Menu

Monthly Archives: March 2019

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a […]

If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. […]

A flaw was found in Nagios Core version 4.4.1 and earlier. The qh_help function is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket (CVE-2018-13441).

Unclosable browser popup! 13-year-old charged for sharing code
RSAC 2019: For Domestic Abuse, IoT Devices Pose New Threat
NSA might shut down phone snooping program, whatever that means

NVIDIA graphics drivers could be made to expose sensitive information.

Monero cryptominers hijack hundreds of unpatched Docker hosts

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

UK’s ICO event on targeted ads opens floor to the adtech industry: Anybody? No? Speak for 10 minutes. Hello?
Backdoored GitHub accounts spewed secret sneakerbot software
The Pirate Bay spreading malware PirateMatryoshka via reputed seeders
NX-OS-hit! Got Cisco Nexus and MDS 9000 switches? Then you’ve got patching to do, too
RSA Conference 2019: NIST’s Privacy Framework Starts to Take Shape
Thousands of patients impacted by ransomware attack at medical billing company
Latest Chrome update plugs a zero-day hole

Users should waste no time in updating to the browser’s latest version The post Latest Chrome update plugs a zero-day hole appeared first on WeLiveSecurity

TalkTalk kept my email account active for 8 years after I left – now it’s spamming my mates
FBI boss warns businesses of Chinese hackers stealing their intellectual property
Schneier: Don’t expect Uncle Sam to guard your web privacy – it’s Europe riding to the rescue
Smashing Security #118: The ‘s’ in IoT stands for security

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

RSA Conference 2019: UniKey Patches BleedingBit Flaws Granting Access To Hotel Rooms, Cars

An update that solves two vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves four vulnerabilities and has four fixes is now available.

security update

RSA Conference 2019: The Sky’s the Limit For Satellite Hacks
RSA Conference 2019: How to Defend Against an AI vs AI ‘Flash War’
Serious Chrome zero-day – Google says update “right this minute”
UK Ministry of Justice: Surprise! We tested out biometric tech in prisons and ‘visitors’ with drugs up their bums ran away

Several security issues were fixed in PHP.

## 1.7.1 – #475: “Loose” lists will now contain paragraphs in all items, not just some. – #433: Links will no longer be double nested – #525: The info- string when beginning a code block may now contain non-word characters (e.g. `c++`) – #561: The `mbstring` extension (which we already depend on) has been added […]

– https://www.drupal.org/project/link/releases/7.x-1.6 – https://www.drupal.org/sa-contrib-2019-020 – https://www.drupal.org/sa- core-2019-003 – https://www.drupal.org/project/link/releases/7.x-1.5 – https://www.drupal.org/project/link/releases/7.x-1.5-beta3

Fixes: CVE-2018-6358, CVE-2018-7867, CVE-2018-7868, CVE-2018-7870, CVE-2018-7871, CVE-2018-7872, CVE-2018-7875, CVE-2018-9165.

Bump to ignition-dracut 2c69925 * support platform configs and user configs in /boot ^ https://github.com/coreos/ignition-dracut/pull/43 * Add ability to parse config.ign file on boot ^ https://github.com/coreos/ignition-dracut/pull/42

– bugfix {foreach} using new style property access like {$item@property} on Smarty 2 style named foreach loop could produce errors https://github.com/smarty-php/smarty/issues/484 31.08.2018 – bugfix some custom left and right delimiters like ‘{^’ ‘^}’ did not work

RSA Conference 2019: Cryptographers’ Panel Decries Adi Shamir’s Visa Issues
RSA Conference 2019: Data-Wiping Cyberattacks Plague Financial Firms
Google reveals BuggyCow macOS security flaw
RSA – IoT security meets SMB

Some tips that businesses can do to get better at it without breaking the bank The post RSA – IoT security meets SMB appeared first on WeLiveSecurity

Leaky ski helmet speakers expose conversations and data
Google Photos disables sharing on Android TV
RSA Conference 2019: Microsoft, Google, Twitter on Federal Privacy Regs
RSAC 2019: TLS Markets Flourish on the Dark Web
How to keep your flock of users secure: Let them know exactly who and where the wolves are
Did you know?! Ghidra, the NSA’s open-sourced decompiler toolkit, is ancient Norse for ‘No backdoors, we swear!’
Level up Mac security, and say game over to malware? System alerts plus Apple game engine equals antivirus package
How to make people sit up and use 2-factor auth: Show ’em a vid reusing a toothbrush to scrub a toilet – then compare it to password reuse
NSA may kill off mass phone spying program Snowden exposed, says Congressional staffer
Facebook criticised for misuse of phone numbers provided for security
You. Shall. Not. Pass… word: Soon, you may be logging into websites using just your phone, face, fingerprint or token
You’ve Invested in an Email Security Solution… Why your Email may be in Danger, Regardless
RSA Conference 2019: BEC Scammer Gang Takes Aim at Boy Scouts, Other Nonprofts
RSA Conference 2019: How to Be Better, on Trust, AI and IoT
FBI boss: Never mind Russia and social media, China ransacks US biz for blueprints, secrets at ‘surprisingly’ huge scale
Adi Shamir visa snub: US govt slammed after the S in RSA blocked from his own RSA conf

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Companies are flying blind on cybersecurity
RSAC 2019: Joomla! Mail Flaw Exploited to Create Mass Phishing Infrastructure
Payment processors remain phishers’ favorites

The latest report from the Anti-Phishing Working Group offers a mixed bag of findings about the phishing landscape in 2018 The post Payment processors remain phishers’ favorites appeared first on WeLiveSecurity

RSAC 2019: Most Consumers Say ‘No’ to Cumbersome Data Privacy Practices
Comcast security nightmare: default ‘0000’ PIN on everybody’s account
Update now! Critical Adobe ColdFusion flaw now being exploited
Huawei opens Brussels code-check office: Hey! EU’ve got our guide – love Huawei
RSAC 2019: Picking Apart the Foreshadow Attack
Linux and Open Source FAQs: Common Myths and Misconceptions Addressed
New & Improved LinuxSecurity Site Coming Soon!
As Trump and Kim Met, North Korean Hackers Hit Over 100 Targets in U.S. and Ally Nations
Hackers have started attacks on Cisco RV110, RV130, and RV215 routers
Revealed: Facebooks global lobbying against data privacy laws

LinuxSecurity.com: An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rhvm-appliance is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for vdsm is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Windows IoT Core exploitable via ethernet
RSAC 2019: Malicious Emailed URLs See Triple-Digit Increase
RSAC 2019: Microsoft Zero-Day Allows Exploits to Sneak Past Sandboxes
How to address IoT’s two biggest challenges: data and security
Find QuadrigaCX’s missing $190 million, and you could win a $100,000 bounty
Apple gets bug for free, while HackerOne declares first $1m bug hunter
That’s a nice ski speaker you’ve got there. Shame if it got pwned
Bad news: Google drops macOS zero-day after Apple misses bug deadline. Good news: It’s fiddly to exploit
SPOILER alert, literally: Intel CPUs afflicted with simple data-spewing spec-exec vulnerability
BSides SF 2019: Remote-Root Bug in Logitech Harmony Hub Patched and Explained

LinuxSecurity.com: Vulnerabilities have been discovered in nss, the Mozilla Network Security Service library.

Alphabet snoop: If you’re OK with Google-spawned Chronicle, hold on, hold on, dipping into your intranet traffic, wait, wait
Oh no Xi didn’t?! China’s hackers nick naval tech blueprints, diddle with foreign elections to boost trade – new claim
Teen Becomes First to Earn $1M in Bug Bounties with HackerOne
When 2FA means sweet FA privacy: Facebook admits it slurps mobe numbers for more than just profile security

LinuxSecurity.com: An update that solves 8 vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

Smart Ski Helmet Headphone Flaws Leak Personal, GPS Data

LinuxSecurity.com: One of the fixes in USN-3885-1 was incomplete.

LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

McAfee: Oops, our bad. Sharpshooter malware was the Norks’ Lazarus Group the whole time
Project Zero Discloses High-Severity Apple macOS Flaw
Armor Games admits all its users’ deets slurped in mega breach as site moves to repair chink