Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: The package logstash before version 6.6.1-1 is vulnerable to information disclosure.

LinuxSecurity.com: The package elasticsearch before version 6.6.1-1 is vulnerable to privilege escalation.

Harassment, hate and bile, suicide instructions for kids… anything else social media’s good at? Ah yes, cybercrime

LinuxSecurity.com: An update for polkit is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

6 Pieces of Tech Every Office Needs
High-Severity SHAREit App Flaws Open Files for the Taking

LinuxSecurity.com: GNOME Keyring could be made to expose sensitive information.

LinuxSecurity.com: USN-3866-2 introduced a regression in Ghostscript.

LinuxSecurity.com: LDB could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

Critical WinRAR Flaw Found Actively Being Exploited
Google aims for password-free app and site logins on Android

With FIDO2 certification for Android, Google is setting the stage for password-less app and website sign-ins on a billion devices The post Google aims for password-free app and site logins on Android appeared first on WeLiveSecurity

LinuxSecurity.com: ultiple vulnerabilities have been discovered in liblivemedia, the LIVE555 RTSP server library: CVE-2019-6256

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 7 vulnerabilities is now available.

LinuxSecurity.com: The package kibana before version 6.6.1-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

Two weeks after hackers tried to steal 13 million euros, Bank of Valletta goes offline again
The Dark Sides of Modern Cars: Hacking and Data Collection
Who needs malware? IBM says most hackers just PowerShell through boxes now, leaving little in the way of footprints
Threatpost Data: Password Managers Are Worth the Risk, Readers Say
Jeez, what a Huawei to go: Now US senators want Chinese kit ripped out of national leccy grid
Check your VPN DNS test tool legitimacy: Is it “good” or deceptive
China’s tech giants are a security threat to the UK, says Brit spy bigwig

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

Risk Level: Very Low. Type: Trojan.

ToRPEDO Privacy Attack on 4G/5G Networks Affects All U.S. Carriers
Russian creator of NeverQuest banking trojan pleads guilty in American court

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Burger chain Wendy’s serves up settlement, NeverQuest hacker guilty, cloudy payroll users hacked and more
Escalating DNS attacks have domain name steward worried

The keeper of the internet’s ‘phone book’ is urging a speedy adoption of security-enhancing DNS specifications The post Escalating DNS attacks have domain name steward worried appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in Bind.

Google Ditches Passwords in Latest Android Devices
Your $350 Nike self-lacing sneakers aren’t as smart as you hoped

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: A newer version of waagent is needed for several features of the Azure platform. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: The package msmtp before version 1.8.3-1 is vulnerable to certificate verification bypass.

LinuxSecurity.com: The package python-mysql-connector before version 8.0.15-1 is vulnerable to authentication bypass.

Understanding VPN through open systems interconnection model
Major Android ad fraud scam campaign drains battery & eats data
Severe flaws in password managers let hackers extract clear-text passwords
Setting up a Django application on RHEL 8 Beta
Phishing Scam Cloaks Malware With Fake Google reCAPTCHA
Reddit Gold: Alice and Bob, Caught in a Web of Lies
Entrust Datacard lined up to unburden Thales of nCipher biz as price for Gemalto buyout
Video: HackerOne CEO on the Evolving Bug Bounty Landscape
Data Breaches of the Week: Tales of PoS Malware, Latrine Status
Threatpost News Wrap Podcast For Feb. 22

Reading Time: ~2 min. Email Phishers Find New Filter Bypass Since email filters have gained popularity over the last decade, scammers have been forced to adapt their attacks. To bypass a normal URL filter that would check for malicious links, these scammers have found a way to alter the “document relationship” file (xml.rels) and continue […]

Android banking malware distributed with fake Google reCAPTCHA
Taking Care of Your Personal Online Security (For Paranoids)
Infosec in spaaace! NCC and Surrey Uni to pore over satellite security
Cyber-extortionists take aim at lucrative targets

A new report shines some light on multiple aspects of the growing threat of cyber-extortion The post Cyber-extortionists take aim at lucrative targets appeared first on WeLiveSecurity

Threatpost Poll: Are Password Managers Too Risky?
WTF PDF: If at first you don’t succeed, you may be Adobe re-patching its Acrobat, Reader patches

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework and Visual Studio are prone to an security vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

ThreatList: Porn-Focused Malware Triples, Dark Web Loves It
Adobe Re-Patches Critical Acrobat Reader Flaw
Black-hat sextortionists required: Competitive salary and dental plan
Highly Critical Drupal RCE Flaw Affects Millions of Websites
19-Year-Old WinRAR Flaw Plagues 500 Million Users
Toyota Australia driven offline by cyber attack, as heart hospital hit by ransomware

Reading Time: ~3 min. “Internet of things” (IoT) is a term that’s becoming increasingly commonplace in our daily lives. Internet-connected devices are being designed and implemented at a rapid clip, especially in our own homes. The internet is not just at our fingertips anymore, but also at our beck and call with smart speakers and […]

How costly are sweetheart swindles?

And that’s on top of the heartache experienced by the tens of thousands of people who fall for romance scams each year The post How costly are sweetheart swindles? appeared first on WeLiveSecurity

Data breach rumours abound as UK Labour Party locks down access to member databases
Welcome to the sunlit uplands of HTTP/2, where a naughty request can send Microsoft’s IIS into a spin
139 US bars, restaurants and coffeeshops infected by credit-card stealing malware
Bored bloke takes control of British Army ‘psyops’ unit’s Twitter
Check yo self before you HyperWreck yo self: Cisco fixes gimme-root holes in HyperFlex, plus more security bugs
Where’s Zero Cool when you need him? Loose chips sink ships: How hackers could wreck container vessels
Smashing Security #116: Stalking debtors, Facebook farce, and a cyber insurance snag
No RESTful the wicked: If your website runs Drupal, you need to check for security updates – unless you enjoy being hacked
Behold… a WinRAR security bug that’s older than your child’s favorite YouTuber. And yes, you should patch this hole
Researcher: Not Hard for a Hacker to Capsize a Ship at Sea
Separ Malware Plucks Hundreds of Companies’ Credentials in Ongoing Phish

security update

Apple’s Shazam App Boots Facebook Ads and Other Third-Party SDKs
Password Manager Firms Blast Back at ‘Leaky Password’ Revelations
GitHub Increases Rewards, Scope For Bug-Bounty Program
Microsoft: Russia’s Fancy Bear Working to Influence EU Elections
Join me to learn more about Magecart attacks – and how to defend against them
Most & least radiation emitting smartphones in 2019
Torrent uploader CracksNow caught distributing GrandCrab ransomware
Dark Web hacker selling 92M new accounts on Dream market
Google in hot water after not revealing it had hidden a secret microphone in home alarm product
Who will stand up for European democracy? Us! says US software giant Microsoft
Siegeware: When criminals take over your smart building

Siegeware is what you get when cybercriminals mix the concept of ransomware with building automation systems: abuse of equipment control software to threaten access to physical facilities The post Siegeware: When criminals take over your smart building appeared first on WeLiveSecurity

The man suing Apple over two-factor authentication has ‘previous’
Password managers may leave your online crown jewels ‘exposed in RAM’ to malware – but hey, they’re still better than the alternative
Unearthed emails could be smoking gun in epic GDPR battle against Google, adtech giants
Download Kali Linux 2019.1 with Metasploit 5.0
Microsoft to Kill Updates for Legacy OS Using SHA-1
ThreatList: APT Adversaries Up the Ante on Speed, Target Telecom

security update

security update