Menu

Category Archives: Security

Articles about security

ThreatList: Security Pros Confident They Could Compromise Their Own Orgs
How to retrofit the cloud for security: 2 essential steps
Cobalt cybercrooks phry up phishing campaign to phling at phinance orgs
Security bods: Android system broadcasts enable user tracking

LinuxSecurity.com: CVE-2018-5740 The “deny-answer-aliases” feature in BIND has a flaw which can cause named to exit with an assertion failure.

LinuxSecurity.com: CVE-2018-10871 By default nsslapd-unhashed-pw-switch was set to ‘on’. So a copy of

New Threat Actor ‘Rocke’: A Rising Monero Cryptomining Menace
Cryptojacking isn’t a path to riches – payout is a lousy $5.80 a day

Type: Vulnerability. The Microsoft Windows LSASS service is prone to a remotely exploitable buffer overrun vulnerability; may allow arbitrary code execution.

LinuxSecurity.com: Several security issues were fixed in libx11.

LinuxSecurity.com: Several security issues were fixed in libx11.

LinuxSecurity.com: An update for OpenDaylight is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for ansible is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: poppler could be made to crash if it received specially crafted PDF file.

Android OS API-Breaking Flaw Offers Useful WiFi Data to Bad Actors
Cobalt Group Targets Banks in Eastern Europe with Double-Threat Tactic
Hackers latch onto new Apache Struts megavuln to mine cryptocurrency
Won’t patch systems? Never run malware scans? Welcome to the US State Department!
Critical Flaws in Syringe Pump, Device Gateways Threaten Patient Safety
Travel Breaches Hit Air Canada and Asia-Pac Hotelier
Instagram expands 2FA and account verification

The move is part of a three-pronged plan that is intended to bolster user trust and safety on the photo-sharing platform The post Instagram expands 2FA and account verification appeared first on WeLiveSecurity

A DDoS Knocked Spain’s Central Bank Offline
A False Sense of Security
Welcome! Mimecast finds interesting door policies on email filters

LinuxSecurity.com: Several issues were discovered in libx11, the client interface to the X Windows System. The functions XGetFontPath, XListExtensions, and XListFonts are vulnerable to an off-by-one override on malicious server responses. A malicious server could also send a reply in which

Chinese hotel chain warns of massive customer data theft
Smashing Security #093: Abandoned domains and dating app dangers
BusyGasper Malware Packs a Simple but Potent Punch
Company that Sells Spyware to Domestic Abusers Hacked
Yahoo Persists in Scanning Emails for In-Depth Ad-Targeting
Error Canada: Airline tells customers to reset mobile app after attack

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2570

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2557

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2571

High-Severity Flaws Patched in Schneider Electric Products
The 4 Critical Building Blocks for Digital Threat Hunting
Podcast: Plugging Leaky Data in the Cloud
Hackers faked Cosmos backend to hoodwink bank out of $13.5m
Hackers Publish PoC of Zero-day Vulnerability in Windows on Twitter
Lazarus Group’s AppleJeus MacOS malware targeting cryptocurrency exchanges
ABBYY woes: Doc-reading software firm leaves thousands of scans blowing in wind
Researchers Shine Light on Smart-Bulb Data Theft
Semi-annual balance of mobile security

For Android, malware detections were down 27.48% compared to the first half of 2017; for iOS, they decreased 15% compared to the same period last year The post Semi-annual balance of mobile security appeared first on WeLiveSecurity

ICO Breach Complaints Jump 160% in a Year
The Difference Between Sandboxing, Honeypots & Security Deception
Fiserv Flaw Exposed Customer Data at Hundreds of Banks
We’re all sick of Fortnite, but the flaw found in its downloader is the latest way to attack Android
If you have to simulate a phishing attack on your org, at least try to get something useful from it

LinuxSecurity.com: Several issues were discovered in the Tomcat servlet and JSP engine. They could lead to unauthorized access to protected resources, denial-of-service, or information leak.

Intel Management Engine JTAG flaw proof-of-concept published

security update

Instagram finally supports third-party 2FA apps for greater account security

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to mitigate security issues.

