Menu

Category Archives: All

Everything

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

NSO Group bloke charged with $50m theft of government malware

LinuxSecurity.com: It was discovered that the Soup HTTP library performed insuffient validation of cookie requests which could result in an out-of-bounds memory read.

LinuxSecurity.com: The system could be made to expose sensitive information.

Don’t fear 1337 exploits. Sloppy mobile, phishing defenses a much bigger corp IT security threat

LinuxSecurity.com: Some security vulnerabilities were found in Mercurial which allow authenticated users to trigger arbitrary code execution and unauthorized data access in certain server configuration. Malformed patches and repositories can also lead to crashes and arbitrary code

Google admits third-party app developers read your Gmail emails
Windows 10’s defences are pretty robust these days, so of course folk are trying to break them

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

Year-Old Critical Vulnerabilities Patched in ISP Broadband Gear

LinuxSecurity.com: Archive Zip module could be made to expose sensitive information if it received a specially crafted input.

LinuxSecurity.com: Archive Zip module could be made to expose sensitive information if it received a specially crafted input.

ThreatList: Biggest Cybercrime Developments in 2018, So Far

Risk Level: Very Low. Type: Trojan.

Android Apps Are Sharing Screenshots, Video Recordings to Third Parties, Report Finds
Ex-employee stole secrets of Israeli spyware firm for dark web deals
Your smartphone can watch you if it wants to, study finds
Cyberboffins drill into World Cup cyber honeypot used to lure Israeli soldiers
Serious Security: How to cut-and-paste your way to Bitcoin riches
Five tips for pentesters in iOS

Recommendations for pentesters looking for security flaws in iOS applications made by developers The post Five tips for pentesters in iOS appeared first on WeLiveSecurity

California’s New Privacy Law Gives GDPR-Compliant Orgs Little to Fear
Iranian Attackers Spoof Security Site for Phishing Lure
Tor-linked nonprofit raided by police
7-year-old’s avatar sexually assaulted on “family-friendly” Roblox
UK.gov: New London courthouse will focus on crimes of a cyber nature
Things that make you go hmmm: Do crypto key servers violate GDPR?
Gentoo hack caused by three rookie mistakes
Thunderbird gets its EFAIL patch
Chrome, Firefox pull invasive browser extension
Smashing Security #085: Doctor Who, Facebook patents, and Bob’s Burgers
Top 7 Most Popular and Best Cyber Forensics Tools

security update

security update

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in Exiv2.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Carole Cadwalladr takes us behind the scenes of the Cambridge Analytica investigation
The Pirate Bay is silently mining cryptocurrency without user consent
Welcome to a New Look for Threatpost
Navigating an Uncharted Future, Bug Bounty Hunters Seek Safe Harbors
ThreatList: Exploit Kits Still a Top Web-based Threat
ThreatList: Top Summer DDoS Trends
Newsmaker Interview: Marten Mickos on the Future of Bug Bounty

LinuxSecurity.com: The package git-annex before version 6.20180626-1 is vulnerable to multiple issues including arbitrary filesystem access and information disclosure.

LinuxSecurity.com: The package gitlab before version 11.0.1-1 is vulnerable to multiple issues including cross-site scripting and insufficient validation.

Want to beat facial recognition? Join the Insane Clown Posse
Elderly scam victims are too embarrassed to speak up
Samsung phones sending photos to contacts without permission
Going on vacation? Five things to do before you leave

You’ve set up an out-of-office auto-responder and packed your stuff, but have you done all of your “homework” before you rush out the front door for that well-deserved time off? The post Going on vacation? Five things to do before you leave appeared first on WeLiveSecurity

Facebook accidentally unblocks people
Someone else is reading your Gmails
Bill Clinton’s cyber-attack novel: The airport haxploit-blockbuster you knew it would be
NHS Developer Error Leads to Data Leak
Ransomware: Not dead, just getting a lot sneakier
‘Plane Hacker’ Roberts: I put a network sniffer on my truck to see what it was sharing. Holy crap!
Huawei enterprise comms kit has a TLS crypto bug
Hands up if you didn’t lose data in the Typeform breach

LinuxSecurity.com: Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program. For the stable distribution (stretch), this problem has been fixed in

LinuxSecurity.com: Several vulnerabilites have been discovered in Exiv2, a C++ library and a command line utility to manage image metadata which could result in denial of service or the execution of arbitrary code if a malformed file is parsed.

