Menu

Category Archives: Security

Articles about security

Meet TLBleed: A crypto-key-leaking CPU attack that Intel reckons we shouldn’t worry about
WannaCry ransomware scam tries to extort money without actually infecting your computer

LinuxSecurity.com: Two vulnerabilities were discovered in LAVA, a continuous integration system for deploying operating systems for running tests, which could result in information disclosure of files readable by the lavaserver system user or the execution of arbitrary code via a XMLRPC call.

LinuxSecurity.com: It was discovered that the low-level interface to the RSA key pair generator of Bouncy Castle (a Java implementation of cryptographic algorithms) could perform less Miller-Rabin primality tests than expected.

Fortnite Fraudsters Infest the Web with Fake Apps, Scams
Malicious App Infects 60,000 Android Devices – But Still Saves Their Batteries

LinuxSecurity.com: git: arbitrary code execution when recursively cloning a malicious repository (CVE-2018-11235) SL7 x86_64 git-1.8.3.1-14.el7_5.x86_64.rpm git-daemon-1.8.3.1-14.el7_5.x86_64.rpm git-debuginfo-1.8.3.1-14.el7_5.x86_64.rpm git-svn-1.8.3.1-14.el7_5.x86_64.rpm noarch emacs-git-1.8.3.1-14.el7_5.noarch.rpm emacs-git-el-1.8.3.1-14.el7_5.noarch.rpm git-all-1.8.3.1-14.el7 [More…]

Supreme Court Bolsters Mobile-Phone Privacy Rights
DDoS-Happy ‘Bitcoin Baron’ Sentenced to Almost 2 Years in Jail
Flight tracking service Flightradar24 hacked; 230,000 accounts affected
Roku TV, Sonos Speaker Devices Open to Takeover

Reading Time: ~4 min.I had the privilege of giving a keynote on one of my favorite topics, busting myths around artificial intelligence (AI) and machine learning (ML), during DattoCon 2018 this week. Webroot has been doing machine learning for more than a decade and consider this aspect one of our key differentiators for our solutions. […]

Microsoft Edge bug could be exploited to spill your emails to malicious sites

Since a patch for the flaw has already been released, users are well advised to make sure that they’re running the browser’s most recent version The post Microsoft Edge bug could be exploited to spill your emails to malicious sites appeared first on WeLiveSecurity

In Russia for World Cup? Beware of fake WiFi hotspots stealing user data

LinuxSecurity.com: It was discovered that there were two remote code execution vulnerabilities in php-horde-image, the image processing library for the Horde groupware tool:

Olympic Destroyer Malware is Back to Wreak Havoc
‘Hidden Tunnels’ Help Hackers Launch Financial Services Attacks
Schneier warns of ‘perfect storm’: Tech is becoming autonomous, and security is garbage
Don’t panic, but your baby monitor can be hacked into a spycam
Malware infected Battery saver app on Play Store infects 60,000 users
Sneaky Web Tracking Technique Under Heavy Scrutiny by GDPR
MOS-SAD: Israeli govt weighs in on Facebook privacy, promises action
Want to know what all that Fortnite hype is about? Whoa, Android fans – mind how you go
Financial Services Sector Rife with Hidden Tunnels

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

LinuxSecurity.com: – Security fix for [CVE-2017-11546, CVE-2017-11547] – Fix the .desktop files so that opening a .mid file from a GUI filemanager works

LinuxSecurity.com: http://www.simplesystems.org/libtiff/v4.0.9.html

LinuxSecurity.com: Update to 2.8.3 – Fix security issue

60,000 Android devices hit by battery-saving app attack
The Pirate Bay is down – Here are its alternatives & Dark Web domain
WannaCry is back! (Psych. It’s just phisher folk doing what they do)
Bithumb Crypto Exchange Hacked Again; $31 Million Stolen
Ham-fisted hacker gets jail time for serial DDoS attacks

The tale of “Bitcoin Baron” reveals a worrying picture and illustrates how easy it has become to wreak havoc on the internet The post Ham-fisted hacker gets jail time for serial DDoS attacks appeared first on WeLiveSecurity

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

Most Websites and Web Apps No Match for Attack Barrage
Mylobot Malware Brings New Sophistication to Botnets
Ex-Tesla employee sued for hacking and stealing company data
Smashing Security #083: Fake email derails clarinetist’s dream
Sorry, but blockchain databases are just not that secure
Israel cyberczar drops hints about country’s new security initiative
South Korea’s largest cryptocurrency exchange hacked

Bithumb has claimed that $31.5 million worth of virtual coins were stolen by hackers The post South Korea’s largest cryptocurrency exchange hacked appeared first on WeLiveSecurity

Please tighten your passwords and assume the brace position, says plane-tracking site
Are your IoT gizmos, music boxes, smart home kit vulnerable to DNS rebinding attacks? Here’s how to check

Risk Level: Very Low. Type: Trojan.

