Menu

Category Archives: All

Everything

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: Django could be made to expose spoofed information over the network.

LinuxSecurity.com: Several security issues were fixed in NSS.

ThreatList: WordPress Vulnerabilities Tripled in 2018
Biometrics in 2019: Increased Security or New Attack Vector?
The Promise and Peril of 5G
Intel Patches High-Severity Privilege-Escalation Bugs
Google Play Store spews malware onto 9 million ‘Droids
IoT weaknesses leave hot tub owners in deep water
Some Android apps are secretly sharing your data with Facebook
Automated phishing attack tool bypasses 2FA protection
Zerodium’s waving fatter payouts for zero-day bug hunters
How to share photos – without using Facebook
Politicians who block social media users are violating First Amendment
Being paid to quit Facebook
This old ransomware is using an unpleasant new trick to try and make you pay up
Ethereum Classic hackers steal over $1.1M with 51% attacks
CES – singularity and securing the car

What’s in store for automotive security once cars morph into mobile living rooms and working spaces? And how about transportation at large? The post CES – singularity and securing the car appeared first on WeLiveSecurity

LinuxSecurity.com: Updates for rh-dotnet21-dotnet and rh-dotnet22-dotnet are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Great, you’ve moved your website or app to HTTPS. How do you test it? Here’s a tool to make local TLS certs painless
Make a SAP decision: Apply these security fixes if you’re using German giant’s software

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Welcome to 2019: Your Exchange server can be pwned by an email (and other bugs need fixing)
Jeep hacking lawsuit shifts into gear for trial after US Supremes refuse to hit the brakes

LinuxSecurity.com: The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file (CVE-2018-11468). DISCOUNT through version 2.2.3a is vulnerable to a Heap-based

LinuxSecurity.com: Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-muscle.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact (CVE-2018-16391).

LinuxSecurity.com: Jeffrey Altman reported that the backup tape controller (butc) process does accept incoming RPCs but does not require (or allow for) authentication of those RPCs, allowing an unauthenticated attacker to perform volume operations with administrator credentials (CVE-2018-16947).

LinuxSecurity.com: It was found that when a retry task in ansible run with -vvv fails, it will log the raw return code, stdout and stderr from ssh which could have contained sensitive data (CVE-2018-16876). References:

LinuxSecurity.com: A leaky data conversion exposing a manager oracle (CVE-2018-16869). References: – https://bugs.mageia.org/show_bug.cgi?id=24080 – https://lists.opensuse.org/opensuse-updates/2018-12/msg00120.html

LinuxSecurity.com: A flaw was found in GNU Coreutils through 8.29 in chown-core.c. The functions chown and chgrp do not prevent replacement of a plain file with a symlink during use of the POSIX “-R -L” options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition (CVE-2017-18018).

LinuxSecurity.com: Double free in QXmlStreamReader (CVE-2018-15518). Denial of Service on malformed BMP file in QBmpHandler (CVE-2018-19873). References:

LinuxSecurity.com: The avidemux package has been updated to version 2.7.1. Avidemux includes a bundled copy of the ffmpeg libraries, which have been updated from version 3.3.3 to version 3.3.9, fixing several security issues and other bugs.

LinuxSecurity.com: It was discovered that ruby-loofah, a general library for manipulating and transforming HTML/XML documents and fragments, performed insufficient sanitising of SVG elements.

LinuxSecurity.com: It was discovered that malformed URLs could spoof the content of the default 404 page of Django, a Python web development framework. For the stable distribution (stretch), this problem has been fixed in

Shipping Firms Speared with Targeted ‘Whaling’ Attacks
Microsoft Issues Multiple Critical Patches for Edge Browser

LinuxSecurity.com: The package elfutils before version 0.175-1 is vulnerable to denial of service.

Senator Wyden goes ballistic after US telcos caught selling people’s location data yet again
Malvertising Campaign Delivers Double Whammy of Ransomware and Info-Stealing

Risk Level: Very Low.

SMS phishing is alive and well… and simply believable
Adobe Patches Important Bugs in Connect and Digital Edition
Fill the gaps in your security knowledge at SANS London April 2019
Cops: German suspect, 20, ‘confessed’ to mass hack of local politicians
A photo will unlock many Android phones using facial recognition
How to spot a social media hoax
Hacker uses early warning system for fake message campaign
How Facebook’s privacy woes might change the rules of the road in 2019
Top 4 enterprise tech trends to watch in 2019
LA sues The Weather Channel over selling users’ location data
New Year’s resolutions: Get your passwords shipshape

In case there are some blank entries in your laundry list of New Year’s resolutions, we have a few tips for a bit of cybersecurity ‘soul searching’. Here’s the first batch, looking at how you can fix your good ol’ passwords. The post New Year’s resolutions: Get your passwords shipshape appeared first on WeLiveSecurity

