Menu

Category Archives: Security

Articles about security

Tesco Bank Fined ?16m After 2016 Cyber Heist
The Right Diagnosis: A Cybersecurity Perspective
MIMEsweeper maker loses UK High Court patent fight over 15-year-old bulletin board post
Ever used an airport lounge printer? You probably don’t know how blabby they can be
100,000 home routers recruited to spread Brazilian hacking scam
Haven’t updated your Adobe PDF software lately? Here’s 85 new reasons to do it now
Boffin: Dump hardware number generators for encryption and instead look within
Adobe Patches 47 Critical Flaws in Acrobat and DC

LinuxSecurity.com: The package lib32-libxml2 before version 2.9.8-4 is vulnerable to denial of service.

LinuxSecurity.com: The package libxml2 before version 2.9.8-5 is vulnerable to denial of service.

LinuxSecurity.com: The package libxml2 before version 2.9.8-5 is vulnerable to denial of service.

LinuxSecurity.com: The package ntp before version 4.2.8.p12-1 is vulnerable to arbitrary code execution.

Desktop Telegram users showing off not only their silly selfies but also their IP addresses

LinuxSecurity.com: An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Nine NAS Bugs Open LenovoEMC, Iomega Devices to Attack
California, U.S. Government Battle Over Net Neutrality State Law
Telegram leaked IP addresses of its desktop app users
50 million Facebook users affected in breach

It has yet to be determined whether the accounts were misused or what information was accessed. In the meantime, you can improve your account security with a few easy steps The post 50 million Facebook users affected in breach appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in Ghostscript.

Financial Conduct Authority fines Tesco Bank £16.4m over 2016 security breach

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

Dark Web Azorult Generator Offers Free Binaries to Cybercrooks
Two reasons to reconsider your Facebook membership

LinuxSecurity.com: Firefox 60 is now the only supported version of the ESR series and it brings a completely new browser engine, designed to take full advantage of the processing power in modern devices. Firefox also now exclusively supports extensions built using the WebExtension API.

UK ruling party’s conference app editable by world+dog, blabs members’ digits
How to enforce SSL in ASP.Net Core
Top tips for protecting your Smart TV

The final few months of 2018 will likely be a busy time of year for people and cybercriminals will be no different as they continue to look for weak spots in networks The post Top tips for protecting your Smart TV appeared first on WeLiveSecurity

Free buyer’s guide to evaluating fraud detection & prevention tools
Location, location, location… technologies under the microscope
AI-powered IT security seems cool – until you clock miscreants wielding it too

security update

Facebook monetizes 2FA, Singapore monetizes hacker, and ransomware creeps monetize US Democrats
Linux Is Getting New Network Libraries From Veteran systemd/BUS1 Developers
Python is a hit with hackers, report finds

LinuxSecurity.com: This is an update to Mozilla’s CA certificates list version 2.26, which has been published as part of Mozilla NSS 3.39. For additional details, please refer to the NSS 3.39 release notes: https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes

LinuxSecurity.com: Security fix for CVE-2018-17336

LinuxSecurity.com: libxkbcommon 0.8.2, CVE-2018-15853 through to 15864. These fix a number of memory handling issues with xkbcommon. Together with the keymap FD handling in various Wayland compositors (keymaps could be mapped rw and clients could thus replace the content) libxkbcommon’s memory issues could serve as attack vector to gain access to another client. The update […]

LinuxSecurity.com: Fixed some small bugs in the previous package: Initial rules now have the correct version, sought channel config is dropped (since it doesn’t exist anymore) and build / runtime deps adjusted. —- Update to 3.4.2. Fixes CVE-2017-15705, CVE-2018-11780 and CVE-2018-11781 along with many other bugfixes and improvements. See https://www.mail-

LinuxSecurity.com: Security fix for CVE-2018-17336

LinuxSecurity.com: **libbson 1.13.0** **Features:** * New functions to save and restore progress of a bson_iter_t: bson_iter_key_len, bson_iter_offset, and son_iter_init_from_data_at_offset Additional functions bson_iter_overwrite_date_time, bson_iter_overwrite_oid, and bson_iter_overwrite_timestamp. All fixed-length BSON values can now be

