Menu

Category Archives: Security

Articles about security

security update

security update

Are Your Smartphones’ Batteries Spying on You?
Facebook shells out $8k bug bounty after quiz web app used by 120m people spews profiles
Norwegian Agency Dings Facebook, Google For “Unethical” Privacy Tactics
Rewards Points Targeted by Teens in Hack of 500K Accounts
Cyber nasties downed NHS systems for 1,300 hours over 36 months
Hitherto unknown marketing firm exposed hundreds of millions of Americans’ data
Ticketmaster Chat Feature Leads to Credit-Card Breach
Ticketmaster breached for months, personal data stolen by hackers

LinuxSecurity.com: – fix out-of-bounds read via a crafted ELF file (CVE-2018-10360)

LinuxSecurity.com: The 4.17.2 kernel rebase contains new drivers, new features, and a number of important fixes across the tree. —- The v4.16.17 update includes important fixes across the tree

NSA Leaker Winner Pleads Guilty
IEEE Calls for Strong Encryption
Smashing Security #084: No! My voice is not my password
That’ll learn ya! Data watchdog spanks two Brit phone botherers
Twitter bots, disassemble

Social media giants announce new measures to tackle bots and abusers The post Twitter bots, disassemble appeared first on WeLiveSecurity

LinuxSecurity.com: Several vulnerabilities have been discovered in exiv2, a C++ library and a command line utility to manage image metadata, resulting in denial of service, heap-based buffer over-read/overflow, memory exhaustion, and

IEEE joins the ranks of non-backdoored strong cryptography defenders

LinuxSecurity.com: An update is now available for Red Hat OpenStack Platform 10.0 (Newton) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Various security issues were discovered in Graphicsmagick, a collection of image processing tools. Heap-based buffer overflows or overreads may lead to a denial of service or disclosure of in-memory information or other unspecified impact by processing a malformed image file.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor: CVE-2018-12891

Firefox Monitor tool informs users if they have been hacked
Infosec bod wagers web bookie BetVictor is lax on password protection

LinuxSecurity.com: Two flaws were discovered in ruby-passenger for Ruby Rails and Rack support that allowed attackers to spoof HTTP headers or exploit a race condition which made privilege escalation under certain conditions possible.

LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code, denial of service, cross-site request forgery or information disclosure.

LinuxSecurity.com: An update for patch is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for patch is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for patch is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for patch is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

Uncle Sam is shocked, SHOCKED to find dark-web bazaars trading drugs, weapons, etc
Ticketmaster gatecrash: Gig revelers’ personal, payment info glimpsed by support site malware
Voice records of millions of Brits stored by tax agency without consent
Reality Winner pleads guilty after being unmasked by microdots
World Cup squads briefed on cybersecurity best practices

The football associations of countries competing at Russia 2018 are taking no chances when it comes to cyber-related issues The post World Cup squads briefed on cybersecurity best practices appeared first on WeLiveSecurity

A year after devastating NotPetya outbreak, what have we learnt? Er, not a lot, says BlackBerry bod
Midsized Organizations More Secure Than Large Ones
Black Hat Survey: Enterprise Tech, US Government Unprepared for Cyberattacks
Twitter gets physical – with support for hardware security keys

LinuxSecurity.com: Updated redhat-virtualization-host packages that fix several bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for org.ovirt.engine-root is now available for Red Hat Virtualization Manager 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

EU summons a CYBER FORCE into existence
FireEye hacked off at claim it hacked Chinese military’s hackers
German researchers defeat printers’ doc-tracking dots
Sophos SafeGuard anything but – thanks to 6 serious security bugs
Mozilla Announces Firefox Monitor Tool Testing, Firefox 61
PBot adware spams ads & installs cryptominer on Windows PCs
Reality Winner, liberty loser: NSA leaker faces 63 months in the cooler

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Risk Level: Very Low. Type: Trojan, Virus, Worm.

WPA3 is the magic number? Protocol refresh promises tighter Wi-Fi security
Simple Security Flaws Could Steer Ships Off Course
UK Minister of Fun Matt Hancock opens London infosec upstart creche
Wi-Fi security gets a boost as WPA3 standard is launched

The new wireless security protocol is poised to make hacking Wi-Fi connections a whole lot harder The post Wi-Fi security gets a boost as WPA3 standard is launched appeared first on WeLiveSecurity

Israel cyber chief’s ‘pants’ analogy for password security deemed, well, ‘pants’
Bill Could Give Californians Unprecedented Control Over Data
Hundreds Report WannaCry Phishing Campaign
Dob in naughty data slurps to top EU court, privacy groups urge
On Kaspersky’s ‘transparency tour’ the truth was clear as mud
‘No questions asked’ Windows code cert slingers ‘fuel trade’ in digitally signed malware
Oracle gets busy with Lazy FPU fix, adds more CPU Spectre-protectors
In non-startling news, EFF says STARTTLS email crypto is mostly done wrong

Risk Level: Very Low. Type: Trojan.