Linus Torvalds opts for the scream test: Linux kernel syscall tweaked to shut data-leak hole – anyone upset, yell now
FYI: Twitter’s API still spews enough metadata to reveal exactly where you lived, worked
Aussie Emergency Warning Network hacked by rank amateurs

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Hackers Infiltrate Early Warning Network System to Send Spam
She will lock you out, livin’ la Vidar loca: Enterprising crims breed ransomware, file thief into hybrid nasty
Zerodium Raises Zero-Day Payout Ceiling to $2M
ThreatList: Container Security Lags Amidst DevOps Enthusiasm

LinuxSecurity.com: A NULL pointer dereference flaw was found in the way dcraw processed images. An attacker could potentially use this flaw to crash dcraw by tricking it into processing crafted images (CVE-2018-5801). References:

LinuxSecurity.com: A flaw was found in libao. The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 can cause a denial of service(memory corruption) via a crafted mp3 file (CVE-2017-11548). References:

LinuxSecurity.com: NULL pointer dereference in the function aubio_source_avcodec_readframe which may lead to DoS when playing a crafted audio file (CVE-2017-17554). A crash in aubio_pitch_set_unit (CVE-2018-14522).

Risk Level: Very Low.

Snowden’s Attorney Urges Canada to Take in Whistleblower Helpers (Part Two)
Earn $2,000,000 by remotely jailbreaking an iPhone
unCAPTCHA AI Cracks Google reCAPTCHAs with 90% Accuracy
EU offers bug bounties on popular open source software

The program with a prize pool of almost US$1 million aims to leverage the ‘power of the crowd’ in order to prevent another Heartbleed The post EU offers bug bounties on popular open source software appeared first on WeLiveSecurity

Skype Glitch Allowed Android Authentication Bypass

Reading Time: ~3 min. SMBs are overconfident about their cybersecurity posture. A survey of SMBs conducted by 451 Research found that in the preceding 24 months, 71% of respondents experienced a breach or attack that resulted in operational disruption, reputational damage, significant financial losses or regulatory penalties. At the same time, 49% of the SMBs […]

No Android passcode? No problem! Skype unlocked it for you

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 6.6 Telco Update Service (TUS). This notification applies only to those customers subscribed to the Telco Update Service (TUS) channel for Red Hat Enterprise Linux 6.6.

Podcast: Beware These Top Security Threats in 2019
Hacker doxes hundreds of German politicians
Major US newspapers crippled by Ryuk ransomware attack
Marriott Sheds New Light on Massive Breach
Singapore Airlines data breach affects 284 accounts, exposes travel details
Update now! Adobe Acrobat and Reader have critical flaws
Monday review – the hot stories of the new year

LinuxSecurity.com: It was discovered that there was a content-spoofing vulnerability in the default 404 pages in the Django web development framework. For more information, please see:

Dark Overlord hackers publish first batch of “secret” 9/11 files
Irish tram system website hacked; held for 1 BTC ransom
How to Turn Your IT Skills into a Business
Google fixes critical vulnerability in Chrome for Android after 3 years
Abine Blur Password Manager exposed data of 2.4M users
Hackers play PewDiePie ad on thousands of hacked Chromecasts & Smart TVs
EU launches Bug Bounty program for 14 free open-source products
Dark Overlord hackers vow to leak 9/11 related data stolen from law firm

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2019:0022

Singapore Airlines customer logs into account, sees stranger’s personal data
Town of Salem Data Breach Exposes 7.6 Million Gamers’ Accounts

LinuxSecurity.com: This release (4.3.1) contains bug fixes only: – Fix checkspell detected typos (#531) – Heap overflow packet2tree and get_l2len (#530) This is Tcpreplay suite 4.3.0 This release contains several bug fixes and enhancements: – Fix maxOS TOS checksum failure (#524) – TCP sequence edits seeding (#514) – Fix issues identifed by Codacy (#493) – […]

LinuxSecurity.com: This release (4.3.1) contains bug fixes only: – Fix checkspell detected typos (#531) – Heap overflow packet2tree and get_l2len (#530) This is Tcpreplay suite 4.3.0 This release contains several bug fixes and enhancements: – Fix maxOS TOS checksum failure (#524) – TCP sequence edits seeding (#514) – Fix issues identifed by Codacy (#493) – […]

LinuxSecurity.com: Since version 1.19 Wget stores the URL and in certain cases the ‘Referer’ URL within extended attributes (xattrs) of the file system – by default. This includes username + password and other credentials or private data *if* those have been used within the URLs. Anyone with read access to

The Advantages of a More Secure and Safer Blockchain

LinuxSecurity.com: Florian Stuelpner discovered that Samba is vulnerable to infinite query recursion caused by CNAME loops, resulting in denial of service (CVE-2018-14629). Alex MacCuish discovered that a user with a valid certificate or smart