Menu

Category Archives: Security

Articles about security

security update

Did you hear? There’s a critical security hole that lets web pages hijack computers. Of course it’s Adobe Flash’s fault
Gmail Glitch Enables Anonymous Messages in Phishing Attacks
APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign

LinuxSecurity.com: The package grafana before version 5.3.4-1 is vulnerable to arbitrary filesystem access.

Sednit: What’s going on with Zebrocy?

In August 2018, Sednit’s operators deployed two new Zebrocy components, and since then we have seen an uptick in Zebrocy deployments, with targets in Central Asia, as well as countries in Central and Eastern Europe, notably embassies, ministries of foreign affairs, and diplomats. The post Sednit: What’s going on with Zebrocy? appeared first on WeLiveSecurity

OceanLotus: New watering hole attack in Southeast Asia

ESET researchers identified 21 distinct websites that had been compromised including some particularly notable government and media sites The post OceanLotus: New watering hole attack in Southeast Asia appeared first on WeLiveSecurity

Two friends jailed for TalkTalk hack plot

LinuxSecurity.com: Assertion failure in BPMDetect class in BPMDetect.cpp (CVE-2018-17096). Out-of-bounds heap write in WavOutFile::write() (CVE-2018-17097). Heap corruption in WavFileBase class in WavFile.cpp (CVE-2018-17098). References:

LinuxSecurity.com: mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user’s credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example,

LinuxSecurity.com: It was discovered that mishandled search requests in servers/slapd/search.c:do_search() in 389-ds-base allows for denial of service (CVE-2018-14648). References:

Texas hospital becomes victim of Dharma ransomware
Russian hacker arrested in Bulgaria for ad fraud of over $7 million
Security warning: UK critical infrastructure still at risk from devastating cyber attack

LinuxSecurity.com: Multiple vulnerabilities have been discovered in uriparser, an Uniform Resource Identifiers (URIs) parsing library.

Germany pushes router security rules, OpenWRT and CCC push back

LinuxSecurity.com: The package chromium before version 70.0.3538.110-1 is vulnerable to information disclosure.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec. CVE-2017-17480

TalkTalk hackhack duoduo thrownthrown in the coolercooler: ‘Talented’ pair sentenced for ransacking ISP
From directory traversal to direct travesty: Crash, hijack, siphon off this TP-Link VPN box via classic exploitable bugs

LinuxSecurity.com: Red Hat OpenShift Container Platform release 3.9.51 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Linux kernel Spectre V2 defense fingered for massively slowing down unlucky apps on Intel Hyper-Thread CPUs

LinuxSecurity.com: systemd was found to suffer from multiple security vulnerabilities ranging from denial of service attacks to possible root privilege escalation.

Olympic Destroyer Wiper Changes Up Infection Routine

LinuxSecurity.com: systemd-tmpfiles could be made to change ownership of arbitrary files.

LinuxSecurity.com: Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.1.37. Please see the MariaDB 10.1 Release Notes for further details:

VisionDirect Blindsided by Magecart in Data Breach
Unlock the power of threat intelligence with this practical guide. Get your free copy now
Symantec execs cooked the books to protect their fat bonuses, investor lawsuit alleges
Ford Eyes Use of Customers’ Personal Data to Boost Profits
Multi-factor failure locks out Microsoft Office 365 and Azure users
Vision Direct hack reveals customer credit card details
Stopping the Infiltration of Things
Cryptojacking Attack Targets Make-A-Wish Foundation Website
Britain may not be able to fend off a determined cyber-attack, MPs warn
Vision Direct ‘fesses up to hack that exposed customer names, payment cards
Cybersecurity a big concern in Canada as cybercrime’s impact grows

90% of Canadians surveyed agreed that cybercrime was an important “challenge to the internal security of Canada” The post Cybersecurity a big concern in Canada as cybercrime’s impact grows appeared first on WeLiveSecurity

Scumbags cram Make-A-Wish website with coin-mining malware
Using Airport and Hotel Wi-Fi Is Much Safer Than It Used to Be
Prepare for the battle against cybercrime at SANS London 2019
Washington Post offers invalid cookie consent under EU rules – ICO
A little phishing knowledge may be a dangerous thing

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Congress Passes Bill to Create New Federal Cybersecurity Agency
New HealthEquity Data Breach Exposes PII/PHI of Almost 21,000 Customers
Instagram bug inadvertently exposed some user’s passwords

LinuxSecurity.com: An out-of-bounds bounds memory access issue was discovered in chromium’s v8 javascript library by cloudfuzzer. This update also fixes two problems introduced by the previous security

security update

LinuxSecurity.com: The ProcessGpsInfo function may have allowed a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT handling (CVE-2018-16554).

LinuxSecurity.com: This update fixes various security vulnerabilities affecting the SDL2_image library, listed below. The fixes are provided in SDL2_image 2.0.4, which depends on SDL2 2.0.8 or later. As such, the SDL2 and SDL2_mixer libraries are also updated to their current stable releases, providing various bug fixes and features.

LinuxSecurity.com: Hanno B?ck discovered that libmspack incorrectly handled certain CHM files. An attacker could possibly use this issue to cause a denial of service (CVE-2018-14679, CVE-2018-14680). Jakub Wilk discovered that libmspack incorrectly handled certain KWAJ

LinuxSecurity.com: Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via a malformed fax message (CVE-2018-17141).

LinuxSecurity.com: Due to incorrect input handling, Squid is vulnerable to a Cross-Site Scripting vulnerability when generating HTTPS response messages about TLS errors (CVE-2018-19131). Due to a memory leak in SNMP query rejection code, Squid is vulnerable

LinuxSecurity.com: nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption (CVE-2018-16843). nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the

LinuxSecurity.com: The package patch before version 2.7.6-7 is vulnerable to multiple issues including arbitrary command execution and denial of service.

Type: Vulnerability. Microsoft Internet Explorer is prone to a memory corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Dynamics 365 is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Dynamics 365 is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure App Service is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Project is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Under attack! Should your company ever ‘hack back’?
SMS 2FA database leak drama, MageCart mishaps, Black Friday badware, and more
Mylobot Botnet Now Exfiltrates Data Using Second Stage Khalesi Trojan
Malicious code hidden in advert images cost ad networks $1.13bn this year

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has 7 fixes is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 8 fixes is now available.

Emoji Attack Can Kill Skype for Business Chat
Gmail Glitch Offers Stealthy Trick for Phishing Attacks

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Active Directory Federation Services is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Powershell is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows PowerShell is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows DirectX is prone to a information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.