Menu

Monthly Archives: November 2018

Children’s apps contain an average of 7 third-party trackers, study finds
CIA’s secret online network unravelled with a Google search
On eve of US elections, Facebook blocked 115 accounts engaged in ‘coordinated inauthentic behavior’
Android fans get fat November security patch bundle – if the networks or mobe makers are kind enough to let ’em have it

LinuxSecurity.com: Several security issues were fixed in Ruby.

Online Radio Stations at Risk from Icecast Flaw
Solid state of fear: Euro boffins bust open SSD, Bitlocker encryption (it’s really, really dumb)

security update

security update

LinuxSecurity.com: Multiple security vulnerabilities were discovered in GlusterFS, a clustered file system. Buffer overflows and path traversal issues may lead to information disclosure, denial-of-service or the execution of arbitrary code.

Newsmaker Interview: Tom Kellermann on Hacking the Midterm Elections
PortSmash Side-Channel Attack Siphons Data From Intel, Other CPUs
Passwords: Here to Stay, Despite Smart Alternatives?
Another wave of Elon Musk bitcoin scams spread by verified Twitter accounts
Malware of the 1980s: Looking back at the Brain Virus and the Morris Worm

This instalment in our series of articles to mark Antimalware Day tells the stories behind two creations that are representative of the 1980s: a virus viewed as the first-ever PC virus and a worm that caused the greatest damage ever wrought by a piece of malware up to that point The post Malware of the […]

Private Facebook data from 81,000 accounts discovered on crime forum
FIFA, hacked again, is leaking like a sieve

Reading Time: ~5 min.You’re probably familiar with some of the most common requirements for creating passwords. A mix of upper and lowercase letters is a simple example. These are known as password constraints. They’re rules for how you must construct a password. If your password must be at least eight characters long, contain lower case, […]

Should company bosses face jail for mishandling your privacy?
PortSmash attack steals secrets from Intel chips on the side
FIFA Hacked Again, Gets Ready for New Stories Based on the Stolen Data
Pentagon preps cyberattack in case Russia interferes with elections
New Intel CPU Flaw Exploits Hyper-Threading to Steal Encrypted Data

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Heighten your organisation’s risk awareness at the SANS Security Awareness summit
Cyber-crooks think small biz is easy prey. Here’s a simple checklist to avoid becoming an easy victim

LinuxSecurity.com: Multiple vulnerabilities were discovered in MuPDF, a PDF, XPS, and e-book viewer which could result in denial of service or the execution of arbitrary code if malformed documents are opened.

LinuxSecurity.com: Nick Rolfe discovered multiple buffer overflows in the Icecast multimedia streaming server which could result in the execution of arbitrary code. For the stable distribution (stretch), this problem has been fixed in

Researchers find Stuxnet, Mirai, WannaCry lurking in industrial USB drives
Biggest data breach penalties for 2018
Hackers found selling private messages of 81k hacked Facebook accounts

security update

LinuxSecurity.com: Updated cimg and gmic packages fix security vulnerabilities: An issue was discovered in CImg v.220. DoS occurs when loading a crafted bmp image that triggers an allocation failure in load_bmp in CImg.h (CVE-2018-7587).

How to boost your VPN connection speed in 5 ways
iOS 12.1 passcode bypass hack discovered just few hours after its release
Google logins make JavaScript mandatory, Huawei China spy shock, Mac malware, Iran gets new Stuxnet, and more

LinuxSecurity.com: Updated java-1.8.0-openjdk packages fix security vulnerabilities: Incorrect handling of unsigned attributes in singed Jar manifests (Security, 8194534) (CVE-2018-3136).

LinuxSecurity.com: The updated packages fix security vulnerabilities: It was found that the GnuTLS implementation of HMAC-SHA-256 and HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and

LinuxSecurity.com: This update provides virtualbox 5.2.20 and fixes the following security vulnerabilities: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This

LinuxSecurity.com: Updated mediawiki packages fix security vulnerabilities: ‘$wgRateLimits’ entry for ‘user’ overrides ‘newbie’ (CVE-2018-0503). When a log event is (partially) hidden Special:Redirect/logid can link

LinuxSecurity.com: Updated gitolite package fixes security vulnerability: Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been

LinuxSecurity.com: Updated mbedtls package fixes security vulnerabilities: Fixed a vulnerability in the TLS ciphersuites based on use of CBC and SHA-384 in DTLS/TLS 1.0 to 1.2, that allowed an active network attacker to partially recover the plaintext of messages under certains conditions

LinuxSecurity.com: Dancer2 0.206000 addresses several potential security issues. There is a potential RCE with regards to Storable. Dancer2 adds session ID validation to the session engine so that session backends based on Storable can reject malformed session IDs that may lead to exploitation of the RCE. Parsing requests now uses HTTP::Entity::Parser which reduces the amount […]

LinuxSecurity.com: The python-cryptography and python-cryptography-vectors packages have been updated to version 2.3.1 and fixes the following security issue: The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to

LinuxSecurity.com: Updated axis packages fix security vulnerability: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services (CVE-2018-8032).

