Menu

Category Archives: Security

Articles about security

Send in the clones: Facebook cloning revisited

As another confusing message spreads, we look at Facebook privacy, cloning, and hacking The post Send in the clones: Facebook cloning revisited appeared first on WeLiveSecurity

LinuxSecurity.com: dnsruby is a feature-complete DNS(SEC) client for Ruby. It ships the DNS Root Key Signing Key (KSK), used as trust anchor to validate the authenticity of DNS records. This update includes the latest KSK

LinuxSecurity.com: An update that contains security fixes can now be installed.

Now, watch this… Network time protocol bugs sting Juniper operating system
If you haven’t already patched your MikroTik router for vulns, then if you could go do that, that would be greeeeaat
Oh no, Xi didn’t! Chinese spymaster cuffed in Belgium, yoinked to US on aerospace snoop rap

LinuxSecurity.com: Ben Pfaff discovered that the convert_to_decimal function in the GNU Portability Library contains a heap-based buffer overflow because memory is not allocated for a trailing ‘’ character during %f processing.

Risk Level: Very Low. Type: Trojan.

Smashing Security #099: Passwords – A Smashing Security splinter (replay)
PINs and needled: Experian site blabbed codes to unlock credit accounts for fraudsters
FruityArmor APT Exploits Yet Another Windows Graphics Kernel Flaw
Who needs custom malware? ‘Govt-backed’ Gallmaker spy crew uses off-the-shelf wares

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure IoT Device Client SDK is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft PowerPoint is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Codecs Library is prone to a information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Media Player is prone to a information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Media Player is prone to a information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Theme API is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2884

LinuxSecurity.com: An update for glusterfs is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Innovative Phishing Tactic Makes Inroads Using Azure Blob
China’s clampdown on Tor pushes its hackers into foreign backyards
Google’s failure to disclose user data leak prompts closure of Google Plus
Critical Data-Loss Bug Identified in New Windows 10 Update
Hackers illegally selling stolen Fortnite accounts & botnets on Instagram
Four Critical Flaws Patched in Adobe Digital Edition
Worker perks flinger Sodexo pulls Engage website after malware smackdown
California outlaws poor default passwords in connected devices

The law is intended to help curb attacks that rely on weak, non-existent or publicly disclosed passwords that far too often ship with web-connected gadgets The post California outlaws poor default passwords in connected devices appeared first on WeLiveSecurity

Podcast: Key Takeaways For DevOps in BSIMM9
MSM-Next Bringing A6xx Performance Improvements, Fixes To The Linux Kernel
Heathrow Airport fined ?120,000 over USB data breach debacle

LinuxSecurity.com: The package patch before version 2.7.6-3 is vulnerable to multiple issues including arbitrary command execution and denial of service.

Google and Microsoft boffins playing nicely together to stop replay attacks in their tracks
Google+ to shut down due to lack of adoption and privacy bug

Google has found no evidence of misuse of user information courtesy of a security glitch in the social platform’s API The post Google+ to shut down due to lack of adoption and privacy bug appeared first on WeLiveSecurity

US may have by far the world’s biggest military budget but it’s not showing in security

LinuxSecurity.com: Updates for rh-dotnetcore11-dotnetcore, and rh-dotnetcore10-dotnetcore are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

World’s largest CCTV maker leaves at least 9 million cameras open to public viewing
Rap for WhatsApp chat app chaps in phone-to-pwn security nap flap
It’s October 2018, and Microsoft Exchange can be pwned by a plucky eight-year-old… bug
Microsoft Patches Zero-Day Under Active Attack by APT

security update

security update

Payment-card-skimming Magecart strikes again: Zero out of five for infecting e-retail sites

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2846

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2898

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2892

New Ninth-Gen Intel CPUs Shield Against Some Spectre, Meltdown Variants
Chinese Super Micro ‘spy chip’ story gets even more strange as everyone doubles down
Slideshow: Intel from Virus Bulletin 2018

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several vulnerabilities were discovered in tinc, a Virtual Private Network (VPN) daemon. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: Several security issues were fixed in libxkbcommon.

MikroTik router vulnerability lets hackers bypass firewall to load malware undetected

Risk Level: Very Low. Type: Trojan.

It’s a cert: Hundreds of big sites still unprepared for starring role in that Chrome 70’s show
How Shared Pools of Cloud Computing Power Are Changing the Way Attackers Operate
Google+ Privacy Snafu Leaves a Cloud Over the Tech Landscape
ThreatList: Microsoft IIS Sees Triple-Digit Spike in Cyberattack Volume

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2881

Magecart Group Targets Shopper Approved in Latest Attack
Don’t make us pay compensation for employee data breach, Morrisons begs UK court
Blockchain: What is it, how it works and how it is being used in the market

A closer look at the technology that is rapidly growing in popularity The post Blockchain: What is it, how it works and how it is being used in the market appeared first on WeLiveSecurity

MikroTik vulnerability climbs up the severity scale, new attack permits root access
What is a Linux server and why does your business need one?

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,