Menu

Monthly Archives: January 2019

Thousands of taxpayers tell HMRC to delete voiceprint data it stored without consent

LinuxSecurity.com: Several issues were discovered in qtbase-opensource-src, a cross-platform C++ application framework, which could lead to denial-of-service via application crash. Additionally, this update fixes a problem affecting vlc, where it would start without a GUI.

LinuxSecurity.com: Multiple vulnerabilities were discovered in coTURN, a TURN and STUN server for VoIP. CVE-2018-4056

Q. What connects the global financial crisis, Ursnif malware, and Coldplay’s Viva la Vida?

security update

security update

LinuxSecurity.com: Tavis Ormandy discovered a vulnerability in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service or the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER sandbox being enabled).

LinuxSecurity.com: The package nasm before version 2.14.02-1 is vulnerable to denial of service.

LinuxSecurity.com: The package haproxy before version 1.9.0-1 is vulnerable to denial of service.

LinuxSecurity.com: The package apache before version 2.4.38-1 is vulnerable to multiple issues including denial of service and insufficient validation.

LinuxSecurity.com: The package powerdns-recursor before version 4.1.9-1 is vulnerable to multiple issues including insufficient validation and access restriction bypass.

LinuxSecurity.com: The package matrix-synapse before version 0.34.1.1-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package go before version 2:1.11.5-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package go before version 2:1.11.5-1 is vulnerable to private key recovery.

Miscreants sweep internet for unpatched Cisco kit, fears over bugged Chinese parts, Roger Stone nabbed…

LinuxSecurity.com: New version 2.6.6. Security fix for CVE-2019-5716, CVE-2019-5717, CVE-2019-5718, CVE-2019-5719

security update

LinuxSecurity.com: krb5, a MIT Kerberos implementation, had several flaws in LDAP DN checking, which could be used to circumvent a DN containership check by supplying special parameters to some calls.

LabKey Vulnerabilities Threaten Medical Research Data
Whats(goes)App must come down… World in shock as Zuck decides to intertwine Facebook, Instagram, WhatsApp
Six Flags fingerprinted my son without consent, says mom. Y’know, this biometric case has teeth, say state supremes…
Threatpost News Wrap Podcast For Jan. 25
Phishing Campaign Delivers Nasty Ransomware, Credential-Theft Two-Punch
SD-WAN admin? Your number came up in Cisco’s latest bug list
Razy Malware Attacks Browser Extensions to Steal Cryptocurrency

Reading Time: ~2 min. Anatova Ransomware Reaches Global Market A new ransomware family, dubbed Anatova by researchers, has been infecting machines across the globe. During encryption, Anatova appears to focus on small files to speed up overall encryption times, but doesn’t append the encrypted files with a new extension. Unexpectedly, this variant demands DASH crypto […]

UK-EU infosec data sharing may not be KO’d by Brexit, reckons ENISA bod
Colorado police encrypt *all* their radio communications, frustrating journalists
Just keep slurping: HMRC adds two million taxpayers’ voices to biometric database
B&Q data leak exposes information on 70,000 thefts from its stores, including names of suspected offenders
Fighting Emotet: lessons from the front line
US gov issues emergency directive after wave of domain hijacking attacks
#DeleteFacebook? #DeleteTwitter? #FatLotOfGood that will do you
Cops catch $15m crypto-crook
Facebook debuts scam ads reporting tool

LinuxSecurity.com: The PostgreSQL project has release a new minor release of the 9.4 branch. For Debian 8 “Jessie”, this has been uploaded as version

Business payroll compromise – a new way for criminals to steal from your company
Data hackers are like toilet ninjas. This is not a clean crime, you know

LinuxSecurity.com: New Version

You’re an admin! You’re an admin! You’re all admins, thanks to this Microsoft Exchange zero-day and exploit
A picture tells a 1,000 words. Pixels pwn up to 5 million nerds: Crims use steganography to stash bad code in ads
Fighting Fire with Fire: API Automation Risks

LinuxSecurity.com: Ghostscript could be made to crash, access files, or run programs if it opened a specially crafted file.

LinuxSecurity.com: Several security issues were fixed in MySQL.

