Menu

Category Archives: Security

Articles about security

Pinterest Browser Extension Injects Unwanted Code into 5K Websites
US Homeland Security warns of latest hacker craze – ERP pwnage
Hey you smart, well-paid devs. Stop clicking on those phishing links and bringing in malware muck on your shoes
Facebook Security Exec Calls for Tightened Data Privacy

LinuxSecurity.com: New version of dcraw is available 9.28.0 Security fix for CVE-2018-5801

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2251

Risk Level: Very Low. Type: Trojan, Worm.

Intel Smart Sound Tech Vulnerable to Three High-Severity Bugs
Podcast: The Industrial World is Facing a Security Crisis
Mind your company’s old Twitter accounts, rather than allowing them to be hijacked by hackers
Security Technologies: ExecShield
2FA? We’ve heard of it: White hats weirded out by lack of account security in enterprise
Hook, line, and sinker: How to avoid looking ‘phish-y’

Top tips to help you avoid being caught receiving or sending phishing-looking emails The post Hook, line, and sinker: How to avoid looking ‘phish-y’ appeared first on WeLiveSecurity

Reading Time: ~4 min.According to the Identity Theft Research Center, 2017 saw 1,579 data breaches—a record high, and an almost 45 percent increase from the previous year. Like many IT service providers, you’re probably getting desensitized to statistics like this. But you still have to face facts: organizations will experience a security incident sooner or […]

Endpoint Concerns Blight IIoT Security
Two-Thirds of Organizations Hit in Supply-Chain Attacks
London Calling with New Strategies to Stop Ransomware
Criminal mastermind injects malicious script into Ethereum tracker. Their message? ‘1337’
Here’s why Twitter will lock your account if you change your display name to Elon Musk
The risks associated with global Internationalized Domain Names | Salted Hash Ep 36
Safeguard your code: 17 tips to develop more-secure code
Intel Xeon workhorses boot evil maids out of the hotel: USB-based spying thwarted by fix
Want a $200k TIP? ZDI sticks bounties on bugs in big-name server code

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: A vulnerability has been discovered in Sympa, a modern mailing list manager, that allows write access to files on the server filesystem. This flaw allows to create or modify any file writable by the Sympa user, located on the server filesystem, using the function of Sympa

Update your devices: New Bluetooth flaw lets attackers monitor traffic

LinuxSecurity.com: The libarchive-zip-perl package is vulnerable to a directory traversal attack in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use

LinuxSecurity.com: CVE-2018-12584 A flaw in function ConnectionBase::preparseNewBytes of resip/stack/ConnectionBase.cxx has been detected, that

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Kronos Banking Trojan Resurfaces After Years of Silence
Google Starts Labeling All HTTP Sites as ‘Not Secure’

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

security update

LinuxSecurity.com: Danny Grander reported that the unzip and untar tasks in ant, a Java based build tool like make, allow the extraction of files outside a target directory. An attacker can take advantage of this flaw by submitting a specially crafted Zip or Tar archive to an ant build to

Emotet Malware Evolves Beyond Banking to Threat Delivery Service
Apache, IBM Patch Critical Cloud Vulnerability

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Bluetooth Bug Allows Man-in-the-Middle Attacks on Phones, Laptops

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Worm.

Oracle Re-Patches Decade-Old Solaris Bug
Dust yourself off and try again: Ancient Solaris patch missed the mark
IBM fixes flaw that let hackers replace its serverless code with their own
Bluetooth bug could expose devices to snoopers

Patches have already been released or are expected to see the light of day soon The post Bluetooth bug could expose devices to snoopers appeared first on WeLiveSecurity

Insecure web still too prevalent: Boffins unveil HSTS wall of shame
Supplier Error Leaks Decade of Data from Carmakers
Campaign’s Election Data Exposed in Virginia
UK university domains spoofed in massive fraud campaign targeting suppliers
Privacy Questions Raised as Tech Giants Join Forces on Data Portability

