Menu

Category Archives: Security

Articles about security

Department of Labour denies server compromise in recent cyberattack
This malware disguises itself as bank security to raid your account
ICO Breach Reports Jump 75% as Human Error Dominates
If an extension goes rogue, everything you do in your browser is compromised
Tiny Island Atoll’s Domain Used in Widespread Ad Fraud
Brit teen pleads guilty to Minecraft-linked bomb and airline hoaxes
Cybercrooks home in on infosec’s weakest link – you poor gullible people
Premera Blue Cross victims accuse insurer of deliberately destroying hacking evidence
Uncle Sam wants tech toolkit to snoop social media stock scammers

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: Quang Nguyen discovered an integer overflow in the Little CMS 2 colour management library, which could in denial of service and potentially the execution of arbitrary code if a malformed IT8 calibration file is processed.

Mikrotik routers pwned en masse, send network data to mysterious box
Multiple Remote Code-Execution Flaws Patched in Opsview Monitor
Google and MasterCard will track your retail spending under a secret deal
Thousands of MikroTik Routers Hijacked for Eavesdropping

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

ThreatList: 60% of BEC Attacks Fly Under the Radar
CamuBot Malware Camouflaged as Bank Security App to Steal Credentials
India’s ISPs show they have good MANRS, sign up to Internet Society’s routing security scheme
Cock-ups, rather than conspiracies, top self-reported data breaches

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Of ML and malware: What’s in store?

All things labeled Artificial Intelligence (AI) or Machine Learning (ML) are making waves, but talk of them in cybersecurity contexts often muddies the waters. A new ESET white paper sets out to bring some clarity to a subject where confusion often reigns supreme The post Of ML and malware: What’s in store? appeared first on […]

Thousands of misconfigured 3D printers on interwebz run risk of sabotage
Five steps that raise your security defences to the next level
‘CamuBot’ Banking Malware Ups the Trojan Game with Biometric Bypass
Excuse me, but your website’s source code appears to be showing

LinuxSecurity.com: An update for collectd is now available for Red Hat Gluster Storage 3.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Updated samba packages that fix several security issues and provide several bug fixes and an enhancement are now available for Red Hat Gluster Storage 3.4 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Updated samba packages that fix several security issues and provide several bug fixes and an enhancement are now available for Red Hat Gluster Storage 3.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Updated glusterfs packages that fix multiple security issues and bugs, and add various enhancements are now available for Red Hat Gluster Storage 3.4 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Updated glusterfs packages that fix multiple security issues, several bugs, and adds various enhancements are now available for Red Hat Gluster Storage 3.4 on Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

Cryptominers killing cryptominers to squeeze more out of your CPU
Parental control spyware app Family Orbit hacked; 281 GB of data exposed

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Hackers selling data of 130 million Chinese hotel clients on Dark Web for 8 BTC
Majority of the world’s top million websites use HTTPS

The adoption of the protocol’s secure variant has continued its growth spurt in recent months, crossing the 50-percent milestone for the first time ever The post Majority of the world’s top million websites use HTTPS appeared first on WeLiveSecurity

Google cracks down on dodgy tech support ads
APT10 Under Close Scrutiny as Potentially Linked to Chinese Ministry of State Security
Twitter testing new feature that reveals when you’re online
Machine Identity Failings Expose Firms
Orgs Still Feel Vulnerable Despite Cyber Standards
Read OneSpan’s 8-page report on the top six e-Signature use cases in banking

LinuxSecurity.com: It was discovered that there was a string injection vulnerability in the “dojo” Javascript library. For Debian 8 “Jessie”, this issue has been fixed in dojo version

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Updated openssl packages fix security vulnerabilities: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a

LinuxSecurity.com: Updated java-1.8.0-openjdk packages fixes atleast the following security vulnerability: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (CVE-2018-2952)

LinuxSecurity.com: The updated packages fix security vulnerabilities: gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a

LinuxSecurity.com: Two security issues have been discovered in the Tomcat servlet and JSP engine. CVE-2018-1336

Hearing Date Set in Georgia Election Security Case
How One Company’s Cybersecurity Problem Becomes Another’s Fraud Problem