LinuxSecurity.com: A vulnerability in the HTML_QuickForm package has been found which potentially allows remote code execution. References: – https://bugs.mageia.org/show_bug.cgi?id=24185

LinuxSecurity.com: It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service (CVE-2018-20544). It was discovered that libcaca incorrectly handled certain images. An

LinuxSecurity.com: An issue has been found in PowerDNS Recursor where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua (CVE-2019-3806).

Risk Level: Very Low. Type: Trojan.

ThreatList: Credential-Sniffing Phishing Attacks Erupted in 2018
Passwords at risk for users who fall for Eileen’s cousin’s voicemail
Colour us shocked: Google in €50m GDPR fine appeal bombshell
Bit-and-Piece DDoS Method Emerges to Torment ISPs
DarkHydrus Phishery tool spreading malware using Google Drive
Malicious apps deploy Anubis banking trojan using motion detection
World’s favourite open-source PDF interpreter needs patching (again)
Bomb threat spam may stem from GoDaddy DNS weakness
Can you spot the phish? Take Google’s test

Everybody loves quizzes. So why not take this one and hone your phish-spotting prowess? The post Can you spot the phish? Take Google’s test appeared first on WeLiveSecurity

Supreme Court won’t consider case against defamatory reviews on Yelp
How to stop a hacker home invasion! [VIDEO]
Update now! Apple releases first 2019 iOS and macOS patches
“Proceed with caution”: Microsoft browser says Mail Online is untrustworthy
Nasty security bug found and fixed in Linux apt
New ransomware strain is locking up Bitcoin mining rigs in China
Sky Go app security failure exposes customers to snooping, data theft
Tech sector meekly waves arms in another bid to get Oz to amend its crypto-busting laws
Hadoop coop thrown for loop by malware snoop n’ scoop troop? Oh poop

LinuxSecurity.com: Security fix for CVE-2018-20551, CVE-2018-20481, CVE-2018-20650 and CVE-2018-18897.

LinuxSecurity.com: – xattr: strip credentials from any URL that is stored (CVE-2018-20483)

LinuxSecurity.com: Security fix for CVE-2019-5010 in Python. Anaconda is joined because an unrelated fix was done there that allowed to remove a workaround in Python.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

8-year-old ‘scared to death’ after hacked Nest security camera warns of missile attack
Smashing Security #112: Payroll scams, gold coin heists, web giants spanked

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

As netizens, devs scream bloody murder over Chrome ad-block block, Googlers insist: It’s not set in stone (yet)
Fake broadband ISP support scammers accidentally cough up IP address to Deadpool in card phish gone wrong

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Redaman Spams Russian Banking Customers with Rotating Tactics
Google faces another GDPR probe – this time in the land of meatballs and flat-pack furniture
Malware in Ad-Based Images Targets Mac Users
Monero: Cybercrime’s Top Choice for Mining Malware
Poisoned PEAR. PHP extension repository download infected for up to six months

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Got a Nest security camera? Enable two-step verification now
6 Signs of Successful Threat Hunting
‘Chaos’ iPhone X Attack Alleges Remote Jailbreak
Popular free Android VPN apps on Play Store contain malware
U.S. Gov Issues Urgent Warning of DNS Hijacking Attacks
100 million online bets exposed by leaky database

Reading Time: ~3 min. Fitness trackers and other digital wearables have unlocked a new era of convenience and engagement in consumer health. Beyond general fitness trackers, you can find wearables for a variety of purposes; some help diabetics, some monitor for seizure activity, and some can aid in senior citizens’ health and quality of life. […]

Black hats are great for language diversity, says Eugene Kaspersky
PewDiePie-spammers and whale-flingers exploit hole in Atlas game
Former employee blamed for hack of WordPress plugin maker

The plugin’s users are recommended to change their passwords on WPML’s website following havoc reportedly wrought by a disgruntled ex-employee The post Former employee blamed for hack of WordPress plugin maker appeared first on WeLiveSecurity

Microsoft Windows RCE Flaw Gets Temporary Micropatch
RogueRobin Malware Uses Google Drive as C2 Channel