Menu

Monthly Archives: December 2018

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Some HTML emails can trick messagelib into opening a new browser window when displaying said email as HTML. This happens even if the option to allow the HTML emails to access remote servers is disabled in KMail settings. This means that the owners of the servers referred in the email can see in their […]

Lawsuit Claims Pegasus Spyware Helped Saudis Spy on Khashoggi
Container code cluster-fact: There’s a hole in Kubernetes that lets miscreants cause havoc

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Fitness-tracking apps caught misusing Touch ID to steal money from iPhone users
Czech yourself, Russia! Prague says its foreign ministry was hacked for more than a year

LinuxSecurity.com: Several security issues were fixed in Perl.

Digitize and automate your customer agreement process for financial transactions. Download this free OneSpan guide.
Private data of more than 82 million US citizens left exposed

LinuxSecurity.com: Several security issues were fixed in Perl.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may lead to arbitrary code execution.

LinuxSecurity.com: A vulnerability in Nagios allows local users to escalate privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in ConnMan, the worst of which could result in the remote execution of code.

LinuxSecurity.com: Multiple vulnerabilities have been found in PHP, the worst of which could result in a Denial of Service condition.

Chris Vickery on the Marriott Breach and a Rash of Recent High-Profile Hacks

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

U.S. Military Members Catfished and Hooked for Thousands of Dollars
Lenovo Ordered to Pay $7.3M in Superfish Fiasco
iOS Fitness Apps Robbing Money From Apple Victims
YouTuber PewDiePie Promoted Via 50K Hacked Printers
Moscow’s cable car service shuts down in 2 days after ransomware attack
Someone hacked 50,000 printers to promote PewDiePie YouTube channel
Indian police & Microsoft busts tech support scam centers
Marriott hotel data breach: Sensitive data of 500 million guests stolen
Dunkin Donuts Perks loyalty data breach: Change your password
Feds charge 2 Iranian hackers behind SamSam ransomware attacks
Gang sentenced for installing card skimmers on gas pumps & stealing data
Dell resets all customer passwords after security breach
FBI & Google shut down largest-ever Ad fraud scheme ‘3VE’
Lenovo to pay $7.3m for installing adware in 750,000 laptops
Wanna save yourself against NotPetya? Try this one little Windows tweak
Scam iOS apps promise fitness, steal money instead

Fitness-tracking apps use dodgy in-app payments to steal money from unaware iPhone and iPad users The post Scam iOS apps promise fitness, steal money instead appeared first on WeLiveSecurity

Printers pulled into 9100 port attack spew PewDiePie propaganda
Router attack exploits UPnP and NSA malware to target PCs
Microsoft cracks down on tech support scams, 16 call centers raided
Faster fuzzing ferrets out 42 fresh zero-day flaws
CyberwarCon – focusing on the impact of cyber-badness

A welcome return to the hacker conferences of yesteryear The post CyberwarCon – focusing on the impact of cyber-badness appeared first on WeLiveSecurity

LinuxSecurity.com: An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: A flaw was found in mod_perl 2.0 through 2.0.10 which allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator’s control of HTTP request processing without also permitting unprivileged users to run

LinuxSecurity.com: It was discovered that Requests incorrectly handled certain HTTP headers. An attacker could possibly use this issue to access sensitive information (CVE-2018-18074). References:

A Dunkin’ Donuts Hack, a Fake FedEx Site, and More Security News This Week
Cyberwar predictions for 2019: The stakes have been raised
Dunkin’ Donuts Serves Up Data Breach Alert
Disorganized crime and state-backed hackers: How the cybercrime and cyberwar landscape is constantly

LinuxSecurity.com: The kdeconnect-kde package has been updated to version 1.3.3, which fixes an issue with modern encryption algorithms being disabled with SSH, and also fixes several bugs and updates compatibility with the Android app.

security update

security update

LinuxSecurity.com: A regression issue has been resolved in the poppler PDF rendering shared library introduced with version 0.26.5-2+deb8u5.

LinuxSecurity.com: Jayakrishna Menon and Christophe Hauser discovered an integer overflow vulnerability in Perl_my_setenv leading to a heap-based buffer overflow with attacker-controlled input.

LinuxSecurity.com: Several vulnerabilities were found in QEMU, a fast processor emulator: CVE-2016-2391

These are the worst hacks, cyberattacks, and data breaches of 2018
Marriott says 500 million Starwood guest records stolen in massive data breach
AWS has a security hub, Open SSL has a new license, London has a problem with cryptocoins, and more
Warning: Malware, rogue users can spy on some apps’ HTTPS crypto – by whipping them with a CAT o’ nine TLS
Giraffe hacks printers worldwide to promote God-awful YouTuber. Did we read that one right?