Menu

Monthly Archives: November 2018

Update now! WordPress sites vulnerable to WooCommerce plugin flaw
Bruce Schneier: You want real IoT security? Have Uncle Sam start putting boots to asses
DerpTrolling game server DDoS attacker pleads guilty
Guess who’s back, back again? China’s back, hacking your friends: Beijing targets American biz amid tech tariff tiff

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A vulnerability in OpenSSL might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A buffer overflow in Python might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in X.Org X11 library, the worst of which could allow for remote code execution.

GDPR USA? ‘A year ago, hell no … More people are open to it now’ – House Rep says EU-like law may be mulled
Pentagon Draws Back the Veil on APT Malware with Sudden Embrace of VirusTotal

LinuxSecurity.com: Three vulnerabilities were discovered in Nginx, a high-performance web and reverse proxy server, which could in denial of service in processing HTTP/2 (via excessive memory/CPU usage) or server memory disclosure in the ngx_http_mp4_module module (used for server-side MP4 streaming).

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3403

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3406

LinuxSecurity.com: Several security issues were fixed in nginx.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

Cisco Accidentally Released Dirty Cow Exploit Code in Software
When your Instagram account has been hacked, how do you get it back?
‘DerpTroll’ Faces 10 Years in Prison for DDoSing Gaming Sites as a Teen
DJI Patches Forum Bug That Allowed Drone Account Takeovers
Spam-spewing IoT botnet infects 100,000 routers using five-year-old flaw
Podcast: Troy Hunt Talks Bad Passwords – and Who’s to Blame for Them
Police crack encrypted chat service IronChat and read 258,000 messages from suspected criminals
Data from “almost every Pakistani Bank” stolen & sold on the dark web
Ranting researcher publishes VM-busting zero-day without warning
Apple Modernizes Its Hardware Security with T2
Oops: Cisco accidentally released in-house Dirty COW exploit attack code with software installer

Reading Time: ~3 min.Threat researchers and other cybersecurity industry analysts spend much of their time trying to anticipate the next major malware strain or exploit with the potential to cause millions of dollars in damage, disrupt global commerce, or put individuals at physical risk by targeting critical infrastructure. However, a new Webroot survey of principals […]

Closed doors are no match for a Wi‑Fi peeping tom and a smartphone
The cyber insurance question

Prevention is the best option but people continue to search for the easiest way out The post The cyber insurance question appeared first on WeLiveSecurity

Google warning: Fix your dodgy ads within 30 days or get banned
Phone companies slammed for lousy robocall efforts
Smashing Security #103: An Instagram nightmare, crazy iPhone deaths, and election hack claims
This MIT PhD Wants to Replace America’s Broken Voting Machines with Open Source Software, Chromebook
Apache Struts vulnerability would allow system take over
‘DerpTroll’ derps into plea deal, admits DDoS attacks on EA, Steam, Sony game servers
If Shadow Home Sec Diane Abbott can be reeled in by phishers, truly no one is safe
Civil rights group says Oracles, Tapads and Experians get let off for wanton info-sucking
Spammer scum hack 100,000 home routers via UPnP vulns to craft email-flinging botnet
StatCounter fingers cache-poisoning caper for Bitcoin-slurping JavaScript hijack
HSBC suffers data breach after hackers access customers’ personal data

LinuxSecurity.com: An update for spice-server is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: The previous update of libdatetime-timezone-perl to tzdata version 2018g was incomplete due to a newly introduced rule type that this version of libdatetime-timezone-perl could not parse.

LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could result in the execution of arbitrary code, privilege escalation or information disclosure.

Vulns in online shopping toolkit WooCommerce can blast a hole in your WordPress security

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 86 fixes is now available.

Program Looks to Tap Military Vets for Cyber-Jobs

LinuxSecurity.com: Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.0.37. Please see the MariaDB 10.0 Release Notes for further details:

LinuxSecurity.com: This update includes the changes in tzdata 2018g for the Perl bindings. For the list of changes, see DLA-1363-1. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several security issues were fixed in SpamAssassin.

LinuxSecurity.com: ppp could be made to crash or bypass authentication if it received specially crafted network traffic.

LinuxSecurity.com: An update for xerces-c is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several security issues were fixed in libxkbcommon.

LinuxSecurity.com: An update for xerces-c is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Security Advisory 2. Description: Red Hat Ansible Tower 3.3.1 is now available and contains the following bug fixes:

LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Sim Swapping Crypto Stealing Hackers Arrested by Turkish Police
WordPress Flaw Opens Millions of WooCommerce Shops to Takeover
Rapidly Growing Router Botnet Takes Advantage of 5-Year-Old Flaw
New Chrome version aims to remove all ads from abusive sites

The move is part of Google’s continued clampdown on adverts that are intended to hoodwink users The post New Chrome version aims to remove all ads from abusive sites appeared first on WeLiveSecurity

StatCounter web analytics script poisoned to steal Bitcoins
Best Anonymization Tools and Techniques for 2019
Voting machine manual tells officials to reuse weak passwords
Serious XSS flaw discovered in Evernote for Windows, update now!
We don’ need no stinkin’ bounties: VirtualBox guest-to-host escape zero-day lands at GitHub
The Unprecedented Effort to Secure Election Day
The OPM hack explained: Bad security practices meet China’s Captain America
WhatsApp ‘martinelli’ warning is a hoax, don’t forward it
SMBs: We don’t want to spoil all of this article, but have you patched, taken away admin rights, made backups yet?
Dutch cops hope to cuff ‘hundreds’ of suspects after snatching server, snooping on 250,000+ encrypted chat texts

LinuxSecurity.com: An update is now available for Red Hat JBoss SOA Platform 5.3.1. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Stop us if you’ve heard this one: Remote code hijacking flaw in Apache Struts, patch ASAP

LinuxSecurity.com: The package ghostscript before version 9.25-4 is vulnerable to sandbox escape.

Hackers seed StatCounter with nasty JavaScript in elaborate Bitcoin cyber-heist caper
HSBC Data Breach Hits Online Banking Customers

LinuxSecurity.com: Several vulnerabilities were discovered in cURL, an URL transfer library. CVE-2016-7141

Android November update fixes flaws galore
ThreatList: Despite Fraud Awareness, Password Reuse Persists for Half of U.S. Consumers
HSBC now stands for Hapless Security, Became Compromised: Thousands of customer files snatched by crims

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.62, which includes additional changes. Please see the MySQL

LinuxSecurity.com: CVE-2018-18718 – CWE-415: Double Free The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

LinuxSecurity.com: NetworkManager could be made to crash or run programs if it received specially crafted network traffic.

LinuxSecurity.com: systemd-networkd could be made to crash or run programs if it received specially crafted network traffic.

LinuxSecurity.com: An update for openvswitch is now available for Fast Datapath for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Risk Level: Very Low. Type: Trojan.

Samsung, Crucial’s Flawed Storage Drive Encryption Leaves Data Exposed
U.S. Elections True Test for Facebook’s Disinformation Crackdown
From cybercrime to cyber defence: How VPNs went mainstream
Supply-chain attack on cryptocurrency exchange gate.io

Latest ESET research shows just how far attackers will go in order to steal bitcoin from customers of one specific virtual currency exchange The post Supply-chain attack on cryptocurrency exchange gate.io appeared first on WeLiveSecurity

Apache Struts Warns Users of Two-Year-Old Vulnerability
Facebook wants to reveal your name to the weirdo standing next to you
Is the US about to get a nationwide, privately owned, biometrics system?
ICO poised to fine Leave campaign and Arron Banks’ insurance biz £135,000