Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: Multiple security vulnerabilities were found in libarchive, a multi-format archive and compression library. Heap-based buffer over-reads, NULL pointer dereferences and out-of-bounds reads allow remote attackers to cause a denial-of-service (application crash) via

GCHQ pushes for ‘virtual crocodile clips’ on chat apps – the ability to silently slip into private encrypted comms

LinuxSecurity.com: An update for ruby is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Multiple vulnerabilities were discovered in the implementation of the Perl programming language. The Common Vulnerabilities and Exposures project identifies the following problems:

Big Blue shoos Db2 blues before rogue staff turn the screws in hijack ruse (translation: patch your IBM databases)
Critical Zoom Flaw Lets Hackers Hijack Conference Meetings

LinuxSecurity.com: Several security vulnerabilities were discovered in Ghostscript, an interpreter for the PostScript language, which could result in denial of service, the creation of files or the execution of arbitrary code if a malformed Postscript file is processed (despite the dSAFER sandbox being

LinuxSecurity.com: The package samba before version 4.9.3-1 is vulnerable to multiple issues including denial of service and access restriction bypass.

LinuxSecurity.com: The package powerdns-recursor before version 4.1.8-1 is vulnerable to denial of service.

Cisco Patches Critical Bug in License Management Tool
Healthcare billing biz AccuDoc ‘fesses up to breach that blabbed 2.65m people’s data
Hackers Breach Dunkin’ Donuts Accounts in Credential Stuffing Attack
US charges Iranian hackers for SamSam ransomware attacks
GCHQ opens kimono for infosec world to ogle its vuln disclosure process
US indicts two over SamSam ransomware attacks

The hacking and extortion scheme took place over a 34-month period with the SamSam ransomware affecting over 200 organizations in the US and Canada The post US indicts two over SamSam ransomware attacks appeared first on WeLiveSecurity

Sorry, we haven’t ACLU what happened in sealed ‘Facebook decryption’ case, but let’s find out
Smashing Security #106: Google Maps, Fed phishing, and Grinch bots
Distributing Malware By Becoming an Admin on an Open-Source Project
Pegasus gov’t spyware used to target colleague of slain drug cartel journalist

LinuxSecurity.com: An update for rh-ruby25-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ruby24-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ruby23-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Symantec comes out in swinging in bitter legal battle over security bug audit conspiracy claims
Oh my chord! Sennheiser hits bum note with major HTTPS certificate cock-up
Dell Warns of Attempted Breach on Network

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenSSL, the worst of which may lead to a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in RPM, the worst of which could allow a remote attacker to escalate privileges.

What the Dell? Customer passwords reset after miscreants break into Big Mike’s IT emporium
Microsoft Warns of Two Apps That Expose Private Keys
WhamWham, bambam, no thank you, SamSam: Iranians accused by the Feds of orchestrating ransomware outbreak

LinuxSecurity.com: The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.1 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file. (CVE-2017-5950)

LinuxSecurity.com: Buffer overflows in URL auth code if there is a “mount” definition that enables URL authentication. A malicious client could send long HTTP headers, leading to a buffer overflow and potential remote code execution (CVE-2018-18820).

security update

security update

ThreatList: Cryptominers Dominate Malware Growth in 2018
FBI Sinkholes $38M Global Ad Fraud Operation
Germany proposes security guidelines for routers, but not everybody is happy
School district fails to reclaim $120,000 wired by bank to scammer
The Nature of Mass Exploitation Campaigns
US told to quit sharing data with human rights-violating surveillance regime. Which one, you ask? That’d be the UK
It’s a patch bonanza as Microsoft showers its OS platforms with update love
Uber fined ?900,000 by UK, Dutch privacy regulators over 2016 data breach
EU Voters Worried About Election Hacking and Disinformation

LinuxSecurity.com: USN-3804-1 introduced a regression in OpenJDK.

Hot fuzz: Bug detectives whip up smarter version of classic AFL fuzzer to hunt code vulnerabilities
3ve Offline: Countless Windows PCs using 1.7m IP addresses hacked to ‘view’ up to 12 billion adverts a day

LinuxSecurity.com: Several security issues were fixed in Git.

