Menu

Category Archives: All

Everything

security update

LinuxSecurity.com: Several issues in wireshark, a tool that captures and analyzes packets off the wire, have been found by different people. These are basically issues with length checks or invalid memory access in

LinuxSecurity.com: libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (CVE-2018-15127) SL7 x86_64 libvncserver-0.9.9-13.el7_6.i686.rpm libvncserver-0.9.9-13.el7_6.x86_64.rpm libvncserver-debuginfo-0.9.9-13.el7_6.i686.rpm libvncserver-debuginfo-0.9.9-13.el7_6.x86_64.rpm libvncserver-devel-0.9.9-13.el7_6.i686.rpm [More…]

Judge: Law Enforcement Can’t Force Suspects to Unlock iPhones with FaceID
ThreatList: $1.7M is the Average Cost of a Cyber-Attack

LinuxSecurity.com: Several security issues were fixed in libcaca.

Yes, you can remotely hack … building site cranes. Wait, what?
Man whose DDoS attacks took down entire country’s Internet jailed
8 million users installed 9 adware apps from Play Store
What makes a cybercriminal?

Forget balaclavas or hoodies, these cybercriminals are hiding in plain sight The post What makes a cybercriminal? appeared first on WeLiveSecurity

Reading Time: ~2 min. For many MSPs, integrating their security solution with their remote monitoring and management (RMM) and professional service automation (PSA) platforms is essential for doing business. Together, these platforms help lower the cost of keeping up with each client, ensuring profitable margins for a healthy, growing business. For true providers of IT […]

Windows 7 users get fix for latest updating woe
Blockchain burglar returns some of $1m crypto-swag
Facebook to start fact-checking fake news in the UK

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2019:0049

Is fake-news sharing driven by age, not politics?

LinuxSecurity.com: An update for libvncserver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Want to get rich from bug bounties? You’re better off exterminating roaches for a living

LinuxSecurity.com: The v4.19.14 stable update contains important fixes across the tree.

Oh, SSH, IT please see this: Malicious servers can fsck with your PC’s files during scp slurps
A city in Texas is using paper after suffering ransomware attack

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

This must be some kind of mistake. IT managers axed, CEO and others’ wallets lightened in patient hack aftermath
Cops told: No, you can’t have a warrant to force a big bunch of people to unlock their phones by fingerprint, face scans
Popular Web-Hosting Platform Bluehost Riddled with Flaws, Researcher Claims
Intel’s Software Guard caught asleep at its post: Patch out now for SGX give-me-admin hole

security update

Threatpost Poll: Can We Fix 2FA?
Hack Allows Escape of Play-with-Docker Containers

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

British TV viewers targeted by email fraudsters
Ryuk Hauls in $3.7M in ‘Earnings,’ Adds TrickBot to the Attack Mix
Mozilla Kills Default Support for Adobe Flash in Firefox 69
RBS reissues punters with new bank cards after Ticketmaster breach
Goddamn the Pusher man: Nominet kicks out domain name hijack bid
Shutdown hits government websites as certificates begin to expire
Poland may consider Huawei ban amid ‘spy’ arrests – reports
Data Exposed in OXO, Amazon and MongoDB Leaks
Nissan EV app password reset prompts user panic

LinuxSecurity.com: An update for systemd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

CES: Smart cities and the challenge of securing the neighborhood

In our final report from CES we take a look at smart city initiatives The post CES: Smart cities and the challenge of securing the neighborhood appeared first on WeLiveSecurity

Podcast: Emotet Grows With Fast-Evolving Tactics
10 years for Boston Children’s Hospital attacker
New Linux Systemd security holes uncovered
Governments need to embrace AI for the good of the people
USB-C Authentication sounds great, so why are people worried?
Facebook exec gets SWATted
The DDoS attacker rescued by a Disney cruise ship is sentenced to over 10 years in prison
Brit hacker hired by Liberian telco to nobble rival now behind bars

LinuxSecurity.com: New zsh packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is now available.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: The Qualys Research Labs discovered multiple vulnerabilities in systemd-journald. Two memory corruption flaws, via attacker-controlled alloca()s (CVE-2018-16864, CVE-2018-16865) and an out-of-bounds read flaw leading to an information leak (CVE-2018-16866), could allow an attacker to

LinuxSecurity.com: The package python2-django before version 1.11.18-1 is vulnerable to content spoofing.

LinuxSecurity.com: The package python-django before version 2.1.5-1 is vulnerable to content spoofing.

security update

LinuxSecurity.com: Due to kernel issue there is a way to reuse start_time of a process. This allows to duplicate process authorized by polkit. This update mitigates polkit issue #75 (slowfork): https://gitlab.freedesktop.org/polkit/polkit/issues/75

It only takes a Skype Call to Unlock an Android Handset
Kaspersky tipped off US about the contractor who stole NSA data
9 million users installed 85 adware infected apps from Play Store
Aussie govt emergency service hacked to send fake warning alerts
WhatsApp Gold Scam is Back with Malware Payload
Hacker ‘BestBuy’ sentenced to prison for operating Mirai DDoS botnet
Facebook staff discussed cashing in on user data, reports say

LinuxSecurity.com: An integer underflow was discovered in the CAF demuxer of the VLC media player. For the stable distribution (stretch), this problem has been fixed in

Facebooker swatted, Kaspersky snares an NSA thief, NASA server exposed, and more

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: Resolves CVE-2018-16869

LinuxSecurity.com: Resolves CVE-2018-16869

*taps on glass* Hellooo, IRS? Anyone in? Anyone guarding taxpayers’ data from crooks? Hellooo?
AT&T, Sprint, Verizon, T-Mobile US pledge, again, to not sell your location to shady geezers. Sorry, we don’t believe them

LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Pre-Installed Android App Impacts Millions with Slew of Malicious Activity
Anonymous hacker jailed for 10 years over hospital DDoS attacks

security update

TA505 Crime Gang Debuts Brand-New ServHelper Backdoor
Unprotected MongoDB leaks resumes of 202M Chinese job seekers
U.S. Government Shutdown Leaves Dozens of .Gov Websites Vulnerable
Yet Another Bypass: Is 2FA Broken? Authentication Experts Weigh In
Medical advice app Your.MD could have been tampered with by anyone, alleges ex-veep
Huawei sales director nicked in Poland on suspicion of ‘spying’

Reading Time: ~2 min. Malicious Apps Get Millions of Installs Google recently removed 85 apps from the Play Store after they were found to contain predatory adware. With over nine million combined downloads, the apps were mostly fake games or utility apps that began pushing a constant stream of full-screen ads to users until the […]

Old tweets reveal hidden secrets
2FA codes can be phished by new pentest tool

LinuxSecurity.com: The package wireshark-cli before version 2.6.6-1 is vulnerable to multiple issues including information disclosure and denial of service.