Menu

Category Archives: Security

Articles about security

Turla: In and out of its unique Outlook backdoor

The latest ESET research offers a rare glimpse into the mechanics of a particularly stealthy and resilient backdoor that the Turla cyberespionage group can fully control via PDF files attached to emails The post Turla: In and out of its unique Outlook backdoor appeared first on WeLiveSecurity

Scot.gov wins pals with pledge not to keep hold of innocents’ mugshots and biometric data
Adobe Patches Critical Photoshop Flaws in Unscheduled Update
Get serious about consumer data protection
Ohio Man Sentenced to 15 Years for BEC Scam
Augusta Health Center Reveals Historic Breach
Elders of internet hash out standards to grant encrypted message security for world+dog
ETSI crypto-based access control standards land

LinuxSecurity.com: Dariusz Tytko, Michal Sajdak and Qualys Security discovered that OpenSSH, an implementation of the SSH protocol suite, was prone to a user enumeration vulnerability. This would allow a remote attacker to check whether a specific user account existed on the target server.

Ryuk Ransomware Emerges in Highly Targeted, Highly Lucrative Campaign
Super-mugs: Hackers claim to have snatched 20k customer records from Brit biz Superdrug
Security MadLibs: Your IoT electrical outlet can now pwn your smart TV
Dark Tequila: A Distilled Threat for Mexican Targets

LinuxSecurity.com: New libX11 packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Airmail 3 Exploit Instantly Steals Info from Apple Users
Use Debian? Want Intel’s latest CPU patch? Small print sparks big problem

Type: Vulnerability. Microsoft Internet Explorer is prone to an unspecified arbitrary code-execution vulnerability; fixes are available.

LinuxSecurity.com: An update for mutt is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: wpa_supplicant and hostapd could be made to expose sensitiveinformation if it received a crafted message.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Belkin IoT Smart Plug Flaw Allows Remote Code Execution in Smart Homes
Republican & Conservative leaders are the new targets of Russian hackers —Microsoft
Microsoft: We busted Russian Fancy Bear disinfo websites
IoT botnet of heaters & ovens can cause massive widespread power outages
Fake Android Fortnite version circulating on the web to spread malware
Video: Bishop Fox on Device Threats and Layered Security
Google Faces Legal Turmoil After Location Tracking Debacle
MadIoT: How an IoT botnet could launch a major attack on the power grid
Smart irrigation systems vulnerable to attacks, warn researchers

Internet-connected irrigation systems suffer from security gaps that could be exploited by attackers aiming, for example, to deplete a city’s water reserves, researchers warn The post Smart irrigation systems vulnerable to attacks, warn researchers appeared first on WeLiveSecurity

Corporate pre-crime: The ethics of using AI to identify future insider threats
UK hacking prosecutions plummet with only 47 charges recorded last year
TLS developers should ditch ‘pseudo constant time’ crypto processing
Connected car data handover headache: There’s no quick fix… and it’s NOT just Land Rovers
That’s the way the cookies crumble: Consent banners up 16% since GDPR

LinuxSecurity.com: Several security issues were fixed in OpenJDK 10.

LinuxSecurity.com: USN-3742-2 introduced regressions in the Linux Hardware Enablement(HWE) kernel for Ubuntu 12.04 ESM.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2439

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2462

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2526

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2526

LinuxSecurity.com: ClamAV, an anti-virus utility for Unix, has released the version 0.100.1. Installing this new version is required to make use of all current virus signatures and to avoid warnings.

Canadian Telcos Patch an APT-Ready Flaw in Disability Services
Side-Channel PoC Attack Lifts Private RSA Keys from Mobile Phones

security update

LinuxSecurity.com: An attacker could trick APT into installing altered packages.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Hackers can intercept and manipulate DNS queries, researchers warn
Darkhotel Exploits Microsoft Zero-Day VBScript Flaw
GandCrab’s Rotten EGGs Hatch Ransomware in South Korea
Cybercrime isn’t going away, but hacking prosecutions are falling
SuperProf gets schooled after assigning weak passwords to tutors
Security Technologies: Stack Smashing Protection (StackGuard)
Rotten EGGs spread ransomware in South Korea

LinuxSecurity.com: An update for openstack-keystone is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for openvswitch is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

So phar, so FUD: PHP flaw puts WordPress sites at risk of hacks
Discover the State of Authentication and the Evolving Threat Landscape in this White Paper by OneSpan. Get your copy!

LinuxSecurity.com: Multiple researchers have discovered a vulnerability in the way the Intel processor designs have implemented speculative execution of instructions in combination with handling of page-faults. This flaw could allow an attacker controlling an unprivileged process to read

The Rise of Bespoke Ransomware
Australian Teen Hacked Apple Network
A heated summer for cybersecurity in Canada

An overview of some of the cyberattacks that Canadian organizations faced in the summer months of 2018 The post A heated summer for cybersecurity in Canada appeared first on WeLiveSecurity

LinuxSecurity.com: An update for rh-postgresql95-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

How’s that encryption coming, buddy? DNS requests routinely spied on, boffins claim
Et tu, Brute? Then fail, Caesars: When it’s hotel staff, not the hackers, invading folks’ privacy

security update

LinuxSecurity.com: CVE-2018-14767 Fix for missing input validation, which could result in denial of service and potentially the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were discovered in Jetty, a Java servlet engine and webserver which could result in HTTP request smuggling. For the stable distribution (stretch), these problems have been fixed in

LinuxSecurity.com: New upstream release fixing YSA-2018-03 (#1613863)

LinuxSecurity.com: New upstream release fixing YSA-2018-03 (#1613863)

LinuxSecurity.com: New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Instagram acknowledges & addresses hacking spree against user accounts
The state of cybersecurity at small organizations
The 5 Challenges of Detecting Fileless Malware Attacks
AI in cybersecurity: what works and what doesn’t
Mastering email security with DMARC, SPF and DKIM
Facebook Messenger backdoor demand, bail in Bitcoin, and lots more
SentinelOne makes YouTube delete Bsides vid ‘cuz it didn’t like the way bugs were reported
‘Oh sh..’ – the moment an infosec bod realized he was tracking a cop car’s movements by its leaky cellular gateway

security update

security update

security update

16-year old compromised Apple networks to steal GBs of sensitive data
Philips Vulnerability Exposes Sensitive Cardiac Patient Information
Unique Malspam Campaign Uses MS Publisher to Drop a RAT on Banks

LinuxSecurity.com: Several vulnerabilities were discovered in Mutt, a text-based mailreader supporting MIME, GPG, PGP and threading, potentially leading to code execution, denial of service or information disclosure when connecting to a malicious mail/NNTP server.

Severe PHP Exploit Threatens WordPress Sites with Remote Code Execution

Risk Level: Very Low. Type: Trojan.

AT&T Faces $224M Legal Challenge Over SIM-Jacking Rings
Web cache poisoning just got real: How to fling evil code at victims
ThreatList: Almost Half of the World’s Top Websites Deemed ‘Risky’
Shiver me timbers: Symantec spots activist investor Starboard side
SuperProf private tutor site massively fails password test, makes accounts super easy to hack