Menu

Category Archives: Security

Articles about security

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Smashing Security #075: Quitting Facebook

LinuxSecurity.com: CVE-2017-17833 An issue has been found in openslp that is related to heap memory

LinuxSecurity.com: An update that solves 18 vulnerabilities and has 29 fixes is now available.

Western Digital My Cloud EX2 NAS Device Leaks Files

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: A remote code execution vulnerability has been found in Drupal, a fully-featured content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2018-004

LinuxSecurity.com: Updated packages that provide Red Hat JBoss Enterprise Application Platform 7.1.2, fixes several bugs, and adds various enhancements are now available for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact

ISO blocks NSA’s latest IoT encryption systems amid murky tales of backdoors and bullying

LinuxSecurity.com: An update for eap7-jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 7.1.2 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.1.2 for Red Hat Enterprise Linux 7.

LinuxSecurity.com: Updated packages that provide Red Hat JBoss Enterprise Application Platform 7.1.2 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Updated packages that provide Red Hat JBoss Enterprise Application Platform 7.1.2 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: **Version 1.6.4** – 2018-04-13 * Security fixes in some edge case scenarios, recommended update for all users * Fixed regression in version guessing of path repositories * Fixed removing aliased packages from the repository, which might resolve some odd update bugs * Fixed updating of package URLs for GitLab * Fixed run-script –list failing […]

LinuxSecurity.com: This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.

LinuxSecurity.com: This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

Thousands of Android apps for kids are secretly tracking their activities
Hotel, motel, Holiday Inn? Doesn’t matter – they may need to update their room key software
Metamorfo Targets Brazilian Users with Banking Trojans
World’s biggest DDoS-for-hire souk shuttered, masterminds cuffed
Europol Smacks Down World’s Largest DDoS-for-Hire Market
Researchers Hacked Amazon’s Alexa to Spy On Users, Again
Website down! DDoS-for-hire site Webstresser shut by crime agencies
Bezop Cryptocurrency Server Spills 25K in Private Investor, Promoter Data
Podcast: Why Manufacturers Struggle To Secure IoT

LinuxSecurity.com: Several security issues were fixed in MySQL.

The firms that piggyback on ransomware attacks for profit
Ethereum cryptocurrency wallets raided after Amazon’s internet domain service hijacked
PyRoMine malware disables security & mines Monero using NSA exploits
UK Financial Sector Must Improve Collaboration: Report
Email security in 2018
Apple debugs debugger, nukes pesky vulns in iOS, WebKit, macOS
Bitcoin Ransomware Hits Ukraine’s Ministry of Energy website

LinuxSecurity.com: It was discovered that psensor, a server for monitoring hardware sensors remotely, was prone to a directory traversal vulnerability because the create_response function in server/server.c lacks a check for whether a file is under the webserver directory.

LinuxSecurity.com: librelp: Stack-based buffer overflow in relpTcpChkPeerName function in src/tcp.c (CVE-2018-1000140) SL6 x86_64 librelp-1.2.7-3.el6_9.1.x86_64.rpm librelp-debuginfo-1.2.7-3.el6_9.1.x86_64.rpm librelp-1.2.7-3.el6_9.1.i686.rpm librelp-debuginfo-1.2.7-3.el6_9.1.i686.rpm librelp-devel-1.2.7-3.el6_9.1.i686.rpm librelp-devel-1.2.7-3.el6_9.1.x86_64.rpm i386 librelp-1.2 [More…]

Exploit Targets Nvidia Tegra-Based Nintendo Systems
Yahoo! fined! $35m! for! covering! up! massive! IT! security! screwup!
Orangeworm Mounts Espionage Campaign Against Healthcare
AWS DNS network hijack turns MyEtherWallet into ThievesEtherWallet

LinuxSecurity.com: It was discovered that there was an XML external entity expansion (XXE) vulnerability in lucene-solr, a search engine library for Java. It could be exploited to read arbitrary local files from the Solr server

LinuxSecurity.com: An update for librelp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Ransomware Attack Hits Ukrainian Energy Ministry, Exploiting Drupalgeddon2

LinuxSecurity.com: An update for librelp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for PackageKit is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

All Nintendo Switch Consoles Contain Unpatchable Chip-Level Flaw
Critical infrastructure needs more 21qs6Q#S$, less P@ssw0rd, UK.gov security committee told
Now Amazon wants the keys to your car
Medic! Orangeworm malware targets hospitals worldwide

LinuxSecurity.com: This update doesn’t fix a vulnerability in linux-tools, but provides support for building Linux kernel modules with the “retpoline” mitigation for CVE-2017-5715 (Spectre variant 2).

Sednit update: Analysis of Zebrocy

Zebrocy heavily used by the Sednit group over last two years The post Sednit update: Analysis of Zebrocy appeared first on WeLiveSecurity

Ransomware runs rampant in 2017, Verizon report finds

Social engineering attacks that involve pretexting nearly tripled on an annual basis while phishing simulations show that curiosity gets the better of 4% of people. The post Ransomware runs rampant in 2017, Verizon report finds appeared first on WeLiveSecurity

Hackers find life-threatening vulnerabilities in Austrian ski lift control unit
Mingis on Tech: The lowdown on Android security

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Ansible Engine 2.4 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash or run programs as an administrator.

Massive cyber attack targets mid-Atlantic nation ‘Berylia’

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

security update

Muhstik Botnet Exploits Highly Critical Drupal Bug
I got 99 secure devices but a Nintendo Switch ain’t one: If you’re using Nvidia’s Tegra boot ROM I feel bad for you, son

Reading Time: ~4 min.According to the Identity Theft Research Center, in 2017 alone, nearly 158 million social security numbers were stolen as a result of 1579 data breaches. Once a cybercriminal has access to your personal info, they can open credit cards, take out loans that quickly ruin your credit, or leave you with a […]

Trustjacking: iTunes’ Wi-Fi Sync Feature Vulnerable to Exploitation
Science fiction becomes science fact – Our brains can be hacked
Join us in San Francisco at the 2018 Red Hat Summit
Uber Rival Careem Hacked, 14 million customer & driver data stolen
Prick up your ears! There’s a new biometric in town

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Firms using WebEx at risk of poisoned Flash attacks
5 Tips to Make your Online Business Secure from Hackers

LinuxSecurity.com: Multiple vulnerabilities were found in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Multiple vulnerabilities were found in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: An update for rh-perl524-perl is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Single single-sign-on SNAFU threatens three Cisco products
Brains behind seL4 secure microkernel begin RISC-V chip port
Chinese web giant finds Windows zero-day, stays schtum on specifics

LinuxSecurity.com: A vulnerability has been found in librelp that may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in unADF that may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in mbed TLS, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Gentoo’s tenshi ebuild is vulnerable to privilege escalation due to the way pid files are handled.

LinuxSecurity.com: Multiple vulnerabilities have been found in Quagga, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ClamAV, the worst of which may allow remote attackers to execute arbitrary code.

Cybercrime Economy Generates $1.5 Trillion a Year
Email attacks continue to cause headaches for companies

LinuxSecurity.com: It was discovered that there was an issue in the gunicorn HTTP server for Python applicatons where CRLF sequences could result in an attacker tricking the server into returning arbitrary headers.

LinuxSecurity.com: Security fix for CVE-2018-1000115, which disables the UDP port by default.

LinuxSecurity.com: Updated to securityupdate u171

security update