Menu

Monthly Archives: December 2018

Operation Sharpshooter Takes Aim at Global Critical Assets
Super Micro Says Its Gear Wasn’t Bugged By Chinese Spies
Bad news for scammers. Huawei executive Meng Wanzhou has been released on bail
Supply Chain Security: Managing a Complex Risk Profile
Samsung fixes flaws that could have let attackers hijack your account
Google+ to power down early after second security hole found
Text CAPTCHAs easily beaten by neural networks
Phones are selling location data from “trusted” apps
New Google+ Breach Will Lead to Early Service Shutdown
Equifax breach was ‘entirely preventable’ had it used basic security measures, says House report
Ticketmaster tells customer it’s not at fault for site’s Magecart malware pwnage

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

It’s December of 2018 and, to hell with it, just patch your stuff

LinuxSecurity.com: Firefox could be made to crash or run programs as your login if it opened a malicious website.

Facebook Fined $11.3M for Privacy Violations
Zero-Day Bug Fixed by Microsoft in December Patch Tuesday
Equifax how-it-was-mega-hacked damning dossier lands, in all of its infuriating glory

security update

25% of NHS trusts have zilch, zip, zero staff who are versed in security

LinuxSecurity.com: pixman could be made to crash or run programs if it processed specially crafted instructions.

Data Privacy Issues Trigger Soul Searching in Tech Industry
Cobalt Group Pushes Revamped ThreadKit Malware

LinuxSecurity.com: pixman could be made to crash or run programs if it processed specially crafted instructions.

LinuxSecurity.com: The package openssl-1.0 before version 1.0.2.q-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package lib32-openssl-1.0 before version 1.0.2.q-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package lib32-openssl before version 1:1.1.1.a-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package openssl before version 1.1.1.a-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package texlive-bin before version 2018.48691-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package wireshark-cli before version 2.6.5-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package chromium before version 71.0.3578.80-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, information disclosure and insufficient validation.

LinuxSecurity.com: CUPS could be made to expose sensitive information.

LinuxSecurity.com: lxml could allow cross-site scripting (XSS) attacks.

LinuxSecurity.com: lxml could allow cross-site scripting (XSS) attacks.

LinuxSecurity.com: This is the one-Month notification for the retirement of Red Hat Enterprise Linux 6.6 Telco Update Service (TUS). This notification applies only to those customers subscribed to the Telco Update Service (TUS) channel for Red Hat Enterprise Linux 6.6.

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 7.3 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.3.

LinuxSecurity.com: This is the one-Month notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.

Adobe December 2018 Security Update Fixes Reader, Acrobat
Biometrics: Security Solution or Issue?
Google+ to shut earlier as new bug exposed data of 52.5 million users

There is no evidence that the flaw was misused during the six days it was alive, said the tech giant The post Google+ to shut earlier as new bug exposed data of 52.5 million users appeared first on WeLiveSecurity

Linux.org Redirected to NSFW Page Spewing Racial Epithets
Android Trojan steals money from PayPal accounts even with 2FA on

ESET researchers discovered a new Android Trojan using a novel Accessibility-abusing technique that targets the official PayPal app, and is capable of bypassing PayPal’s two-factor authentication The post Android Trojan steals money from PayPal accounts even with 2FA on appeared first on WeLiveSecurity

Lenovo tells Asia-Pacific staff: Work lappy with your unencrypted data on it has been nicked
Dark web goldmine busted by Europol
Teen SWATter who had 400 schools evacuated lands 3 years in jail
Facebook fined $11m for misleading users about how data will be used
Texas Instruments flicks Armis’ Bluetooth chip vuln off its shoulder
Google admits Google Plus hit by *another* privacy flaw, speeds up site’s closure
GlobeImposter ransomware victims find themselves abandoned by their extortionists
Latest Google+ flaw leads Chocolate Factory to shut down site early

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Women in Cyber Take the Spotlight
Did you know that iOS ad clicks cost more than Android? These scammers did

LinuxSecurity.com: Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: The EXIF module was susceptible to denial of service/information disclosure when parsing malformed images, the Apache module allowed cross-site-scripting via the body of a

Nice phone account you have there – shame if something were to happen to it: Samsung fixes ID-theft flaws
Google Accelerates Google+ Shutdown After New Bug Discovered
Sextortion Emails Force Payment via GandCrab Ransomware

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

Risk Level: Very Low. Type: Trojan.

Old-School Bagle Worm Spotted in Modern Spam Campaigns
Volkswagen Giveaway Scam Peddles Ad Networks
Privacy, security fears about ID cards? UK.gov’s digital bod has one simple solution: ‘Get over it’
Next Generation Dark Markets? Think Amazon or eBay for criminals

The “evolution” of these markets is making cybercrime easier than ever before The post Next Generation Dark Markets? Think Amazon or eBay for criminals appeared first on WeLiveSecurity

Massive botnet chews through 20,000 WordPress sites
Android click fraud apps mimic Apple iPhones to boost revenue
Microsoft’s gutting Edge and stuffing it with Chromium
235 members of dark web money counterfeiting gang busted
Security News This Week: Did Quora Get Hacked? Top Answer: Yes
Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
Microsoft calls for laws on facial recognition, issues principles

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: It was discovered that there was a XSS injection vulnerability in the LXML HTML/XSS manipulation library for Python. LXML did not remove “javascript:” URLs that used escaping such as

LinuxSecurity.com: An update for rh-git218-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service (CVE-2018-1336). The defaults settings for the CORS filter are insecure and enable

LinuxSecurity.com: An update that fixes 27 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

DuckDuckGo study claims Google Incognito searches are not private
Hackers conducting botnet attacks through 20k hacked WordPress sites
Another MongoDB database exposes personal data of 66M users
Days After Massive Breach, Marriott Customers Await Details

security update

22 malware infected apps on Play Store found draining phone’s battery

LinuxSecurity.com: Use after free flaw enabling arbitrary code execution. (CVE-2018-15982) Insecure Library Loading (DLL hijacking) flaw enabling privilege escalation. (CVE-2018-15983)

LinuxSecurity.com: The HTML thumbnailer was incorrectly accessing some content of remote URLs listed in HTML files. This meant that the owners of the servers referred in HTML files in your system could have seen in their access logs your IP address every time the thumbnailer tried to create the thumbnail (CVE-2018-19120).

GDPR Implementation Slow but Improving
Addresses and Names of Customers Exposed by Bethesda in Support Tickets
Linux 4.19.8 Released With BLK-MQ Fix To The Recent Data Corruption Bug
6 Critical Website Elements You Need to Review
415,000 routers infected by cryptomining malware – Prime target MikroTik
New AI tool aims to make CAPTCHA a thing of the past
Bethesda blunders, IRS sounds the alarm, China ransomware, and more
In case you’re not already sick of Spectre… Boffins demo Speculator tool for sniffing out data-leaking CPU holes
Identity stolen because of the Marriott breach? Come and claim your new passport
‘Say hello to my little vacuum cleaner!’ US drug squad puts spycams in cleaner’s kit
ThreatList: Gift Card-Themed BEC Holiday Scams Spike
Linux.org domain hacked, plastered with trolling, filth and anti-transgender vandalism

security update

Type: Vulnerability. Adobe Flash Player is prone to an unspecified remote code-execution vulnerability; fixes are available.