Menu

Category Archives: All

Everything

security update

LinuxSecurity.com: CVE-2018-14767 Fix for missing input validation, which could result in denial of service and potentially the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were discovered in Jetty, a Java servlet engine and webserver which could result in HTTP request smuggling. For the stable distribution (stretch), these problems have been fixed in

LinuxSecurity.com: New upstream release fixing YSA-2018-03 (#1613863)

LinuxSecurity.com: New upstream release fixing YSA-2018-03 (#1613863)

LinuxSecurity.com: New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Instagram acknowledges & addresses hacking spree against user accounts
The state of cybersecurity at small organizations
The 5 Challenges of Detecting Fileless Malware Attacks
AI in cybersecurity: what works and what doesn’t
Mastering email security with DMARC, SPF and DKIM
Facebook Messenger backdoor demand, bail in Bitcoin, and lots more
SentinelOne makes YouTube delete Bsides vid ‘cuz it didn’t like the way bugs were reported
‘Oh sh..’ – the moment an infosec bod realized he was tracking a cop car’s movements by its leaky cellular gateway

security update

security update

security update

16-year old compromised Apple networks to steal GBs of sensitive data
Philips Vulnerability Exposes Sensitive Cardiac Patient Information
Unique Malspam Campaign Uses MS Publisher to Drop a RAT on Banks

LinuxSecurity.com: Several vulnerabilities were discovered in Mutt, a text-based mailreader supporting MIME, GPG, PGP and threading, potentially leading to code execution, denial of service or information disclosure when connecting to a malicious mail/NNTP server.

Severe PHP Exploit Threatens WordPress Sites with Remote Code Execution

Risk Level: Very Low. Type: Trojan.

AT&T Faces $224M Legal Challenge Over SIM-Jacking Rings
Web cache poisoning just got real: How to fling evil code at victims
ThreatList: Almost Half of the World’s Top Websites Deemed ‘Risky’
Shiver me timbers: Symantec spots activist investor Starboard side
SuperProf private tutor site massively fails password test, makes accounts super easy to hack
Apple gets cored: 90GB of ‘secure files’ stolen by high schooler
‘Foreshadow’ flaw found in Intel CPUs – what to do

LinuxSecurity.com: An update that solves 12 vulnerabilities and has 60 fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves 14 vulnerabilities and has 41 fixes is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

Most staffers expect bosses to snoop on them, say unions
US rolls back cyberwarfare rules
Australian schoolboy hacks into Apple’s network, steals files

His lawyer claims that the teen did the hacking because he admired Apple and dreamed of landing a job in the company The post Australian schoolboy hacks into Apple’s network, steals files appeared first on WeLiveSecurity

Apple hacked by 16-year-old who “dreamed” of working for firm
Indian Bank Loses $13.5m in Global Attack
UK Identity Fraud Falls but Online Scams Rise
Nigerian National Convicted for Phishing US Universities
ATM Heists Only Set to Accelerate After $13M Break-In
Week in security with Tony Anscombe

The first week in security video round-up from WeLiveSecurity The post Week in security with Tony Anscombe appeared first on WeLiveSecurity

What happens to your online accounts when you die?
Romance scam victim allegedly plotted to kill her mother for cash

LinuxSecurity.com: Fariskhi Vidyan and Thomas Jarosch discovered several vulnerabilities in php-horde-image, the image processing library for the Horde groupware suite. They would allow an attacker to cause a denial-of-service or execute arbitrary code.

Reading Time: ~2 min.Instagram Hack Baffles Users Hundreds of Instagram users have found themselves locked out of their accounts over the past week, with all methods of retrieving them having been removed as well. The episode began with many users noticing their accounts had been logged out and contact information changed, including email addresses with […]

Sextortion and what to do about it [VIDEO]

Risk Level: Very Low. Type: Trojan.

security update

security update

Who was it that hacked Apple? Ozzie Ozzie Ozzie, boy boy boy!

LinuxSecurity.com: mysql: Client programs unspecified vulnerability (CPU Jul 2017) (CVE-2017-3636) * mysql: Server: DML unspecified vulnerability (CPU Jul 2017) (CVE-2017-3641) * mysql: Client mysqldump unspecified vulnerability (CPU Jul 2017) (CVE-2017-3651) * mysql: Server: Replication unspecified vulnerability (CPU Oct 2017) (CVE-2017-10268) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 20 [More…]

LinuxSecurity.com: QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams (CVE-2018-11806) * QEMU: i386: multiboot OOB access while loading kernel image (CVE-2018-7550) Bug Fix(es): * Previously, live migrating a Windows guest in some cases caused the guest to become unresponsive. This update ensures that Real-time Clock (RTC) interrupts are not missed, which prevents the problem […]

Highly Flexible Marap Malware Enters the Financial Scene
Juno this ain’t right! Chinese hackers target Alaska

Type: Vulnerability. Adobe Flash Player is prone to multiple information-disclosure vulnerabilities; fixes are available.

New Trickbot Variant Touts Stealthy Code-Injection Trick
‘China’s MIT’ Linked to Espionage Campaign Against Alaska, Economic Partners
Google Expands Bug-Bounty Program to Battle Abuse Methods
Open MQTT Servers Raise Physical Threats in Smart Homes
Hackers steal $13.5 million from Indian bank in global attack
Some 2.6 billion data records exposed in first half of 2018

The newly-released report provides an overview of the data breach landscape in the first half of this year The post Some 2.6 billion data records exposed in first half of 2018 appeared first on WeLiveSecurity

ThreatList: Telecom Sector Plagued with Advanced Malware
Ex-NSA hacker proves how easily macOS user warnings can be bypassed by malware

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Google Chrome Bug Opens Access to Private Facebook Information
Australians who won’t unlock their phones could face 10 years in jail
Hackers Target Instagram, Users Blame Russia
Washington Man Sentenced in Ransomware Conspiracy
Election Websites, Backend Systems Most at Risk of Cyberattack in Midterms
Sacramento admits to tracking welfare recipients’ license plates
Silk Road founder Ross Ulbricht is dictating tweets from prison
Smashing Security #091: Sextortion, Las Vegas hotels, and Alex Jones
Bogus journals being used to publish fake science

LinuxSecurity.com: fix for CVE-2018-14526

Risk Level: Very Low. Type: Trojan.

Mozilla-endorsed security plug-in accused of tracking users
Making money mining Coinhive? Yeah, you and nine other people
Microsoft Cortana Flaw Allows Web Browsing on Locked PCs
BlackIoT Botnet: Can Water Heaters, Washers Bring Down the Power Grid?

security update

New Intel chip flaw “Foreshadow” attacks SGX technology to extract sensitive data
India’s Cosmos bank raided for $13m by hackers
Support for ageing key exchange crypto leaves VPNs open to attack

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.