Menu

Category Archives: Security

Articles about security

In County Crippled by Hurricane, Water Utility Targeted in Ransomware Attack
Bug in Newly Released iOS 12.0.1 Gives Access To Your Photos
ThreatList: Half of Execs Feel Unprepared to Respond to a Cyber-Incident
Facebook Expands Efforts to Squash Voter Suppression
Privacy Regulation Could Be a Test for States’ Rights
UK’s National Cyber Security Centre gives itself big ol’ pat on the back in annual review

LinuxSecurity.com: Net-SNMP could be made to crash if it received specially crafted network traffic.

Phishers are after something unusual in ploy targeting book publishers

In a new twist on the theme, the scammers have their sights set on book manuscripts, among other things The post Phishers are after something unusual in ploy targeting book publishers appeared first on WeLiveSecurity

Considering Electronic Document Signing? Try OneSpan Sign Free For 30 Days
How to secure your Azure network

LinuxSecurity.com: An update for tomcat is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Pentagon data breach puts personal details of 30,000 staff at risk
Web browsers sharpen knives for TLS 1.0, 1.1, tell protocols to dig their own graves for 2019

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing

LinuxSecurity.com: Several security issues were fixed in Thunderbird.

Hunt for Red Bugtober: US military’s weapon systems riddled with security holes – auditors

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2916

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2918

security update

Up to 35 Million 2018 Voter Records For Sale on Hacking Forum

LinuxSecurity.com: Frediano Ziglio reported a missing check in the script to generate demarshalling code in the SPICE protocol client and server library. The generated demarshalling code is prone to multiple buffer overflows. An authenticated attacker can take advantage of this flaw to cause a denial

Talking DerbyCon, spy chip whispers and Google’s data breach | Salted Hash Ep 47

LinuxSecurity.com: Net-SNMP could be made to crash if it received specially crafted network traffic.

Did Jamal Khashoggi’s Apple Watch record his murder at Saudi consulate? Probably not
NotPetya Linked to Industroyer Attack on Ukraine Energy Grid
Facebook downgrades victim count, details data accessed in breach

While the number of victims is lower than previously thought, the data accessed for millions of them is more sensitive than originally believed The post Facebook downgrades victim count, details data accessed in breach appeared first on WeLiveSecurity

Facebook Offers Details on ‘View As’ Breach, Revises Numbers
Google Maps: Hubby divorces wife after finding her on Street View with another man
The Occasional Orator Part 3

Proper preparation can make all the difference when it comes to speaking at conferences The post The Occasional Orator Part 3 appeared first on WeLiveSecurity

Fake Adobe update really *does* update Flash (while also installing cryptominer)

LinuxSecurity.com: Requests could be made to expose sensitive information if it received a specially crafted HTTP header.

AMD Posts Latest Open-Source Linux Patches For FreeSync / Adaptive-Sync / VRR
How OpenStack Barbican deployment options secure your cloud

LinuxSecurity.com: Three vulnerabilities were discovered in the Open Ticket Request System which could result in privilege escalation or denial of service. For the stable distribution (stretch), these problems have been fixed in

Top cybersecurity facts, figures and statistics for 2018
30 Million Facebook Accounts Were Hacked: Check If You’re One of Them

LinuxSecurity.com: Nextcloud has been updated to 13.0.6 and fixes atleast the following security issue: A missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization

LinuxSecurity.com: joernchen of Phenoelit discovered that git is prone to an arbitrary code execution vulnerability due to insufficient validation of submodule url and path via a specially crafted .gitmodules file in a project cloned with –recurse-submodules (CVE-2018-17456).

LinuxSecurity.com: Updated firefox packages fix security vulnerabilities: A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered

LinuxSecurity.com: Updated texlive packages fix security vulnerability: A buffer overflow in the handling of Type 1 fonts allowed arbitrary code execution when a malicious font is loaded by one of the vulnerable tools: pdflatex, pdftex, dvips, or luatex (CVE-2018-17407).

security update

security update

LinuxSecurity.com: spamassassin: Certain unclosed tags in crafted emails allow for scan timeouts and result in denial of service (CVE-2017-15705) * spamassassin: Local user code injection in the meta rule syntax (CVE-2018-11781) SL7 x86_64 spamassassin-3.4.0-4.el7_5.x86_64.rpm spamassassin-debuginfo-3.4.0-4.el7_5.x86_64.rpm – Scientific Linux Development Team

