Menu

Category Archives: Security

Articles about security

Malicious Docker Containers Earn Cryptomining Criminals $90K
Microsoft Reveals Which Bugs It Won’t Patch
Intel chip flaw: Math unit may spill crypto secrets to apps – modern Linux, Windows, BSDs immune
Two Bugs in WordPress Tooltipy Plugin Patched

security update

US senators get digging to find out the truth about FCC DDoS attack
Japanese police to charge scammers with crypto mining without consent

LinuxSecurity.com: plexus-archiver: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file (CVE-2018-1002200) SL7 noarch plexus-archiver-2.4.2-5.el7_5.noarch.rpm plexus-archiver-javadoc-2.4.2-5.el7_5.noarch.rpm – Scientific Linux Development Team

LinuxSecurity.com: An update for rh-maven33-plexus-archiver and rh-maven35-plexus-archiver is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for plexus-archiver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Citation needed: The EU claims Kaspersky wares ‘confirmed as malicious’

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Banco de Chile Wiper Attack Just a Cover for $10M SWIFT Heist
Dixons Carphone breach: Millions of card and user data compromised
World Cup watching: The common threats found when using streaming sites

On the eve of the 2018 FIFA World Cup in Russia, we take a closer look at the possible cybersecurity risks that exist on sports streaming websites The post World Cup watching: The common threats found when using streaming sites appeared first on WeLiveSecurity

Dixons Carphone data breach – millions put at risk of fraud

LinuxSecurity.com: An update is now available for Red Hat JBoss Core Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

74 Arrested in International Email Scam Schemes
UK watchdog issues $330k fine for Yahoo’s 2014 data breach
US government report highlights gaps in battle against botnets

The report also identifies goals that are intended to help mitigate risks associated with botnets and to increase the resilience of the internet ecosystem The post US government report highlights gaps in battle against botnets appeared first on WeLiveSecurity

What’s new in PHP 7.3
Dixons Carphone ‘fesses to mega-breach: Probes ‘attempt to compromise’ 5.9m payment cards
Microsoft reveals which Windows bugs it might decide not to fix

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

June 2018, and Windows Server can be pwned with a DNS request
June Patch Tuesday: Microsoft Issues Fixes for DNS, Cortana

LinuxSecurity.com: Danny Grander discovered a directory traversal flaw in plexus-archiver, an Archiver plugin for the Plexus compiler system, allowing an attacker to overwrite any file writable by the extracting user via a specially crafted Zip archive.

Android Devices With Misconfigured ADB, a Ripe Target for Cryptojacking Malware
Amazon Fire TV & Fire TV Stick hit by crypto mining Android malware

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Reading Time: ~3 min.Cyberattacks are on the rise, with UK firms being hit, on average, by over 230,000 attacksin 2017. Managed service providers (MSPs) need to make security a priority in 2018, or they will risk souring their relationships with clients. By following 3 simple MSP best practices consisting of user education, backup and recovery, […]

Type: Vulnerability. Adobe Flash Player is prone to multiple security vulnerabilities; fixes are available.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Bypass Glitch Allows Malware to Masquerade as Legit Apple Files
Spain’s La Liga app uses fans’ phones to detect illegal soccer broadcasts

La Liga says that the functionality requires the user’s express consent and that it is only intended to detect unauthorized broadcasts of soccer games. The post Spain’s La Liga app uses fans’ phones to detect illegal soccer broadcasts appeared first on WeLiveSecurity

FBI’s BEC Crackdown Leads To 74 Arrests Globally

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Hello, ‘Apple’ here, and this dodgy third-party code is A-OK with us
UK! watchdog! slaps! Yahoo! with! £250k! fine! for! 2014! data! breach!
Ericsson’s Chris Price on the need for collaboration between open source communities and projects
Over 301,000 Open Jobs in Cybersecurity

LinuxSecurity.com: An update for Red Hat JBoss Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

OnePlus 6 smartphone flash override demoed
AWS Best Practices webinar series: Building security into your environment
How the Spanish cybercriminal underground operates | Salted Hash Ep 30
How to get the most cloud security
74 people arrested in US-led crackdown on email scams

The international effort to disrupt Business Email Compromise (BEC) schemes also resulted in the seizure of nearly $2.4 million and the recovery of around $14 million in fraudulent wire transfers. The post 74 people arrested in US-led crackdown on email scams appeared first on WeLiveSecurity

GnuPG patched to thwart ‘fake filename’

LinuxSecurity.com: Jakub Wilk discovered a directory traversal flaw in the Archive::Tar module, allowing an attacker to overwrite any file writable by the extracting user via a specially crafted tar archive.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Youth crime falls as kids stay inside to play Grand Theft Auto instead of going out to steal cars
VMware’s remote management agent allows remote execution

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Type: Vulnerability. Microsoft Windows is prone to a remote denial-of-service vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

security update

Type: Vulnerability. Microsoft Windows is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

LinuxSecurity.com: Several security issues were fixed in GnuPG.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Meet Summit, world’s fastest AI-powered supercomputer
Tens of thousands of Android devices are leaving their debug port exposed
Foscam Issues Patches For Vulnerabilities in IP Cameras

security update

Scammers ahoy! International police operation harpoons 74 email whaling suspects
InvisiMole Burrows into Targets with Rich Espionage Tools
Report: Chinese Hackers Siphon Off ‘Massive’ Amounts of Undersea Military Data
Unprotected Server Exposes Weight Watchers Internal IT Infrastructure
Hackers target payment transfer system at Chile’s biggest bank
Android users: Beware these popularity-faking tricks on Google Play

Tricksters have been misleading users about the functionality of apps by displaying bogus download numbers The post Android users: Beware these popularity-faking tricks on Google Play appeared first on WeLiveSecurity

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Bitcoin price takes a dive after another cryptocurrency exchange hack