LinuxSecurity.com: Multiple vulnerabilities have been discovered in uriparser, an Uniform Resource Identifiers (URIs) parsing library.

Germany pushes router security rules, OpenWRT and CCC push back
Instagram accidentally reveals plaintext passwords in URLs

LinuxSecurity.com: The package chromium before version 70.0.3538.110-1 is vulnerable to information disclosure.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec. CVE-2017-17480

TalkTalk hackhack duoduo thrownthrown in the coolercooler: ‘Talented’ pair sentenced for ransacking ISP
From directory traversal to direct travesty: Crash, hijack, siphon off this TP-Link VPN box via classic exploitable bugs

LinuxSecurity.com: Red Hat OpenShift Container Platform release 3.9.51 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Linux kernel Spectre V2 defense fingered for massively slowing down unlucky apps on Intel Hyper-Thread CPUs

LinuxSecurity.com: systemd was found to suffer from multiple security vulnerabilities ranging from denial of service attacks to possible root privilege escalation.

Olympic Destroyer Wiper Changes Up Infection Routine

LinuxSecurity.com: systemd-tmpfiles could be made to change ownership of arbitrary files.

LinuxSecurity.com: Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.1.37. Please see the MariaDB 10.1 Release Notes for further details:

VisionDirect Blindsided by Magecart in Data Breach
Unlock the power of threat intelligence with this practical guide. Get your free copy now
Symantec execs cooked the books to protect their fat bonuses, investor lawsuit alleges
Ford Eyes Use of Customers’ Personal Data to Boost Profits
Multi-factor failure locks out Microsoft Office 365 and Azure users
Vision Direct hack reveals customer credit card details
Stopping the Infiltration of Things
Cryptojacking Attack Targets Make-A-Wish Foundation Website
Britain may not be able to fend off a determined cyber-attack, MPs warn
Vision Direct ‘fesses up to hack that exposed customer names, payment cards
Cybersecurity a big concern in Canada as cybercrime’s impact grows

90% of Canadians surveyed agreed that cybercrime was an important “challenge to the internal security of Canada” The post Cybersecurity a big concern in Canada as cybercrime’s impact grows appeared first on WeLiveSecurity

Mozilla’s IoT gift guide ranks gadgets from secure to shoddy
Scumbags cram Make-A-Wish website with coin-mining malware