Menu

Monthly Archives: January 2019

Happy Thursday! 770 MEEELLLION email addresses and passwords found in yuge data breach
As the Government Shutdown Drags on, Security Risks Intensify
Oracle Java Card updated for IoT applications

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.

South Korea says mystery hackers cracked advanced weapons servers
$24m in fun bux stolen from crypto-mogul. Now he fires off huge fraud charge. Like, RICO, say?
Smashing Security #111: When rivals hack, and ‘extreme’ baby monitors

Risk Level: Very Low. Type: Trojan.

Threatpost Survey Says: 2FA is Just Fine, But Go Ahead and Kill SMS
Millions of Oklahoma Gov Files Exposed by Wide-Open Server
Exploring the economic realities of cybersecurity insurance | Salted Hash Ep 43

LinuxSecurity.com: Several security issues were fixed in libcaca.

Lowjax city: Researchers crack open notorious Fancy Bear rootkit
U.S. Issues Multiple Charges For 2016 SEC Hack
Fortnite Hacked Via Insecure Single Sign-On
Magecart Returns with Advertising Library Tactic
Car and almost $1m on offer for Tesla Model 3 hacks

The electric car maker is raising the ante in automotive security, putting one of its swanky models as a target at a hacking contest The post Car and almost $1m on offer for Tesla Model 3 hacks appeared first on WeLiveSecurity

Epic’s Fortnite fail: Ancient UT2004 server used for login-stealing proof-of-concept
VOIPO Database Exposes Millions of Texts, Call Logs
Microsoft sends a raft of Windows 10 patches out into the Windows Update ocean
Are you sure those WhatsApp messages are meant for you?
Intel patches another security flaw in SGX technology
Beware buying Fortnite’s V-Bucks, you could be funding organised crime
Firms fined $1M for SingHealth data security breach
UK Banks Finally Issue New Cards After Ticketmaster Breach
Feds can’t force you to unlock your phone with finger or face, says judge

LinuxSecurity.com: This update fixes CVE-2018-20685 (the first “variant”) and backports several fixes to unbreak ECDSA authentication from PKCS#11, certificate authentication and so on.

LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).

LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).

LinuxSecurity.com: Patch for CVE-2016-10091

EDGAR Wrong: Ukrainians hacked SEC, stole docs for inside trading, says Uncle Sam

LinuxSecurity.com: Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation. A local attacker could possibly use this issue to perform a cache-timing attack and recover private ECDSA keys (CVE-2018-0495). References:

LinuxSecurity.com: A heap use-after-free vulnerability in the server code of the file transfer extension, which can result in remote code execution. This attack appears to be exploitable via network connectivity (CVE-2018-6307).

LinuxSecurity.com: It was observed that URL’s which gets downloaded via “–log=” attribute stores sensitive information. This update fixes that. References: – https://bugs.mageia.org/show_bug.cgi?id=24112

IDenticard Zero-Days Allow Corporate Building Access, Location Recon
‘It’s like they took a rug and covered it up’: Flight booking web app used by scores of airlines still vuln to attack – claim
Data Breach Roundup: U.S. Healthcare, Cryptopia, SingHealth and Experian

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

security update

security update

LinuxSecurity.com: Several issues in wireshark, a tool that captures and analyzes packets off the wire, have been found by different people. These are basically issues with length checks or invalid memory access in

LinuxSecurity.com: libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (CVE-2018-15127) SL7 x86_64 libvncserver-0.9.9-13.el7_6.i686.rpm libvncserver-0.9.9-13.el7_6.x86_64.rpm libvncserver-debuginfo-0.9.9-13.el7_6.i686.rpm libvncserver-debuginfo-0.9.9-13.el7_6.x86_64.rpm libvncserver-devel-0.9.9-13.el7_6.i686.rpm [More…]

Judge: Law Enforcement Can’t Force Suspects to Unlock iPhones with FaceID
ThreatList: $1.7M is the Average Cost of a Cyber-Attack

LinuxSecurity.com: Several security issues were fixed in libcaca.

Yes, you can remotely hack … building site cranes. Wait, what?
Man whose DDoS attacks took down entire country’s Internet jailed
8 million users installed 9 adware apps from Play Store
What makes a cybercriminal?

Forget balaclavas or hoodies, these cybercriminals are hiding in plain sight The post What makes a cybercriminal? appeared first on WeLiveSecurity

Reading Time: ~2 min. For many MSPs, integrating their security solution with their remote monitoring and management (RMM) and professional service automation (PSA) platforms is essential for doing business. Together, these platforms help lower the cost of keeping up with each client, ensuring profitable margins for a healthy, growing business. For true providers of IT […]

Windows 7 users get fix for latest updating woe
Blockchain burglar returns some of $1m crypto-swag
Facebook to start fact-checking fake news in the UK

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2019:0049

Is fake-news sharing driven by age, not politics?

LinuxSecurity.com: An update for libvncserver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Want to get rich from bug bounties? You’re better off exterminating roaches for a living

LinuxSecurity.com: The v4.19.14 stable update contains important fixes across the tree.

Oh, SSH, IT please see this: Malicious servers can fsck with your PC’s files during scp slurps
A city in Texas is using paper after suffering ransomware attack

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

This must be some kind of mistake. IT managers axed, CEO and others’ wallets lightened in patient hack aftermath
Cops told: No, you can’t have a warrant to force a big bunch of people to unlock their phones by fingerprint, face scans
Popular Web-Hosting Platform Bluehost Riddled with Flaws, Researcher Claims
Intel’s Software Guard caught asleep at its post: Patch out now for SGX give-me-admin hole

security update

Threatpost Poll: Can We Fix 2FA?
Hack Allows Escape of Play-with-Docker Containers

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

British TV viewers targeted by email fraudsters
Ryuk Hauls in $3.7M in ‘Earnings,’ Adds TrickBot to the Attack Mix
Mozilla Kills Default Support for Adobe Flash in Firefox 69
RBS reissues punters with new bank cards after Ticketmaster breach
Goddamn the Pusher man: Nominet kicks out domain name hijack bid
Shutdown hits government websites as certificates begin to expire
Poland may consider Huawei ban amid ‘spy’ arrests – reports
Data Exposed in OXO, Amazon and MongoDB Leaks
Nissan EV app password reset prompts user panic

LinuxSecurity.com: An update for systemd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

CES: Smart cities and the challenge of securing the neighborhood

In our final report from CES we take a look at smart city initiatives The post CES: Smart cities and the challenge of securing the neighborhood appeared first on WeLiveSecurity

Podcast: Emotet Grows With Fast-Evolving Tactics
10 years for Boston Children’s Hospital attacker
New Linux Systemd security holes uncovered
Governments need to embrace AI for the good of the people
USB-C Authentication sounds great, so why are people worried?
Facebook exec gets SWATted
The DDoS attacker rescued by a Disney cruise ship is sentenced to over 10 years in prison
Brit hacker hired by Liberian telco to nobble rival now behind bars

LinuxSecurity.com: New zsh packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is now available.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: The Qualys Research Labs discovered multiple vulnerabilities in systemd-journald. Two memory corruption flaws, via attacker-controlled alloca()s (CVE-2018-16864, CVE-2018-16865) and an out-of-bounds read flaw leading to an information leak (CVE-2018-16866), could allow an attacker to