Menu

Category Archives: Security

Articles about security

An update for the ruby:2.5 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Bipartisan Senate Committee Releases Report on Election Security Threats

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for qemu-kvm-rhev is now available for Red Hat Virtualization for Red Hat Virtualization Host 7. Red Hat Product Security has rated this update as having a Important security impact. A Common Vulnerability Scoring System (CVSS) base score,

Updated samba packages that fix one security issue and provide several bug fixes and enhancements are now available for Red Hat Gluster Storage 3.4 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

Capital One gets Capital Done: Hacker swipes personal info on 106 million US, Canadian credit card applicants
Microsoft preps to purge its cloud access security broker of shonky crypto protocols TLS 1.0, 1.1
Whistleblower says Apple contractors listen to your Siri conversions
Oh sh*t’s, 11: VxWorks stars in today’s security thriller – hijack bugs discovered in countless gadgets’ network code
ThreatList: DMARC Adoption Nonexistent at 80% of Orgs
Cloud Security Concerns Loom for 93% of Businesses Adopting Apps and BYOD
‘URGENT/11’ Critical Infrastructure Bugs Threaten EternalBlue-Style Attacks
Android ransomware is back

ESET researchers discover a new Android ransomware family that attempts to spread to victims’ contacts and deploys some unusual tricks The post Android ransomware is back appeared first on WeLiveSecurity

Fearing WannaCry-Level Danger, Enterprises Wrestle with BlueKeep
Android exploit code emerges, ransomware goes south, Citrix calls off hack probe, and more
IoT botnet launched massive 13-day DDoS attack against streaming service

tmpreaper could be made to overwrite files as the administrator.

‘WannaCry Hero’ Avoids Jail Time in Kronos Malware Charges

An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com Launches New site, Celebrates 20 Years of Following Open Source Security News and Resources
Welcome to the New LinuxSecurity.com!

An update for docker is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for podman is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Dear hackers: If you try to pwn a website for phishing, make sure it’s not the personal domain of a senior Akamai security researcher

An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for curl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for qemu-kvm-ma is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Improve security of your Linux OS with simple steps
Scam impersonates WhatsApp, offers ‘free internet’

The fraudulent campaign is hosted by a domain that is home to yet more bogus offers pretending to come from other well-known brands The post Scam impersonates WhatsApp, offers ‘free internet’ appeared first on WeLiveSecurity

Brit infosec firms urge PM Boris to reform the Computer Misuse Act
As the world secures itself, so do crims: Encrypted malware on the rise, warns Sonicwall

security update

Security fix for CVE-2019-13228, CVE-2019-13229, CVE-2019-13227, CVE-2019-13226.

Security fix for CVE-2019-13228, CVE-2019-13229, CVE-2019-13227, CVE-2019-13226.

Security fix for CVE-2019-13228, CVE-2019-13229, CVE-2019-13227, CVE-2019-13226.

OpenSSL versions 1.1.0 through 1.1.0j and 1.1.1 through 1.1.1b are susceptible to a vulnerability that could lead to disclosure of sensitive information or the addition or modification of data (CVE-2019-1543). Oracle VM VirtualBox prior to 6.0.10 has an easily exploitable vulnerability

Imre Rad discovered several vulnerabilities in GNU patch, leading to shell command injection or escape from the working directory and access and overwrite files, if specially crafted patch files are processed.

WannaCry hero Marcus Hutchin aka MalwareTech won’t serve prison time

Fixed out of bounds heap read in function rtreenode() Enhance the rtreenode() function of rtree (used for testing) so that it uses the newer sqlite3_str object for better performance and improved error reporting.

Louisiana Gov Declares Emergency After Cyberattacks Plague Schools
He’s coming home, he’s coming home … Hutchins’ coming home: British Wannacry killer held in US on malware dev rap set free by judge
Rare Steganography Hack Can Compromise Fully Patched Websites
Gamers Are Easy Prey for Credential Thieves

Several security issues were fixed in the Linux kernel.

VLC 3.0.7 has been released on June 6 including security fixes References: – https://bugs.mageia.org/show_bug.cgi?id=24940 – http://www.jbkempf.com/blog/post/2019/VLC-3.0.7-and-security

USN-4054-1 caused some minor regressions in Firefox.

An update that solves two vulnerabilities and has 10 fixes is now available.

Various security problems have been additionally fixed in libssh2, an SSH client implementation written in C++.

Louisiana declares state of emergency after ransomware attacks
‘Google’ Sites Are the Latest Ploy by Card-Skimming Thieves

Reading Time: ~ 2 min. Vulnerability Exposes Dozens of U.S. Colleges At least 62 U.S. colleges have been compromised after an authentication vulnerability was discovered by hackers, allowing them to easily access user accounts. At several of the compromised colleges, officials were tipped off after hundreds of fraudulent user accounts were created within a 24-hour […]

An update that solves two vulnerabilities and has two fixes is now available.

Cyberlaw wonks squint at NotPetya insurance smackdown: Should ‘war exclusion’ clauses apply to network hacks?

This is the one-month notification for the end of the maintenance phase for Red Hat OpenShift Enterprise 3.6 and 3.7. This notification applies only to customers with subscriptions for Red Hat OpenShift Enterprise 3.6 and 3.7. 2. Description:

Risk Level: Very Low. Type: Trojan.

Streamlining Patch Management: Expert Advice

Update to v5.1.19

Update to v5.1.19

South Africans shivering in the dark after file-scrambling nasty hits Johannesburg power biz
Backdoors won’t weaken your encryption, wails FBI boss. And he’s right. They won’t – they’ll fscking torpedo it
New Loader Variant Behind Widespread Malware Attacks

An issue with quoting has been found in patch, a tool to apply a diff file to an original, when invoking ed. In order to avoid this, ed is now directly started instead of calling a shell which starts ed.

An update for atomic-openshift and jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Streaming service endures 13‑day DDoS raid

The attack, unleashed by a 400,000-strong Mirai-style botnet, may be the largest of its kind on record The post Streaming service endures 13‑day DDoS raid appeared first on WeLiveSecurity

Protecting Against Ransomware Attacks: A Checklist

An update that solves three vulnerabilities and has 9 fixes is now available.

An update that fixes one vulnerability is now available.

Exim could be made to run programs as an administrator if it received specially crafted network traffic.

An update for rh-redis32-redis is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat Certificate System achieves Common Criteria certification
Interview with Security Expert and Author Ira Winkler: Advanced Persistent Security, Threat Intelligence, Social Engineering and more

An update that solves two vulnerabilities and has one errata is now available.

Several security issues were fixed in VLC.

libEBML could be made to crash if it opened a specially crafted file.

Jeremy Harris discovered that Exim, a mail transport agent, does not properly handle the ${sort } expansion. This flaw can be exploited by a remote attacker to execute programs with root privileges in non-default (and unusual) configurations where ${sort } expansion is used for items

Smashing Security #138: Logic bombs, brain data exploitation, and Digga D tweets

security update

Popular File-Sharing Service WeTransfer Used in Malicious Spam Campaigns

Update including July CPU fixes.

Update including July CPU fixes.

ThreatList: Human Error is Behind One Quarter of Data Breaches

security update

security update

security update

Several security issues were fixed in Ansible.

Sanctions-hit Russian developers fingered for crafting ‘Monokle’ Android snoopware
New malware attack turns Elasticsearch databases into DDoS botnet
Unique Monokle Android Spyware Self-Signs Certificates

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.