LinuxSecurity.com: An update for rhev-hypervisor7 is now available for RHEV 3.X Hypervisor and Agents for Red Hat Enterprise Linux 6 and RHEV 3.X Hypervisor and Agents Extended Lifecycle Support for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

Mega medical tester pester: It smacked a big one, that malware scam, if indeed it was SamSam

LinuxSecurity.com: An update for rh-ror50-rubygem-sprockets is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ror42-rubygem-sprockets is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

No big deal… Kremlin hackers ‘jumped air-gapped networks’ to pwn US power utilities
Big bad Bluetooth blunder bug battered – check for security fixes
Robo-drop: Factory bot biz ‘leaks’ automakers’ secrets onto the web
If at first you, er, make things worse, you’re probably Microsoft: Bug patch needed patching

LinuxSecurity.com: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) (CVE-2018-2952) SL6 x86_64 java-1.8.0-openjdk-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8.0-openjdk-debug-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8 [More…]

LinuxSecurity.com: Update to 1.2.6 to fix a local authenticated privilege escalation bug (CVE-2018-10900). The issue has been discovered and responsibly disclosed by Denis Andzakovic: https://pulsesecurity.co.nz/advisories/NM-VPNC-Privesc

Spectre rises from the dead to bite Intel in the return stack buffer
IT biz embezzlement brouhaha leaves bloke with $456k migraine
Google Chrome users met with ‘Not secure’ warnings when visiting HTTP sites
Uber driver recorded passengers & live-streamed videos on Twitch
New Spectre-Level Flaw Targets Return Stack Buffer
Spectre Will Haunt Us For a Long Time

LinuxSecurity.com: A regression that caused boot failures was fixed in the Linux kernel.

LinuxSecurity.com: A regression that caused boot failures was fixed in the Linux kernel.

Leaky Backup Spills 157 GB of Automaker Secrets
Who watches Sony’s watcher? Boffins poke holes in surveillance kit
Facebook Suspends Analytics Firm Over Surveillance Concerns
ThreatList: Supply-Chain Defenses Need Improvement
Robotics supplier’s sloppy security leaks ten years’ worth of data from major car manufacturers
Major sites still largely lax on prompting users towards safer password choices, study finds

A study assessed whether or not the most popular English-language websites help users strengthen their security by providing them with guidance on creating safer passwords during account sign-up or password-change processes The post Major sites still largely lax on prompting users towards safer password choices, study finds appeared first on WeLiveSecurity

Google Chrome: HTTPS or bust. Insecure HTTP D-Day is tomorrow, folks
Has GDPR Impacted Insider Threats?
UK Gov Launches Consultation to Speed-Up Cybersecurity Strategy
Attention Airline Passengers, Your Data Is at Risk
Don’t ignore application security | Salted Hash Ep 35

LinuxSecurity.com: Multiple vulnerabilities have been found in Passenger, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: CVE-2018-7033 Fix for issue in accounting_storage/mysql plugin by always escaping strings within the slurmdbd.

Data breach: Millions of SingHealth users affected including Singapore’s PM

LinuxSecurity.com: Early versions of opencv have problems while reading data, which might result in either buffer overflows, out-of bounds errors or integer

Exposed: 157 GB of sensitive data from Tesla, GM, Toyota & others
US Intel Officials Share Their National Cybersecurity Concerns
Key takeaways from Singapore healthcare data breach

LinuxSecurity.com: The package networkmanager-vpnc before version 1.2.6-1 is vulnerable to privilege escalation.

LinuxSecurity.com: The package apache before version 2.4.34-1 is vulnerable to denial of service.

LinuxSecurity.com: The package znc before version 1.7.1-1 is vulnerable to multiple issues including privilege escalation and directory traversal.

DNS rebinding attack puts half a billion IoT devices at risk
The Fundamental Flaw in Security Awareness Programs
IoT hacker builds Huawei-based botnet, enslaves 18,000 devices in one day
LabCorp ransomed, 18k routers rooted, a new EXIF menace, and more

LinuxSecurity.com: Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program.

Microsoft: The Kremlin’s hackers are already sniffing, probing around America’s 2018 elections