Menu

Category Archives: Security

Articles about security

Um, excuse me. Do you have clearance to patch that MRI scanner?
Getting hands-on with industrial control system setups at RSA | Salted Hash Ep 31
Europol and partners dismantle prolific cyber-extortion gang

The arrest of a 25-year-old French man in Thailand apparently seals the fate of Rex Mundi, a hack-and-extort collective that operated since at least 2012 The post Europol and partners dismantle prolific cyber-extortion gang appeared first on WeLiveSecurity

Pass gets a fail: Simple Password Store suffers GnuPG spoofing bug

LinuxSecurity.com: An update for pcs is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for glibc is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for zsh is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for samba is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for sssd and ding-libs is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

It’s time for TLS 1.0 and 1.1 to die (die, die)
Fraudster admits she was OPM dealer: Leaked US govt staff files used to bag cash, car loans
Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke
Not so private eye: Got an Axis network cam? You’ll need to patch it, unless you like hackers
“Unbreakable” Smart Lock Tapplock Issues Critical Security Patch
Google Home, Chromecast Leak Location Information
Zacinlo malware spams Windows 10 PCs with ads and takes screenshots

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are avalable.

LinuxSecurity.com: Multiple vulnerabilities were discovered in the Lua subsystem of Redis, a persistent key-value database, which could result in denial of service. For the stable distribution (stretch), these problems have been fixed in

macOS QuickLook Feature Leaks Data Despite Encrypted Drive
22K Open, Vulnerable Containers Found Exposed on the Net
Strip Capita of defence IT contract unless things improve – Brit MPs
New Telegram-abusing Android RAT discovered in the wild

Entirely new malware family discovered by ESET researchers The post New Telegram-abusing Android RAT discovered in the wild appeared first on WeLiveSecurity

13 Ways Cyber Criminals Spread Malware
US government finds new malware from North Korea
Dixons Carphone Breach Hits 5.9 Million Cards
’90s hacker collective man turned infosec VIP: Internet security hasn’t improved in 20 years
US Government warns of more North Korean malware attacks
Pwned with ‘4 lines of code’: Researchers warn SCADA systems are still hopelessly insecure
US-CERT warns of more North Korean malware
Authorities shut down Dark Web marketplace “Black Hand”

LinuxSecurity.com: Update to latest nodejs-uri-js for CVE fix

LinuxSecurity.com: Update to latest nodejs-uri-js for CVE fix

LinuxSecurity.com: It was discovered that Libgcrypt is prone to a local side-channel attack allowing recovery of ECDSA private keys. For the stable distribution (stretch), this problem has been fixed in

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

ClipboardWalletHijacker malware replaces address to steal cryptocurrency
Bank of Chile Suffers $10m Loss
Trump-Kim Meeting Was a Magnet For Russian Cyberattacks

security update

security update

security update

LinuxSecurity.com: Update to latest nodejs-uri-js for CVE fix

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2018-4190](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4190), [CVE-2018-4199](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4199), [CVE-2018-4218](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4218), [CVE-2018-4222](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4222),

LinuxSecurity.com: Update to latest nodejs-uri-js for CVE fix

LinuxSecurity.com: This rebases singularity from 2.2.1 to 2.5.1, which should include all corresponding updates (n.b. a request for rebase permission has been put into FESCo; hence auto-push has been disabled until they approve). Please test for functionality and backward compatibility issues, particularly around the runtime components.

LinuxSecurity.com: This rebases singularity from 2.2.1 to 2.5.1, which should include all corresponding updates (n.b. a request for rebase permission has been put into FESCo; hence auto-push has been disabled until they approve). Please test for functionality and backward compatibility issues, particularly around the runtime components.

