Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.

LinuxSecurity.com: Applications using Oslo middleware could be made to expose sensitiveinformation.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service: CVE-2017-11613

LinuxSecurity.com: The Qualys Research Labs discovered multiple vulnerabilities in procps, a set of command line and full screen utilities for browsing procfs. The Common Vulnerabilities and Exposures project identifies the following problems:

ICANN Launches GDPR Lawsuit to Clarify the Future of WHOIS

LinuxSecurity.com: Several security issues were fixed in libytnef.

LinuxSecurity.com: An update for xmlrpc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Nocturnal Stealer Lets Low-Skilled Cybercrooks Harvest Sensitive Info
Paris Police Arrests Alleged Vevo Hackers
Huawei Patches Four Server Bugs Rated High Severity

LinuxSecurity.com: xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003) SL6 noarch xmlrpc3-client-3.0-4.17.el6_9.noarch.rpm xmlrpc3-common-3.0-4.17.el6_9.noarch.rpm xmlrpc3-client-devel-3.0-4.17.el6_9.noarch.rpm xmlrpc3-common-devel-3.0-4.17.el6_9.noarch.rpm xmlrpc3-javadoc-3.0-4.17.el6_9.noarch.rpm xmlrpc3-server-3.0-4.17.el6_9.noarch.rpm [More…]

Podcast: How Cities Can Be Security Smart
These Chrome extensions & Android apps collect your Facebook data

LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Smashing Security #080: Country bans Facebook, eavesdropping Alexa, and PornHub VPN
Court says ‘nyet’ to Kaspersky’s US govt computer ban appeal
Yahoo hacker involved in 500 million accounts breach jailed for 5 years
Law forcing Feds to get warrants for email slurping is sneaked into US military budget

security update

security update

Bug In Git Opens Developer Systems Up to Attack
Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans
Inmates pirated movies from computers they build with spare parts
Yahoo! merc! hacker! Karim! Baratov! gets! five! years! in! the! clink!

LinuxSecurity.com: Several security issues were fixed in the kernel.

Yahoo Hacker Sentenced; Coke Opens Up a Can of Data Breach
SpamCannibal blacklist service reanimated by squatters, claims every IP address is spammy
Git security vulnerability could lead to an attack of the (repo) clones
Google Patches 34 Browser Bugs in Chrome 67, Adds Spectre Fixes
Multiple Internet-Connected BMW vehicles vulnerable to getting hacked
Hidden Cobra Strikes Again with Custom RAT, SMB Malware

LinuxSecurity.com: Several vulnerabilities have been found in the Apache HTTPD server. CVE-2017-15710

An acoustic attack can blue screen your Windows computer
Jail for the man who helped Russia hack Yahoo’s email accounts
An Industry In Transition: Key Tech Trends In 2018
FBI to all router users: Reboot now to neuter Russia’s VPNFilter malware
See me speak at the Cloud Security Summit in London
Have you heard about ransomware? Now’s the time to ask: Are you covered?

LinuxSecurity.com: Git contains multiple vulnerabilities that allow for the remote execution of arbitrary code.

FBI fingers North Korea for two malware strains

LinuxSecurity.com: The package strongswan before version 5.6.2-2 is vulnerable to denial of service.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: The package wireshark-qt before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package wireshark-common before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package wireshark-cli before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package wireshark-gtk before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several vulnerabilities were discovered in qemu, a fast processor emulator. CVE-2017-15038

Fraudsters Claim To Hack Two Canadian Banks

LinuxSecurity.com: Etienne Stalmans discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability exploitable via specially crafted submodule names in a .gitmodules file.

SEVered Attack Extracts the Memory of AMD-Encrypted VMs

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1726

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1669

Sonic Tone Attacks Damage Hard Disk Drives, Crashes OS

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Google Patches reCAPTCHA Bypass
GCHQ bod tells privacy advocates: Most of our work is making sure we operate within the law
Brazilian Banking Trojan Communicates Via Microsoft SQL Server
Hackers demand $1m ransom after stealing data from 2 Canadian banks
Despite Ringeader’s Arrest, Cobalt Group Still Active
BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts

LinuxSecurity.com: Batik could be made to expose sensitive information if it received a specially crafted XML.

UNICEF now using cryptocurrency mining for fundraising

So far in 2018, the NGO has launched two charity campaigns with the aim of raising funds through cryptocurrency mining. The post UNICEF now using cryptocurrency mining for fundraising appeared first on WeLiveSecurity

Watch thieves steal keyless Mercedes within 23 seconds
Papua New Guinea to ban Facebook for a month
Inside Microsoft’s Azure Sphere hardware for secure IoT
Ex-staffer of UK.gov dept bags payout after boss blabbed medical info to colleagues
Two Canadian banks warn attackers may have stolen customer data

Simplii Financial and Bank of Montreal are believed to have suffered a twin attack that was soon followed by blackmail threats The post Two Canadian banks warn attackers may have stolen customer data appeared first on WeLiveSecurity

ISP popped router ports, saving customers the trouble of making themselves hackable
Softbank’s ‘Pepper’ robot is a security joke
10 years prison for man who hacked 200 firms & sold data on Dark Web

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Scammers raid man’s bank account while he waits on hold to fraud hotline

Criminals have set their sights on customers of a bank that has been struggling with a switchover to a new computer platform The post Scammers raid man’s bank account while he waits on hold to fraud hotline appeared first on WeLiveSecurity

Singapore ISP Leaves 1,000 Routers Open to Attack
This Chrome extension reveals if your password has been breached
Man arrested for possession of 58 terabytes of child sexual abuse material

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

Privacy International Launches GDPR Probe into Data Companies
Clear Linux Exploring Support For Windows WSL
GDPR latest: Fraudsters posing as banks in data protection emails phishing scam
One in Three HCOs Hit by Cyber-Attack
Hacker jailed for selling personal data on dark web

Grant West used popular food app Just Eat to gain access to thousands of emails and passwords The post Hacker jailed for selling personal data on dark web appeared first on WeLiveSecurity

FBI to World+Dog: Please, try turning it off and turning it back on
15 years prison for man who hired attackers to DDoS his ex-employer
Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more
Cola-Cola breach: ex-employee stole hard drive with 8,000 workers’ data
GDPR Oddsmakers: Who, Where, When Will Enforcement Hit First?
Xenotime Attack Group Expands Activity

LinuxSecurity.com: CVE-2017-18248 It was found that by submitting a print job with an invalid username, the CUPS server can be crashed, when D-Bus support is enabled (which

FBI: Protect yourself from VPNFilter malware; reboot your router now

LinuxSecurity.com: Security fix for CVE-2018-10536 CVE-2018-10537 CVE-2018-10538 CVE-2018-10539 CVE-2018-10540

security update

New cryptojacking malware hits Mac devices
Hackers deface Airport screens in Iran with anti-government messages