Voting machine maker claims vote machine hack-fests a ‘green light’ for foreign hackers
Crashing Mobile Apps Capture Screens, Leak Private Data
Brazilian Crypto exchange hacked; private data of over 264,000 users exposed

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Facebook Flaw Allowed Remote Commands

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Multiple researchers have discovered a vulnerability in the way the Intel processor designs have implemented speculative execution of instructions in combination with handling of page-faults. This flaw could allow an attacker controlling an unprivileged process to read

LinuxSecurity.com: bind: processing of certain records when “deny-answer-aliases” is in use may trigger an assert leading to a denial of service (CVE-2018-5740) SL6 x86_64 bind-debuginfo-9.8.2-0.68.rc1.el6_10.1.i686.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.1.x86_64.rpm bind-libs-9.8.2-0.68.rc1.el6_10.1.i686.rpm bind-libs-9.8.2-0.68.rc1.el6_10.1.x86_64.rpm bind-utils-9.8.2-0.68.rc1.el6_10.1 [More…]

LinuxSecurity.com: bind: processing of certain records when “deny-answer-aliases” is in use may trigger an assert leading to a denial of service (CVE-2018-5740) SL7 x86_64 bind-debuginfo-9.9.4-61.el7_5.1.i686.rpm bind-debuginfo-9.9.4-61.el7_5.1.x86_64.rpm bind-libs-9.9.4-61.el7_5.1.i686.rpm bind-libs-9.9.4-61.el7_5.1.x86_64.rpm bind-libs-lite-9.9.4-61.el7_5.1.i686.rpm bind-libs-lite-9. [More…]

LinuxSecurity.com: Several security issues were fixed in GD.

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low. Type: Trojan.

OCR software firm ABBYY leaks 203,000 customer documents in MongoDB server snafu
6 Tips to Protect Your Online Business from Cyber Attacks
Microsoft Windows Zero-Day Found in Task Scheduler
No, eight characters, some capital letters and numbers is not a good password policy
Footie fans calling for a red card over West Ham United CC email blunder
PoC targeting critical Apache Struts bug found online

The discovery was made barely two days after the release of a patch that fixes the critical flaw in the web application framework The post PoC targeting critical Apache Struts bug found online appeared first on WeLiveSecurity

LinuxSecurity.com: This is the Six-Month notification for the retirement of Red Hat Enterprise Linux 6.4 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.4.

ThreatList: Ransomware Attacks Down, Fileless Malware Up in 2018
Give yourselves a pat on the back, top million websites, half of you now use HTTPS
Adobe Pushes Out Unscheduled Creative Cloud Application Fix
Lukáš Štefanko: I hope other app developers don’t follow Epic‘s example

After Epic Games shunned Google Play, debates about threats faced by Android users have taken on a whole new tenor. Joining us to add his voice to the mix is ESET Malware Researcher Lukáš Štefanko The post Lukáš Štefanko: I hope other app developers don’t follow Epic‘s example appeared first on WeLiveSecurity

Black hats are baddie hackers, white hats are goodies, grey hats will sell IP to kids in hoodies
EU may fine political groups misusing personal data to skew elections
How hackers managed to steal $13.5 million in Cosmos bank heist
None too chuffed with your A levels? Hey, why not bludgeon the exam boards with GDPR?
Event management kit can take a hammering these days: Use it well and it’ll save your ass
Boffins bork motion control gear with the power of applied sound
Windows 0-day pops up out of nowhere Twitter

LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 10 fixes is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Lawyers sued for impersonating rival firm online to steal clients
Side-Channel Attack Allows Remote Listener to ‘Hear’ On-Screen Images

LinuxSecurity.com: Several vulnerabilities were discovered in Ruby 2.1. CVE-2016-2337

AT Command Hitch Leaves Android Phones Open to Attack

LinuxSecurity.com: The Bootstrap framework was found to have cross-site scripting vulnerabilities in the “collapse” plugin. For Debian 8 “Jessie”, this problem has been fixed in version

Ah, um, let’s see. Yup… Fortnite CEO is still mad at Google for revealing security hole early

LinuxSecurity.com: The system could be made to expose sensitive information.