Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Marriott Revises Breach Scope to 383M Records
Phishing Tactic Hides Tracks with Custom Fonts
Wide-Ranging German Doxxing Incident Hits Hundreds of Politicians
Town of Salem hack exposes details of 7.6 million gamers
Germany hacked: Angela Merkel’s colleagues among mass data dump victims

Reading Time: ~2 min. American Newspapers Shutdown After Ransomware Attack Nearly all news publications owned by Tribune Publishing suffered disruptions in printing or distribution after the publisher was hit by a ransomware attack. Many of the papers across the country were delivered incomplete or hours or days late. Even some papers that had been sold […]

Adobe Fixes Two Critical Acrobat and Reader Flaws
German politicians suffer massive hack of personal details and private communications
Can’t unlock an Android phone? No problem, just take a Skype call: App allows passcode bypass
A Dozen Flaws in Popular Mac Clean-Up Software Allow Local Root Access

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.

Hope you’re over that New Year’s hangover – there’s an Adobe PDF app patch to install
Pewdiepie fanboi printer, Chromecast haxxx0r retreats, says they’re ‘afraid of being caught’

LinuxSecurity.com: An update for rh-perl524-perl is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-perl526-perl and rh-perl526-perl-Module-CoreList is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Dual Data Leaks of Blur, Town of Salem Impact Millions
MobSTSPY Info-Stealing Trojan Goes Global Via Google Play
Snowden’s Attorney Talks Govt Harrassment of Whistleblower Helpers (Part One)
TheHackerGiraffe says he’s retired from hacking smart TVs to promote PewDiePie
Um, I’m not that Gary, American man tells Ryanair after being sent other Gary’s flight itinerary
What is threat cumulativity and what does it mean for digital security?

A reflection on how acknowledging the cumulative nature of cyber-threats and understanding its implications can benefit our digital security The post What is threat cumulativity and what does it mean for digital security? appeared first on WeLiveSecurity

Hackers Hijack Smart TVs to Promote PewDiePie
Hackers demand ransom from Dublin’s tram system, after Luas website defaced
Did you #DeleteFacebook? Shady players can still exploit your data
Vietnam’s New Cyber Law Threatens Free Speech
Hackers Target North Korean Defectors
Google-whisperers beat reCaptcha voice challenge with 90% success rate

LinuxSecurity.com: Multiple issues were fixed in Qt. CVE-2018-15518 A double-free or corruption during parsing of a specially crafted

It’s 2019, and from Beijing to Blighty folk are still worried about slurp-happy apps
Hacker cyber-gang: Give us cyber-cash for cyber-cache of 18,000 stolen Sept 11th insurance docs

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Detailed: How Russian government’s Fancy Bear UEFI rootkit sneaks onto Windows PCs

security update

Newsmaker Interview: Bruce Schneier on Physical Cyber Threats

LinuxSecurity.com: This update includes the changes in tzdata 2018i for the Perl bindings. For the list of changes, see DLA-1625-1. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: This update includes the changes in tzdata 2018i. Notable changes are: – Qyzylorda, Kazakhstan moved from +06 to +05 on 2018-12-21. A new

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: Fix CVEs as described in related RHBZ bug.

LinuxSecurity.com: Fix CVEs as described in related RHBZ bug.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

This Netflix-themed scam prompts FTC to issue warning

The message starts off with the kind of information that is apt to send shivers down the spines of many binge-watchers The post This Netflix-themed scam prompts FTC to issue warning appeared first on WeLiveSecurity

EU Offers Bug Bounties For 14 Open Source Projects
Chrome in Android Leaks Device Fingerprinting Info
Train for the fight against cybercrime at SANS London 2019
Open-source devs: Wget off your bloated festive behinds and patch this user cred-blabbing bug
IT Security Vulnerability Roundup – December 2018
What happens when a Royal Navy warship sees a NATO task force headed straight for it? A crash course in Morse
Appearing on the ‘Random but Memorable’ podcast

