Menu

Monthly Archives: December 2018

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for bluez fixes the following issues: Security issues fixed:

US told to appoint a damn Privacy Shield ombudsperson already or EU will take action
Hackers Succeed in NASA Mission, Lifting Thousands of Employee Records
Chill, it’s not WikiLeaks 2: Pile of EU diplomatic cables nicked by hackers
Threatpost Poll: Do You Hate Facebook?
NASA fears hackers may have stolen employee data

A probe launched immediately after the discovery of the suspected incident has yet to establish the scale of the potential damage The post NASA fears hackers may have stolen employee data appeared first on WeLiveSecurity

Serious Security: When cryptographic certificates attack
Facebook waited months before admitting privacy bug exposed millions of users’ unposted photos
Facebook Fights Back on Secret Data-Sharing Partnerships

LinuxSecurity.com: An update that solves three vulnerabilities and has four fixes is now available. Description: Description: This new package for go1.11 fixes the following issues: Security issues fixed: – CVE-2018-16873: Fixed a remote code execution in go get, when executed [More…] with the -u flag (bsc#1118897) with the -u flag (bsc#1118897) [More…] – CVE-2018-16874: Fixed […]

Snack-happy parrot shows insider threats come in all shapes and sizes
Instagram became the preferred tool in Russia’s propaganda war
SQLite creator fires back at Tencent’s bug hunters
How not to secure US missile defences
Stop the credential thieves before they stop your business

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3834

LinuxSecurity.com: Update to 2.7.5 bugfix release. Fix for CVE-2018-16876

Houston, we’ve had a problem: NASA fears internal server hacked, staff personal info swiped by miscreants
Russia-Linked Sofacy Debuts Fresh Zebrocy Malware Variant
American bloke hauls US govt into court after border cops ‘cuffed him, demanded he unlock his phone at airport’
After SamSam, Ryuk shows targeted ransomware is still evolving
German cybersecurity chief: Anyone have any evidence of Huawei naughtiness?

Risk Level: Very Low. Type: Trojan.

WordPress Targeted with Clever SEO Injection Malware
Target targeted: Five years on from a breach that shook the cybersecurity industry

In December 2013 news broke that Target suffered a breach that forced consumers and the cybersecurity community to question the security practices of retailers The post Target targeted: Five years on from a breach that shook the cybersecurity industry appeared first on WeLiveSecurity

Hidden Code in Memes Instruct Malware via Twitter
WSJ Webpage Defaced to Support PewDiePie
Newsmaker Interview: Troy Mursch on Top Botnet Trends

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Cybersecurity Trends 2019: Privacy and intrusion in the global village

With just days left in 2018, ESET experts offer their reflections in ‘Cybersecurity Trends 2019’ on themes that are set to figure prominently in the upcoming year The post Cybersecurity Trends 2019: Privacy and intrusion in the global village appeared first on WeLiveSecurity

Facebook photo API bug exposed users’ unpublished photos
Save the Children Hit by $1m BEC Scam
Cybercriminals Change Tactics to Outwit Machine-Learning Defense
Logitech flaw fixed after Project Zero disclosure
Twitter fixes bug that lets unauthorized apps get access to DMs
Sneaky phishing campaign beats two-factor authentication
Memes, messengers, and missiles: From Twitter to chat apps and weapons, security is ho-ho-hosed this Xmas
You better watch out, you better not cry. Better not pout, I’m telling you why: SQLite vuln fixes are coming to town

Risk Level: Very Low. Type: Trojan.

U.S. Ballistic Missile Defense System Rife with Security Holes
Twitter Draws Data Privacy Concerns with Two New Bugs

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation (bsc#1118319). – CVE-2018-5848: Fixed an unsigned integer overflow in […]

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation (bsc#1118319). – CVE-2018-5848: Fixed an unsigned integer overflow in wmi_set_ie. […]

Risk Level: Very Low. Type: Trojan.

Automotive Security: It’s More Than Just What’s Under The Hood
Charming Kitten Iranian Espionage Campaign Thwarts 2FA
Influential cypherpunk and crypto-anarchist Tim May dies aged 67
PewDiePie Hackers Say They Launched Second Printer Siege
Facebook bug exposed private photos of 6.8M users to third-party developers
Hackers bypassed Gmail & Yahoo’s 2FA to target US officials
Personal & banking data of 120 million Brazilians leaked online
IT consultancy firm caught running ransomware decryption scam
Who’s watching you from an unmarked van while you shop in London? Cops with facial recog tech
The most popular passwords of 2018 revealed: Are yours on the list?

Besides the usual suspects among the worst of passwords, a handful of notable – but similarly poor – choices make their debuts The post The most popular passwords of 2018 revealed: Are yours on the list? appeared first on WeLiveSecurity

Worst passwords list is out, but this time we’re not scolding users
phpMyAdmin Releases Critical Software Update – Patch Your Sites Now!
Facebook bug exposed unposted photos of 6.8 million users
Former rave kingpin back in jail for bizarre bank heist
Fake face fools fones

LinuxSecurity.com: Updated packages are now available for Red Hat Gluster Storage 3.4 Web Administration on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: – Update to 2.14.1 – CVE-2018-19608 (#1656784) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2018-03 —- – Update to 2.14.0 Release notes:

PewDiePie fan hacker compromise 100,000 printers
Wicked scammers steal $1 million from Save the Children charity
Critical SQLite Flaw Leaves Millions of Apps Vulnerable to Hackers

LinuxSecurity.com: New upstream version 1.8.2. Fix low priority security issue with TLS: https://www.redhat.com/archives/libguestfs/2018-December/msg00047.html —- New upstream version 1.8.1. —- Rebase to new stable version 1.8.0. —- nbdkit metapackage should depend on versioned -server subpackage etc. —- New upstream version 1.6.3.

LinuxSecurity.com: Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644

LinuxSecurity.com: Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

LinuxSecurity.com: It was discovered there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack (CVE-2018-19208). References:

LinuxSecurity.com: – Buffer overflow using computed size of canvas element. (CVE-2018-12359) – Use-after-free when using focus(). (CVE-2018-12360) – Integer overflow in SwizzleData. (CVE-2018-12361)

LinuxSecurity.com: A buffer overflow and out-of-bounds read can occur in TextureStorage11 within the ANGLE graphics library, used for WebGL content. This results in a potentially exploitable crash (CVE-2018-17466). A use-after-free vulnerability can occur after deleting a selection

LinuxSecurity.com: Cache side-channel variant of the Bleichenbacher attack.(CVE-2018-12404) References: – https://bugs.mageia.org/show_bug.cgi?id=23972 – https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.36.6_release_notes

LinuxSecurity.com: A vulnerability in Scala could result in privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been found in SpamAssassin, the worst of which may lead to remote code execution.

LinuxSecurity.com: Multiple vulnerabilities have been found in CouchDB, the worst of which could lead to the remote execution of code.

Facebook could face billion dollar fine for data breaches

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

Blockchains should have ‘privacy by design’ for GDPR compliance
Fake Bomb Threat Emails Demanding Bitcoins Sparked Chaos Across US, Canada

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

Brazil bested by hackers, Virgin plugs hub bugs, and France surrenders… records
‘Bomb threat’ scammers linked to earlier sextortion campaign
Scumbag hackers lift $1m from children’s charity
Electric Vehicle Charging Stations Open to IoT Attacks
Stop us if you’ve heard this one: Facebook apologizes for bug leaking private photos
WordPress 5.0 Patched to Fix Serious Bugs
ZipRecruiter has been flying low: User email addresses exposed to unauthorised accounts