Menu

Category Archives: Security

Articles about security

Thunderbird gets its EFAIL patch
Chrome, Firefox pull invasive browser extension
Smashing Security #085: Doctor Who, Facebook patents, and Bob’s Burgers
Top 7 Most Popular and Best Cyber Forensics Tools

security update

security update

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in Exiv2.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Carole Cadwalladr takes us behind the scenes of the Cambridge Analytica investigation
The Pirate Bay is silently mining cryptocurrency without user consent
Welcome to a New Look for Threatpost
Navigating an Uncharted Future, Bug Bounty Hunters Seek Safe Harbors
ThreatList: Exploit Kits Still a Top Web-based Threat
ThreatList: Top Summer DDoS Trends
Newsmaker Interview: Marten Mickos on the Future of Bug Bounty

LinuxSecurity.com: The package git-annex before version 6.20180626-1 is vulnerable to multiple issues including arbitrary filesystem access and information disclosure.

LinuxSecurity.com: The package gitlab before version 11.0.1-1 is vulnerable to multiple issues including cross-site scripting and insufficient validation.

Going on vacation? Five things to do before you leave

You’ve set up an out-of-office auto-responder and packed your stuff, but have you done all of your “homework” before you rush out the front door for that well-deserved time off? The post Going on vacation? Five things to do before you leave appeared first on WeLiveSecurity

Bill Clinton’s cyber-attack novel: The airport haxploit-blockbuster you knew it would be
NHS Developer Error Leads to Data Leak
Ransomware: Not dead, just getting a lot sneakier
‘Plane Hacker’ Roberts: I put a network sniffer on my truck to see what it was sharing. Holy crap!
Huawei enterprise comms kit has a TLS crypto bug
Hands up if you didn’t lose data in the Typeform breach

LinuxSecurity.com: Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program. For the stable distribution (stretch), this problem has been fixed in

LinuxSecurity.com: Several vulnerabilites have been discovered in Exiv2, a C++ library and a command line utility to manage image metadata which could result in denial of service or the execution of arbitrary code if a malformed file is parsed.

Samsung Investigates Claims of Spontaneous Texting of Images to Contacts

LinuxSecurity.com: libsoup could be made to crash if it received a specially crafted input.

LinuxSecurity.com: Two vulnerabilities affecting the cups printing server were found which can lead to arbitrary IPP command execution and denial of service.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2001

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1979

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1997

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1965

Four US govt agencies poke probe in Facebook following more ‘oops, we spilled your data’ shocks
More Federal Agencies Wrapped Up in Facebook Data Privacy Probe
Google Chrome update to label HTTP-only sites insecure within WEEKS
Typeform data breach exposes users of many websites
Britain’s tax authority reports takedown of record 20,000 fake sites

Her Majesty’s Revenue & Customs (HMRC) is “consistently the most abused government brand”, according to the National Cyber Security Centre (NCSC) The post Britain’s tax authority reports takedown of record 20,000 fake sites appeared first on WeLiveSecurity

HMRC: 29% Increase in Malicious Site Deactivations
Two-Fifths of UK CEOs See Cyber-Attacks as Inevitable
The difference between red team engagements and vulnerability assessments | Salted Hash Ep 34
‘Coding’ cockup blamed for NHS cough-up of confidential info against patients’ wishes
Budget hotel chain, UK political party, Monzo Bank, Patreon caught in Typeform database hack
Smash-hit game Fortnite is dangerous… for cheaters: Tools found laced with malware

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Quick look your right eyes and ears while using public WiFi network
Cryptocurrency users on Discord & Slack hit by MacOS malware

LinuxSecurity.com: glibc: Buffer overflow in glob with GLOB_TILDE (CVE-2017-15670) * glibc: Buffer overflow during unescaping of user names with the ~ operator (CVE-2017-15804) SL6 x86_64 glibc-2.12-1.212.el6.i686.rpm glibc-2.12-1.212.el6.x86_64.rpm glibc-common-2.12-1.212.el6.x86_64.rpm glibc-debuginfo-2.12-1.212.el6.i686.rpm glibc-debuginfo-2.12-1.212.el6.x86_64.rpm glibc-debuginfo- [More…]

LinuxSecurity.com: libvirt: Resource exhaustion via qemuMonitorIORead() method (CVE-2018-5748) * libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent (CVE-2018-1064) SL6 x86_64 libvirt-0.10.2-64.el6.x86_64.rpm libvirt-client-0.10.2-64.el6.i686.rpm libvirt-client-0.10.2-64.el6.x86_64.rpm libvirt-debuginfo-0.10.2-64.el6.i686.rpm libvirt-debuginfo-0.10.2-64.el6.x86_64.rpm [More…]

