Menu

Category Archives: All

Everything

Dark web sites could be exposed by routine slip-up
How a data request turned into a data breach
Russia ‘front of the queue’ when it comes to hacking, says security minister
ThreatList: Attacks on Industrial Control Systems on the Rise
Teenage hacker admits making hoax bomb threats against schools and airlines
M-M-M-MONSTER KILL: Cisco’s bug-wranglers swat 29 in single week
It looks like tech-savvy drivers will have to lead connected car data purge
Could you hack your bosses without hesitation, repetition or deviation? AI says: No
Supermicro wraps crypto-blanket around server firmware to hide it from malware injectors

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Bug bounty alert: Musk lets pro hackers torpedo Tesla firmware risk free
U.S. Ties Lazarus to North Korea and Major Hacking Conspiracy
Wannabe Supreme Brett Kavanaugh red-faced after leaked emails contradict spy testimony

LinuxSecurity.com: Firefox could be made to crash or run programs as your login if it opened a malicious website.

LinuxSecurity.com: Several vulnerabilities were found in qemu, a fast processor emulator: CVE-2015-8666

security update

security update

FBI fingers the Norks it wants to pinch for Sony hack, WannaCry attacks
‘World’s favorite airline’ favorite among hackers: British Airways site, app hacked for two weeks
British Airways hacked – customer data and details of 380,000 card payments stolen

LinuxSecurity.com: Several security issues were fixed in libtirpc.

LinuxSecurity.com: Several security issues were fixed in libtirpc.

Risk Level: Very Low. Type: Trojan.

Active Spy Campaign Exploits Unpatched Windows Zero-Day
Open Source Summit: Innovation, Allies, and Open Development
Mozilla Patches Critical Code Execution Bug in Firefox 62
Could home appliances knock down power grids?

Far-fetched though it may sound, the answer is yes, according to researchers, who show that electrical grids and smart home appliances could make for a dangerous mix The post Could home appliances knock down power grids? appeared first on WeLiveSecurity

Mobile spyware maker mSpy leaks millions of records – AGAIN
Social Security numbers exposed on US government transparency site
How to manipulate Apple’s podcast charts, and get yourself a top-rated show
HTTPS crypto-shame: TV Licensing website pulled offline
High-Severity Flaws in Cisco Secure Internet Gateway Service Patched
Thousands of MikroTik routers are snooping on user traffic
Thousands of unsecured 3D printers discovered online
Ungagged Google warns users about FBI accessing their accounts

LinuxSecurity.com: It was discovered that there was an integer overflow vulnerability in the “Little CMS 2” colour management library. A specially-crafted input file could lead to a heap-based buffer overflow.

Using just a laptop, boffins sniff, spoof and pry – without busting browser padlock
Nope, the NSA isn’t sitting in front of a supercomputer hooked up to a terrorist’s hard drive

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.2 to fix security issues.

LinuxSecurity.com: New ghostscript packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

NASA ‘sextortionist’ allegedly tricked women into revealing their password reset answers, stole their nude selfies
Smashing Security #094: Rogue browser extensions, Twitter presence, and how to cheat in exams
Do you really think crims would do that? Just go on the ‘net and exploit a Windows zero-day?
Take a pinch of autofill, mix in HTTP, and bake on a Wi-Fi admin page: Quirky way to swipe a victim’s router password
Premera Blue Cross hacker victims claim insurer trashed server to hide data-slurp clues

Reading Time: ~4 min.If you saw a file called eicar.com on your computer, you might think it was malware. But, you would be wrong. Readers, if you haven’t yet met the EICAR test file, allow me to introduce you to it. If you have used the EICAR test file, let’s get a bit cozier with […]

LinuxSecurity.com: Zhaoyang Wu discovered that cURL, an URL transfer library, contains a buffer overflow in the NTLM authentication code triggered by passwords that exceed 2GB in length on 32bit systems.

OilRig Sends an OopsIE to Mideast Government Targets

security update

LinuxSecurity.com: Michael Kaczmarczik discovered a vulnerability in the web interface template editing function of Sympa, a mailing list manager. Owner and listmasters could use this flaw to create or modify arbitrary files in the server with privileges of sympa user or owner view list config files

LinuxSecurity.com: The git-annex package was found to have multiple vulnerabilities when operating on untrusted data that could lead to arbitrary command execution and encrypted data exfiltration.

Misconfigured Tor sites using SSL certificates exposing public IP addresses
Google Rolls Out 40 Fixes with Chrome 69

LinuxSecurity.com: The daemon in GDM does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rhvm-appliance is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Active Campaign Exploits Critical Apache Struts 2 Flaw in the Wild
MEGA secure upload service gets its Chrome extension hacked
The Vulnerability Disclosure Process: Still Broken
Ran Levi interviews Graham Cluley on the Malicious Life podcast
IDG Contributor Network: How enterprise knowledge graphs can proactively reduce risk
IDG Contributor Network: Replication isn’t data protection. Here’s why
MEGA Chrome extension hacked with cryptocurrency malware
Linus Torvalds: Changes in hardware change Linux development
You are not alone; Facebook, Instagram and WhatsApp are down for many (Updated)
Don’t Fall for Webcam Blackmail: Here’s How to Protect Yourself
PowerPool malware exploits ALPC LPE zero-day vulnerability

Malware from newly uncovered group PowerPool exploits zero-day vulnerability in the wild, only two days after its disclosure The post PowerPool malware exploits ALPC LPE zero-day vulnerability appeared first on WeLiveSecurity

Everything DM gets direct message slap: Marketing biz cops £60k ICO fine
Silence! Cybercrime’s Pinky and the Brain have nicked $800k off banks
Serious Fraud Office trialling AI for data-heavy cases
Knock, knock: Digital key flaw unlocks door control systems
Department of Labour denies server compromise in recent cyberattack
This malware disguises itself as bank security to raid your account
ICO Breach Reports Jump 75% as Human Error Dominates
If an extension goes rogue, everything you do in your browser is compromised
Tiny Island Atoll’s Domain Used in Widespread Ad Fraud
Can ‘sonar’ sniff out your Android’s lock code?
Google releases free AI tool to stamp out child sexual abuse material
Brit teen pleads guilty to Minecraft-linked bomb and airline hoaxes
Cybercrooks home in on infosec’s weakest link – you poor gullible people
Premera Blue Cross victims accuse insurer of deliberately destroying hacking evidence
Uncle Sam wants tech toolkit to snoop social media stock scammers

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: Quang Nguyen discovered an integer overflow in the Little CMS 2 colour management library, which could in denial of service and potentially the execution of arbitrary code if a malformed IT8 calibration file is processed.

Mikrotik routers pwned en masse, send network data to mysterious box
Multiple Remote Code-Execution Flaws Patched in Opsview Monitor
Google and MasterCard will track your retail spending under a secret deal
Thousands of MikroTik Routers Hijacked for Eavesdropping

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

ThreatList: 60% of BEC Attacks Fly Under the Radar
Credit card gobbling malware found piggybacking on ecommerce sites