Hacker vows to delete Mark Zuckerberg’s Facebook account; reports it for bounty instead

security update

LinuxSecurity.com: It was discovered that the emergency logging system in 389-ds-base (the 389 Directory Server) is affected by a race condition caused by the invalidation of the concurrently used log file file descriptor without proper locking. This issue might be triggered by remote attackers to

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2731

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2731

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2766

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2757

Fancy Bear’s VPNfilter malware is back with 7 new modules
Firefox Monitor will Notify you When Your Account is Hacked- Mozilla
11 million personal unprotected MongoDB records leaked online
Exploring the Way Technology Has Changed Entertainment
Mobile password managers vulnerable to phishing apps
Linux firewalls: What you need to know about iptables and firewalld
YouTuber reveals iPhone XS passcode bypass bug exposing contacts/photos

LinuxSecurity.com: CVE-2017-7653 As invalid UTF-8 strings are not correctly checked, an attacker could

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

Hacky hack on whack ‘Hacky Hack Hack’ Mac chaps hack attack rap cut some slack

LinuxSecurity.com: Multiple security issues were discovered in Python: ElementTree failed to initialise Expat’s hash salt, two denial of service issues were found in difflib and poplib and a buffer overflow in PyString_DecodeEscape.

Facebook Data Breach Impacts Almost 50 Million Accounts
Facebook hacked: Hackers steal access tokens of 50 million accounts
Another Linux Kernel Bug Surfaces, Allowing Root Access

LinuxSecurity.com: This release fixes a heap-based buffer over-read when parsing a mallformed BSON document (CVE-2018-16790).

LinuxSecurity.com: Changes since 10.1.8.16: === v 10.1.9.6 handle legacy external message recipients * [XSS] Updated known HTML5 events * Better IPV6 support * UI support for protocol-only entries v 10.1.9.5

LinuxSecurity.com: Security fix for CVE-2018-10897

LinuxSecurity.com: This release fixes a heap-based buffer over-read when parsing a mallformed BSON document (CVE-2018-16790).

Facebook: Up to 90 million addicts’ accounts slurped by hackers, no thanks to crappy code
iPhone XS Passcode Bypass Hack Exposes Contacts, Photos
Demonoid goes offline with owner missing in action for last two months
Zuckerberg’s Facebook page? I’ll livestream its deletion, says hacker
Health insurer Bupa fined £175k after staffer tried to sell customer data on dark web souk
Android App Verification Issues Pave Way For Phishing Attacks
Australian teen who hacked into Apple and stole 90 GB of files avoids jail
VirusTotal slips on biz suit, says Google’s daddy will help the search for nasties

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Who’s behind DDoS attacks at UK universities?

The timing of the attacks suggests that many attempts to take the networks offline may not necessarily be perpetrated by organized cybercriminal gangs The post Who’s behind DDoS attacks at UK universities? appeared first on WeLiveSecurity

Majority of Orgs Failing to Make Machine Learning Fair, Safe & Balanced
Critical Linux Kernel Flaw Gives Root Access to Attackers
BLK-MQ To Support Runtime Power Management With Linux 4.20~5.0
Come to the National Information Security Conference (NISC), 10-12 October 2018

Reading Time: ~2 min.Firefox Vulnerability Leads to Crash A new denial-of-service (DoS) attack has been created with the ability to cause desktop versions of the browser Firefox to freeze or crash. Upon visiting sites where the malicious script is present, the user’s browser forces download requests for a massive junk file that can cause the […]

Oslo clever clogs craft code to scan di mavens and snare dodgy staff

LinuxSecurity.com: Several security issues were fixed in Mutt.

Your specialist subject? The bleedin’ obvious… Feds warn of RDP woe
Resident evil: Inside a UEFI rootkit used to spy on govts, made by you-know-who (hi, Russia)
DEF CON hackers’ dossier on US voting machine security is just as grim as feared

LinuxSecurity.com: CVE-2018-14404 Fix of a NULL pointer dereference which might result in a crash and thus in a denial of service.

LinuxSecurity.com: Multiple security issues were discovered in Python: ElementTree failed to initialise Expat’s hash salt, two denial of service issues were found in difflib and poplib and the shutil module was affected by a command injection vulnerability.

Perimeter Defenses are Dead, So Now What?

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from