Menu

Category Archives: All

Everything

Fortnite ditches Google Play – will it undermine Android security?
Bank on it: It’s either legal to port-scan someone without consent or it’s not, fumes researcher
Chipmaker TSMC Hit by Virus Outbreak
Privacy International Takes Police Phone ‘Hacking’ Case to IPC
Podcast: Black Hat USA 2018 Preview
No, Michael J Fox isn’t dead
What is a phishing kit? Watch this in-depth explainer | Salted Hash Ep 39
Top tip? Sprinkle bugs into your code to throw off robo-vuln scanners
Battle lines drawn over US mass surveillance as senators probe NSA’s bonfire of phone records
IBM, ATMs – WTF? Big Blue to probe cash machines, IoT, vehicles, etc in new security labs

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

BlackBerry claims it can do to ransomware what Apple did to its phones
Cracking the passwords of some WPA/WPA2 W-Fi networks just got easier
Fortnite Skips Google Play For Android Apps, Irking Security Experts
Ramnit Changes Shape with Widespread Black Botnet
Chip flinger TSMC warns ‘WannaCry’ outbreak will sting biz for $250m
Facebook cracks opens its bottle of Fizz – a carbonated TLS 1.3 lib

Reading Time: ~4 min.This week, I’ll be at Black Hat USA 2018 in Las Vegas. If you’ve ever been to Black Hat, then you know all about the flood of information and how hard it can be to take it all in. This year’s presentations will range from the newest trends in browser exploits, bots, […]

Top iPhone Supplier Battles WannaCry Infection
Making millions out of prisoners’ email
Interviewing ESET’s experts about the Web’s journey so far – part 1

What has the journey of the World Wide Web been like so far, as seen and experienced by ESET’s security folk? ESET Senior Research Fellow David Harley provides his take in the first installment of our series of interviews marking the Web’s 27th birthday. The post Interviewing ESET’s experts about the Web’s journey so far […]

Windows 10 updates under fire from unhappy security admins
Man arrested for blackmailing women with porn fakes
‘Unhackable’ Bitfi hardware rooted within a week
Guilty! Court sinks children’s hospital attacker found stranded on a boat
You’ll have to disable a recommended Android security setting to install Fortnite

LinuxSecurity.com: It was discovered that there were several vulnerabilities in libsmpack, a library used to handle Microsoft compression formats. A remote attacker could craft malicious .CAB, .CHM or .KWAJ files

An introduction to Kit Hunter, a phishing kit detector | Salted Hash Ep 40

LinuxSecurity.com: It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data.

LinuxSecurity.com: It was discovered that there was a directory traversal vulnerability in cgit, a web frontend for Git repositories. For Debian 8 “Jessie”, this issue has been fixed in cgit version

LinuxSecurity.com: An update for openslp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for rhvm-setup-plugins is now available for Red Hat Virtualization Engine 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for xmlrpc is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The fix for CVE-2018-10886 was incomplete in the previous upload. New changes was implemented upstream which check and resolve symlinks before expanding the archives.

LinuxSecurity.com: It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data.

LinuxSecurity.com: Andreas Hug discovered an open redirect in Django, a Python web development framework, which is exploitable if django.middleware.common.CommonMiddleware is used and the APPEND_SLASH setting is enabled.

security update

security update

LinuxSecurity.com: Backport fix for CVE 2017-11548

LinuxSecurity.com: Update to 3.2.1 (CVE-2017-12627)

LinuxSecurity.com: Update to 3.2.1 (CVE-2017-12627)

security update

LinuxSecurity.com: The package python2-django before version 1.11.15-1 is vulnerable to open redirect.

LinuxSecurity.com: The package cgit before version 1.2.1-1 is vulnerable to directory traversal.

Hacking tools & ready-made phishing pages being sold on dark web for $2
ZombieBoy cryptomining malware exploits CVEs to evade detection
Industrial Sector Targeted in Highly Personalized Spear-Phishing Campaign
GDPR: What’s really changed so far?

LinuxSecurity.com: Jann Horn discovered a directory traversal vulnerability in cgit, a fast web frontend for git repositories written in C. A remote attacker can take advantage of this flaw to retrieve arbitrary files via a specially crafted request, when ‘enable-http-clone=1’ (default) is not turned off.

TSMC chip fab tools hit by virus, payment biz BGP hijacked, CCleaner gets weird – and more
Security world to hit Las Vegas for a week of hacking, cracking, fun

security update

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 10 vulnerabilities is now available.

