Menu

Category Archives: Security

Articles about security

IoT Security Concerns Peaking – With No End In Sight
Eight months after Equifax megahack, some Brits are only just being notified
Cloud Credentials: New Attack Surface for Old Problem
48 million personal profiles left exposed by data firm LocalBlox
Chris Vickery Discusses Data Leak of 48 Million Users by Private Intelligence Firm
Excel pivot table data leak leads to £120,000 fine for London council
Use of ‘StegWare’ Increases in Stealth Malware Attacks
RSA 2018: Hacking the grid

The challenges facing critical infrastructure systems The post RSA 2018: Hacking the grid appeared first on WeLiveSecurity

Rough patch, or how to shut the window of (unpatched) opportunity

Simply throwing more staff at the patching problem won’t cut it, a study suggests. The post Rough patch, or how to shut the window of (unpatched) opportunity appeared first on WeLiveSecurity

Cutting custody snaps too costly for cash-strapped cops – UK.gov
PCI Council releases vastly expanded cards-in-clouds guidance
Facebook’s login-to-other-sites service lets scum slurp your stuff

LinuxSecurity.com: New gd packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New upstream release with security fix for CVE-2018-1084

Flash! Ah-ahhh! WebEx pwned for all of us!

LinuxSecurity.com: Security fix for CVE-2018-1086 and CVE-2018-1079

LinuxSecurity.com: It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities that could result in infinite loops in different dissectors. Other issues are related to crash in dissectors that are

LinuxSecurity.com: Two vulnerabilities were found in OpenCV, the “Open Computer Vision Library”. CVE-2018-5268

How’s your Wednesday? Things going well? OK, your iPhone, iPad can be pwned via Wi-Fi sync
Surprise! Wireless brain implants are not secure, and can be hijacked to kill you or steal thoughts
iOS Sync Glitch Lets Attackers Control Devices
Millions of apps are exposing sensitive & unencrypted user data
Gold Galleon Hacking Group Plunders Shipping Industry
Vlogger loses $2M in cryptocurrency during YouTube live stream
German Government Chooses Open Source For Its Federal Cloud Solution
50,000 Minecraft users infected with hard drive wiping malware
Microsoft built its own custom Linux kernel for its new IoT service
Researcher Billy Rios, Talks Medical Device Security at RSA Conference 2018
Facebook pushes ahead with controversial facial recognition feature in Europe
ID theft in UK hits record high as crooks shift to more vulnerable targets
RSA 2018: Untangling the enterprise security mess

Securely keeping track of data and security applications The post RSA 2018: Untangling the enterprise security mess appeared first on WeLiveSecurity

Nate Cardozo, Attorney with EFF Talks Encryption at RSA Conference 2018

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

Hackers are using botnets to take the hard work out of breaking into networks
Detailing The Idle Loop Ordering Problem & The Power Improvement In Linux 4.17
Casino Gets Hacked Through Its Internet-Connected Fish Tank Thermometer
My letter urging Georgia governor to veto anti-hacking bill
Trends 2018: Democracy hack

Can the electoral processes be protected? The post Trends 2018: Democracy hack appeared first on WeLiveSecurity

NHS given a lashing for lack of action plan one year since WannaCry
Cisco, Microsoft and 32 big vendor pals join ‘Accord’ to improve security by doing … security stuff
Hop to it, bunnies: TaskRabbit breach means new passwords

LinuxSecurity.com: Wojciech Regula discovered an XML External Entity vulnerability in the XML Parser of the mindmap loader in freeplane, a Java program for working with mind maps, resulting in potential information disclosure if a malicious mind map file is opened.

You’re a govt official. You accidentally slap personal info on the web. Quick, blame a kid!

LinuxSecurity.com: Version 2.1.3 (March 5th, 2018) ——————————- **Security fixes** * Attributes that have URI values weren’t properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized. This security issue was introduced in Bleach 2.1. […]

Hey, govt hacker bod. Made some really nasty malware? Don’t be upset if it returns to bite you

security update

Millions of Apps Leak Private User Data Via Leaky Ad SDKs
Woman who hacked airline network busted through VPN logs

security update

Signal app guru Moxie: Facebook is like Exxon. Everyone needs it, everyone despises it
RSAC 2018: Tech Giants Form Cybersecurity Tech Accord
Android malware on Play Store targeting Palestinians on Facebook

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Worm.