Silk road adviser caught, Kaspersky sues Dutch paper, and Vietnam’s tech clampdown
DDoS Amped Up: DNS, Memcached Attacks Rise
23,000 Compromised in HealthEquity Data Breach

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1852

Paul Manafort accused of ‘foldering’ to hide communications
Boffins offer to make speculative execution great again with Spectre-Meltdown CPU fix

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Chinese hackers attack National Data Center using watering hole attack
Vermont Librarian Wins Small-Claims Suit Against Equifax

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

security update

74 arrested after FBI disrupts International gang of BEC scammers
WannaCry Kill Switch Hero Faces New Charges, But Code Evals Say Little
New Banking Trojan Can Launch Overlay Attacks on Latest Android Versions

Reading Time: ~2 min.Apple Bans All Cryptocurrency Mining Apps from App Store Apple has made several policy changes over the last few days that will effectively ban all cryptocurrency mining features from apps in the App Store. This change comes not long after Apple removed an app called Calender 2, which silently began background mining […]

Sir, you’ve been using Kaspersky Lab antivirus. Please come with us, sir
Former FBI boss Comey used private email for official business – DoJ
U.S. Intelligence Cautions World Cup Travelers on Mobile Use

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Stop Cyberbullying Day: Advice for victims and witnesses

A comprehensive list of some of the online resources available to victims, their families and friends The post Stop Cyberbullying Day: Advice for victims and witnesses appeared first on WeLiveSecurity

Xen Project patches Intel’s Lazy FPU flaw

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: GnuPG 2 could be made to present validity information incorrectly.

LinuxSecurity.com: Kernel: FPU state information leakage via lazy FPU restore (CVE-2018-3665) SL7 x86_64 kernel-3.10.0-862.3.3.el7.x86_64.rpm kernel-debug-3.10.0-862.3.3.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-862.3.3.el7.x86_64.rpm kernel-debug-devel-3.10.0-862.3.3.el7.x86_64.rpm kernel-debuginfo-3.10.0-862.3.3.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-862.3.3.el7.x86_ [More…]

Quantum cryptography demo shows no need for ritzy new infrastructure

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Apple Removes iPhone USB Access Feature, Blocking Out Hackers, Law Enforcement

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Cops fined £80,000 for revealing childhood abuse victims’ names
Dixons Carphone Cyberattack Targets 5.9M Bank Cards

LinuxSecurity.com: Several security issues were fixed in Ruby.

Phishing anniversary: Here’s a free $50/month subscription

Adidas “prize” used as bait in attempt to lure people into biting The post Phishing anniversary: Here’s a free $50/month subscription appeared first on WeLiveSecurity

Apple will throw forensics cops off the iPhone Lightning port every hour

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

World Cup dream team: ESET vs. Malware

An all-star line-up to go head-to-head with malware The post World Cup dream team: ESET vs. Malware appeared first on WeLiveSecurity

Modern Cybersecurity Demands a Different Corporate Mindset
Major breach at British retailer Dixons Carphone affects nearly six million bank cards

Intruders also accessed 1.2 million personal data records, such as names, addresses or email addresses, in what is shaping up to be one of Britain’s biggest data breaches involving a single company The post Major breach at British retailer Dixons Carphone affects nearly six million bank cards appeared first on WeLiveSecurity

LinuxSecurity.com: The package chromium before version 67.0.3396.87-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package gnupg before version 2.2.8-1 is vulnerable to content spoofing.

Apple confirms it’s closing security loophole that police were using to crack iPhones
Podcast: The Growing Social Media Threat Landscape
Chile to revolutionize cybersecurity after the recent cyberattack

The country’s financial authorities met to establish a new cybersecurity plan following attack on the Bank of Chile The post Chile to revolutionize cybersecurity after the recent cyberattack appeared first on WeLiveSecurity

Smashing Security #082: World Cup cybersecurity, crypto crashes, and a bang of a password fail

LinuxSecurity.com: Several vulnerabilities were found in SPIP, a website engine for publishing, resulting in cross-site scripting and PHP injection. For the oldstable distribution (jessie), this problem has been fixed

LinuxSecurity.com: Multiple vulnerabilities have been found in Quassel, the worst of which could allow remote attackers to execute arbitrary code.

Da rude sand storm seizes the Opportunity, threatens to KO rover