LinuxSecurity.com: Updated lighttpd package fixes security vulnerabilities: Potential path traversal with specific configs or in some use cases in mod_alias.

LinuxSecurity.com: Updated dnsmasq packages fix a security issue Upstream dnsmasq run as nobody user which could lead to security issue if multiple services run as this same user.

Giant ransomware bundle threatens to make malware attacks easier for crooks
Shipbuilder, defense contractor Austal reveals data breach

LinuxSecurity.com: Several vulnerabilities have been discovered in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following problems:

security update

Feds accuse Chinese firm of stealing trade secrets of US tech giant
30 spies dead after Iran cracked CIA comms network with, er, Google search – new claim
Facebook Blames Malicious Extensions in Breach of 81K Private Messages
PortSmash attack punches hole in Intel’s Hyper-Thread CPUs, leaves with crypto keys
Web domain owners paid EasyDNS to cloak their contact info from sight. It was blabbed via public Whois anyway

LinuxSecurity.com: Several security issues were fixed in curl.

LinuxSecurity.com: tzdata upstream released version 2018g. Notables changes since 2018e (previous version available in jessie)

Cisco Security Appliance Zero-Day Found Actively Exploited in the Wild
ThreatList: Fewer Big DDoS Attacks in Q3, Overall Rate Holds Steady
Another day, another update, another iPhone lockscreen bypass
Popular browsers made to cough up browsing history
Antimalware Day: The evolution of malicious code

Celebrated annually on November 3, Antimalware Day is an opportunity to recognize the work of cybersecurity professionals The post Antimalware Day: The evolution of malicious code appeared first on WeLiveSecurity

Google’s stealthy sign-in sentry can pick up pilfered passwords

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2018-5179

What’s that? SSH can still use RC4? Not for much longer, promise
Report reveals one-dimensional support for two-factor authentication
BBC micro:bit vendor Kitronik says customers’ deets nicked, fingers Magecart malware
I know what you’re thinking: Outsource or in-source IT security? I’ve worked both sides, so here’s my advice…

Reading Time: ~2 min.DemonBot Botnet Gaining Traction DemonBot, while not the most sophisticated botnet discovered to date, has seen a significant rise in usage over the last week. With the ability to take control of Hadoop cloud frameworks, DemonBot has been using the platform to carry out DDoS attacks across the globe. By exploiting Hadoop’s […]

security update

Yi IoT Home Camera Riddled with Code-Execution Vulnerabilities
GDPR’s First 150 Days Impact on the U.S.

LinuxSecurity.com: The package linux-lts before version 4.14.75-1 is vulnerable to denial of service.

LinuxSecurity.com: The package linux before version 4.18.13.arch1-1 is vulnerable to denial of service.

LinuxSecurity.com: It was discovered that there was a cross-site scripting (XSS) vulnerability in phpldapadmin, a web-based interface for administering LDAP servers. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: OpenJDK: Improper field access checks (Hotspot, 8199226) (CVE-2018-3169) * OpenJDK: Incomplete enforcement of the trustURLCodebase restriction (JNDI, 8199177) (CVE-2018-3149) * OpenJDK: Incorrect handling of unsigned attributes in signed Jar manifests (Security, 8194534) (CVE-2018-3136) * OpenJDK: Leak of sensitive header data via HTTP redirect (Networking, 8196902) (CVE-2018-3139) * OpenJ [More…]

Radisson Hotel Group reveals breach of rewards site
Utilities, Energy Sector Attacked Mainly Via IT, Not ICS
PoC Exploit Compromises Microsoft Live Accounts via Subdomain Hijacking
Eurostar resets customers’ passwords after accounts breached
Two Zero-Day Bugs Open Millions of Wireless Access Points to Attack
IT Wi-Fi kit bit by TI chip slip: Wireless gateways open to hijacking via BleedingBit chipset vuln
Smashing Security #102: Ethical dilemmas, Girl Scouts, and porn-loving US officials
New AI system DARKMENTION will detect upcoming cyberattacks from dark web
Passcodes are protected by Fifth Amendment, says court
Facebook is still approving fake political ads
Update now! Apple releases security fixes for iOS, MacOS, Safari, others
US indicts alleged Chinese spies for hacking aerospace companies
RoboCops: AI on the rise in policing to predict crime and uncover lies
Feds: Chinese spies orchestrated massive hack that stole aviation secrets
Spooking the C-Suite: The Ephemeral Specter of Third-Party Cyber-Risk
GDPR Alert as Average ICO Fines Double in a Year
Welcome back, ‘ping of death’, it has been… a few months. Now it’s Apple’s turn to do the patching
£220k fines for dodgy dialling duo who didn’t do due dil on data