Menu

Category Archives: Security

Articles about security

Hackers deface Saudi ‘Davos in the Desert’ site against Khashoggi’s death

LinuxSecurity.com: It was discovered that 389-ds-base (the 389 Directory Server) is vulnerable to search queries with malformed values in the do_search() function (servers/slapd/search.c). Attackers could leverage this vulnerability by sending crafted queries in a loop to cause DoS.

Yahoo agrees to pay $50 million to settle data breach lawsuit
EU Laws Could Spell Double Trouble for Firms
Cathay Pacific hack: Personal data of up to 9.4 million airline passengers laid bare
Hackers steal personal data of up to 9.4 million Cathay Pacific passengers
ESET releases new decryptor for Syrian victims of GandCrab ransomware

ESET experts have created a new decryption tool that can be used by Syrian victims of the GandCrab ransomware. It is based on a set of keys recently released by the malware operators The post ESET releases new decryptor for Syrian victims of GandCrab ransomware appeared first on WeLiveSecurity

Smashing Security #101: Rule 34, Twitter scams, and Facebook fails

LinuxSecurity.com: It was discovered that mosquitto, an MQTT broker, was vulnerable to remote denial-of-service attacks that could be mounted using various vectors.

From ‘WebEx’ to ‘WebExec’ to ‘WTF, my PC!’ Cisco rapped in chat app security flap

security update

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.6.0-sun is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.6.0-sun is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Teacher linked to Celebgate hacking scandal facing 7 years in prison
Ex spy bosses: Cyber-warfare needs rules of engagement for nations to promptly ignore

LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could result in the execution of arbitrary code, privilege escalation or information disclosure.

Magecart Cybergang Targets 0days in Third-Party Magento Extensions
Worrying Windows 10 wrecking-ball weapon weirdly wanders wildly on worldwide web
Windows ‘Deletebug’ Zero-Day Allows Privilege Escalation, Destruction
Supermarket told it must compensate 100,000 workers after payroll data deliberately leaked by rogue employee

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves 25 vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

sLoad Banking Trojan Downloader Displays Sophisticated Recon and Targeting
ThreatList: Ransomware, EKs and Trojans lead the Way in Q3 Malware Trends
Russia launched Triton malware to sabotage Saudi petrochemical plant
Vesta control panel servers infected with DDoS malware after supply chain attack
Banking Trojans continue to surface on Google Play

The malicious apps have all been removed from the official Android store but not before the apps were installed by almost 30,000 users The post Banking Trojans continue to surface on Google Play appeared first on WeLiveSecurity

Morrisons Loses Insider Breach Liability Appeal
Twitter thought Elon Musk’s bizarre tweets were evidence he’d been hacked
LuminosityLink RAT author sentenced to 2.5 years in jail

As part of his plea agreement, the author of the malware also forfeited the proceeds from his crimes – 114 Bitcoin worth $725,000 The post LuminosityLink RAT author sentenced to 2.5 years in jail appeared first on WeLiveSecurity

That Saudi oil and gas plant that got hacked. You’ll never guess who could… OK, it’s Russia

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

You patch my back(up) and I’ll patch yours… Arcserve bugs burrow remotely exploited holes in UDP storage systems
City Pays $2K in Ransomware, Stirs ‘Never Pay’ Debate

LinuxSecurity.com: Several security issues were fixed in MySQL.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2942

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2943

StrongPity APT Changes Tactics to Stay Stealthy
ProtonVPN Subscriptions Now Available on Firefox for $10
ThreatList: 3 Out of 4 Employees Pose a Security Risk to Businesses
Adult Website Hack Exposes 1.2M ‘Wife Lover’ Fans
How to Choose the Most Secure Software for your Business
Thousands of Applications Vulnerable to RCE via jQuery File Upload

LinuxSecurity.com: Several security issues were fixed in Tex Live.

Get Essential Security Information from Linux Security Summit Videos
Morrisons supermarket: We’re taking payroll leak liability fight to UK Supreme Court
‘The inmates have taken over the asylum’: DNS godfather blasts DNS over HTTPS adoption

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

If Facebook buys a security company, how will it retain the staff who absolutely hate Facebook?
jQuery? More like preyQuery: File upload tool can be exploited to hijack at-risk websites
Watch how a Tesla Model S was stolen with just a tablet
Patch me, if you can: Grave TCP/IP flaws in FreeRTOS leave IoT gear open to mass hijacking
Forgotten that Chinese spy chip story? We haven’t – it’s still wrong, Super Micro tells SEC

LinuxSecurity.com: Paramiko could allow unintended access to network services.

LinuxSecurity.com: Net-SNMP could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: libssh could allow unintended access to network services.

LinuxSecurity.com: Requests could be made to expose sensitive information if it received a specially crafted HTTP header.

The Danger and Opportunity in 5G Connectivity and IoT
Obamacare Sign-Up Channel Breach Affects 75K Consumers
Personal data of 75,000 individuals exposed after HealthCare.gov system hack
Critical Bug Impacts Live555 Media Streaming Libraries
Take this short Recorded Future survey to assess your organization’s threat intelligence maturity
Strict password policy could prevent credential reuse, paper suggests

The solution to password recycling may be easier to implement than previously thought, according to a recent paper The post Strict password policy could prevent credential reuse, paper suggests appeared first on WeLiveSecurity

Vendors confirm products affected by libssh bug as PoC code pops up on GitHub
A Twitter employee groomed by the Saudi government prompted 2015 state-sponsored hacking warning

LinuxSecurity.com: Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file (CVE-2016-5319). In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function

Bad to the Bot Bone

LinuxSecurity.com: A vulnerability has been discovered in exiv2 (CVE-2018-16336), a C++ library and a command line utility to manage image metadata, resulting in remote denial of service (heap-based buffer over-read/overflow) via

Watch out: MPlayer and VLC media player hit by critical vulnerability

LinuxSecurity.com: The package thunderbird before version 60.2.1-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

Two Critical RCE Bugs Patched in Drupal 7 and 8
Apache Access Vulnerability Could Affect Thousands of Applications
Hackers breach Healthcare.gov system, taking files on 75,000 people
Password and credit card-stealing Azorult malware adds new tricks
North Korean hacker crew steals $571M in cryptocurrency across 5 attacks
Apple boss demands Bloomberg Super Micro U-turn, Russian troll charged, NSA hands out cash, and more
Facebook Portal isn’t designed to be as private as you might hope
Spotted: Miscreants use pilfered NSA hacking tools to pwn boxes in nuke, aerospace worlds

LinuxSecurity.com: Updated ghostscript packages fix many bugs and security vulnerabilities: Bypassing executeonly to escape -dSAFER sandbox. (CVE-2018-17961) Saved execution stacks can leak operator arrays. (CVE-2018-18073)

security update