Menu

Category Archives: Security

Articles about security

Kremlin hacking crew went on a ‘Roman Holiday’ – researchers
New sextortion scheme uses victims’ real password for blackmailing
DanaBot Trojan Targets Bank Customers In Phishing Scam
IoT search engine exposes passwords of over 30,000 vulnerable DVRs
Road navigation systems can be spoofed using $223 equipment
Who is the weakest link in software security?
A highly targeted malware campaign is spying on 13 iPhones in India
Free eBook: If your friend was put in charge of a cyber budget, what advice would you give them?
Irishman extradited to the US to face charges relating to Silk Road

Gary Davis accused of working as an administrator for the notorious dark web marketplace appears in a federal court in New York The post Irishman extradited to the US to face charges relating to Silk Road appeared first on WeLiveSecurity

Major International Airport System Access Sold for $10 on Dark Web
Western E-Tailers Set to Lose Nearly $19bn to Fraud
GandCrab Ransomware Continues to Evolve But Can’t Spread Via SMB Shares Yet
GitHub to Pythonistas: Let us save you from vulnerable code

LinuxSecurity.com: CVE-2015-1854 A flaw was found while doing authorization of modrdn operations. An unauthenticated attacker able to issue an ldapmodrdn call to

LinuxSecurity.com: It was discovered that there were two issues in znc, a modular IRC bouncer: * There was insufficient validation of lines coming from the network

Australia’s Airport Security Threatened by Hack
FBI: Email Account Compromise Losses Reach $12B
Russian intelligence officers indicted in DNC hacking

LinuxSecurity.com: Update to 4.9.7 security release. https://wordpress.org/news/2018/07/wordpress-4-9-7-security-and-maintenance- release/

LinuxSecurity.com: Security fix for CVE-2018-8009 —- Version update to 2.7.6. Fixes many open CVEs and bugs.

LinuxSecurity.com: Update to Sprockets 3.7.2. Fixes CVE-2018-3760: https://access.redhat.com/security/cve/cve-2018-3760

security update

LinuxSecurity.com: Several vulnerabilities were discovered in CUPS, the Common UNIX Printing System. These issues have been identified with the following CVE ids: CVE-2018-4180

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.

Timehop Reveals More Personal Data Was Breached
WordPress Sites Targeted in World Cup-Themed Spam Scam
Hope for Hutchins, Navy sinks contractor, there’s another Russian hacking scandal, and more

LinuxSecurity.com: Multiple vulnerabilities were found in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes 15 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Thought two-factor auth completely locks down Office 365? Not quite
US drug cops snared crooks with pre-cracked BlackBerry mobes – and that’s just the start
Scam alert: No, hackers don’t have webcam vids of you enjoying p0rno. Don’t give them any $$s

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.

You are not alone; Instagram is down for many

Reading Time: ~2 min.Ticketmaster Snafu Only Tip of the Iceberg After last month’s Ticketmaster breach, a follow-up investigation found it to be part of a larger payment card compromising campaign affecting more than 800 online retail sites worldwide. The cause of the breach appears to stem from the third-party breaches of several Ticketmaster suppliers, which […]

Indictment bombshell: ‘Kremlin intel agents’ hacked, leaked Hillary’s emails same day Trump asked Russia for help
Justice Department Indicts 12 Russian Nationals Tied to 2016 Election Hacking

LinuxSecurity.com: gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification (CVE-2018-12020) SL6 x86_64 gnupg2-2.0.14-9.el6_10.x86_64.rpm gnupg2-debuginfo-2.0.14-9.el6_10.x86_64.rpm gnupg2-smime-2.0.14-9.el6_10.x86_64.rpm i386 gnupg2-2.0.14-9.el6_10.i686.rpm gnupg2-debuginfo-2.0.14-9.el6_10.i686.rpm gnupg2-smim [More…]

LinuxSecurity.com: Red Hat JBoss Core Services Pack Apache Server 2.4.29 packages are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Red Hat JBoss Core Services Pack Apache Server 2.4.29 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Red Hat JBoss Core Services Pack Apache Server 2.4.29 packages are now available. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

Indian iPhone Spy Campaign Used Fake MDM Platform

Risk Level: Very Low. Type: Trojan.

ThreatList: Bug Bounty Payouts Increase Six Percent for Critical Vulnerabilities
Sextortionists Shift Scare Tactics to Include Legit Passwords
It pays to know your enemies: Sophos webinar gives you the cybercrime lowdown
Unsanctioned Apps Invite Fox into Cybersecurity Hen House
Spectre bug protection forcing Chrome to use 10 to 13% more RAM
Bogus Mobile Device Management system used to hack iPhones in India
Ukraine claims it blocked VPNFilter attack at chemical plant

LinuxSecurity.com: It was discovered that there was a symlink attack in the Cinnamon desktop environment. An attacker could overwrite an arbitrary file on the filesystem via

Risk Level: Very Low. Type: Trojan.

Google’s ghost busters: We can scare off Spectre haunting Chrome tabs

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2112

Now Pushing Malware: NPM package dev logins slurped by hacked tool popular with coders
Hacker Compromises Air Force Captain to Steal Sensitive Drone Info
Dark web marketplace found selling access to airport’s security system
Cisco Patches High-Severity Bug in VoIP Phones
ThreatList: 6-Year-Old Dorkbot Banking Malware Resurfaces as Big Threat
Chrome Now Features Site Isolation to Defend Against Spectre
Timehop data breach is worse than they initially said
Average cost of a data breach exceeds $3.8 million, claims report
Ransomware is so 2017, it’s all cryptomining now among the script kiddies

LinuxSecurity.com: Update to upstream version 9.4.11. Fixes CVE-2017-7656, CVE-2017-7657, CVE-2017-7658, CVE-2018-12538.

Palo Alto Networks rattles tin, wants $1.5bn for, er, stuff and things
Insights Security Hardening Rules

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Facebook fined over data privacy scandal

Social media giant fined in the UK for failing to protect users’ personal information and for a lack of transparency The post Facebook fined over data privacy scandal appeared first on WeLiveSecurity

Not All Hacks Are Created Equal
This Is How Much a ‘Mega Breach’ Really Costs
Hacker Exploits 2-Year Old Router Issue To Steal Sensitive US Military Data
Smashing Security #086: Elon Musk submarine scams and 2FA bypass
What can $10 stretch to these days? Lunch… or access to international airport security systems
Trends 2018: Doing time for cybercrime

Law enforcement and malware research join forces to take down cybercriminals The post Trends 2018: Doing time for cybercrime appeared first on WeLiveSecurity

Who’s Reading Your Gmail Messages?
Stolen Taiwanese Certs Used in Malware Campaign
Asian Countries Frequent Targets of APT Attacks
Cost of UK Data Breaches Rises to ?2.7m
Facebook doesn’t want to eradicate fake news. If it did they’d kick out InfoWars

LinuxSecurity.com: It was discovered that there was a discovered a path traversal flaw in ruby-sprockets, a Rack-based asset packaging system. A remote attacker could take advantage of this flaw to read arbitrary files outside an application’s root directory via “file://” requests.

LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Ticketmaster breach ‘part of massive card-skimming campaign’
Tim? Larry? We need to talk about smartphones and privacy
Timehop admits to more data leakage, details GDPR danger
FBI for the Apple guy: Bloke accused of stealing car kit collared

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2113

Like my new wheels? All I did was squash a bug, and they gave me $72k

LinuxSecurity.com: An update for gnupg2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for gnupg2 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Ticketmaster Breach: Just One Part of a Wide-Ranging Campaign

Type: Vulnerability. Microsoft Access is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.