LinuxSecurity.com: samba: Null pointer indirection in printer server process (CVE-2018-1050) SL6 x86_64 libsmbclient-3.6.23-51.el6.i686.rpm libsmbclient-3.6.23-51.el6.x86_64.rpm samba-client-3.6.23-51.el6.x86_64.rpm samba-common-3.6.23-51.el6.i686.rpm samba-common-3.6.23-51.el6.x86_64.rpm samba-debuginfo-3.6.23-51.el6.i686.rpm samba-debuginfo-3.6.23-51.el6.x86_64.rpm samba-winb [More…]

LinuxSecurity.com: zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c (CVE-2018-1083) * zsh: buffer overflow when scanning very long directory paths for symbolic links (CVE-2014-10072) * zsh: buffer overrun in symlinks (CVE-2017-18206) * zsh: buffer overflow in utils.c:checkmailpath() can lead to local arbitrary code execution (CVE-2018-1100) SL6 x86_64 zsh-4.3.11-8.el6.x86_64.rpm [More…]

Risk Level: Very Low.

Dr Symantec offers quick and painless checkup for VPNFilter menace on routers
Android devices since 2012 vulnerable to RAMpage vulnerability
The principle of least privilege: A strategy of limiting access to what is essential

The principle of least privilege is a security strategy applicable to different areas, which is based on the idea of only granting those permissions that are necessary for the performance of a certain activity The post The principle of least privilege: A strategy of limiting access to what is essential appeared first on WeLiveSecurity

Phishing Cited by SMBs as Top Attack Threat
Natural Language Processing Fights Social Engineers
Boffins want to stop Network Time Protocol’s time-travelling exploits
Surveys-as-a-service outfit Typeform spilled a backup in May

security update

Bug Bounty Programs Turn Attention to Data Abuse
MacOS Malware Targets Cryptocurrency Community on Slack, Discord
Hackers steal millions of customers’ data from Adidas US website
Adidas US Website Hit by Data Breach
The 6 Worst Insider Attacks of 2018 – So Far

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes is now available.

Gentoo Linux on Github hacked; repositories modified
Ticketmaster Breach Discovered in April, Says Bank
Cyber-Attacks Caused 18 Days of NHS Downtime
Rowhammer returns, Spectre fix unfixed, Wireguard makes a new friend, and much more

LinuxSecurity.com: CVE-2017-7651 fix to avoid extraordinary memory consumption by crafted CONNECT packet from unauthenticated client

LinuxSecurity.com: CVE-2017-12872 / CVE-2017-12868 The (1) Htpasswd authentication source in the authcrypt module and (2)

LinuxSecurity.com: An update that fixes one vulnerability is now available.

And that’s now all three LTE protocol layers with annoying security flaws
Worse than Equifax: Personal records of 340M people leaked online
EFF Sues to Repeal Controversial Online Sex Trafficking FOSTA Law
Rowhammer Variant ‘RAMpage’ Targets Android Devices All Over Again

Reading Time: ~2 min.Weaponized USB Drives Targeting Japan and South Korea In an effort to target air-gapped internal systems, a new wave of weaponized USB drives has been found throughout Japanese and South Korean organizations. While these attacks are relatively uncommon, that only heightens the threat as most companies are ill-prepared for such an attack […]

Reality Winner, N.S.A. Contractor, Sentenced to 5+ Years in Leak Case
WebAssembly Changes Could Ruin Meltdown and Spectre Browser Patches
Hundreds of Hotels Hit in FastBooking Breach
Cyber Risk at All-Time High for UK Financial Sector
Adidas US breach may have exposed millions of customers’ personal info
How (over)sharing on social media can trip you up

Profuse recounting of details from your life via social media may come at a price The post How (over)sharing on social media can trip you up appeared first on WeLiveSecurity

It’s a bad, bad web ad world, and some hosting biz like it that way
Brave Brave browser’s hamburger menu serves Tor onion routing
UK.gov’s long-awaited, lightweight biometrics strategy fails to impress
How polite: Fun-bucks coin miners graciously ease off CPU pounding
Et tu, Gentoo? Horrible gits meddle with Linux distro’s GitHub code
Startup bank Monzo: We warned Ticketmaster months ago of site fraud