Menu

Category Archives: Security

Articles about security

Android apps prove a goldmine for dodgy password practices
Australian Feds cuff woman who used BTC to buy drugs on dark web

LinuxSecurity.com: A vulnerability in Go allows remote attackers to execute arbitrary commands.

So you’ve got a zero-day – do you sell to black, grey or white markets?

LinuxSecurity.com: The package lib32-openssl before version 1:1.1.0.h-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package zsh before version 5.5-1 is vulnerable to arbitrary code execution.

security update

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Multiple vulnerabilities were discovered in the implementation of the Perl programming language. The Common Vulnerabilities and Exposures project identifies the following problems:

How Netflix Deploys Open Source AI to Reveal Your Favorites

LinuxSecurity.com: * Rebase to Ruby 2.5.1. * Several CVE fixes. * Conflict requirement needs to generate dependency. * Stop using –with-setjmp-type=setjmp on aarch64.

LinuxSecurity.com: Minor update from upstream with fix for CVE-2018-9234 and other bug fixes.

LinuxSecurity.com: Security fix for CVE-2018-1086 and CVE-2018-1079 Rebased to latest upstream sources

LinuxSecurity.com: harden the binaries (rhbz#1548670)

LinuxSecurity.com: Fixes several heap-buffer-overflows, see related Bugzilla tickets!

LinuxSecurity.com: Fix CVE-2017-11550 and CVE-2004-2779

LinuxSecurity.com: GwanYeong Kim reported that ‘pack()’ could cause a heap buffer write overflow with a large item count. For Debian 7 “Wheezy”, these problems have been fixed in version

security update

UK health service boss in the guts of WannaCry outbreak warns of more nasty code infections
Tried checking under the sofa? Indian BTC exchange Coinsecure finds itself $3.5m lighter

LinuxSecurity.com: python-paramiko: Authentication bypass in transport.py (CVE-2018-7750) SL6 noarch python-paramiko-1.7.5-4.el6_9.noarch.rpm – Scientific Linux Development Team

New malware mine cryptocurrency without open browser session
Critical Vulnerability in Drupal CMS Used for Cryptomining
Router ravaging, crippling code, and why not to p*ss off IT staff
Q1 Cyber-Attacks on UK Firms Jump 27%
USING OPEN SOURCE DESIGNS TO CREATE MORE SPECIALIZED CHIPS
Exposed: Lazy Android mobe makers couldn’t care less about security
Don’t Trust Android OEM Patching, Claims Researcher
Website security firm Sucuri hit by large scale volumetric DDoS attacks
NHS boss at the centre of WannaCry outbreak warns of more attacks

LinuxSecurity.com: USN-3621-1 caused a regression in Ruby.

$3.5 beeeellion Bitcoin falls out of Indian BTC exchange’s wallet

LinuxSecurity.com: The package apache before version 2.4.33-1 is vulnerable to multiple issues including session hijacking, access restriction bypass, content spoofing and denial of service.

Someone stole $3 million from Coinsecure Bitcoin exchange
This ransomware wants you to play, not pay

Unlike its much more malicious counterparts, this ransomware has a rather benign demand. It also provides two curious ways of recovering one’s files. The post This ransomware wants you to play, not pay appeared first on WeLiveSecurity

Anti-Malware testing needs standards, and testers need to adopt them

A closer look at Anti-Malware tests and the somewhat unreliable nature of the process. The post Anti-Malware testing needs standards, and testers need to adopt them appeared first on WeLiveSecurity

Story of a ransomware victim
From Bangkok to Phuket, they cry out: Oh, Bucket! Thai mobile operator spills 46k people’s data
What Facebook and the CLOUD Act mean for cloud privacy
Quarterly cybercrime digest: Part 1

In Part 1, our roundup of some of the most notable law enforcement actions against computer crime in the first quarter of 2018 will focus on arrests and charges involving suspected cyber-crooks. The post Quarterly cybercrime digest: Part 1 appeared first on WeLiveSecurity

Thousands of compromised websites spreading malware via fake updates

Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Music-Oriented YouTube Channels Hacked Within the last week, hackers have defaced multiple YouTube music […]

Cloudflare promises to tend not two, but 65,535 ports in a storm

LinuxSecurity.com: An update that solves three vulnerabilities and has 7 fixes is now available.