Samsung Investigates Claims of Spontaneous Texting of Images to Contacts

LinuxSecurity.com: libsoup could be made to crash if it received a specially crafted input.

LinuxSecurity.com: Two vulnerabilities affecting the cups printing server were found which can lead to arbitrary IPP command execution and denial of service.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2001

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1979

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1997

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1965

Four US govt agencies poke probe in Facebook following more ‘oops, we spilled your data’ shocks
More Federal Agencies Wrapped Up in Facebook Data Privacy Probe
Google Chrome update to label HTTP-only sites insecure within WEEKS
Typeform data breach exposes users of many websites
Tool scrubs hidden tracking data from printed documents
Immigrant identity thief and ICE lawyer gets four years
Britain’s tax authority reports takedown of record 20,000 fake sites

Her Majesty’s Revenue & Customs (HMRC) is “consistently the most abused government brand”, according to the National Cyber Security Centre (NCSC) The post Britain’s tax authority reports takedown of record 20,000 fake sites appeared first on WeLiveSecurity

HMRC: 29% Increase in Malicious Site Deactivations
Two-Fifths of UK CEOs See Cyber-Attacks as Inevitable
The difference between red team engagements and vulnerability assessments | Salted Hash Ep 34
‘Coding’ cockup blamed for NHS cough-up of confidential info against patients’ wishes
Facebook gave certain companies special access to customer data
Typeform data breach hits thousands of survey accounts
Budget hotel chain, UK political party, Monzo Bank, Patreon caught in Typeform database hack
Smash-hit game Fortnite is dangerous… for cheaters: Tools found laced with malware

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Quick look your right eyes and ears while using public WiFi network
Cryptocurrency users on Discord & Slack hit by MacOS malware

LinuxSecurity.com: glibc: Buffer overflow in glob with GLOB_TILDE (CVE-2017-15670) * glibc: Buffer overflow during unescaping of user names with the ~ operator (CVE-2017-15804) SL6 x86_64 glibc-2.12-1.212.el6.i686.rpm glibc-2.12-1.212.el6.x86_64.rpm glibc-common-2.12-1.212.el6.x86_64.rpm glibc-debuginfo-2.12-1.212.el6.i686.rpm glibc-debuginfo-2.12-1.212.el6.x86_64.rpm glibc-debuginfo- [More…]

LinuxSecurity.com: libvirt: Resource exhaustion via qemuMonitorIORead() method (CVE-2018-5748) * libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent (CVE-2018-1064) SL6 x86_64 libvirt-0.10.2-64.el6.x86_64.rpm libvirt-client-0.10.2-64.el6.i686.rpm libvirt-client-0.10.2-64.el6.x86_64.rpm libvirt-debuginfo-0.10.2-64.el6.i686.rpm libvirt-debuginfo-0.10.2-64.el6.x86_64.rpm [More…]

LinuxSecurity.com: samba: Null pointer indirection in printer server process (CVE-2018-1050) SL6 x86_64 libsmbclient-3.6.23-51.el6.i686.rpm libsmbclient-3.6.23-51.el6.x86_64.rpm samba-client-3.6.23-51.el6.x86_64.rpm samba-common-3.6.23-51.el6.i686.rpm samba-common-3.6.23-51.el6.x86_64.rpm samba-debuginfo-3.6.23-51.el6.i686.rpm samba-debuginfo-3.6.23-51.el6.x86_64.rpm samba-winb [More…]

LinuxSecurity.com: zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c (CVE-2018-1083) * zsh: buffer overflow when scanning very long directory paths for symbolic links (CVE-2014-10072) * zsh: buffer overrun in symlinks (CVE-2017-18206) * zsh: buffer overflow in utils.c:checkmailpath() can lead to local arbitrary code execution (CVE-2018-1100) SL6 x86_64 zsh-4.3.11-8.el6.x86_64.rpm [More…]

Risk Level: Very Low.

Fake Bitcoin exchange traps drug dealers on the dark web