Menu

Monthly Archives: December 2018

International email bomb hoax proves to be a spectacular failure

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Facebook Flaw Exposes Private Photos for 6.8M Users
Logitech Keystroke Injection Flaw Went Unaddressed for Months
Save the Children Federation Duped in $1M Scam
A critical bug in Microsoft left 400M accounts exposed
Nasty Android malware found stealing its victims’ PayPal funds
Apps on smartphones are selling and sharing our location data 24/7
PlayStation Classic hacked to become platform-free console
Google Plus hit by another breach – Data of 52.5M users exposed
Toyota’s PASTA- A car hacking tool to enhance automobile cybersecurity

Reading Time: ~2 min. Clemson Supercomputer Susceptible to Cryptojacking IT staff at Clemson University have been working to remove the recent introduction of a cryptominer on its supercomputer, known as Palmetto. As they compromised the system for the mining of Monero, the attackers’ ploy was only spotted due to spikes in computing power and rising operating […]

YouTube is reading text in users’ videos
Facebook has filed patents to predict our future locations
Kanye West tops the charts for year’s worst password pratfall
Rhode Island sues Google after latest Google+ API leak
Apache Misconfig Leaks Data on 120 Million Brazilians

LinuxSecurity.com: This update fixes libstdc++ std::future support on armel, which is necessary to get firefox-esr and thunderbird updates built on that architecture.

2018 – a year of data breaches in review
How to protect yourself as the threat of scam apps grows

As the threat of bogus apps continues, what can we do to protect ourselves against these fraudulent practices? The post How to protect yourself as the threat of scam apps grows appeared first on WeLiveSecurity

Update now! WordPress 5.0.1 release fixes seven flaws
US bitcoin bomb threat ransom scam looks like a hoax say FBI, cops
US elections watchdog says it’s OK to spend surplus campaign cash on cybersecurity gear
Bomb Threat Bitcoin Demands Cause Disruption, Evacuations
Fraudster convicted of online banking thefts using… whatever the hell this thing is
The fastest, most secure browser? Microsoft Edge apparently

security update

Grammarly Launches Public Bug Bounty Program
Unlocking Android phones with a 3D-printed head

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The package firefox before version 64.0-1 is vulnerable to multiple issues including arbitrary code execution, same-origin policy bypass and access restriction bypass.

Secure Critical Infrastructure Top of Mind for U.S.
Google Beefs Up Android Key Security for Mobile Apps
‘Exclusive swag’ up for grabs as GitLab flings bug bounty scheme open to world+dog
Border agents are copying travelers’ data, leaving it on USB drives
Shamoon Reappears, Poised for a New Wiper Attack
Supermicro: We told you the tampering claims were false

Reading Time: ~2 min. Virtual Private Networks (VPNs) are quickly becoming a fundamental necessity for staying safe online. From large corporations to family households, people are turning to VPNs to ensure their data is encrypted end to end. But as with any emerging technology, it’s easy to become overwhelmed with new and untested VPN options. […]

Update now! Microsoft and Adobe’s December 2018 Patch Tuesday is here
Taylor’s gonna spy, spy, spy, spy, spy… fans can’t shake cam off, shake cam off

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or bypass of the same-origin policy.

Smashing Security #108: Hoaxes, Huawei and chatbots – with Mikko Hyppönen
UK white hats blacklisted by Cisco Talos after smart security code stumbles

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com:

Supermicro says independent investigation found no spy chips on its motherboards
It is with a heavy heart that we must inform you hackers are targeting ‘nuclear, defense, energy, financial’ biz
Android Trojan Targets PayPal Users

LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or bypass of the same-origin policy.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Azure Pack is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Dynamics NAV is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft PowerPoint is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a memory corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a heap-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to an information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: USN-3837-1 introduced a regression in poppler.

ThreatList: Holiday Spam, the Perfect Seasonal Gift for Criminals
Bulk surveillance is always bad, say human rights orgs appealing against top Euro court
Britain approved £2.5m of snooping kit exports to thoroughly snuggly regime in Saudi Arabia