When SecureRandom()… isn’t: JavaScript fingered for poking cash-spilling holes in Bitcoin wallets

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, and Red Hat Enterprise

‘Well intentioned lawmakers could stifle IoT innovation’, warns bug bounty pioneer

Type: Vulnerability. Microsoft Jet Database Engine is prone to a buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Outlook Bug Allowed Hackers to Use .RTF Files To Steal Windows Passwords
Calls For Regulation Build After Facebook Privacy Fallout
Microsoft Outlook bug expose Windows credentials to hackers

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton), Red Hat OpenStack Platform 11.0 (Ocata), Red Hat OpenStack Platform 12.0 (Pike), Red Hat OpenStack Platform 8.0 (Liberty), and Red Hat OpenStack Platform 9.0 (Mitaka).

LinuxSecurity.com: An update for sensu is now available for Red Hat OpenStack Platform 11.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: This updates LibOFX to fix assorted CVEs.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Worm.

Risk Level: Very Low. Type: Worm.

Avoiding the Ransomware Mistakes that Crippled Atlanta
GCHQ boss calls out Russia for ‘industrial scale disinformation’
Hackers can takeover & control emergency alarm system with a $35 radio
New ‘Early Bird’ Code Injection Technique Helps APT33 Evade Detection

LinuxSecurity.com: It was discovered that the poppler upload for the oldstable distribution (jessie), released as DSA-4079-1, did not correctly address CVE-2017-9776 and additionally caused regressions when rendering PDFs embedding JBIG2 streams. Updated packages are now available to correct

Using Outlook? You should probably do some patching
Fake Chrome & Firefox browser update lead users to malware infection
Where’s my free monitoring service, One Plus? – hacked-off customers
How many Linux users are there anyway?
Top Ten Ways to Detect Phishing
UK defines Cyber DEFCON 1, 2 and 3, though of course doesn’t call it that
Kemi Badenoch MP, self-confessed website hacker
Data exfiltrators send info over PCs’ power supply cables
Smashing Security #073: Rick Astley: Never gonna hack you up

LinuxSecurity.com: This update upgrades Firefox to version 52.7.3 ESR. * firefox: Use-after-free in compositor potentially allows code execution (CVE-2018-5148) SL6 x86_64 firefox-52.7.3-1.el6_9.x86_64.rpm firefox-debuginfo-52.7.3-1.el6_9.x86_64.rpm firefox-52.7.3-1.el6_9.i686.rpm firefox-debuginfo-52.7.3-1.el6_9.i686.rpm i386 firefox-52.7.3-1.el6_9.i686.rpm firefox-debuginfo-52.7.3-1 [More…]

Boffins pull off quantum leap in true random number generation

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

Type: Vulnerability. Adobe Flash Player is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: This updates LibOFX to fix assorted CVEs.

LinuxSecurity.com: Fixes for CVE-2018-1002150.

17-year-old finds screen lock bypass vulnerability in Signal app for iOS

LinuxSecurity.com: Several security issues were fixed in Patch.

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update that solves 5 vulnerabilities and has one errata is now available.

Rudd-y hell, dark web! Amber alert! UK Home Sec is on the war path for stealthy cyber-crims
AMD Rolls Out Spectre Fixes
New ransomware locks files & asks victims to play PUBG game

LinuxSecurity.com: An update that solves three vulnerabilities and has 7 fixes is now available.

An apology to my Facebook followers
Ransomware, hackers, insider threats and human error featured in data breach report
As legal threats rise, this new report aims to guide ethical hackers
Cyber-Criminals Could Earn CEO-Level Salary: Report

LinuxSecurity.com: C?dric Buissart from Red Hat discovered an information disclosure bug in pcs, a pacemaker command line interface and GUI. The REST interface normally doesn’t allow passing –debug parameter to prevent information leak, but the check wasn’t sufficient.

Breach at UK’s Great Western Railway: Commuters told to reset passwords
Imagine you’re having a CT scan and malware alters the radiation levels – it’s doable
While Zuck squirmed, Reddit revealed it found and killed 944 Russian troll factory accounts
No password? No worries! Two new standards aim to make logins an API experience
SAP’s Business Client can own entire apps, DDOS them into dust
Want to terrify a city with an emergency broadcast? All you need is a laptop and $30