Menu

Category Archives: All

Everything

Phishing Attack Bypasses Two-Factor Authentication

LinuxSecurity.com: An update that solves 6 vulnerabilities and has 6 fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Hacker access critical code of British cell operator EE
Google Project Zero Calls Windows 10 Edge Defense ‘ACG’ Flawed

security update

Vega Stealer Malware Takes Aim at Chrome, Firefox
CIO Leadership Live, with guest Jack Clare, CIO and chief strategy officer at Dunkin’ Brands
Panda Banking Trojan Diversifies into Cryptocurrency, Porn, Other Targets
Researcher shows how hackers can bypass Two-factor authentication
Hacking train Wi-Fi may expose passenger data and control systems
IBM bans USB drives – but will it work?

LinuxSecurity.com: Harry Sintonen have discovered a cookie injection vulnerability in wget caused by insufficient input validation, enabling an external attacker to inject arbitrary cookie values cookie jar file, adding new

Firefox support for WebAuthn shows passwords the door
Are firms and regulators prepared for GDPR?

The answer may hinge on if you’re a glass-half-full or glass-half-empty kind of person. While we’re at it, how about regulators’ level of preparedness, anyway? The post Are firms and regulators prepared for GDPR? appeared first on WeLiveSecurity

Apple boots out apps that abuse location data collection
Former Iranian Hacker Exposes Cyber-Efforts
Professionals ‘Lack Time’ or Ignore Critical Patch Application
iOS 11.4 to come with 7-day USB shutout
What your provider won’t tell you about cloud security
12 months on, what are the lessons learned from WannaCryptor?

Time does fly! It feels like only yesterday that a new strain of hitherto little-known malware achieved celebrity status among global ransomware campaigns The post 12 months on, what are the lessons learned from WannaCryptor? appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code or denial of service.

Shining lasers at planes in the UK could now get you up to 5 years in jail
Text bombs and ‘Black Dots of Death’ plague WhatsApp and iMessage users

Reading Time: ~2 min.Crypto Mining Makes the Jump to Excel With the recent Microsoft release supporting JavaScript within Excel, it was only a matter of time before the scripting service was manipulated to mine cryptocurrency. Mere hours after the release, the first proof of concept appeared, with easy-to-replicate steps to get CoinHive functioning. While this […]

Telstra warns cloud customers they’re at risk of malware or worse

LinuxSecurity.com: Updated to latest upstream release (#1571443, #1573318, #1573319).

LinuxSecurity.com: Several security issues were fixed in OpenJDK 8.

LinuxSecurity.com: Update to 1.10.1

New law would stop Feds from demanding encryption backdoor
Zero-day flaw exploited in targeted attacks is fixed by Microsoft
Man who hacked West Point military academy website arrested from LA

security update

security update

GandCrab Ransomware Found Hiding on Legitimate Websites
PoS Malware ‘TreasureHunter’ Source Code Leaked
Bombshell discovery: When it comes to passwords, the smarter students have it figured
Apple’s iOS 11.4 update may protect devices from phone cracking firms
New Facebook-Spread Malware Triggers Credential Theft, Cryptomining
Major OS Players Misinterpret Intel Docs, and Now Kernels Can Be Hijacked

Reading Time: ~2 min.Fake tech support scams aren’t going anywhere. In fact, recent data shows this type of social engineering attack is on the rise—with phony tech support calls, emails, and pop-ups peddling the digital equivalent of snake oil to unsuspecting internet users around the world. While many people have grown wise enough to spot […]

Nigerian BEC Scammers Growing Smarter, More Dangerous
One year later: EternalBlue exploit more popular now than during WannaCryptor outbreak

The infamous outbreak may no longer be causing mayhem worldwide but the threat that enabled it is still very much alive and posing a major threat to unpatched and unprotected systems The post One year later: EternalBlue exploit more popular now than during WannaCryptor outbreak appeared first on WeLiveSecurity

The WhatsApp text bomb – no, it won’t destroy your phone!
Online voting is impossible to secure. So why are some governments using it?
Small Firms Up to 20 Times More Likely to be Breached
Google Maps flaw lets hackers redirect users to malicious sites
Watch out: photo editor apps hiding malware on Google Play
Windows-crashing bug not patch-worthy, says Microsoft
Secrets of the Wiper: Inside the World’s Most Destructive Malware
Grade hacking may cost high school its valedictorian
Data breach disclosure is still taking too long, report reveals as GDPR looms
Brit govt told to do its homework ahead of talks over post-Brexit spy laws and data flows
IBM bans all removable storage, for all staff, everywhere

LinuxSecurity.com: New wget packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1319

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1364

LinuxSecurity.com: The package freetype2 before version 2.9.1-1 is vulnerable to denial of service.

LinuxSecurity.com: Dancer2 0.206000 addresses several potential security issues. There is a potential RCE with regards to Storable. Dancer2 adds session ID validation to the session engine so that session backends based on Storable can reject malformed session IDs that may lead to exploitation of the RCE. Parsing requests now uses HTTP::Entity::Parser which reduces the amount […]

LinuxSecurity.com: ## 4.9.2 https://ckeditor.com/cke4/release/CKEditor-4.9.2 ### Security Updates – Fixed XSS vulnerability in the Enhanced Image (image2) plugin reported by Kyaw Min Thein. – Issue summary: It was possible to execute XSS inside CKEditor using the tag and specially crafted HTML. Please note that the default presets (Basic/Standard/Full) do not include this plugin, so you are […]

LinuxSecurity.com: Security fix for CVE-2017-6888.

LinuxSecurity.com: Security fix for CVE-2018-1000156

LinuxSecurity.com: Regenerate autoconf files using current tools so proper build flags from redhat- rpm-config are used. This applies hardened LDFLAGS. No functional change intended.

LinuxSecurity.com: This release provides Perl 5.26.2 that fixes a heap buffer overflow in the pack() function and two overflows in regular expression engine.

LinuxSecurity.com: Knot Resolver 2.3.0 (2018-04-23) ——– – fix CVE-2018-1110: denial of service triggered by malformed DNS messages (!550, !558, security!2, security!4) – increase resilience against slow lorris attack (security!5) Bugfixes ——– – validation: fix SERVFAIL in case of CNAME to NXDOMAIN in a single zone (!538) – validation: fix SERVFAIL for

1-year prison for man behind Blizzard’ World of Warcraft DDoS attacks

security update

Bugs in Logitech Harmony Hub Put Connected IoT Devices at ‘High Risk’

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework Device Guard is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Multiple Microsoft Azure IoT SDKs are prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Paris Hilton’s hacker sentenced to 57 months in prison
Severe Keyboard Flaws in LG Smartphones Allow Remote Code Execution
Patch now! Microsoft and Adobe release critical security updates
Georgia Governor Vetoes Controversial Hack-Back Bill
Smashing Security #077: Why Paris Hilton doesn’t use iCloud, lottery hacking, and Facebook dating
Inside fake Interac transfer and tax refund SMS phishing

It’s tax season in Canada and scammers are using fake tax refund forms to lure victims into supplying their personal information via phishing pages The post Inside fake Interac transfer and tax refund SMS phishing appeared first on WeLiveSecurity

Spyware uses malicious adult games to infect Android & Window devices
Drupe app removed from Google Play store after photos and messages leaked publicly
Critical bug in 7-Zip – make sure you’re up to date!
Trial set for Latvian accused of running malware operation