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

security update

security update

Cryptomining scripts will be blocked in upcoming versions of Firefox browser
Hacker who leaked naked photos of Jennifer Lawrence jailed for 8 months
Cell-Site surveillance devices (Stingray) could disrupt 911 emergency calls
RIG Exploit Toolkit Distributing CeidPageLock Malware to Hijack Browsers

LinuxSecurity.com: Two vulnerabilities have been discovered in php5, a server-side, HTML-embedded scripting language. One (CVE-2018-14851) results in a potential denial of service (out-of-bounds read and application crash)

Lessons From the Black Hat USA NOC
Congress wants CVE stability, China wants your LinkedIn details, and Adobe wants you to patch Creative Cloud

LinuxSecurity.com: A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or,

Boffins trying to build a open source secure enclave on RISC-V

LinuxSecurity.com: This update provides mercurial version 4.6.2 and fixes the following security issues: Fix the mpatch_apply function in mpatch.c that incorrectly proceeds in cases where the fragment start is past the end of the original data

LinuxSecurity.com: The updated packages fix a security vulnerability: Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial

LinuxSecurity.com: The updated packages fix security vulnerabilities: An out-of-bounds read flaw exists in parse_file_info in archive_read_support_format_iso9660.c in libarchive 3.3.2 when extracting a specially crafted iso9660 iso file, related to

LinuxSecurity.com: This update provides libraw 0.18.13 fixing atleast the following security issues: LibRaw versions prior to 0.18.12 are vulnerable to an integer overflow in the internal/dcraw_common.cpp:parse_qt() function. An attacker could

LinuxSecurity.com: Updated mariadb packages fix security vulnerabilities: Vulnerability in the MariaDB Server component of MariaDB (subcomponent: MyISAM). Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MariaDB Server.

LinuxSecurity.com: Updated quazip packages fix security vulnerability: A vulnerability has been found in the way developers have implemented the archive extraction of files. An arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other

LinuxSecurity.com: This update provides the virtualbox 5.1.18 maintenance release that fixes atleast the following security issues: Fixed an easily exploitable vulnerability that allowed unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox

LinuxSecurity.com: OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c (CVE-2018-15473).

LinuxSecurity.com: Updated libxcursor packages fix security vulnerability _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow. (CVE-2015-9262)

LinuxSecurity.com: Updated squirrelmail packages fix XSS-security vulnerability: It was discovered that some special tags have not been filtered accordingly which can be used for an XSS-attack.

Apple Watch saves one more life by notifying user about his unusual heart rate
DraftKings rides to court, asks to unmask 10 DDoS suspects
VirusTotal Intelligence, a search engine for malware | Salted Hash Ep 45

Reading Time: ~2 min.Texas Voters’ Data Leaked A security researcher just discovered a publicly-available file containing sensitive voting informationfor nearly 99% of all registered voters in the state of Texas. The file was compiled by a data firm that was trying to gauge political opinion for the 2016 elections, as well as more localized campaigns. […]

LinuxSecurity.com: It was discovered that there were a number of Cross Site Scripting (XSS) vulnerabilities in the squirrelmail webmail client. For Debian 8 “Jessie”, these issues has been fixed in squirrelmail

John McAfee backed Bitfi wallet pwned again
MagentoCore Card Skimmer Found on Mass Numbers of E-Commerce Sites
Threatpost News Wrap Podcast For Aug. 31
C’mon, if you say your device is ‘unhackable’, you’re just asking for it: Bitfi retracts edgy claim
Bucking the Norm, Mozilla to Block Tracking Cookies in Firefox
DDoS attack from Anonymous Catalonia cripples Bank of Spain website
Air Canada admits app data breach included customers’ passport details
Spies still butthurt they can’t get at encrypted comms data
Fourth ‘Fappening’ celeb nude snap thief treated to 8 months in the clink

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

Passport Numbers Exposed in Air Canada Data Breach
‘Celebgate’ Hacker Heading to Prison
What is WannaCry ransomware, how does it infect, and who was responsible?
ThreatList: Security Pros Confident They Could Compromise Their Own Orgs
How to retrofit the cloud for security: 2 essential steps