Menu

Category Archives: All

Everything

Risk Level: Very Low.

Everyone screams patch ASAP – but it takes most organizations a month to update their networks
Apache’s latest SNAFU – Struts normal, all fscked up: Web app framework needs urgent patching
DNC Becomes Latest Target in Series of Election-Season Attacks

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

One-in-two JavaScript project audits by NPM tools sniff out at least one vulnerability…
Unpatched Ghostscript Flaws Allow Remote Takeover of Systems

LinuxSecurity.com: The security update announced as DSA 4279-1 caused regressions on the ARM architectures (boot failures on some systems). Updated packages are now available to correct this issue.

LinuxSecurity.com: An update for openstack-keystone is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: mutt: Remote code injection vulnerability to an IMAP mailbox (CVE-2018-14354) * mutt: Remote Code Execution via backquote characters (CVE-2018-14357) * mutt: POP body caching path traversal vulnerability (CVE-2018-14362) SL6 x86_64 mutt-1.5.20-9.20091214hg736b6a.el6.x86_64.rpm mutt-debuginfo-1.5.20-9.20091214hg736b6a.el6.x86_64.rpm i386 mutt-1.5.20-9.20091214hg736b6a.el6.i68 [More…]

LinuxSecurity.com: base-files could be made to hang or overwrite files as the administrator.

Researchers Blame ‘Monolithic’ Linux Code Base for Critical Vulnerabilities
Cisco smells a RAT in Breaking Security’s Remcos PC wrangler
Triout Malware Carries Out Extensive, Targeted Android Surveillance
Misconfigured backup leads to exposure of 50.5 million GOMO Mobile customers
Podcast: Bad Packets Report Founder on Rising Cryptojacking Attacks
New Red Hat Product Security OpenPGP key
Turla: In and out of its unique Outlook backdoor

The latest ESET research offers a rare glimpse into the mechanics of a particularly stealthy and resilient backdoor that the Turla cyberespionage group can fully control via PDF files attached to emails The post Turla: In and out of its unique Outlook backdoor appeared first on WeLiveSecurity

Scot.gov wins pals with pledge not to keep hold of innocents’ mugshots and biometric data
Adobe Patches Critical Photoshop Flaws in Unscheduled Update
Netflix, HBO GO, Hulu passwords found for sale on the Dark Web
Extortionist lawyer pleads guilty to creating porn honeypot
Get serious about consumer data protection
Ohio Man Sentenced to 15 Years for BEC Scam
Augusta Health Center Reveals Historic Breach
Elders of internet hash out standards to grant encrypted message security for world+dog
Microsoft disrupts Fancy Bear election meddlers
ETSI crypto-based access control standards land

LinuxSecurity.com: Dariusz Tytko, Michal Sajdak and Qualys Security discovered that OpenSSH, an implementation of the SSH protocol suite, was prone to a user enumeration vulnerability. This would allow a remote attacker to check whether a specific user account existed on the target server.

Ryuk Ransomware Emerges in Highly Targeted, Highly Lucrative Campaign
Super-mugs: Hackers claim to have snatched 20k customer records from Brit biz Superdrug
Security MadLibs: Your IoT electrical outlet can now pwn your smart TV
Dark Tequila: A Distilled Threat for Mexican Targets

LinuxSecurity.com: New libX11 packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Airmail 3 Exploit Instantly Steals Info from Apple Users
Use Debian? Want Intel’s latest CPU patch? Small print sparks big problem

Type: Vulnerability. Microsoft Internet Explorer is prone to an unspecified arbitrary code-execution vulnerability; fixes are available.

Serious Security: How to stop dodgy HTTP headers clogging your website

LinuxSecurity.com: An update for mutt is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: wpa_supplicant and hostapd could be made to expose sensitiveinformation if it received a crafted message.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Belkin IoT Smart Plug Flaw Allows Remote Code Execution in Smart Homes
Republican & Conservative leaders are the new targets of Russian hackers —Microsoft
Microsoft: We busted Russian Fancy Bear disinfo websites
IoT botnet of heaters & ovens can cause massive widespread power outages
Fake Android Fortnite version circulating on the web to spread malware
Video: Bishop Fox on Device Threats and Layered Security
Google Faces Legal Turmoil After Location Tracking Debacle
MadIoT: How an IoT botnet could launch a major attack on the power grid
Twitch admits exposing user messages after archiving error
Social networks to be fined for hosting terrorist content
Smart irrigation systems vulnerable to attacks, warn researchers

Internet-connected irrigation systems suffer from security gaps that could be exploited by attackers aiming, for example, to deplete a city’s water reserves, researchers warn The post Smart irrigation systems vulnerable to attacks, warn researchers appeared first on WeLiveSecurity

The security changes you can expect in iOS 12
Corporate pre-crime: The ethics of using AI to identify future insider threats
UK hacking prosecutions plummet with only 47 charges recorded last year
TLS developers should ditch ‘pseudo constant time’ crypto processing
Connected car data handover headache: There’s no quick fix… and it’s NOT just Land Rovers
That’s the way the cookies crumble: Consent banners up 16% since GDPR

LinuxSecurity.com: Several security issues were fixed in OpenJDK 10.

LinuxSecurity.com: USN-3742-2 introduced regressions in the Linux Hardware Enablement(HWE) kernel for Ubuntu 12.04 ESM.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2439

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2462

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2526

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2526

LinuxSecurity.com: ClamAV, an anti-virus utility for Unix, has released the version 0.100.1. Installing this new version is required to make use of all current virus signatures and to avoid warnings.

Canadian Telcos Patch an APT-Ready Flaw in Disability Services
Side-Channel PoC Attack Lifts Private RSA Keys from Mobile Phones

security update

LinuxSecurity.com: An attacker could trick APT into installing altered packages.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Hackers can intercept and manipulate DNS queries, researchers warn
Darkhotel Exploits Microsoft Zero-Day VBScript Flaw
GandCrab’s Rotten EGGs Hatch Ransomware in South Korea
Cybercrime isn’t going away, but hacking prosecutions are falling
SuperProf gets schooled after assigning weak passwords to tutors
Security Technologies: Stack Smashing Protection (StackGuard)
Rotten EGGs spread ransomware in South Korea

LinuxSecurity.com: An update for openstack-keystone is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for openvswitch is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

So phar, so FUD: PHP flaw puts WordPress sites at risk of hacks
Discover the State of Authentication and the Evolving Threat Landscape in this White Paper by OneSpan. Get your copy!

LinuxSecurity.com: Multiple researchers have discovered a vulnerability in the way the Intel processor designs have implemented speculative execution of instructions in combination with handling of page-faults. This flaw could allow an attacker controlling an unprivileged process to read

The Rise of Bespoke Ransomware
Australian Teen Hacked Apple Network
Firefox axes add-ons, developer pushes back
Los Angeles to use body scanners on metro riders
A heated summer for cybersecurity in Canada

An overview of some of the cyberattacks that Canadian organizations faced in the summer months of 2018 The post A heated summer for cybersecurity in Canada appeared first on WeLiveSecurity

LinuxSecurity.com: An update for rh-postgresql95-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Google employees protest work on censored search engine for China
Adblocking and browser privacy can be bypassed, researchers find
How’s that encryption coming, buddy? DNS requests routinely spied on, boffins claim
Et tu, Brute? Then fail, Caesars: When it’s hotel staff, not the hackers, invading folks’ privacy