Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: Updated rust packages fix security vulnerability The Rust Programming Language Standard Library before version 1.29.1 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in the standard library that can result in buffer overflow. This attack

LinuxSecurity.com: The updated clamav packages fix a security vulnerability: Vulnerability in ClamAV’s MEW unpacking feature that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition on an affected device (CVE-2018-15378).

LinuxSecurity.com: Updated docker packages fix security vulnerabilities: Lack of content verification in docker allowed a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing (CVE-2017-14992).

LinuxSecurity.com: Updated calibre package fixes security vulnerability: gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that

LinuxSecurity.com: pdated tcpflow package fixes security vulnerability: An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handle_prism during caplen processing. If the caplen is less than 144, one can cause

LinuxSecurity.com: Smarty 3.1.32 or below is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files (CVE-2018-13982).

LinuxSecurity.com: Updated mgetty packages fix security vulnerabilities: The function do_activate() did not properly sanitize shell metacharacters to prevent command injection (CVE-2018-16741).

LinuxSecurity.com: This update provides vlc 3.0.4 and fixes atleast the following security issue: A use-after-free was discovered in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media

LinuxSecurity.com: Updated 389-ds-base package fixes security vulnerabilities: a race condition on reference counter leads to DoS using persistent search (CVE-2018-10850)

LinuxSecurity.com: The updated glib2.0 packages fix security vulnerabilities: In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference (CVE-2018-16428).

Risk Level: Very Low.

AWS FreeRTOS Bugs Allow Compromise of IoT Devices
Celebrating 100 episodes of the Smashing Security podcast
Manager who worked on Equifax’s breach website sentenced for insider trading

Reading Time: ~2 min.2018 Voter Records for Sale As the United States midterm elections draw closer, concern surrounding voter information is on the rise, and for good reason. Records for nearly 35 million registered voters from 19 different states were found for sale on a hacker forum, with prices ranging from $500 to $12,500, depending […]

Trivial Post-Intrusion Attack Exploits Windows RID
How to Make the Payment Process Easy for Online Customers
FBI Investigates Attack on Critical Water Utility
Pentagon Staff Hit by Major Data Breach
European Banks and Police Warn Consumers of Cyber Scams
Scams and flaws: Why we get duped

What are the emotional triggers and errors in judgment that make you fall for an online scam? The post Scams and flaws: Why we get duped appeared first on WeLiveSecurity

Swedish court tells ISP to block The Pirate Bay in the country
You like HTTPS. We like HTTPS. Except when a quirk of TLS can smash someone’s web privacy

LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata is now available.

LinuxSecurity.com: Two vulnerabilities were found in Drupal, a fully-featured content management framework, which could result in arbitrary code execution or an open redirect. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2018-006

security update

Talk about a curveball: Microsoft director of sports marketing fired, charged with fraud over ‘fake’ invoices
Equifax exec’s inside trade shame: Software boss sentenced for mega-hack stock profit
New APT Could Signal Reemergence of Notorious Comment Crew
Author of Luminosity RAT Gets 2.5 Years in Federal Prison
Tumblr Privacy Bug Could Have Exposed Sensitive Account Data
GreyEnergy Spy APT Mounts Sophisticated Effort Against Critical Infrastructure
400% increase in cryptomining malware attacks against iPhones

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.

Reading Time: ~3 min.There’s a reason major industry players have been discussing cybersecurity more and more: the stakes are at an all-time high for virtually every business today. Cybersecurity is not a matter businesses can afford to push off or misunderstand—especially small and medium-sized businesses (SMBs), which have emerged as prime targets for cyberattacks. The […]

RAT author jailed for 30 months, ordered to hand over $725k worth of Bitcoin
NCSC Tackles 10 Attacks on Government Per Week
LibSSH Flaw Allows Hackers to Take Over Servers Without Password
Tumblr patches bug that could have exposed user data

The microblogging platform is assuring its users that has found no evidence that any data was actually stolen The post Tumblr patches bug that could have exposed user data appeared first on WeLiveSecurity

LinuxSecurity.com: An update for rh-nodejs8-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

How to use the Shodan search engine to secure an enterprise’s internet presence
VestaCP compromised in a new supply-chain attack

Customers see their admin credentials stolen and their servers infected with Linux/ChachaDDoS The post VestaCP compromised in a new supply-chain attack appeared first on WeLiveSecurity

LinuxSecurity.com: The package chromium before version 70.0.3538.67-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, sandbox escape, information disclosure and denial of service.