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For the stable distribution (stretch), this problem has been fixed in

Threatlist: Dark Web Markets See an Evolution in Q3
2019 Malware Trends to Watch
Hackers Threaten to Dump Insurance Files Related to 9/11 Attacks
My Health Record had 42 data breaches in 2017-18 but no ‘malicious’ attacks: ADHA
The Linux Kernel In 2018 Summed Up: Spectre/Meltdown, CoC, Speck Fears, New Features

LinuxSecurity.com: An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by “j a v a s c r i p t:” in Internet Explorer (CVE-2018-19787).

LinuxSecurity.com: Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment. (CVE-2018-19149) References:

LinuxSecurity.com: Graphicsmagick has been updated to fix several bugs and security issues. References: – https://bugs.mageia.org/show_bug.cgi?id=23157 – http://www.graphicsmagick.org/NEWS.html#november-17-2018

LinuxSecurity.com: Possible denial of service vulnerability due to a missing check in Lib/wave.py to verify that at least one channel is provided (CVE-2017-18207). Python’s elementtree C accelerator failed to initialise Expat’s hash

LinuxSecurity.com: debian-security-support, the Debian security support coverage checker, has been updated in jessie. The jessie relevant changes are: * Mark jasperreports as end-of-life in Jessie.

Malware Attack Crippled Production of Major U.S. Newspapers
Ransomware vs. printing press? US newspapers face “foreign cyberattack”

Did malware disrupt newspaper deliveries in major US cities? Here’s what’s known about the incident so far and the leading suspect: Ryuk ransomware. Plus, advice on defending your organization against such attacks. The post Ransomware vs. printing press? US newspapers face “foreign cyberattack” appeared first on WeLiveSecurity

Cryptocurrency Wallet Hacks Spark Dustup
2018: Research highlights from ESET’s leading lights

As the curtain slowly falls on yet another eventful year in cybersecurity, let’s look back on some of the finest malware analysis by ESET researchers in 2018 The post 2018: Research highlights from ESET’s leading lights appeared first on WeLiveSecurity

Hackers pocketed $878,000 from cryptocurrency bug bounties in 2018
EU offers bounties to help find security flaws in open source tools

LinuxSecurity.com: It was discovered that there was a potential denial of service vulnerability in tar, the GNU version of the tar UNIX archiving utility.

LinuxSecurity.com: Updated to 3.3.4. Security fix by upstream: Anti-Phishing protection.. Server-provided text will not appear in user-facing GUI windows anymore. Server error messages are instead parsed and mapped to predefined strings.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: A vulnerability in GKSu might allow attackers to execute arbitrary commands.

LinuxSecurity.com: Multiple vulnerabilities have been found in Rust, the worst which may allow local attackers to execute arbitrary code.

Graham Cluley’s Desert Planet Picks

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves four vulnerabilities and has 17 fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

How Facebook Tracks Non-Users via Android Apps

LinuxSecurity.com: This update fixes CVE-2018-16646, CVE-2018-19058, CVE-2018-19059, CVE-2018-19060, CVE-2018-19149.

LinuxSecurity.com: **Archive_Tar version 1.4.4** * Fix Bug #21058: Long symlinks are not supported [mrook] * Fix Bug #23782: Prevent phar:// files from being extracted [mrook] — **PEAR** * drop deprecated option used when running `pear run-tests`

LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.

LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

security update

‘Snowden Refugee’ Has No Regrets for Helping Whistleblower
Depressing lessons 2018’s endless data breaches taught us
Hackers steal personal info of 1,000 North Korean defectors

LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.

LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: This update fixes CVE-2017-18267, CVE-2018-13988, CVE-2018-16646, CVE-2018-19058, CVE-2018-19059, CVE-2018-19060, CVE-2018-19149

LinuxSecurity.com: Security fix for CVE-2018-16869

LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit