Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Hacker holds the data of 20,000 Superdrug customers to ransom
Hackers Use Public Cloud Features to Breach, Persist In Business Networks

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: The security update announced as DSA 4279-1 caused regressions on the ARM architectures (boot failures on some systems). Updated packages are now available to correct this issue.

LinuxSecurity.com: An update for openstack-keystone is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: mutt: Remote code injection vulnerability to an IMAP mailbox (CVE-2018-14354) * mutt: Remote Code Execution via backquote characters (CVE-2018-14357) * mutt: POP body caching path traversal vulnerability (CVE-2018-14362) SL6 x86_64 mutt-1.5.20-9.20091214hg736b6a.el6.x86_64.rpm mutt-debuginfo-1.5.20-9.20091214hg736b6a.el6.x86_64.rpm i386 mutt-1.5.20-9.20091214hg736b6a.el6.i68 [More…]

LinuxSecurity.com: base-files could be made to hang or overwrite files as the administrator.

New Red Hat Product Security OpenPGP key
Get serious about consumer data protection
Ohio Man Sentenced to 15 Years for BEC Scam
Augusta Health Center Reveals Historic Breach

LinuxSecurity.com: Dariusz Tytko, Michal Sajdak and Qualys Security discovered that OpenSSH, an implementation of the SSH protocol suite, was prone to a user enumeration vulnerability. This would allow a remote attacker to check whether a specific user account existed on the target server.

LinuxSecurity.com: New libX11 packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: An update for mutt is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: wpa_supplicant and hostapd could be made to expose sensitiveinformation if it received a crafted message.

Corporate pre-crime: The ethics of using AI to identify future insider threats
UK hacking prosecutions plummet with only 47 charges recorded last year

LinuxSecurity.com: Several security issues were fixed in OpenJDK 10.

LinuxSecurity.com: USN-3742-2 introduced regressions in the Linux Hardware Enablement(HWE) kernel for Ubuntu 12.04 ESM.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2439

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2462

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2526

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2526

LinuxSecurity.com: ClamAV, an anti-virus utility for Unix, has released the version 0.100.1. Installing this new version is required to make use of all current virus signatures and to avoid warnings.

security update

LinuxSecurity.com: An attacker could trick APT into installing altered packages.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Security Technologies: Stack Smashing Protection (StackGuard)

LinuxSecurity.com: An update for openstack-keystone is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for openvswitch is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Multiple researchers have discovered a vulnerability in the way the Intel processor designs have implemented speculative execution of instructions in combination with handling of page-faults. This flaw could allow an attacker controlling an unprivileged process to read

The Rise of Bespoke Ransomware
Australian Teen Hacked Apple Network

LinuxSecurity.com: An update for rh-postgresql95-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

LinuxSecurity.com: CVE-2018-14767 Fix for missing input validation, which could result in denial of service and potentially the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were discovered in Jetty, a Java servlet engine and webserver which could result in HTTP request smuggling. For the stable distribution (stretch), these problems have been fixed in

LinuxSecurity.com: New upstream release fixing YSA-2018-03 (#1613863)

LinuxSecurity.com: New upstream release fixing YSA-2018-03 (#1613863)

LinuxSecurity.com: New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

The state of cybersecurity at small organizations
The 5 Challenges of Detecting Fileless Malware Attacks
AI in cybersecurity: what works and what doesn’t
Mastering email security with DMARC, SPF and DKIM

security update

security update

security update

LinuxSecurity.com: Several vulnerabilities were discovered in Mutt, a text-based mailreader supporting MIME, GPG, PGP and threading, potentially leading to code execution, denial of service or information disclosure when connecting to a malicious mail/NNTP server.

LinuxSecurity.com: An update that solves 12 vulnerabilities and has 60 fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves 14 vulnerabilities and has 41 fixes is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

Indian Bank Loses $13.5m in Global Attack
UK Identity Fraud Falls but Online Scams Rise
Nigerian National Convicted for Phishing US Universities

LinuxSecurity.com: Fariskhi Vidyan and Thomas Jarosch discovered several vulnerabilities in php-horde-image, the image processing library for the Horde groupware suite. They would allow an attacker to cause a denial-of-service or execute arbitrary code.

security update

security update

LinuxSecurity.com: mysql: Client programs unspecified vulnerability (CPU Jul 2017) (CVE-2017-3636) * mysql: Server: DML unspecified vulnerability (CPU Jul 2017) (CVE-2017-3641) * mysql: Client mysqldump unspecified vulnerability (CPU Jul 2017) (CVE-2017-3651) * mysql: Server: Replication unspecified vulnerability (CPU Oct 2017) (CVE-2017-10268) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 20 [More…]

LinuxSecurity.com: QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams (CVE-2018-11806) * QEMU: i386: multiboot OOB access while loading kernel image (CVE-2018-7550) Bug Fix(es): * Previously, live migrating a Windows guest in some cases caused the guest to become unresponsive. This update ensures that Real-time Clock (RTC) interrupts are not missed, which prevents the problem […]

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Hackers Target Instagram, Users Blame Russia
Washington Man Sentenced in Ransomware Conspiracy
Election Websites, Backend Systems Most at Risk of Cyberattack in Midterms

LinuxSecurity.com: fix for CVE-2018-14526

security update

NHS Patient Data at Risk from Historic Breach: Report

security update

LinuxSecurity.com: Several security issues were fixed in libarchive.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Managing risk in the modern world
#DEFCON Vote Hacking Village Refute NASS ‘Unfair’ Claims
Butlin’s Customers Face Anxious Holiday After Breach Alert

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

security update

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: The package thunderbird before version 60.0-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

LinuxSecurity.com: Chris Coulson discovered a use-after-free flaw in the GNOME Display Manager, triggerable by an unprivileged user via a specially crafted sequence of D-Bus method calls, leading to denial of service or potentially the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in various parsers of Blender, a 3D modeller/ renderer. Malformed .blend model files and malformed multimedia files (AVI, BMP, HDR, CIN, IRIS, PNG, TIFF) may result in the execution of arbitrary code.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 9 fixes is now available.

PGA of America Struck By Ransomware
#DEFCON DHS Says Collaboration Needed for Secure Infrastructure and Elections
#DEFCON Government Attacks and Surveillance Continue to Increase
The Enigma of AI & Cybersecurity