Intel finds a cure for its software security pain: Window Snyder
The Pirate Bay stays down – Here’s how to access its Dark Web domain

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

WannaCry Extortion Fraud Reemerges
‘Black hat’ extortionist thrown back in the clink after Yelp-slamming biz
Meet MyloBot malware turning Windows devices into Botnet
UK Tax Agency Collects 5.1M Biometric Voice IDs, May Violate GDPR
Misconfiguration of Java web server component Jolokia puts orgs at risk
GDPR and the REAL impact on business

Reading Time: ~4 min.We’ve seen some tricky techniques used by cybercriminals to distribute malware through social media. One common threat begins with a previously compromised Facebook account sending deceptive messages that contain SVG image attachments via Facebook Messenger. (The SVG extention is an XML-based vector image format for two-dimensional graphics with support for interactivity and […]

UK taxman has amassed voice profiles of 5.1 million taxpayers
China Escalates Hacks Against the US as Trade Tensions Rise
Tesla Employee Steals, Sabotages Company Data

LinuxSecurity.com: This update fixes multiple security vulnerabilities: CVE-2017-7380, CVE-2017-7381, CVE-2017-7382, CVE-2017-7383, CVE-2017-5852, CVE-2017-5853, CVE-2017-6844, CVE-2017-5854, CVE-2017-5855, CVE-2017-5886, CVE-2018-8000, CVE-2017-6840, CVE-2017-6842, CVE-2017-6843, CVE-2017-6845, CVE-2017-6847, CVE-2017-6848, CVE-2017-7378, CVE-2017-7379, CVE-2017-7994, CVE-2017-8054,

LinuxSecurity.com: Backport security fixes for: CVE-2017-7380, CVE-2017-7381, CVE-2017-7382, CVE-2017-7383, CVE-2017-5852, CVE-2017-5853, CVE-2017-6844, CVE-2017-5854, CVE-2017-5855, CVE-2017-5886, CVE-2018-8000, CVE-2017-6840, CVE-2017-6842, CVE-2017-6843, CVE-2017-6845, CVE-2017-6847, CVE-2017-6848, CVE-2017-7378, CVE-2017-7379, CVE-2017-7994, CVE-2017-8054, CVE-2017-8378, CVE-2017-8787,

LinuxSecurity.com: This update fixes multiple security vulnerabilities: CVE-2017-7380, CVE-2017-7381, CVE-2017-7382, CVE-2017-7383, CVE-2017-5852, CVE-2017-5853, CVE-2017-6844, CVE-2017-5854, CVE-2017-5855, CVE-2017-5886, CVE-2018-8000, CVE-2017-6840, CVE-2017-6842, CVE-2017-6843, CVE-2017-6845, CVE-2017-6847, CVE-2017-6848, CVE-2017-7378, CVE-2017-7379, CVE-2017-7994, CVE-2017-8054,

LinuxSecurity.com: Backport security fixes for: CVE-2017-7380, CVE-2017-7381, CVE-2017-7382, CVE-2017-7383, CVE-2017-5852, CVE-2017-5853, CVE-2017-6844, CVE-2017-5854, CVE-2017-5855, CVE-2017-5886, CVE-2018-8000, CVE-2017-6840, CVE-2017-6842, CVE-2017-6843, CVE-2017-6845, CVE-2017-6847, CVE-2017-6848, CVE-2017-7378, CVE-2017-7379, CVE-2017-7994, CVE-2017-8054, CVE-2017-8378, CVE-2017-8787,

Beware malicious software updates for legitimate apps
A volt out of the blue: Phone batteries reveal what you typed and read
India tells its banks to get Windows XP off ATMs – in 2019!

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Update to 2.5.5 bugfix/security release See https://github.com/ansible/ansible/blob/stable-2.5/changelogs/CHANGELOG-v2.5.rst for full changes. Fixes CVE-2018-10855 —- Update to 2.5.3 with bugfixes. https://github.com/ansible/ansible/blob/stable-2.5/changelogs/CHANGELOG-v2.5.rst

security update

LinuxSecurity.com: A vulnerability in PNP4Nagios which may allow local attackers to gain root privileges.

LinuxSecurity.com: A vulnerability in file could lead to a Denial of Service condition.

LinuxSecurity.com: The 4.17.2 kernel rebase contains new drivers, new features, and a number of important fixes across the tree.

security update

Ransomhack; a new attack blackmailing business owners using GDPR

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1957

Hackers Steal $31m+ From South Korean Crypto-Exchange
Destructive Nation-State Cyber Attacks Will Rise, Say European Infosec Pros
Hardened Azure, softened containers, force unlocking iOS 12, 11 iPhones – and more

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.