Menu

Category Archives: Security

Articles about security

Type: Vulnerability. Microsoft ASP.NET Core is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft MSR JavaScript Cryptography Library is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a remote code-execution vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Visual Studio is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Macro Assembler is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Wireless Display Adapter is prone to a command-injection vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft WordPad is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Web Customization for ADFS is prone to a cross-site scripting vulnerability; fixes are available.

Polar fitness app exposed location data of users in military & airbases

LinuxSecurity.com: Orange Tsai discovered a path traversal flaw in ruby-sprockets, a Rack-based asset packaging system. A remote attacker can take advantage of this flaw to read arbitrary files outside an application’s root directory via specially crafted requests, when the Sprockets server is

Apple OS Update Lifts Curtain on iPhone USB Restricted Mode
How to Solve the Developer vs. Cybersecurity Team Battle
Polar Fitness App Exposes Location of ‘Spies’ and Military Personnel

Risk Level: Very Low. Type: Trojan.

Microsoft might not support Windows XP any more, but GandCrab v4.1 ransomware does
ThreatList: Virtualization-related Bug Reports Jump 275 Percent in 2018
Cops suspect Detroit fuel station was hacked before 10 drivers made off with 3k ‘free’ litres
Poor security at Thomas Cook airlines leads to simple extraction of fliers’ personal data
Timehop Breach Impacts Personal Data of 21 Million Users
Newsmaker Interview: Patrick Wardle Talks Apple Malware Flubs and Successes
Leatherbound analogue password manager: For the hipster who doesn’t mind losing everything
State of the SOC? Depends on Who You Ask
New Malware Variant Hits With Ransomware or Cryptomining
Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign

D-Link and Changing Information Technologies code-signing certificates stolen and abused by highly skilled cyberespionage group focused on East Asia, particularly Taiwan The post Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign appeared first on WeLiveSecurity

‘Domain Factory’ confirms January 2018 data breach
Nostalgic social network ‘Timehop’ loses data from 21 million users
Fitness app Polar even better at revealing secrets than Strava

LinuxSecurity.com: Fix CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI

Looking for another great cyber podcast? CyberTangent is your new home with expert guests every episode

LinuxSecurity.com: Several security vulnerabilities were found in Bouncy Castle, a Java implementation of cryptographic algorithms. CVE-2016-1000338

Crooks hack gas station fuel pump to steal 600 gallons of gas

LinuxSecurity.com: New upstream version

LinuxSecurity.com: ## 3.3.17 (2018-05-25) * security #cve-2018-11407 [Ldap] cast to string when checking empty passwords * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user is logged out * security #cve-2018-11385 migrating session for UsernamePasswordJsonAuthenticationListener * security #cve-2018-11386

LinuxSecurity.com: Latest upstream release, omits some mounting code found to be insecure and not well tested.

LinuxSecurity.com: Latest upstream release, omits some mounting code found to be insecure and not well tested.

Snooping passwords from literally hot keys, China’s AK-47 laser, malware, and more
Digital India Susceptible to Security Breaches
UK Banks Must Produce Backup Plans for Cyberattacks

LinuxSecurity.com: There have been a number of updates to the set of Certificate Authority (CA) certificates that are considered “valid” or otherwise should be trusted.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

security update

security update

Old Malware Gives Criminals Tricky New Choice: Ransomware or Mining
Google Patches Critical Remote Code Execution Bugs in Android OS
Keeping False Positives in Check
Japanese Coinhive JS injector slapped with suspended sentence
The Pirate Bay is cryptomining for Monero with your CPU again
Attackers could use heat traces left on keyboard to steal passwords

The attack, called “Thermanator”, could use your body heat against you in order to steal your credentials or any other short string of text that you have typed on a computer keyboard The post Attackers could use heat traces left on keyboard to steal passwords appeared first on WeLiveSecurity

Welsh firm fined £60k for pummelling phones with 270k pay-day loan texts
Disgruntled programmer accused of trying to sell his firm’s iPhone spyware for $50 million

LinuxSecurity.com: It was discovered that the Soup HTTP library performed insuffient validation of cookie requests which could result in an out-of-bounds memory read.

Fortnum & Mason: 23,000 Affected by Data Hack
Machine Learning, Cloud, Compliance and Business Awareness Drive Cybersecurity

LinuxSecurity.com: Several vulnerabilities were found in phpMyAdmin, the web-based MySQL administration interface, including SQL injection attacks, denial of service, arbitrary code execution, cross-site scripting, server-side request forgery, authentication bypass, and file system traversal.

Newsmaker Interview: VDOO CEO Talks Top IoT Threats

Reading Time: ~2 min.Canadian college breach targets thousands Last Friday, Algonquin College officials announced that an earlier data breachpotentially affected thousands of current and former students, as well as employees. While it is still unclear exactly what systems were affected, the officials have been working to contact all potential victims and inform them of the […]

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

NSO Group bloke charged with $50m theft of government malware

LinuxSecurity.com: It was discovered that the Soup HTTP library performed insuffient validation of cookie requests which could result in an out-of-bounds memory read.

LinuxSecurity.com: The system could be made to expose sensitive information.

Don’t fear 1337 exploits. Sloppy mobile, phishing defenses a much bigger corp IT security threat

LinuxSecurity.com: Some security vulnerabilities were found in Mercurial which allow authenticated users to trigger arbitrary code execution and unauthorized data access in certain server configuration. Malformed patches and repositories can also lead to crashes and arbitrary code

Google admits third-party app developers read your Gmail emails
Windows 10’s defences are pretty robust these days, so of course folk are trying to break them

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

Year-Old Critical Vulnerabilities Patched in ISP Broadband Gear

LinuxSecurity.com: Archive Zip module could be made to expose sensitive information if it received a specially crafted input.

LinuxSecurity.com: Archive Zip module could be made to expose sensitive information if it received a specially crafted input.

ThreatList: Biggest Cybercrime Developments in 2018, So Far

Risk Level: Very Low. Type: Trojan.

Android Apps Are Sharing Screenshots, Video Recordings to Third Parties, Report Finds
Ex-employee stole secrets of Israeli spyware firm for dark web deals
Cyberboffins drill into World Cup cyber honeypot used to lure Israeli soldiers
Five tips for pentesters in iOS

Recommendations for pentesters looking for security flaws in iOS applications made by developers The post Five tips for pentesters in iOS appeared first on WeLiveSecurity

California’s New Privacy Law Gives GDPR-Compliant Orgs Little to Fear
Iranian Attackers Spoof Security Site for Phishing Lure
UK.gov: New London courthouse will focus on crimes of a cyber nature
Things that make you go hmmm: Do crypto key servers violate GDPR?
Gentoo hack caused by three rookie mistakes