Traffic sign near ICE headquarters hacked with “Abolish ICE” message
IBM’s McAfee-as-a-service cloudy antivirus wobbled for nearly a day

LinuxSecurity.com: An update for git is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: The system could be made to expose sensitive information.

Script kiddie goes from ‘Bitcoin Baron’ to ‘Lockup Lodger’ after DDoSing 911 systems
Microsoft Edge bug odyssey shows why we can’t have nice things

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Tesla fingers former Gigafactory hand as alleged blueprint-leaking sabotage mastermind
Private sector needs a little sumthin’ sumthin’ to get it sharing threat intel – US security chap
New Phishing Scam Reels in Netflix Users to TLS-Certified Sites
Tesla sues ex-employee for hacking & sharing GBs of data with 3rd parties
Mylobot Botnet Emerges with Rare Level of Complexity
At last, a use for Intel’s SGX – locking AI and blockchain, says Intel
Bitcoin Baron Gets 20 Months in Prison for DDoS Attacks
16 arrested for hacking Internet cafes to mine cryptocurrency

LinuxSecurity.com: Update to 2.8.3 – Fix security issue

LinuxSecurity.com: Update to Chromium 67. Security fix for CVE-2018-6123 CVE-2018-6124 CVE-2018-6125 CVE-2018-6126 CVE-2018-6127 CVE-2018-6128 CVE-2018-6129 CVE-2018-6130 CVE-2018-6131 CVE-2018-6132 CVE-2018-6133 CVE-2018-6134 CVE-2018-6135 CVE-2018-6136 CVE-2018-6137 CVE-2018-6148

LinuxSecurity.com: Secunia Advisory SA83507, credits Kasper Leigh Haabb, Secunia Research at Flexera parse_qt: possible integer overflow reject broken/crafted NOKIARAW files Backported 0.19-patch to recover read position if TIFF/EXIF tag is too long

LinuxSecurity.com: – Security fix for [CVE-2017-11546, CVE-2017-11547] – Fix the .desktop files so that opening a .mid file from a GUI filemanager works

11 ‘teammates’ to help you win your own cybersecurity game

Our lineup may seem heavy on the defensive side, but such is the nature of game plans for warding off a range of threats lurking in cyberspace The post 11 ‘teammates’ to help you win your own cybersecurity game appeared first on WeLiveSecurity

US Fraudster Pleads Guilty to Using OPM Breach Data
‘Wallchart’ Phishing Campaign Exploits World Cup Watchers
Shared, not stirred: GCHQ chief says Europe needs British spies

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: This update provides mitigations for the “lazy FPU” vulnerability affecting a range of Intel CPUs, which could result in leaking CPU register states belonging to another vCPU previously scheduled on the same CPU. For additional information please refer to

Hot new application for blockchain: How does botnet control sound?
OpenBSD disables Intel’s hyper-threading over CPU data leak fears
(Cryptographically) sign me up! Android to take bad app checks offline
PayPal reminds users: TLS 1.2 and HTTP/1.1 are no longer optional

security update

Flaw in Google Home and Chromecast devices reveals user location
APT15 Pokes Its Head Out With Upgraded MirageFox RAT
When It Comes To IoT Security, Liability Is Muddled
Stop downloading fake malicious Fortnite Android apps
Olympic Destroyer Returns to Target Biochemical Labs

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Axis Cameras Riddled With Vulnerabilities Enabling “Full Control”
Rex Mundi hacking extortion gang busted by Europol

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Cryptography is the Bombe: Britain’s Enigma-cracker on display in new home

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Tesla saboteur caused extensive damage and leaked highly sensitive data, claims Elon Musk
Why open source is good for business, and people
Europol Disrupts Rex Mundi Cybercrime Group
Um, excuse me. Do you have clearance to patch that MRI scanner?
Getting hands-on with industrial control system setups at RSA | Salted Hash Ep 31
Europol and partners dismantle prolific cyber-extortion gang

The arrest of a 25-year-old French man in Thailand apparently seals the fate of Rex Mundi, a hack-and-extort collective that operated since at least 2012 The post Europol and partners dismantle prolific cyber-extortion gang appeared first on WeLiveSecurity

Pass gets a fail: Simple Password Store suffers GnuPG spoofing bug

LinuxSecurity.com: An update for pcs is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for glibc is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for zsh is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from