Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: CVE-2016-10728 If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it can lead to missed TCP/UDP detection

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Patch for EE’s 4G Wi-Fi mini modem nails local privilege escalation flaw
Mirai Masterminds Helping FBI Snuff Out Cybercrime
Heads up: Get ready to tune in live and watch us probe insider threats menacing today’s IT
Critical Out-of-Band Patch Issued for Adobe Acrobat Reader
Security Embargos at Red Hat
National Museum of Computing to hold live Enigma code-breaking demo with a Bombe
Hackers disrupt UK’s Bristol Airport flight info screens after ransomware attack
A Hybrid Solution to Taming SOC Alert Overload
XBash Malware Packs Double Punch: Destroys Data and Mines for Crypto Coins
Fake finance apps on Google Play target users from around the world

Cybercrooks use bogus apps to phish six online banks and cryptocurrency exchange The post Fake finance apps on Google Play target users from around the world appeared first on WeLiveSecurity

Why waste away in a cubicle when you could be a goddamn infosec neuromancer on £50k*?
‘Peekaboo’ zero-day lets hackers view and alter surveillance camera footage
The makers of the Mirai IoT-hijacking botnet are sentenced
Employee Personal Info Exposed in State Department Hack
FBI Warns Parents of Edtech Security Risk

LinuxSecurity.com: Several security issues were fixed in PHP.

LinuxSecurity.com: Several security issues were fixed in Ghostscript.

How to secure your PostgreSQL database
Who ate all the PII? Not the blockchain, thankfully

LinuxSecurity.com: Several security issues were fixed in GLib.

LinuxSecurity.com: Several security issues were fixed in GLib.

Your business should be more afraid of phishing than malware

LinuxSecurity.com: Two vulnerabilities have been discovered in the chromium web browser. Kevin Cheung discovered an error in the WebAssembly implementation and evil1m0 discovered a URL spoofing issue.

security update

US Dept of State says attack on email system exposed employees’ personal data
Judge: Georgia’s e-vote machines are awful – but go ahead and use them
US State Department confirms: Unclassified staff email boxes hacked
‘I am admin’ bug turns WD’s My Cloud boxes into Everyone’s Cloud
ThreatList: Malware Samples Targeting IoT More Than Double in 2018
Dark Web: US court seizes assets and properties of deceased AlphaBay operator

LinuxSecurity.com: An update for openstack-neutron is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Risk Level: Very Low.

State Government Online Payment Service Exposes 14M Customers
Linux & Windows hit with disk wiper, ransomware & cryptomining Xbash malware
Biz! Formerly! Known! As! Yahoo! Settles! Data! Breach! Cases! To! The! Tune! Of! $47m!
Dangerous Pegasus Spyware Has Spread to 45 Countries
Medical records & patient-doctor recordings of thousands of people exposed
Apache Struts & SonicWall’s GMS exploits key targets of Mirai & Gafgyt IoT malware
Insiders Continue to be Data Theft’s Best Friend
Linus Torvalds takes a break from Linux
Oh Smeg! Hacked white goods maker resurfaces after system shutdown

LinuxSecurity.com: An update is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

The Occasional Orator Part 1

Speaking at conferences can be daunting for presenters but often it is about striking the right balance between content and delivery The post The Occasional Orator Part 1 appeared first on WeLiveSecurity

This new phishing attack uses an old trick to steal passwords and credit card details
Bristol Airport Hit by Ransomware Blackout
C’mon, biz: Give white hats a chance to tell you how screwed you are

LinuxSecurity.com: Several security issues were fixed in PHP.

LinuxSecurity.com: USN-3722-1 introduced a regression in ClamAV.

LinuxSecurity.com: USN-3722-1 introduced a regression in ClamAV.

TV Licensing admits: We directed 25,000 people to send their bank details in the clear

LinuxSecurity.com: Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes

LinuxSecurity.com: Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes

LinuxSecurity.com: Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes

LinuxSecurity.com: Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes

LinuxSecurity.com: Security fix for CVE-2018-1000801

Just 13 – no, er, make that 3,200 punters hit in Oz’s Perth Mint hack

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

security update

security update

security update

LinuxSecurity.com: Security update for `CVE-2018-16543` and `CVE-2018-16510`, which were recently discovered.

LinuxSecurity.com: Security fix for CVE-2017-15422

Facebook Now Offers Bounties For Access Token Exposure
Check out this link! It’s not like it’ll crash your iPhone or anything (Hint: Of course it will)
Old WordPress Plugin Being Exploited in RCE Attacks
CSS-Based Attack Causes iOS, macOS Devices to Crash
Safari & Firefox browser to block user data tracking with new security add-ons
Another wave of sextortion emails
Bristol Airport says it did not pay any ransom to recover from cyber attack

LinuxSecurity.com: USN-3761-1 caused several regressions in Firefox.

8 Industry Best Practices for a Successful Mobile First Strategy (eBook by OneSpan)
Brit airport pulls flight info system offline after attack by ‘online crims’
Bristol airport takes flight screens offline after apparent ransomware attack

The screens in “key locations” are back up and running again, while the airport paid no ransom to return its systems to working order The post Bristol airport takes flight screens offline after apparent ransomware attack appeared first on WeLiveSecurity

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves four vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has 26 fixes is now available.

Cybersecurity Is Only 1 Part of Election Security
The Linux Kernel Has Grown By 225k Lines of Code So Far This Year From 3.3k Developers
Who’s hacking into UK unis? Spies, research-nickers… or rival gamers living in res hall?
One in three UK orgs hit by cryptojacking in previous month, survey finds

Conversely, only a little over one-third of IT executives believe that their systems have never been hijacked to surreptitiously mine digital currencies The post One in three UK orgs hit by cryptojacking in previous month, survey finds appeared first on WeLiveSecurity

LinuxSecurity.com: curl could be made to run arbitrary code if it received a specially crafted input.

Tick-tock, tick-tock. Oh, that’s just the sound of compromised logins waiting to ruin your day

LinuxSecurity.com: curl could be made to run arbitrary code if it received a speciallycrafted input.

How to crash and restart an iPhone with a CSS-based web attack
Equifax IT staff had to rerun hackers’ database queries to work out what was nicked – audit
Amazon staff said to be taking bribes to leak data

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes one vulnerability is now available.