Menu

Category Archives: Security

Articles about security

ThreatList: Hackers Turn to Python as Attack Coding Language of Choice
Sunny Cali goes ballistic, this ransomware is atrocious. Even our IT bill will be something quite ferocious

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty), Red Hat OpenStack Platform 9.0 (Mitaka), Red Hat OpenStack Platform 10.0 (Newton), Red Hat OpenStack Platform 12.0 (Pike), and Red Hat OpenStack Platform 13.0 (Queens).

Local-Privilege Escalation Flaw in Linux Kernel Allows Root Access
Weakness in Apple MDM Tool Allows Access to Sensitive Corporate Info
Looking after the corporate Apple mobile fleet? Beware: MDM onboarding is ‘insecure’
Trump’s axing of cyber czar role has left gaping holes in US defence
Cisco coughs up baker’s dozen of vulns and other security nasties
Linux Readying Spectre V2 Userspace-Userspace Protection
Mirai Authors Escape Jail Time – But Here Are 7 Other Criminal Hackers Who Didn’t
Malware steals passwords from 6.4 million SHEIN customers
Uber to dole out $148m settlement among US states over breach it paid $100k to bury
LoJax: First UEFI rootkit found in the wild, courtesy of the Sednit group

ESET researchers have shown that the Sednit operators used different components of the LoJax malware to target a few government organizations in the Balkans as well as in Central and Eastern Europe The post LoJax: First UEFI rootkit found in the wild, courtesy of the Sednit group appeared first on WeLiveSecurity

Smashing Security #097: Dash cam surveillance, robocall plague, and Zoho woe
Fancy Bear still Putin out new modules for VPNFilter malware
‘Mutagen Astronomy’ Linux kernel vulnerability sighted

LinuxSecurity.com: Security fix for CVE-2018-16435

LinuxSecurity.com: HylaFAX+ 5.6.1 vulnerabilities (18 Sep 2018)

Boffins bypass password protection with pilfering by phony programs
2018 Has Been Open Season on Open Source Supply Chains
Pain spotting: Russia’s Aeroflot Docker server lands internal source code, config files on public internet

LinuxSecurity.com: The 4.18.9 stable update contains a number of important fixes across the tree. —- The 4.18.8 update contains a number of important fixes across the tree

LinuxSecurity.com: Security fix for CVE-2017-5950.

LinuxSecurity.com: Fixed 2.1.0 update, includes security fixes and added performance fix

LinuxSecurity.com: Fix for CVE-2018-14630

VPNFilter’s Arsenal Expands With Newly Discovered Modules
Google Vows Privacy Changes in Chrome Browser After User Backlash
Banking trojan found in call recorder app on Play Store – stole over €10,000
Almost Every Major Free VPN Service is a Glorified Data Farm
Twitter patches bug that may have spilled users’ private messages

The flaw affected one of the platform’s APIs between May 2017 and September 10 of this year, when it was patched “within hours” The post Twitter patches bug that may have spilled users’ private messages appeared first on WeLiveSecurity

Security Technologies: FORTIFY_SOURCE
Can’t read my, can’t read my… broker face: Premium Credit back online a week after cyber attack
Defending your company from cyberattack

ESET CTO Juraj Malcho outlines some of the ways in which organizations can reduce their cybersecurity risk The post Defending your company from cyberattack appeared first on WeLiveSecurity

The Sony hacker indictment: 5 lessons for IT security
Vulnerable open source component adoption skyrockets in the enterprise
French cybersecurity agency open sources security hardened CLIP OS
Google actually listens to users, hands back cookies and rethinks Chrome auto sign-in
Canadian security boss ain’t afraid of no Huawei, sees no reason for ban
Malware steals passwords from SHEIN, 6.4 million customers impacted

LinuxSecurity.com: Red Hat OpenShift Container Platform release 3.6.173.0.130 is now available with updates to packages that fix one security issue and several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Multiple vulnerabilities were found in the CPython interpreter which can cause denial of service, information gain, and arbitrary code execution.

NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits

LinuxSecurity.com: Multiple vulnerabilities were found in the CPython interpreter which can cause denial of service, information gain, and arbitrary code execution.

While the UN laughed at Trump, hackers chortled at the UN’s lousy web application security

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

Have I been pwned, Firefox? OK, let’s ask its Have I Been Pwned tool

security update

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Once Popular Online Ad Format Opens Top Tier Sites to XSS Attacks
Malware on SHEIN Servers Compromises Data of 6.4M Customers
Cookie clutter: Chrome saves Google cookies from cookie jar purges

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for mod_perl is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Reading Time: ~3 min.While ransomware, last year’s dominant threat, has taken a backseat to cryptomining attacks in 2018, it has by no means disappeared. Instead, ransomware has become a more targeted business model for cybercriminals, with unsecured remote desktop protocol (RDP) connections becoming the favorite port of entry for ransomware campaigns. RDP connections first gained […]

How to thwart rogue employees: Tune in this month to our live insider threat webcast
MI5: Gosh, awkward, but we looked down the sofa again and turns out we *do* have intel on NGO
Open-source software supply chain vulns have doubled in 12 months
Mac Mojave Zero-Day Allows Malicious Apps to Access Sensitive Info
Aggregate this: NewsNow has spilt a bunch of ‘encrypted’ passwords

LinuxSecurity.com: The package zsh before version 5.6-1 is vulnerable to insufficient validation.

How to improve hiring practices in cybersecurity

Should schools and businesses do more to combat the shortfall of cybersecurity professionals by changing the hiring process for those interested in having a career in the industry? The post How to improve hiring practices in cybersecurity appeared first on WeLiveSecurity

Freelance workers targeted in new malware campaign
Linux or Windows: 25 Things You Must Know While Choosing The Best Platform
Braking bad: Mitsubishi recalls 68k SUVs over buggy software
WWII Bombe operator Ruth Bourne: I’d never heard of Enigma until long after the war
14 years prison for man who helped hackers evade detection by anti-virus software
NewsNow suffers security breach – passwords should be considered compromised
Bug? Feature? Power users baffled as BitLocker update switch-off continues

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Microsoft ‘kills’ passwords, throws up threat manager, APIs Graph Security
Cybercriminals Target Kodi Media Player for Malware Distribution

security update

security update

security update

security update

LinuxSecurity.com: mod_perl: arbitrary Perl code execution in the context of the user account via a user-owned .htaccess (CVE-2011-2767) SL6 x86_64 mod_perl-2.0.4-12.el6_10.x86_64.rpm mod_perl-debuginfo-2.0.4-12.el6_10.x86_64.rpm mod_perl-debuginfo-2.0.4-12.el6_10.i686.rpm mod_perl-devel-2.0.4-12.el6_10.i686.rpm mod_perl-devel-2.0.4-12.el6_10.x86_64.rpm i386 mod_perl-2.0.4-12.el6_10. [More…]

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Several vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems:

Adwind RAT Scurries By AV Software With New DDE Variant
Google’s Forced Sign-in to Chrome Raises Privacy Red Flags
Malware hits Freelancers at Fiverr and Freelancer.com
Baddies just need one email account with clout to unleash phishing hell
Assessing the Human Element in Cyber Risk Analysis
Thousands of stolen frequent flyer miles of top airlines sold on Dark Web
Tricky DoS Attack Crashes Mozilla Firefox

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.