Fake Adobe updates installing cryptomining malware while updating Flash
Azure goes quiet, Huawei Canada ban urged, US Senators are after Google, and more
It’s the real Heart Bleed: Medtronic locks out vulnerable pacemaker programmer kit
30M Facebook breach; includes users phone numbers and location data
ICS Security Plagued with Basic, Avoidable Mistakes

LinuxSecurity.com: This update fixes several vulnerabilities in Imagemagick, a graphical software suite. Various memory handling problems or incomplete input sanitising have been found in the coders for BMP, DIB, PICT, DCM, CUT and PSD.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer which could result in denial of service or the execution of arbitrary code.

security update

Now this might be going out on a limb, but here’s how a branch.io bug left ‘685 million’ netizens open to website hacks

LinuxSecurity.com: The package wireshark-cli before version 2.6.4-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Threatpost News Wrap Podcast For Oct. 12
Facebook mass hack last month was so totally overblown – only 30 million people affected

Risk Level: Very Low. Type: Trojan.

Microsoft Zero-Day Patch for JET Bug Incomplete, Claims Firm

Reading Time: ~2 min.Latest Windows 10 Update Removes User Files Microsoft recently pulled its latest update, version 1809, after several users complained about personal files being deleted. While some users were able to use third-party software to retrieve deleted files, users whose files wnet missing from the Documents folder are having a much trickier time […]

Baby Got Bots
Shining a Light on a New Technique for Stealth Persistence
Facebook Bans More Than 800 Accounts in Disinformation Purge
Shocking: Hackers using Googlebots in cryptomining malware attacks
It is 2018 and the NHS is still counting the cost of WannaCry. Carry the 2, + aftermath… um… £92m

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

This is how much the WannaCry ransomware attack cost the NHS
Threat Hunters & Security Analysts: A Dynamic Duo
Tips for minding the digital skills gap

The times they are a-changin‘, so how do you build and sharpen the skills that you need to avoid being left behind by the digital revolution? The post Tips for minding the digital skills gap appeared first on WeLiveSecurity

AMD Stages A Number Of Fixes Ahead Of Linux 4.20~5.0 – Plus Vega 20 “MGPU Fan Boost”
Arrest of top Chinese intelligence officer sparks fears of new Chinese hacking efforts

LinuxSecurity.com: Git could be made to run programs as your login if it recursivelyopened a malicious git repository.

000000 is Kanye West’s iPhone passcode
WebSphere and loathing in New York: IBM yanks buggy application server security fix from admins

LinuxSecurity.com: An update for spamassassin is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

FitMetrix Exposes Millions of Customer Details, Accessed by Criminals
New Drupalgeddon Attacks Enlist Shellbot to Open Backdoors
ThreatList: Credential Theft Spikes by Triple Digits in U.S.

LinuxSecurity.com: Magnus Klaaborg Stubman discovered a NULL pointer dereference bug in net-snmp, a suite of Simple Network Management Protocol applications, allowing a remote, authenticated attacker to crash the snmpd process (causing a denial of service).

Bloke gets six months for fixing up Russia’s US election trolls with bank accounts, fake identities

Type: Vulnerability. The Microsoft .NET Core is prone to an information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: Several security issues were fixed in Tex Live.

Major weapon systems developed by US DoD highly vulnerable to cyber attacks
Adaptable, All-in-One Android Trojan Shows the Future of Malware
UK.gov teams up with Five Eyes chums to release spotters’ guide for hacking tools
Dark web kingpin visiting US for beard competition gets 20 years in prison
Fake Adobe Flash Updates Hide Malicious Crypto Miners
Calif. Law Takes Aim at Weak IoT Passwords
In the two years since Dyn went dark, what have we learned? Not much, it appears

LinuxSecurity.com: An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

New TeleBots backdoor: First evidence linking Industroyer to NotPetya

ESET’s analysis of a recent backdoor used by TeleBots – the group behind the massive NotPetya ransomware outbreak – uncovers strong code similarities to the Industroyer main backdoor, revealing a rumored connection that was not previously proven The post New TeleBots backdoor: First evidence linking Industroyer to NotPetya appeared first on WeLiveSecurity

Mozilla grants distrusted Symantec certs a stay of execution, claims many sites yet to make switch
The Obama-era cyber détente with China was nice, wasn’t it? Yeah well it’s obviously over now
Mingis on Tech: Data breaches in a world of ‘surveillance capitalism’