Menu

Monthly Archives: December 2018

Australia Anti-Encryption Law Triggers Sweeping Backlash
TA505 Crooks are Now Targeting US Retailers with Personalized Campaigns

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Reading Time: ~2 min. Touch ID Used to Scam Apple Users Two apps were recently removed from the Apple App Store after several users reported being charged large sums of money after installing the app and scanning their fingerprint. Both apps were fitness-related and had users scan their fingerprint immediately so they could monitor calories or […]

Brit bomb hoax teen who fantasised about being a notorious hacker cops 3 years in jail
Using Fuzzing to Mine for Zero-Days
Three years in jail for teenager who spammed out school bomb threats
Microsoft Calls For Facial Recognition Tech Regulation

LinuxSecurity.com: An update that fixes one vulnerability is now available.

UK Supreme Court considers whether spy court should be immune to legal probes

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves 7 vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Flash zero-day exploit spotted – patch now!
Kids’ VTech tablets vulnerable to eavesdropping hackers
Unencrypted medical data leads to 12-state litigation
Hacker-besieged DNA data tucked away under military care
Australia now has encryption-busting laws as Labor capitulates
The path to cloud security goes through integration
Wow, what a lovely early Christmas present for Australians: A crypto-busting super-snoop law passes just in time

security update

LinuxSecurity.com: A vulnerability in EDE could result in privilege escalation.

LinuxSecurity.com: The package jupyter-notebook before version 5.7.2-1 is vulnerable to cross-site scripting.

LinuxSecurity.com: It was discovered that incorrect processing of very high UIDs in Policykit, a framework for managing administrative policies and privileges, could result in authentication bypass.

LinuxSecurity.com: Several security issues were fixed in OpenSSL.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3760

Infected WordPress Sites Are Attacking Other WordPress Sites

LinuxSecurity.com: Several security issues were fixed in SpamAssassin.

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Facebook Defends Data Policies On Heels of Incriminating Internal Docs
UK spies: You know how we said bulk device hacking would be used sparingly? Well, things have ‘evolved’…
DanaBot evolves beyond banking Trojan with new spam-sending capability

ESET research shows that DanaBot operators have been expanding the malware’s scope and possibly cooperating with another criminal group The post DanaBot evolves beyond banking Trojan with new spam-sending capability appeared first on WeLiveSecurity

Windows 10 security question: How do miscreants use these for post-hack persistence?
Malicious Chrome extension which sloppily spied on academics believed to originate from North Korea
Facebook staff’s private emails published by fake news inquiry
Patch now (if you can!): Latest Android update fixes clutch of RCE flaws
Google’s private browsing doesn’t keep your searches anonymous
More data joy: Email scammers are buying marks’ info from legit biz intelligence firms
Chrome 71 stomps on abusive advertising
Ukraine: We Blocked Major Russian Attack on Judiciary
#BHEU: How Google Aurora Attacks Changed the Consciousness of Cybersecurity
Brits’ DNA data sent to military base after ‘foreign’ hack attacks – report
Pencil manufacturers rejoice: Oz government doesn’t like e-voting
Smashing Security #107: Sextorting the US army, and a Touch ID scam
It’s December 2018, and a rogue application can still tell your Apple Mac: I’m your El Capitan now
Talk about a GAN-do attitude… AI software bots can see through your text CAPTCHAs
Adobe Flash zero-day exploit… leveraging ActiveX… embedded in Office Doc… BINGO!
White House Facial Recognition Pilot Raises Privacy Alarms

LinuxSecurity.com: An update for openstack-neutron is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: It was discovered that the ghostscript /invalidaccess checks fail under certain conditions. An attacker could possibly exploit this to bypass the – -dSAFER protection and, for example, execute arbitrary shell commands via a specially crafted PostScript document. (CVE-2018-16509) SL6 x86_64 ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-8.70-24.el6_10.2.x86_64.rpm ghostscript- [More…]

LinuxSecurity.com: ghostscript: incomplete fix for CVE-2018-16509 (CVE-2018-16863) Bug Fix(es): * Previously, the flushpage operator has been removed as part of a major clean-up of a non-standard operator. However, flushpage has been found to be used in a few specific use cases. With this update, it has been re- added to support those use cases. SL7 […]

Adobe Flash Zero-Day Leveraged Via Office Docs in Campaign
Kubernetes Flaw is a “Huge Deal,” Lays Open Cloud Deployments
Adobe Patches Zero-Day Vulnerability in Flash Player
It looked like a Citrix ShareFile phishing attack, but wasn’t
The Dark Side of the ForSSHe

ESET researchers discovered a set of previously undocumented Linux malware families based on OpenSSH. In the white paper, “The Dark Side of the ForSSHe”, they release analysis of 21 malware families to improve the prevention, detection and remediation of such threats The post The Dark Side of the ForSSHe appeared first on WeLiveSecurity

Estonian ex-foreign sec urges governments: Get cosy with the private sector on cybersecurity
Kubernetes cloud computing bug could rain data for attackers
Quora.com admits data breach affecting 100 million accounts
Now you, too, can snoop on mobe users from 3G to 5G with a Raspberry Pi and €1,100 of gizmos
Those are NOT your grandchildren! FTC warns of new scam
Coalition and Labor strike deal on encryption legislation
Facebook Exposes Nonprofits to Donors-and Hackers
Could adult content ban spell the end for Tumblr?
Google Chrome 71 Touts 43 Fixes, Fights Ad Abuse
Windows 10 version 1809 is incompatible with Morphisec anti-malware
GOPwned: Republicans fall victim to email hack
1-800-Flowers Becomes Latest Payment Breach Victim

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

He’s not cracked RSA-1024 encryption, he’s a very naughty Belarusian ransomware middleman

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform release 3.5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform release 3.6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Google Patches 11 Critical RCE Android Vulnerabilities
Quora Breach Exposes a Wealth of Info on 100M Users
Bleichenbacher’s CAT puts another scratch in TLS
Quora hack leaves details of 100 million accounts exposed
AirDrop an unwanted nude pic and you could face stiff penalties
Quora hacked: Personal data of 100 million users stolen
Zoom patches serious video conferencing bug
‘Iceman’ hacker charged with running drone-smuggling ring from jail
Marriott sued hours after announcing data breach
Magecart Group Ups Ante: Now Goes After Admin Credentials
Yet another mega-leak: 100 million Quora accounts compromised by system invaders

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Malware since 2017: Auction giant Sotheby’s Home hit by Magecart attack
Customers baffled as Citrix forces password changes for document-slinging Sharefile outfit

Risk Level: Very Low. Type: Trojan, Virus, Worm.