Menu

Monthly Archives: July 2019

This update addresses an arbitrary file copy vulnerability in mod_copy in ProFTPD, which allowed for remote code execution and information disclosure without authentication due to not honoring “ constraints. Upstream bug: http://bugs.proftpd.org/show_bug.cgi?id=4372

New Android ransomware uses pornographic posts to infect devices
Malvertising Campaigns Skirt Ad Blockers, Serve Up Mac Malware
If you could forget the $125 from Equifax and just take the free credit monitoring, that would be great – FTC

An update that fixes two vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes three vulnerabilities is now available.

An update that solves three vulnerabilities and has 41 fixes is now available.

Several vulnerabilities were discovered in WPA supplicant / hostapd. Some of them could only partially be mitigated, please read below for details.

$1.7 million still missing after North Carolina county hit by business email compromise scam
Honda’s Security ‘Soft Spots’ Exposed in Unsecured Database
Fix LibreOffice now to thwart silent macro viruses – and here’s how to pwn those who haven’t
Cybercrooks attempted credential-stuffing banks 3.5 BEEELLION times in the last 18 months alone
‘Urgent/11’ flaws affect 200 million devices – from routers to elevators
Chrome 76 Dumps Default Adobe Flash Player Support
Trivial Bug Turns Home Security Cameras Into Listening Posts
New UK Home Sec invokes infosec nerd rage by calling for an end to end-to-end encryption

An update that fixes 10 vulnerabilities is now available.

An update for icedtea-web is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

iMessage bug could have allowed attackers to read data from any iPhone
Georgia hit with malware yet again
Black Hat USA 2019 Preview
What’s the last piece of software you’d expect to spy on you? Maybe your enterprise security suite? Bad news
Evolving OVAL
Lancaster Uni cordons off breached systems a week after thousands of folks’ data pinched

An update that fixes one vulnerability is now available.

Cyberattacks on connected cars could gridlock entire cities

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1898

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1883

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1884

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1880

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1896

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1873

Hack a small airplane? Yes, we CAN (bus) – once we physically break into one, get at its wiring, plug in evil kit…

Update to v5.1.20 —- Update to v5.1.19

Update to v5.1.20 —- Update to v5.1.19

Some security issues are found on oniguruma. This new rpm should fix these issues

Watch as 10 cops with guns and military camo storm suspected Capital One hacker’s house…
DHS Warning: Small Aircraft are Ripe for Hacking
Apple iMessage Flaw Allows Remote Attackers to Read iPhone Messages
Capital One data breach: 106m customers affected; suspected hacker arrested
Hacker swipes personal deets of 20,000 peeps from under Los Angeles Police Dept’s nose
Android Ransomware Spreads Via ‘Sex Simulation Game’ Links on Reddit, SMS
Capital One breach – 100 million users’ data stolen
Nation-State Actors Go All-In on Mobile Malware

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes 10 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes 52 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Hackers target Telegram accounts through voicemail backdoor
Listening in: Humans hear the private info Siri accidentally records
US chases fraudulent bitcoin exchange BTC-e for $100m
Post-Equifax settlement, NY updates data breach notification laws
Former AWS Engineer Arrested as Capital One Admits Massive Data Breach
Google found a way to remotely attack Apple iOS devices by sending a boobytrapped iMessage

An update for the ruby:2.5 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Bipartisan Senate Committee Releases Report on Election Security Threats

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for qemu-kvm-rhev is now available for Red Hat Virtualization for Red Hat Virtualization Host 7. Red Hat Product Security has rated this update as having a Important security impact. A Common Vulnerability Scoring System (CVSS) base score,

Updated samba packages that fix one security issue and provide several bug fixes and enhancements are now available for Red Hat Gluster Storage 3.4 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

Capital One gets Capital Done: Hacker swipes personal info on 106 million US, Canadian credit card applicants
Microsoft preps to purge its cloud access security broker of shonky crypto protocols TLS 1.0, 1.1
Whistleblower says Apple contractors listen to your Siri conversions
Oh sh*t’s, 11: VxWorks stars in today’s security thriller – hijack bugs discovered in countless gadgets’ network code
ThreatList: DMARC Adoption Nonexistent at 80% of Orgs
Cloud Security Concerns Loom for 93% of Businesses Adopting Apps and BYOD
‘URGENT/11’ Critical Infrastructure Bugs Threaten EternalBlue-Style Attacks
Android ransomware is back

ESET researchers discover a new Android ransomware family that attempts to spread to victims’ contacts and deploys some unusual tricks The post Android ransomware is back appeared first on WeLiveSecurity

Fearing WannaCry-Level Danger, Enterprises Wrestle with BlueKeep
Android exploit code emerges, ransomware goes south, Citrix calls off hack probe, and more
IoT botnet launched massive 13-day DDoS attack against streaming service

tmpreaper could be made to overwrite files as the administrator.

NAS targeted by brute force ransomware attacks
‘WannaCry Hero’ Avoids Jail Time in Kronos Malware Charges

An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com Launches New site, Celebrates 20 Years of Following Open Source Security News and Resources
Welcome to the New LinuxSecurity.com!

An update for docker is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for podman is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Three quarters of gamers suffer hate and harassment online
Dear hackers: If you try to pwn a website for phishing, make sure it’s not the personal domain of a senior Akamai security researcher

An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for curl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for qemu-kvm-ma is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Improve security of your Linux OS with simple steps
Russia targeted all 50 states in 2016 election, Senate report says
Scam impersonates WhatsApp, offers ‘free internet’

The fraudulent campaign is hosted by a domain that is home to yet more bogus offers pretending to come from other well-known brands The post Scam impersonates WhatsApp, offers ‘free internet’ appeared first on WeLiveSecurity

Brit infosec firms urge PM Boris to reform the Computer Misuse Act
As the world secures itself, so do crims: Encrypted malware on the rise, warns Sonicwall

security update

WannaCry hero gets off lightly, avoids prison – was justice done?