Menu

Category Archives: All

Everything

LinuxSecurity.com: Two vulnerabilities have been found in Solr, a search server based on Lucene, which could result in the execution of arbitrary code or path traversal.

LinuxSecurity.com: Kelby Ludwig and Scott Cantor discovered that the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to incorrect XML parsing. For additional details please refer to the upstream advisory at

LinuxSecurity.com: Joonun Jang discovered several problems in wavpack, an audio compression format suite. Incorrect processing of input resulted in several heap- and stack-based buffer overflows, leading to application crash or potential code execution.

WordPress Users Warned of Malware Masquerading as ionCube Files

LinuxSecurity.com: From upstream announcement: **Security fix: phpMyAdmin 4.7.8 is released** Welcome to phpMyAdmin 4.7.8, a security releaes also containing regular maintenance bug fixes. The security fix relates to a self-XSS vulnerability in the central columns feature that is reported as PMASA-2018-1 https://www.phpmyadmin.net/security/PMASA-2018-1/. Thanks to Mayur Udiniya

Remote Code Execution Bug Patched in Adobe Acrobat Reader DC
Mirai Variant ‘OMG’ Turns IoT Devices into Proxy Servers for Cryptomining
Can the FBI really unlock ANY iPhone in existence?
Cellebrite’ Hacking Tool Unlocks Any iOS Devices Including iPhone X
Use of HTTPS among top sites is growing, but weirdly so is deprecated HTTP public key pinning
Apple Tackles Cellebrite Unlock Claims, Sort Of
MS Word Maybe Used for Cryptojacking Attacks
Oops! Apple repair center making around 20 false emergency calls a day
Unsecured AWS led to cryptojacking attack on LA Times
SEC says insider trading is not the right response to cyber risk
GDPR deadline looms: The price and penalties | Salted Hash Ep 20
Fender’s ‘smart’ guitar amp has no Bluetooth pairing controls
Opt-in cryptomining script Coinhive ‘barely used’ say researchers
RAT king thrown in the slammer for peddling NanoCore PC nasty
You get a criminal record! And you get a criminal record! Peach state goes bananas with expanded anti-hack law
Developer of NanoCore RAT that targeted Canada, US & Steam jailed

LinuxSecurity.com: A flaw was found in the AWT component of OpenJDK. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions. (CVE-2018-2641) * It was discovered that the LDAPCertStore class in the JNDI component of OpenJDK failed to securely handle LDAP referrals. An attacker could possibly use this flaw […]

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution (CVE-2018-5345) SL7 x86_64 gcab-debuginfo-0.7-4.el7_4.i686.rpm gcab-debuginfo-0.7-4.el7_4.x86_64.rpm libgcab1-0.7-4.el7_4.i686.rpm libgcab1-0.7-4.el7_4.x86_64.rpm gcab-0.7-4.el7_4.x86_64.rpm libgcab1-devel-0.7-4.el7_4.i686.rpm libgcab1-devel-0.7-4.el7_4.x86 [More…]

Revamp of ‘Pwned Passwords’ Boosts Privacy and Size of Database

LinuxSecurity.com: An update for gcab is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: It was discovered that there was an arbitrary command execution vulnerability in the Go programming language. The “go get” implementation did not correctly validate “import path”

Insecure CCTV feeds of kids at school are being streamed live online
Facebook bug reveals identity of page admin via email
Chrome OS Will Soon Start Supporting Linux Applications
Teen Exposes T-Mobile Flaw Allowing Mass Hijacking of User Accounts
NanoCore’s author didn’t hack anyone, but he was imprisoned anyway
Form W-2 data thefts are rocketing, warns FBI
Over 40% of online login attempts are attackers trying to invade accounts

Bots that traverse the internet on behalf of their human operators can fulfill both legitimate and malicious automated tasks. Statistics indicate that bot-driven internet traffic, by helper and harmful bots combined, surpasses human traffic. The post Over 40% of online login attempts are attackers trying to invade accounts appeared first on WeLiveSecurity

US border agents haven’t verified e-passport data for over 10 years
‘In Fraud We Trust’ – Cybercrime org bust shows we’re fighting pros

LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available.

Privacy by Design: Can you create a safe smart home?

The Internet of Things (IoT) can be a network of connected convenience but this should not come at the expense of safeguarding your privacy and the personal data that connected devices collect and share. The post Privacy by Design: Can you create a safe smart home? appeared first on WeLiveSecurity

Private browsing isn’t: Boffins say smut-mode can’t hide your tracks
Cisco NFV controller is a bit too elastic: It has an empty password bug

LinuxSecurity.com: New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35

LinuxSecurity.com: This update updates QtWebEngine to the 5.10.1 bugfix and security release. QtWebEngine 5.10.1 is part of the Qt 5.10.1 release, but only the QtWebEngine component is included in this update. This update includes: * Security fixes from Chromium up to version 64.0.3282.140. Including: CVE-2017-15407, CVE-2017-15409, CVE-2017-15410, CVE-2017-15411, CVE-2017-15415, CVE-2017-15416,

LinuxSecurity.com: New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35

LinuxSecurity.com: CVE-2017-13194 Fix for a flaw in libvpx related to odd frame width, which may lead to a denial of service.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in the Drupal content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2018-001

Russia hacked Winter Olympics & framed N.Korea in false-flag attack: US

LinuxSecurity.com: It was discovered that there was a remote denial of service vulnerability in the imagemagick graphics library via a specially- crafted TIFF file.

Top The Pirate Bay Alternatives – Best Torrent Download Sites (2018)

LinuxSecurity.com: This update includes the changes in tzdata 2018c for the Perl bindings. For the list of changes, see DLA-1291-1. For Debian 7 “Wheezy”, these problems have been fixed in version

LinuxSecurity.com: This update includes the changes in tzdata 2018c. Notable changes are: – S?o Tom? and Pr?ncipe switched from +00 to +01. – Brazil’s DST will now start on November’s first Sunday.

Use 1Password’ ‘pwned password’ to verify if your password was leaked
Stunning infosec tips from Uncle Sam, furries exposed, Chase bank web leak, and more
Tor pedo’s torpedo torpedoed: FBI spyware crossed the line but was in good faith, say judges

LinuxSecurity.com: The package unixodbc before version 2.3.5-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-wavpack before version 5.1.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package wavpack before version 5.1.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package phpmyadmin before version 4.7.8-1 is vulnerable to cross- site scripting.

security update

LA Times website hacked to mine Monero cryptocurrency
Drupal Patches Critical Bug That Leaves Platform Open to XSS Attack
NPM update changes critical Linux filesystem permissions, breaks everything

security update

security update

Man Sues Feds For Installing Surveillance Camera on his Property

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2017-5715

LinuxSecurity.com: It was discovered that there was an issue in the CUPS printer framework where remote attackers could execute arbitrary commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding.

LinuxSecurity.com: Several security issues were fixed in WavPack.

LinuxSecurity.com: This update doesn’t fix a vulnerability in GCC itself, but instead provides support for building retpoline-enabled Linux kernel updates. For the stable distribution (stretch), this problem has been fixed in

2,000 Colorado DOT computers infected with SamSam Ransomware
FBI Warns of Spike in W-2 Phishing Campaigns
Hacking these IoT baby monitors is child’s play, researchers reveal
Bitcoin exchange founder charged with covering up hack
Supporters of Net Neutrality Vow to Fight Rule Changes
Rancher sues Feds for sneaking a spy camera on to his land
3,000 Databases with 200 Million Unique accounts found on Dark Web
5 signs you may be talking to a bot
Hacker claims spyware maker Retina-X has been breached, again
Six tips to help you avoid targeted marketing

If you get sick of shopping sites sending you “I see you stared at this item, here’s some similar stuff” messages, you may be able to modify your subscriptions or notifications to make this stop. The post Six tips to help you avoid targeted marketing appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Intel didn’t tell CERTS, govs, about Meltdown and Spectre because they couldn’t help fix it

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Hackers Run Linux OS On Nintendo Switch When gaming consoles get hacked, it’s usually by someone who […]

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

OpenBSD releases Meltdown patch

LinuxSecurity.com: On February 22, fixes for CVE-2017-5715 were released into the Ubuntu Xenialkernel version 4.4.0-116.140. This CVE, also known as “Spectre,” is caused by flaws in the design of speculative execution hardware in the computer’sCPU, and could be used to access sensitive information in kernel memory. [More…]

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

security update

LinuxSecurity.com: Several vulnerabilities have been discovered in Squid3, a fully featured web proxy cache. The Common Vulnerabilities and Exposures project identifies the following issues:

Hackers spread Android spyware through Facebook using Fake profiles

LinuxSecurity.com: It was discovered that there where a number of vulnerabilities in irssi, the terminal based IRC client: – CVE-2018-7050: Null pointer dereference for an “empty” nick.

That microchipped e-passport you’ve got? US border cops still can’t verify the data in it

LinuxSecurity.com: An update that solves 8 vulnerabilities and has 19 fixes is now available.

Cryptojacking Attack Found on Los Angeles Times Website
How to protect your browser from Unicode domain phishing attacks

LinuxSecurity.com: The package libmspack before version 1:0.6alpha-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Over 50,000 baby monitors can be hacked but its vendor is AWOL