Massive ransomware attack forcing authorities to move to typewriters

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: The 4.17.11 stable update contains a number of important fixes across the tree. Also of note, starting with this release, kernel-headers is built from a different srpm. The contents should be the same, but there were some benefits to breaking it from the kernel build. —- The 4.17.10 stable kernel update contains a number […]

LinuxSecurity.com: Sync with git (CVE-2017-14160, CVE-2018-10392, CVE-2018-10393, bz#1516379)

LinuxSecurity.com: Update Python 2 dependency declarations to new packaging standards

security update

LinuxSecurity.com: Update Python 2 dependency declarations to new packaging standards

LinuxSecurity.com: The 4.17.11 stable update contains a number of important fixes across the tree. Also of note, starting with this release, kernel-headers is built from a different srpm. The contents should be the same, but there were some benefits to breaking it from the kernel build. —- The 4.17.10 stable kernel update contains a number […]

Consumer DNA Testing Takes a Step Towards Privacy, Transparency
Ever seen printer malware in action? Install this HP Ink patch – or you may find out

LinuxSecurity.com: Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to open redirects, cross-site request forgery, information disclosure, session fixation or denial of service.

LinuxSecurity.com: Enrico Zini discovered a vulnerability in Syntastic, an addon module for the Vim editor that runs a file through external checkers and displays any resulting errors. Config files were looked up in the current working directory which could result in arbitrary

LinuxSecurity.com: Update to 2.26, fixes CVE-2018-9275

LinuxSecurity.com: Update to 2.26, fixes CVE-2018-9275

LinuxSecurity.com: Several security issues were fixed in ClamAV.

Salesforce.com Warns Marketing Customers of Data Leakage SNAFU
Threatlist: SMB Security Challenges Grow with the Cloud
Web doc iCliniq plugs leaky S3 bucket stuffed full of medical records

LinuxSecurity.com: It was found that the security update of busybox announced as DLA-1445-1 to prevent the exploitation of CVE-2011-5325, a symlinking attack, was too strict in case of cpio archives. This update restores the old behavior.

Routers turned into zombie cryptojackers – is yours one of them?
Alleged “high-ranking” members of the Fin7 cybercrime group arrested
DHS Launches Cyber-Risk Management Center
Reddit Breached After SMS 2FA Fail
How safe is your DNA data?
Alaskan borough dusts off the typewriters after ransomware crims pwn entire network
Amnesty International spearphished with government spyware

Reading Time: ~2 min.Cryptojacking “Game” Found on Steam Store Valve has taken recent action against an indie-developed game available on Steam, the company’s game/app store, and removed their listing after many customers had complained about cryptomining slowing their systems, once launched. Additionally, the developers have been caught selling in-game items on third-party sites, that were […]

LinuxSecurity.com: Various vulnerabilities were discovered in graphicsmagick, a collection of image processing tools and associated libraries, resulting in denial of service, information disclosure, and a variety of buffer overflows and overreads.

MikroTik routers grab their pickaxes, descend into the crypto mines

security update

Dear alt-right morons and other miscreants: Disrupt DEF CON, and the goons will ‘ave you
Porn parking, livid lockers and botched blenders: The nightmare IoT world come true
Putting the ass in Atlassian: Helpdesk email server passwords blabbed to strangers

LinuxSecurity.com: New lftp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Several vulnerabilities were discovered in libsmpack, a library used to handle Microsoft compression formats. A remote attacker could craft malicious CAB, CHM or KWAJ files and use these flaws to cause a denial of service via application crash, or potentially execute arbitrary code.

LinuxSecurity.com: openslp: Heap memory corruption in slpd/slpd_process.c allows denial of service or potentially code execution (CVE-2017-17833) SL6 x86_64 openslp-2.0.0-3.el6.i686.rpm openslp-2.0.0-3.el6.x86_64.rpm openslp-debuginfo-2.0.0-3.el6.i686.rpm openslp-debuginfo-2.0.0-3.el6.x86_64.rpm openslp-devel-2.0.0-3.el6.i686.rpm openslp-devel-2.0.0-3.el6.x86_64.rpm openslp-server- [More…]

DEF CON plans to show US election hacking is so easy kids can do it
Did you know: Lawyers can certify web domain ownership? Well, not no more they ain’t
ThreatList: Spam’s Revival is Tied to Adobe Flash’s Demise
Castaway hacker guilty of sedating children’s hospital computers

LinuxSecurity.com: New version 2.6.2. Security fix for CVE-2018-14339, CVE-2018-14340, CVE-2018-14341, CVE-2018-14342, CVE-2018-14343, CVE-2018-14344, CVE-2018-14367, CVE-2018-14368, CVE-2018-14369, CVE-2018-14370.

LinuxSecurity.com: Update to 6.6. —- Version 6.5 – address CVE-2018-10773, CVE-2018-10774, CVE-2018-10775 – fix injection of Fedora LDFLAGS

LinuxSecurity.com: Update to 6.6. —- Version 6.5 – address CVE-2018-10773, CVE-2018-10774, CVE-2018-10775 – fix injection of Fedora LDFLAGS

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.