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for rh-nodejs6-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Decoding the Google Titan, Titan, and Titan M – that last one is the Pixel 3’s security chip

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has four fixes is now available.

Smashing Security #100: One flippin’ hundred
Tumblr turns stumblr, left humblr: Blogging biz blogs bloggers’ private info to world+dog
Naked celebrity photo hacker used to be a high school teacher

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Someone’s in hot water: Tea party super PAC group ‘spilled 500,000+ voters’ info’ all over web
Authorities search & seize properties of GTA V’s “Infamous” cheat developers

security update

security update

LinuxSecurity.com: An update is now available for Red Hat Fuse Integration Services. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LuminosityLink spyware mastermind gets 30 months in the clink, forfeits $725k in Bitcoin
Oracle Fixes 301 Flaws in October Critical Patch Update

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2921

LinuxSecurity.com: An update is now available for Red Hat JBoss Operations Network. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: It was discovered that there was a denial-of-service vulnerability in libpdfbox-java, a PDF library for Java. A malicious PDF file could have triggered an extremely long running

LinuxSecurity.com: An update is now available for Red Hat Satellite 6.4 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

GreyEnergy: New malware targeting energy sector with espionage
libssh Authentication Bypass Makes it Trivial to Pwn Rafts of Servers
Podcast: A Utility Ransomware Attack, Post-Hurricane
Multiple D-Link Routers Open to Complete Takeover with Simple Attack
On Heels of Criticism, Newly-Released Google Chrome 70 Prioritizes Privacy
Text Bomb Causing PS4 to Crash
Malicious Platform Independent Trojan GPlayed Disguised as Google Play Store

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

UK’s MoD Exposed in 37 Security Breaches: Report
The Biggest Features Of Linux 4.19: Intel/AMD, CoC, 802.11ax, EROFS, GPS & GASKET
Linux’s LoRa Is Ready To Deliver Long-Range, Low-Power Wireless
Remote Code Implantation Flaw Found in Medtronic Cardiac Programmers
GreyEnergy: Updated arsenal of one of the most dangerous threat actors

ESET research reveals a successor to the infamous BlackEnergy APT group targeting critical infrastructure, quite possibly in preparation for damaging attacks The post GreyEnergy: Updated arsenal of one of the most dangerous threat actors appeared first on WeLiveSecurity

Last year, D-Link flubbed a router bug-fix, so it’s back with total pwnage

Reading Time: ~3 min.For the past 20 years, Webroot’s technology has been driven by our dedication to protecting users from malware, viruses, and other online threats. The release of Webroot® WiFi Security—a new virtual private network (VPN) app for phones, computers, and tablets—is the next step in fulfilling our commitment to protect everyone’s right to […]

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Party like it’s 1989… SVGA code bug haunts VMware’s house, lets guests flee to host OS

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Thought Patch Tuesday was a load? You gotta check out this Oracle mega-advisory, then

LinuxSecurity.com: Several vulnerabilities have been discovered in GraphicsMagick, a set of command-line applications to manipulate image files, which could result in denial of service or the execution of arbitrary code if malformed image files are processed.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Asterisk, an open source PBX and telephony toolkit, which may result in denial of service or information disclosure.

As End of Life Nears, More Than Half of Websites Still Use PHP V5

security update

security update

Insult to injury: Malware menace soaks water-logged utility ravaged by Hurricane Florence
Alphabet in the soup for keeping quiet about Google+ data leak bug

LinuxSecurity.com: ClamAV could be made to crash if it opened a specially crafted file.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Anthem, Apple and the Pentagon: A Data-Breach Cornucopia
Penta-gone! Personal records of 30,000 US Dept of Defense workers swiped by miscreants

LinuxSecurity.com: Nitin Venkatesh discovered a cross-site scripting vulnerability in moin, a Python clone of WikiWiki. A remote attacker can conduct cross-site scripting attacks via the GUI editor’s link dialogue. This only affects installations which have set up fckeditor (not enabled by default).

Risk Level: Very Low. Type: Trojan, Virus, Worm.