US, UK, and Australian governments accuse Russia of targeting networking infrastructure
We ‘could’ send troubled Watchkeeper drones to war, insists UK minister
Over 20 million Chrome users have installed fake malicious Ad Blockers
Cryptominer Malware Threats Overtake Ransomware, Report Warns
Automated Bots Growing Tool For Hackers
Fake or not fake – that is the question

An interview with ESET’s Lukáš Štefanko on the thin line between what deserves the name “security app” and what can be called fake. The post Fake or not fake – that is the question appeared first on WeLiveSecurity

Build up your security credentials at SANS London June 2018
Security Trends to Watch Out for in 2018
Quarterly cybercrime digest: Extraditions and more

As Internet crime knows no borders, mutual legal assistance involving various nations and, by extension, requests for extraditing suspected cyber-offenders are sometimes part and parcel of prosecution efforts. The post Quarterly cybercrime digest: Extraditions and more appeared first on WeLiveSecurity

LinuxSecurity.com: The Citrix Security Response Team discovered that corosync, a cluster engine implementation, allowed an unauthenticated user to cause a denial-of-service by application crash.

Facebook admits it does track non-users, for their own good
Intel’s security light bulb moment: Chips to recruit GPUs to scan memory for software nasties
Microsoft has designed an Arm Linux IoT cloud chip. Repeat, an Arm Linux IoT cloud chip

LinuxSecurity.com: – update to the latest upstream release (fixes CVE-2018-1000168)

LinuxSecurity.com: Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use python send2trash module from system * use correct shebang for python2 * upstream changelog: https://apps.ankiweb.net/docs/changes.html

LinuxSecurity.com: Update to latest upstream version.

LinuxSecurity.com: New upstream release with security fix for CVE-2018-1084

LinuxSecurity.com: update to latest upstream release, which fixes the following vulnerabilities: – CVE-2018-1100 – stack-based buffer overflow in utils.c:checkmailpath() – CVE-2018-1083 – stack-based buffer overflow in compctl.c:gen_matches_files() – CVE-2018-1071 – stack-based buffer overflow in exec.c:hashcmd()

LinuxSecurity.com: Removing dependency on wireshark metapackage from wireshark-cli —- Added wireshark-qt to wireshark metapackage —- – New version 2.4.5 – Contains fixes for CVE-2018-7419, CVE-2018-7418, CVE-2018-7417, CVE-2018-7420, CVE-2018-7320, CVE-2018-7336, CVE-2018-7337, CVE-2018-7334, CVE-2018-7335, CVE-2018-6836, CVE-2018-5335, CVE-2018-5334, CVE-2017-6014, CVE-2017-9616,

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

security update

LinuxSecurity.com: This update doesn’t fix a vulnerability in linux-tools, but provides support for building Linux kernel modules with the “retpoline” mitigation for CVE-2017-5715 (Spectre variant 2).

Threatpost RSA Conference 2018 Preview
Police bust drug dealers using fingerprint from a WhatsApp photo
US, UK cyber cops warn Russians are rooting around in your routers

LinuxSecurity.com: Marcin Noga discovered multiple vulnerabilities in readxl, a GNU R package to read Excel files (via the integrated libxls library), which could result in the execution of arbitrary code if a malformed spreadsheet is processed.

Google to add extra Gmail security … by building a walled garden
Security? We’ve heard of it, say web-app devs. 31 in 33 codebases have at least one big bad vuln

LinuxSecurity.com: Several security issues were fixed in Ruby.

LinuxSecurity.com: Minor update from upstream with fix for CVE-2018-9234 and other bug fixes.

Police locate suspect from a crowd of 50,000 using Facial Recognition
Google Play Boots Three Malicious Apps From Marketplace Tied to APTs
UK spy agency warns Brit telcos to flee from ZTE gear
Hackers attack Casino’s fish tank thermometer to obtain sensitive data

LinuxSecurity.com: Several security issues were fixed in Patch.

Quarterly cybercrime digest: Sentencing

The long arm of the law caught up with a number of cybercriminals in the first three months of this year. The post Quarterly cybercrime digest: Sentencing appeared first on WeLiveSecurity

LinuxSecurity.com: It was discovered that there was an input validation vulnerability in the patch(1) utility where an ed(1) script embedded in a regular input file could result in arbitrary code execution. This was reported by Rachel Kroll [0] et al.

Nation-State Attacks Take 500% Longer to Find
Allscripts: Ransomware, recovery, and frustrated customers
Cisco backs test to help classical crypto outlive quantum computers
Security bods liberate EITest malware slaves

LinuxSecurity.com: A NULL Pointer Dereference was discovered in the TIFFPrintDirectory function (tif_print.c) when using the tiffinfo tool to print crafted TIFF information. This vulnerability could be leveraged by remote attackers to cause a crash of the application.

LinuxSecurity.com: A NULL Pointer Dereference was discovered in the TIFFPrintDirectory function (tif_print.c) when using the tiffinfo tool to print crafted TIFF information. This vulnerability could be leveraged by remote attackers to cause a crash of the application.