Menu

Category Archives: All

Everything

Prison for man who assisted scareware scheme that targeted newspaper website
The Reg takes the US government’s insider threat training course
Kodi add-ons launch cryptomining campaign

ESET researchers have discovered several third-party add-ons for the popular open-source media player Kodi being used to distribute Linux and Windows cryptocurrency-mining malware The post Kodi add-ons launch cryptomining campaign appeared first on WeLiveSecurity

California bill regulates IoT for first time in US
Update now! Microsoft’s September 2018 Patch Tuesday is here
Solid password practice on Capital One’s site? Don’t bank on it
Smashing Security #095: British Airways hack, Mac apps steal browser history, and one person has 285,000 texts leaked

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: USN-3747-1 introduced a regression in OpenJDK 10.

Card-stealing code that pwned British Airways, Ticketmaster pops up on more sites via hacked JS

security update

security update

PowerShell Obfuscation Ups the Ante on Antivirus

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.

Whisky business: Uni of Edinburgh servers Irn-Scru’d by cyber-attack
Apple Yet to Patch Safari Browser Address Bar Spoofing Flaw
Osiris Banking Trojan Displays Modern Malware Innovation
TV License website said it was secure. It wasn’t
Back up a minute: Veeam database config snafu exposed millions of customer records
Researchers demonstrate how to unlock Tesla wireless key fobs in 2 seconds
Patch Tuesday: Microsoft plugs zero-day hole exploited by PowerPool

Microsoft and Adobe have each shipped out their scheduled batches of patches to address security flaws in their respective software The post Patch Tuesday: Microsoft plugs zero-day hole exploited by PowerPool appeared first on WeLiveSecurity

Microsoft purges 3,000 tech support scams hiding on TechNet
Beware: WhatsApp scammers target children with ‘Olivia’ porn message

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has four fixes is now available.

Younger Facebook users 4 times more likely to delete app, study shows

LinuxSecurity.com: Two input sanitization failures have been found in the faxrunq and faxq binaries in mgetty. An attacker could leverage them to insert commands via shell metacharacters in jobs id and have them executed with the

LinuxSecurity.com: It was discovered that there was a denial of service and a potential arbitrary code execution vulnerability in the kamailio SIP server. A specially-crafted SIP message with an invalid “Via” header could cause a

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Vizio to send class notices through the TVs that spied on viewers
Explore the threat landscape at Sophos ‘See the Future’ event
2-bit punks’ weak 40-bit crypto didn’t help Tesla keyless fobs one bit
Brit armed forces still don’t have enough techies, thunder MPs
Generally Disclosing Pretty Rapidly: GDPR strapped a jet engine on hacked British Airways

LinuxSecurity.com: Updates for rh-dotnet21 and rh-dotnet21-dotnet are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Low.

Risk Level: Very Low. Type: Trojan.

It’s September 2018, and Windows VMs can pwn their host servers by launching an evil app
Threatlist: Email Attacks Surge, Targeting Execs

LinuxSecurity.com: Two input sanitization failures have been found in the faxrunq and faxq binaries in mgetty, a smart modem getty replacement. An attacker could leverage them to insert commands via shell metacharacters in jobs id and have them executed with the privilege of the faxrunq/faxq user.

Security firm uses Twitter to disclose critical zero-day flaw in Tor Browser
Microsoft Patches Three Actively Exploited Bugs as Part of Patch Tuesday

LinuxSecurity.com: Zsh could be made to execute arbitrary code if it received a specially crafted script.

security update

LinuxSecurity.com: Henning Westerholt discovered a flaw related to the Via header processing in kamailio, a very fast, dynamic and configurable SIP server. An unauthenticated attacker can take advantage of this flaw to mount a denial of service attack via a specially crafted SIP message

Bad Actors Sizing Up Systems Via Lightweight Recon Malware
Millions of Records Exposed in Veeam Misconfigured Server
When is a patch not a patch? When it’s for this McAfee password bug

LinuxSecurity.com: A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Drive away a Tesla today (even if it isn’t yours)
Law firm seeking leak victims to launch £500m suit at British Airways
Live broadcast: Threat hunting in the modern attack landscape
Adobe Patches Six Critical Flaws in ColdFusion
The rise of targeted ransomware
Airbnb launches investigation after man finds hidden camera in clock
Abandoning a domain name can come back to bite you, research shows

A domain name once left behind can catch up with you – by giving fraudsters access to a treasure trove of sensitive information The post Abandoning a domain name can come back to bite you, research shows appeared first on WeLiveSecurity

Fetish app put users’ identities at risk with plain-text passwords
Magecart Group Pinned in Recent British Airways Breach
Yikes: 1 in 5 employees share their email passwords with coworkers

LinuxSecurity.com: Several security issues were fixed in the kernel.

Trend Micro apologises after Mac apps found scooping up users’ browser history
British Airways hack: Infosec experts finger third-party scripts on payment pages
Keybase browser extension weakness discovered
Microsoft extends security patch support for some Windows 7 users
Email security crisis… What email security crisis?

LinuxSecurity.com: An update is now available for Red Hat Fuse. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Safari, Edge fans: Is that really the website you think you’re visiting? URL spoof bug blabbed

LinuxSecurity.com: The system could be made to crash if it received specially craftednetwork traffic.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows kernel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft System.IO.Pipelines is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft OData is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Subsystem for Linux is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows kernel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.