Pegasus Spyware Targets Investigative Journalists in Mexico

LinuxSecurity.com: Several vulnerabilities were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service or the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER sandbox being enabled).

Reading Time: ~4 min.At Webroot, we stay ahead of cybersecurity trends in order to keep our customers up-to-date and secure. As the end of the year approaches, our team of experts has gathered their top cybersecurity predictions for 2019. What threats and changes should you brace for? General Data Protection Regulation Penalties “A large US-based […]

3ve – Major online ad fraud operation disrupted

International law enforcement swoops on fake ad viewing outfit The post 3ve – Major online ad fraud operation disrupted appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in Samba.

Cisco Re-Issues Patch For High-Severity WebEx Flaw
Cheetah Mobile Blames SDKs for Rampant Ad Fraud in Its Android Apps

LinuxSecurity.com: USN-3816-1 caused a regression in systemd-tmpfiles.

LinuxSecurity.com: Several security issues were fixed in WebKitGTK+.

Risk Level: Very Low. Type: Trojan, Worm.

Widespread Malvertising Campaign Hijacks 300 Million Sessions
More details on One Planet York app vulnerability doesn’t paint council in a good light
When the FBI rather than the fraudsters make the fake FedEx website
German chat site faces fine under GDPR after data breach

The country’s first fine under GDPR is lower than might have been expected, however, as the company was acknowledged for its post-incident cooperation and enhanced security measures The post German chat site faces fine under GDPR after data breach appeared first on WeLiveSecurity

Baroness Trumpington, former Bletchley Park clerk, dies aged 96

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

Uber fined £385k by ICO for THAT hack of 57m customers’ deets
Sacked NCC Group grad trainee emailed 300 coworkers about Kali Linux VM ‘playing up’

LinuxSecurity.com: An update for rh-nginx114-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-nginx112-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-dotnet21-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Oz opposition caves, offers encryption backdoor compromise

LinuxSecurity.com: A vulnerability in spice-gtk could allow an attacker to remotely execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Libav, the worst of which may allow a Denial of Service condition.

LinuxSecurity.com: A vulnerability in Tablib might allow remote attackers to execute arbitrary python commands.

LinuxSecurity.com: Multiple vulnerabilities have been found in Binutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for sos-collector is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for NetworkManager is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low. Type: Trojan, Worm.

Did UK city council over-react to a vulnerability report in its recycling app or not?
Knuddels Flirt App Slapped with Hefty Fine After Data Breach
Check your repos… Crypto-coin-stealing code sneaks into fairly popular NPM lib (2m downloads per week)
Mobile Rotexy Malware Touts Ransomware, Banking Trojan Functions
USPS, Amazon Data Leaks Showcase API Weaknesses
User Confidence in Smartphone Security Abysmal

Reading Time: ~5 min.‘Tis the season of giving, which means scammers may try to take advantage of your good will. A surprising fact about American donation habits is that everyday folks like yourself are the single largest driver of charitable donations in the United States. Giving USA’s Annual Report on Philanthropy found that individuals gave […]

Bedroom design outfit slapped with £160k fine for 1.6 million spam calls
Bug Bounty: Earn $40,000 for hacking Facebook, Instagram or WhatsApp
Man arrested for stealing $1m from Silicon Valley Exec via SIM-swapping
L0rdix malware on dark web steals data, mines crypto & enslaves PCs as botnet
Adult video game website High Tail Hall hacked; user data stolen

LinuxSecurity.com: An update for rh-mysql57-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-nginx110-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-nginx18-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The frustratingly simple techniques of ‘human hacking’ – and how to fight them
LinkedIn violated data protection by using 18M email addresses of non-members to buy targeted ads on
Smartphone shopping: Avoid the blues on Cyber Monday

As we increasingly make use of our smartphones to satisfy our shopping needs, let’s shine a light on how these hubs of our digital lives can be used to shop securely, on and around a day dedicated to online deals The post Smartphone shopping: Avoid the blues on Cyber Monday appeared first on WeLiveSecurity

Tighten up your security defences at SANS London 2019

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,