Menu

Monthly Archives: December 2018

India authorizes 10 agencies to intercept, monitor, and decrypt citizens’ data
Facebook suspends accounts for pushing false info in Alabama election

LinuxSecurity.com: Fix low-severity CVE-2018-20217 (an authenticated user who can obtain a TGT using an older encryption type (DES, DES3, or RC4) can cause an assertion failure in the KDC by sending an S4U2Self request.)

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: Version update + Security fix for CVE-2018-19131 and CVE-2018-19132

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has 5 fixes is now available.

LinuxSecurity.com: **MariaDB C / C++ connector** Release notes: https://mariadb.com/kb/en/library/mariadb-connector-c-307-release-notes/ Maintainer notes: Marking as a security update, beacuse of fixed resource leaks. Moving libmariadb pkgconfig file to this package from mariadb- devel. Test with MariaDB-3:10.2.19-2

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in Go, the worst which could lead to the execution of arbitrary code.

Anonymous social network Blind left user data exposed
Researcher publishes proof-of-concept code for creating Facebook worm
New email extortion scam warns “Pay $4,000 or a hitman is coming for you”
China hacked the US Navy and stole personal info on at least 100K sailors
Iranian APT Group Pegged for Shamoon Disk Wiping Attacks
Caribou Coffee Card Breach Hits 265 Stores

LinuxSecurity.com: New netatalk packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more

LinuxSecurity.com: **MariaDB 10.3.11** Release notes: https://mariadb.com/kb/en/mariadb-10311-release-notes/ CVEs fixed: CVE-2018-3282 CVE-2016-9843 CVE-2018-3174 CVE-2018-3143 CVE-2018-3156 CVE-2018-3251 CVE-2018-3185 CVE-2018-3277 CVE-2018-3162 CVE-2018-3173 CVE-2018-3200 CVE-2018-3284

LinuxSecurity.com: Security experts at Tencent’s Blade security team have discovered a critical vulnerability in SQLite database software (nicknamed “Magellan”).

LinuxSecurity.com: Daniel Axtens discovered a double-free and use-after-free vulnerability in libarchive’s RAR decoder that can result in a denial-of-service (application crash) or may have other unspecified impact when a malformed RAR archive is processed.

LinuxSecurity.com: This kernel update is based on the upstream 4.14.89 and fixes atleast the following security issues: Cross-hyperthread Spectre v2 mitigation is now provided by the Single Thread Indirect Branch Predictors (STIBP) support. Note that STIBP also

security update

LinuxSecurity.com: Update to 4.2.5

LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit sqlite rebased to version 3.26.0 per: https://sqlite.org/releaselog/3_26_0.html spatialite-tools rebuilt for latest sqlite version

LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit sqlite rebased to version 3.26.0 per: https://sqlite.org/releaselog/3_26_0.html spatialite-tools rebuilt for latest sqlite version

LinuxSecurity.com: Upstream announcement: The phpMyAdmin team is pleased to announce the release of **phpMyAdmin version 4.8.4**. Among other bug fixes, this contains several important security fixes. The security fixes involve: * Local file inclusion (https://www.phpmyadmin.net/security/PMASA-2018-6/), * XSRF/CSRF vulnerabilities allowing a specially-crafted URL to perform harmful operations

FBI Denies Service to 15 DDoS-for-Hire Sites, Charges Operators
More phishing attacks on Yahoo and Gmail SMS 2FA authentication

Reading Time: ~5 min. The cybersecurity landscape is in constant flux, keeping our team busy researching the newest threats to keep our customers safe. As the new year approaches, we asked our cybersecurity experts to predict which security trends will have the most impact in 2019 and what consumers should prepare for. Continued Growth of […]

Caribou Coffee, Bruegger’s Bagels Bitten by Months-Long Breach
SPARE: Five tips for a safer online shopping experience

There is still some time left to pick up some last-minute shopping before it’s too late but in the rush to do so don’t forget to do it safely The post SPARE: Five tips for a safer online shopping experience appeared first on WeLiveSecurity

Microsoft gets users test driving Patch Tuesday’s non-security updates

Reading Time: ~2 min. Facebook API Bug Reveals Photos from 6.8 Million Users Facebook announced this week that an API bug had been found that allowed third-party apps to access all user photos, rather than only those posted to their timeline. The vulnerability was only available for 12 days in mid-September, but could still impact […]

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for netatalk fixes the following issues: Security issue fixed:

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. Description: Description: This update for keepalived to version 2.0.10 fixes the following issues: Security issues fixed (bsc#1015141): – CVE-2018-19044: Fixed a check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats – CVE-2018-19045: Fixed mode when […]

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. Description: Description: This update for keepalived to version 2.0.10 fixes the following issues: Security issues fixed (bsc#1015141): – CVE-2018-19044: Fixed a check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats – CVE-2018-19045: Fixed mode when […]

London Gatwick Airport reopens but drone chaos perps still not found
Celebrating 20 Years of OpenSSL
The 18 biggest data breaches of the 21st century
Fortnite hackers making a fortune from reselling stolen accounts
Nagging text messages can help you to quit smoking
Apple spams users with unwanted ‘Carpool Karaoke’ push notifications
Google’s policy change reduces security, privacy and safety for 75% of users of ESET’s Android anti-theft service

The unfortunate implications of a well-intentioned change to Google Play Developer policies – and the negative impact it has on ESET’s Android app customers The post Google’s policy change reduces security, privacy and safety for 75% of users of ESET’s Android anti-theft service appeared first on WeLiveSecurity

LinuxSecurity.com: Two more security issues have been corrected in the libav multimedia library. This is a follow-up announcement for DLA-1611-1. CVE-2015-6823

2018 ain’t done yet… Amazon sent Alexa recordings of man and girlfriend to stranger
Update now! Microsoft patches another zero-day flaw

security update

Uncle Sam fingers two Chinese men for hacking tech, aerospace, defense biz on behalf of Beijing
Huawei Router Flaw Leaks Default Credential Status

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

U.S. Indicts China-Backed Duo for Massive, Years-Long Spy Campaign
Drones shut down major international airport

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Amazon Sends 1,700 Alexa Voice Recordings to a Random Person
Facebook Admits Giving Partners Access to Messages
Microsoft IE Zero Day Gets Emergency Patch
Microsoft issues emergency fix for Internet Explorer zero-day

Details are sparse about a security hole that Microsoft said is being exploited in targeted attacks The post Microsoft issues emergency fix for Internet Explorer zero-day appeared first on WeLiveSecurity

Here is a list of top 25 worst passwords of 2018
Hacker found using Twitter memes to spread malware
Pro-PewDiePie messages appear on hacked Wall Street Journal website
Chinese hackers reportedly stole secret US Navy data
France next up behind Britain, Netherlands to pummel Uber with €400k fine over 2016 breach
Spooked by a speaking security camera? Polite hacker tells owner how to fix his IoT security
Facebook denies sharing private messages without user knowledge
Most home routers lack simple Linux OS hardening security
Glitter bomb engineer exacts revenge on parcel thieves
Facebook defends giving tech giants access to extensive user data
Mayday! NASA Warns Employees of Personal Information Breach
Phone repair shop employees accused of stealing nude photos
London’s Gatwick airport suspends all flights after ‘multiple’ reports of drones
Holiday online shopping special tips

Some useful advice for staying safe while hunting for bargains in this holiday season The post Holiday online shopping special tips appeared first on WeLiveSecurity

Facebook’s Rough History of Failed User Revolts
NASA suffers data breach – Staff’s personal data stolen
Smashing Security #109: Grinches target Amazon and Reddit, stealing Christmas from the poor

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3854

LinuxSecurity.com: Several local side channel attacks and a denial of service via large Diffie-Hellman parameters were discovered in OpenSSL, a Secure Sockets Layer toolkit.

Facebook gave Amazon, Netflix, Spotify & others access to private user data

LinuxSecurity.com: An update that solves two vulnerabilities and has 11 fixes is now available. Description: Description: This update for salt fixes the following issues: – Crontab module fix: file attributes option missing (boo#1114824) – Fix git_pillar merging across multiple __env__ repositories (boo#1112874) – Bugfix: unable to detect os arch when RPM is not installed (boo#1114197) […]

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for the Linux Kernel 3.12.61-52_141 fixes one issue. The following security issue was fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.61-52_111 fixes several issues. The following security issues were fixed:

Patched Click2Gov Flaw Still Afflicting Local Govs
On the first day of Christmas, Microsoft gave to me… an emergency out-of-band security patch for IE

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. Description: Description: This update for ovmf fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for libnettle fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. Description: Description: This update for tiff fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for git fixes the following issues: Security issue fixed: