Menu

Monthly Archives: March 2019

RSAC 2019: 58% of Orgs Have Unfilled Cyber Positions

LinuxSecurity.com: This is the six-month notification for the retirement of Red Hat Enterprise Linux 7.4 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.4.

Teen earns US$1 million in bug bounties

A ‘white hat’ from Argentina has come a long way since winning his first reward of US$50 in 2016 The post Teen earns US$1 million in bug bounties appeared first on WeLiveSecurity

Container Escape Hack Targets Vulnerable Linux Kernel
TikTok to pay record fine for collecting children’s data
Is a Facebookcoin in the works?
YouTube disables comments on millions of videos of children
Anomaly in pen-test tool made malware servers visible
RSAC 2019: An Antidote for Tech Gone Wrong
Visitor Kiosk Access Systems Riddled with Bugs

LinuxSecurity.com: The package file before version 5.36-1 is vulnerable to multiple issues including information disclosure and denial of service.

LinuxSecurity.com: The package lib32-openssl-1.0 before version 1.0.2.r-1 is vulnerable to information disclosure.

LinuxSecurity.com: The package openssl-1.0 before version 1.0.2.r-1 is vulnerable to information disclosure.

LinuxSecurity.com: The package gdm before version 3.30.3-1 is vulnerable to access restriction bypass.

LinuxSecurity.com: The package pcre before version 8.43-1 is vulnerable to denial of service.

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 6.4 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.4.

Ah, this military GPS system looks shoddy but expensive. Shall we try to break it?
RSAC 2019: New Operation Sharpshooter Data Reveals Higher Complexity, Scope

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: The package chromium before version 72.0.3626.121-1 is vulnerable to arbitrary code execution.

How the Dark Web Data Bazaar Fuels Enterprise Attacks

LinuxSecurity.com: Update to 4.01. Fixes lots of security bugs (and non-security bugs).

LinuxSecurity.com: It was found that a security update (DSA-4387-1) of OpenSSH, an implementation of the SSH protocol suite, was incomplete. This update did not completely fix CVE-2019-6111, an arbitrary file overwrite vulnerability in the scp client implementing the SCP protocol.

iPhone hacking tool Cellebrite being sold on eBay
Cellular networks flaws expose 4G & 5G devices to IMSI capturing attacks
WannaCry-hero Hutchins’ trial date set, Microsoft readies Google’s Spectre V2 fix for Windows 10, Coinhive axed, and more

LinuxSecurity.com: gdm 3.30.3 release. – Screen lock bypass fix (when timed login is enabled) (CVE-2019-3825) – Translation updates

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: fix for CVE-2018-5704 (RHBZ 1534844)

LinuxSecurity.com: Restrict default configuration to localhost.

LinuxSecurity.com: fix for CVE-2018-5704 (RHBZ 1534844)

LinuxSecurity.com: This release fixes various buffer overflows when parsing or processing damaged Waveform audio and BMP image files.

LinuxSecurity.com: Restrict default configuration to localhost.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

When the bits hit the FAN: US military accused of knackering Russian trolls, news org’s IT gear amid midterm elections

security update

security update

security update

security update

Adobe Patches Critical ColdFusion Vulnerability With Active Exploit

Type: Vulnerability. WinRAR is prone to multiple security vulnerabilities; fixes are available.

19-year-old ethical hacker is a millionaire now; thanks to his skills
Podcast: RSA Conference 2019 Preview
Did you hear the one about Cisco routers using strcpy insecurely for login authentication? Makes you go AAAAA-AAAAAAAA *segfault*

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 5 fixes is now available.

The Momo Challenge urban legend – what on earth is going on?
Necurs Botnet Evolves to Hide in the Shadows, with New Payloads
Dow Jones’ high-risk screening watchlist data exposed online

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 33 fixes is now available.

After last year’s sexism shambles, 2019’s RSA infosec event has upped its inclusivity game

LinuxSecurity.com: A vulnerability was discovered in uw-imap, the University of Washington IMAP Toolkit, that might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a

Data-tracking Chrome flaw triggered by viewing PDFs
For sale: iPhone hacking tool, one previous (not very careful) owner
Disgruntled dev blames crypto-wallet for losing cryptocoins
Latest container exploit (runc) can be blocked by SELinux
A year in review: 2018 Product Security Risk Report

Reading Time: ~2 min. Fake Apex Legends App Spreads Malware As the popularity of the latest free-to-play battle royale pushes ever higher, malicious Apex Legends apps have been spotted in the Google Play store with upwards of 100,000 downloads. The fake apps typically offer free in-game currency, or free downloads for an already free game, while […]

Dow Jones Watchlist of risky businesses exposed on public server

LinuxSecurity.com: Garming Sam reported an out-of-bounds read in the ldb_wildcard_compare() function of ldb, a LDAP-like embedded database, resulting in denial of service.

Spot the cyber-crims before they spot your data: Find out more in this here webinar – free for every Reg reader

LinuxSecurity.com: Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform various Cross-Side Scripting (XSS) and PHP injections attacks, delete files, leak potentially sensitive data, create posts of unauthorized types, or

The “Momo challenge” – why it’s time to stop the hype [VIDEO]

security update