Menu

Category Archives: All

Everything

Intel finally emits Puma 1Gbps modem fixes – just as new ping-of-death bug emerges

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

security update

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

It’s official: TLS 1.3 approved as standard while spies weep

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: The package thunderbird before version 60.0-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

LinuxSecurity.com: Chris Coulson discovered a use-after-free flaw in the GNOME Display Manager, triggerable by an unprivileged user via a specially crafted sequence of D-Bus method calls, leading to denial of service or potentially the execution of arbitrary code.

New Variant of KeyPass Ransomware Discovered
Blue Team Village, DEF CON 2018 | Salted Hash Ep 43
Black Hat 2018: IoT Security Issues Will Lead to Legal ‘Feeding Frenzy’
GoDaddy Leaks ‘Map of the Internet’ via Amazon S3 Cloud Bucket Misconfig

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

DEF CON 2018: ‘Man in the Disk’ Attack Surface Affects All Android Phones
How a cryptocurrency-destroying bug almost didn’t get reported
Black Hat Video Exclusive: Mobile APTs Redefining Phishing Attacks
US voting systems: Full of holes, loaded with pop music, and hacked by an 11-year-old
DEF CON 2018: Voting Hacks Prompt Push Back from Election Officials, Vendors

LinuxSecurity.com: Multiple vulnerabilities have been discovered in various parsers of Blender, a 3D modeller/ renderer. Malformed .blend model files and malformed multimedia files (AVI, BMP, HDR, CIN, IRIS, PNG, TIFF) may result in the execution of arbitrary code.

Can cramming code with bugs make it more secure? Some think so

Unbeknownst to exploit writers, the seemingly mouth-watering bugs would be bogus and non-exploitable The post Can cramming code with bugs make it more secure? Some think so appeared first on WeLiveSecurity

Siri is listening to you, but she’s NOT spying, says Apple
Feds indict 12 for allegedly buying iPhones on other people’s dimes
In-flight satellite comms vulnerable to remote attack, researcher finds

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 9 fixes is now available.

Security breach in the White House’s Situation Room
PGA of America Struck By Ransomware
#DEFCON DHS Says Collaboration Needed for Secure Infrastructure and Elections
#DEFCON Government Attacks and Surveillance Continue to Increase
Criminal justice software code could send you to jail and there’s nothing you can do about it
Hackers can manipulate Police body cam footages
Prank ‘Give me a raise!’ email nearly lands sysadmin with dismissal
Former NSA top hacker names the filthy four of nation-state hacking
Black Hat: Protecting Industrial Control System

Aiming to protect critical infrastructure against attacks The post Black Hat: Protecting Industrial Control System appeared first on WeLiveSecurity

UK cyber cops: Infosec pros could help us divert teens from ‘dark side’
DEF CON 2018: Critical Bug Opens Millions of HP OfficeJet Printers to Attack
DEF CON 2018: Apple 0-Day (Re)Opens Door to ‘Synthetic’ Mouse-Click Attack
The Enigma of AI & Cybersecurity
NSA Brings Nation-State Details to DEF CON
#DEFCON L0pht Reunite to Find Security Unimproved
DEF CON 2018: Hacking Medical Protocols to Change Vital Signs

security update

security update

LinuxSecurity.com: – update to 2.56.x

LinuxSecurity.com: – update to 2.56.x

LinuxSecurity.com: rebase to 8.37.0 ———————- – few fixes and enhancements handling journal input – now requires librelp at least 1.2.16, adding support for setting address to bind – various other rsyslog core bugfixes and stability fixes

DEF CON 2018: Telltale URLs Leak PII to Dozens of Third Parties

LinuxSecurity.com: New upstream version 0.7alpha. Fixes CVE-2018-14679 libmspack: off-by-one error in the CHM PMGI/PMGL chunk number validity checks

Cyber Criminals selling Bitcoin ATM Malware on Dark Web
Snap code snatched, Pentagon bans bands, pacemakers cracked, etc
Blue Team village, Deffcon 2018 | Salted Hash Ep. 43

LinuxSecurity.com: New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

PGA Golf Championship hit with Bitcoin ransomware
The off-brand ‘military-grade’ x86 processors, in the library, with the root-granting ‘backdoor’
Chris Valasek and Charlie Miller: How to Secure Autonomous Vehicles
Sensitive data on 31,000 GoDaddy servers exposed online

LinuxSecurity.com: Two vulnerabilities have been found in the PostgreSQL database system: CVE-2018-10915

LinuxSecurity.com: It was discovered that the PatternSyntaxException class in the Concurrency component of OpenJDK, an implementation of the Oracle Java platform could result in denial of service via excessive memory consumption.

LinuxSecurity.com: Various vulnerabilities leading to denial of service or possible unspecified other impacts were discovered in sam2p, an utility to convert raster images to EPS, PDF, and other formats.

Hackers phish Butlin’s holiday camp chain, access customers’ personal data
Black Hat 2018: Voice Authentication is Broken, Researchers Say
Hi-de-Hack! Redcoats red-faced as Butlin’s holiday camp admits data breach hit 34,000
Congresscritters want answers on Tillerson’s rm -rf /opt/gov/infosec
How one man could have hacked every Mac developer (73% of them, anyway)
Comcast Xfinity web flaws exposed customer data
15,000-strong army of Twitter robots found spreading cryptocurrency spam

LinuxSecurity.com: Several security issues were fixed in the kernel.

Over 20 Flaws Discovered in Popular Healthcare Software
#BHUSA: Politics and Cyber-Defense Are Colliding
Off-colour tweet earns Google’s Spectre whizz a midnight eviction from Caesars and DEF CON

Reading Time: ~2 min.Chipmaker Production Halts After WannaCry Attack A recent WannaCry attack at a Taiwanese chip manufacturerhas brought production to a standstill and threatens delays for new Apple products yet to be released. The manufacturer has announced that after two days their systems are clear and production is able to continue, blaming their own […]

Black Hat 2018: With Healthcare Security Flaws, Safety’s Increasingly at Stake
Facebook ‘regrets’ balloons and confetti triggered by earthquake posts
Hackers can cook people alive using sat-comms ‘microwave oven’ death rays – claim
Encryption doesn’t stop him or her or you… from working out what Thing 1 is up to
Spec-exec CPU bugs sweep hacking Oscars – and John McAfee’s in there like a bullet
Can we talk about the little backdoors in data center servers, please?
Say what you will about self-driving cars – the security is looking ‘OK’

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.