Menu

Category Archives: Security

Articles about security

22 malware infected apps on Play Store found draining phone’s battery

LinuxSecurity.com: Use after free flaw enabling arbitrary code execution. (CVE-2018-15982) Insecure Library Loading (DLL hijacking) flaw enabling privilege escalation. (CVE-2018-15983)

LinuxSecurity.com: The HTML thumbnailer was incorrectly accessing some content of remote URLs listed in HTML files. This meant that the owners of the servers referred in HTML files in your system could have seen in their access logs your IP address every time the thumbnailer tried to create the thumbnail (CVE-2018-19120).

GDPR Implementation Slow but Improving
Addresses and Names of Customers Exposed by Bethesda in Support Tickets
Linux 4.19.8 Released With BLK-MQ Fix To The Recent Data Corruption Bug
6 Critical Website Elements You Need to Review
415,000 routers infected by cryptomining malware – Prime target MikroTik
New AI tool aims to make CAPTCHA a thing of the past
Bethesda blunders, IRS sounds the alarm, China ransomware, and more
In case you’re not already sick of Spectre… Boffins demo Speculator tool for sniffing out data-leaking CPU holes
Identity stolen because of the Marriott breach? Come and claim your new passport
‘Say hello to my little vacuum cleaner!’ US drug squad puts spycams in cleaner’s kit
ThreatList: Gift Card-Themed BEC Holiday Scams Spike
Linux.org domain hacked, plastered with trolling, filth and anti-transgender vandalism

security update

Type: Vulnerability. Adobe Flash Player is prone to an unspecified remote code-execution vulnerability; fixes are available.

Australia Anti-Encryption Law Triggers Sweeping Backlash
TA505 Crooks are Now Targeting US Retailers with Personalized Campaigns

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Reading Time: ~2 min. Touch ID Used to Scam Apple Users Two apps were recently removed from the Apple App Store after several users reported being charged large sums of money after installing the app and scanning their fingerprint. Both apps were fitness-related and had users scan their fingerprint immediately so they could monitor calories or […]

Brit bomb hoax teen who fantasised about being a notorious hacker cops 3 years in jail
Using Fuzzing to Mine for Zero-Days
Three years in jail for teenager who spammed out school bomb threats
Microsoft Calls For Facial Recognition Tech Regulation

LinuxSecurity.com: An update that fixes one vulnerability is now available.

UK Supreme Court considers whether spy court should be immune to legal probes

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves 7 vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Australia now has encryption-busting laws as Labor capitulates
The path to cloud security goes through integration
Wow, what a lovely early Christmas present for Australians: A crypto-busting super-snoop law passes just in time

security update

LinuxSecurity.com: A vulnerability in EDE could result in privilege escalation.

LinuxSecurity.com: The package jupyter-notebook before version 5.7.2-1 is vulnerable to cross-site scripting.

LinuxSecurity.com: It was discovered that incorrect processing of very high UIDs in Policykit, a framework for managing administrative policies and privileges, could result in authentication bypass.

LinuxSecurity.com: Several security issues were fixed in OpenSSL.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3760

Infected WordPress Sites Are Attacking Other WordPress Sites

LinuxSecurity.com: Several security issues were fixed in SpamAssassin.

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Facebook Defends Data Policies On Heels of Incriminating Internal Docs
UK spies: You know how we said bulk device hacking would be used sparingly? Well, things have ‘evolved’…
DanaBot evolves beyond banking Trojan with new spam-sending capability

ESET research shows that DanaBot operators have been expanding the malware’s scope and possibly cooperating with another criminal group The post DanaBot evolves beyond banking Trojan with new spam-sending capability appeared first on WeLiveSecurity

Windows 10 security question: How do miscreants use these for post-hack persistence?
Malicious Chrome extension which sloppily spied on academics believed to originate from North Korea
More data joy: Email scammers are buying marks’ info from legit biz intelligence firms
Ukraine: We Blocked Major Russian Attack on Judiciary
#BHEU: How Google Aurora Attacks Changed the Consciousness of Cybersecurity
Brits’ DNA data sent to military base after ‘foreign’ hack attacks – report
Pencil manufacturers rejoice: Oz government doesn’t like e-voting
Smashing Security #107: Sextorting the US army, and a Touch ID scam
It’s December 2018, and a rogue application can still tell your Apple Mac: I’m your El Capitan now
Talk about a GAN-do attitude… AI software bots can see through your text CAPTCHAs
Adobe Flash zero-day exploit… leveraging ActiveX… embedded in Office Doc… BINGO!
White House Facial Recognition Pilot Raises Privacy Alarms

LinuxSecurity.com: An update for openstack-neutron is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: It was discovered that the ghostscript /invalidaccess checks fail under certain conditions. An attacker could possibly exploit this to bypass the – -dSAFER protection and, for example, execute arbitrary shell commands via a specially crafted PostScript document. (CVE-2018-16509) SL6 x86_64 ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-8.70-24.el6_10.2.x86_64.rpm ghostscript- [More…]

LinuxSecurity.com: ghostscript: incomplete fix for CVE-2018-16509 (CVE-2018-16863) Bug Fix(es): * Previously, the flushpage operator has been removed as part of a major clean-up of a non-standard operator. However, flushpage has been found to be used in a few specific use cases. With this update, it has been re- added to support those use cases. SL7 […]

Adobe Flash Zero-Day Leveraged Via Office Docs in Campaign
Kubernetes Flaw is a “Huge Deal,” Lays Open Cloud Deployments
Adobe Patches Zero-Day Vulnerability in Flash Player
It looked like a Citrix ShareFile phishing attack, but wasn’t
The Dark Side of the ForSSHe

ESET researchers discovered a set of previously undocumented Linux malware families based on OpenSSH. In the white paper, “The Dark Side of the ForSSHe”, they release analysis of 21 malware families to improve the prevention, detection and remediation of such threats The post The Dark Side of the ForSSHe appeared first on WeLiveSecurity

Estonian ex-foreign sec urges governments: Get cosy with the private sector on cybersecurity
Now you, too, can snoop on mobe users from 3G to 5G with a Raspberry Pi and €1,100 of gizmos
Coalition and Labor strike deal on encryption legislation
Facebook Exposes Nonprofits to Donors-and Hackers
Google Chrome 71 Touts 43 Fixes, Fights Ad Abuse
Windows 10 version 1809 is incompatible with Morphisec anti-malware
GOPwned: Republicans fall victim to email hack
1-800-Flowers Becomes Latest Payment Breach Victim

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

He’s not cracked RSA-1024 encryption, he’s a very naughty Belarusian ransomware middleman

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform release 3.5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform release 3.6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Google Patches 11 Critical RCE Android Vulnerabilities
Quora Breach Exposes a Wealth of Info on 100M Users
Quora hack leaves details of 100 million accounts exposed
Quora hacked: Personal data of 100 million users stolen
Marriott sued hours after announcing data breach
Magecart Group Ups Ante: Now Goes After Admin Credentials
Yet another mega-leak: 100 million Quora accounts compromised by system invaders

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Malware since 2017: Auction giant Sotheby’s Home hit by Magecart attack
Customers baffled as Citrix forces password changes for document-slinging Sharefile outfit