Menu

Category Archives: All

Everything

DDoS attacks: How an 18-year-old got arrested for trying to knock out systems
CyberThreat18: 2 days of bughunting, techie chat and code lockdown
Apple’s top-secret iBoot firmware source code spills onto GitHub for some insane reason
Intel adopts Orwellian irony with call for fast Meltdown-Spectre action after slow patch delivery
New strife for Strava: Location privacy feature can be made transparent
PSA: If your security starts and ends with bug bounties, you’re gonna have a bad time
Unlucky 13 collared by cops hunting cyber-crew who stole up to $2.2bn
WordPress users – do an update now, and do it by hand!
Smashing Security #064: So just a ‘teeny tiny’ security issue then?
Google Expands Play Marketplace Bug Bounty Program

LinuxSecurity.com: It was discovered that the webhook validation of Anymail, a Django email backends for multiple ESPs, is prone to a timing attack. A remote attacker can take advantage of this flaw to obtain a WEBHOOK_AUTHORIZATION secret and post arbitrary email tracking events.

security update

LinuxSecurity.com: A vulnerabilities has been found in the PostgreSQL database system: CVE-2018-1053

Type: Vulnerability. Adobe Flash Player is prone to an remote code-execution vulnerability; fixes are available.

LinuxSecurity.com: Two vulnerabilities were discovered in Libtasn1, a library to manage ASN.1 structures, allowing a remote attacker to cause a denial of service against an application using the Libtasn1 library.

LinuxSecurity.com: An update that solves two vulnerabilities and has 17 fixes is now available.

LinuxSecurity.com: Security fix for CVE-2017-17969 (from Debian)

LinuxSecurity.com: Security fix for CVE-2018-6381

LinuxSecurity.com: This update includes a rebase from 8.0.47 to 8.0.49.

LinuxSecurity.com: This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error […]

Hotspot Shield Vulnerability Could Reveal ‘Juicy’ Info About Users, Researcher Claims

Risk Level: Very Low. Type: Trojan.

WordPress update stopped WordPress automatic updates from working. So update now
UK-led police operation quashes Luminosity Link RAT

The investigation showed that the tool, which required little technical knowledge to deploy, had over 8,600 users in 78 countries. Victims are believed to be in the thousands. The post UK-led police operation quashes Luminosity Link RAT appeared first on WeLiveSecurity

Reddit users, beware its evil twin
YouTube Kids hasn’t cleaned up its act

LinuxSecurity.com: Security fixes for CVE-2017-17485 and CVE-2018-5968.

Alleged Kelihos botmaster and spam king extradited to US
Boffins crack smartphone location tracking – even if you’ve turned off the GPS
Abusing X.509 Digital Certificates for Covert Data Exchange
Hacking suspect Lauri Love wins landmark appeal against US extradition
Australian cops to enter kindergartens to teach kids not to cyber
Malware Exploiting Spectre, Meltdown Flaws Emerges
Beware the looming Google Chrome HTTPS certificate apocalypse!
Uber quits GitHub for in-house code after 2016 data breach
Registrar Namecheap let miscreants slap spam, malware on customers’ web domains willy-nilly

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to mitigate the speculative side channel attack known as Spectre variant 2.

Amazon explained ‘Key’ crack before it shipped fix, says hacker who found the hole
Web analytics outfit Mixpanel slurped surfers’ passwords

LinuxSecurity.com: It was discovered that mpv, a media player, was vulnerable to remote code execution attacks. An attacker could craft a malicious web page that, when used as an argument in mpv, could execute arbitrary code in the host of the mpv user.

Who doesn’t like a good mobile game? Especially a free one! They allow you to blow off steam while fine-tuning your skills, competing with others or maybe even winning bragging rights among friends. Free games can be fun to play, yet there are some common-sense guidelines to make sure these apps don’t surprise you with […]

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Leaky Amazon S3 Bucket Exposes Personal Data of 12,000 Social Media Influencers
Adobe: Two critical Flash security bugs fixed for the price of one
Safer Internet Day 2018 [VIDEO]
All Ledger hardware wallets vulnerable to man in the middle attack
Uber and Waymo clash in court over driverless technology
Firefox 59’s privacy mode plugs leaky referrers
MacUpdate Hacked to Distribute Mac Cryptocurrency Miner
Cisco Issues New Patches for Critical Firewall Software Vulnerability
Early Google, Facebook employees band together to tame tech addiction
One year later, the UK’s Active Cyber Defence is seeing good results
Security hole meant Grammarly would fix your typos, but let snoopers read your private writings
Keeping kids safe online – trying to practice what I preach
FBI warns of email scams claiming to be from Bureau

Another template attempts to scare, rather than thrill, the recipients. Upon learning that “your IP address and other identifying information were used to commit multiple online crimes”, the mark is urged to contact the sender by phone immediately. The post FBI warns of email scams claiming to be from Bureau appeared first on WeLiveSecurity

Spectre and Meltdown | Salted Hash Ep 17
How I Got Paid $0 From the Uber Security Bug Bounty
Why cops won’t need a warrant to pull the data off your autonomous car
Open source turns 20 years old, looks to attract normal people
Think you have a tracker on your phone? Learn how to make your device more resilient

While it certainly doesn’t hurt to ask for help from local law enforcement, know that even major cities may not have the expertise or the bandwidth to investigate compromised mobile devices. The most important objective is to take steps to make sure you’re safe. Ask for help, but do not wait for others to help […]

LinuxSecurity.com: ClamAV 0.99.3 recommended for all ClamAV users. Please see details below: 1. ClamAV UAF (use-after-free) Vulnerabilities (CVE-2017-12374) ————————————————————— The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could

LinuxSecurity.com: This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error […]

LinuxSecurity.com: Security fix for CVE-2017-17969 (from Debian)

Safer Internet Day: 3 things your social networks can do for you
Safer Internet Day: 3 things you can do for your social networks
Cops find ATM spewing cash, car with dodgy plates, stack of $20 bills and hacking kit inside
X.509 metadata can carry information through the firewall
T-Mobile US let hackers nick my phone number, drain my crypto-wallets, cries man who lost $20k
Grammarly user? Patch now to stop crooks stealing all your data…
Grammarly Patches Chrome Extension Bug That Exposed Users’ Docs
Authorities shut down Luminosity RAT used by buyers in 78 countries

security update

Don’t worry, it’ll be all Reich! Googler saves Grammarly nazis from hacker invasion
Covert Data Channel in TLS Dodges Network Perimeter Protection
New Monero Crypto Mining Botnet Leverages Android Debugging Tool

LinuxSecurity.com: It was discovered that an XHR/AJAX call did not properly encode user input in the “dokuwiki” wiki platform. This resulted in a reflected file download vulnerability.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Lauri Love judgment: Extradition would be ‘oppressive’ and breach forum bar
GCHQ unit claims it has ‘objectively’ made the UK a less desirable target to cybercrims
Alleged hacker Lauri Love avoids US extradition: “Try him in England”
Lauri Love won’t be extradited to the United States to face hacking charges
British Hacker Lauri Love will not be extradited to the United States
Buying Bitcoin on your credit card? Not any more…
It’s time to say ‘Welcome to dumpsville Adobe Flash’, as new unpatched flaw exploited by criminals

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

What online sex toys can teach you about secure coding
Accused Brit hacker Lauri Love will NOT be extradited to America

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Vulnerabilities reached a historic peak in 2017

In 2017, the number of vulnerabilities smashed records set in previous years. According to CVE Details, more than 14,600 vulnerabilities were reported in 2017, compared to 6447 in 2016. The post Vulnerabilities reached a historic peak in 2017 appeared first on WeLiveSecurity

Russian-monitoring Shetlands radar station was nearly sold off
Knock, knock. Who’s there? Another Amazon Key door-lock hack

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: ‘landave’ discovered a heap-based buffer overflow vulnerability in the NCompress::NShrink::CDecoder::CodeReal method in p7zip, a 7zr file archiver with high compression ratio. A remote attacker can take advantage of this flaw to cause a denial-of-service or, potentially the