Menu

Category Archives: Security

Articles about security

Hackers compromise AOL advertising platform to mine cryptocurrency
Is it a bird? Is it a plane? No, it’s a terrible breach of drone buyers’ data
Study: White House email domains at risk of being misused for phishing scams

Most of the White House’s email domains have yet to deploy an email authentication protocol known as DMARC that is designed to reduce the risk of attackers impersonating legitimate email addresses for distributing spam or phishing messages. The post Study: White House email domains at risk of being misused for phishing scams appeared first on […]

Lawmakers press Linux on security of open-source software
Facebook knew for years scammers were harvesting users’ details with phone number searches. Did nothing
Email Fraud is a Top Business Risk for 2018
Iran ‘the New China’ as a Pervasive Nation-State Hacking Threat

LinuxSecurity.com: Update to the latest upstream release, which fixes CVE-2017-14062.

LinuxSecurity.com: Fixes for CVE-2018-1002150.

LinuxSecurity.com: – spec cleanup, silent rpmlint – remove upstreamed patches, fixes rhbz #1507577 – update to 1.2.2

LinuxSecurity.com: Update to 3.6.5

NUC, NUC! Who’s there? Intel, warning you to kill a buggy keyboard app
Buggy Verge crypto-cash gets hacked, devs go fork themselves, hard

LinuxSecurity.com: This update includes the latest upstream release of the Apache HTTP Server, version 2.4.33. A number of security vulnerabilities are fixed in this release: * *Low*: Possible out of bound read in mod_cache_socache (CVE-2018-1303) * *Low*: Possible out of bound access after failure in reading the HTTP request (CVE-2018-1301) * *Low*: Weak Digest auth […]

LinuxSecurity.com: This update includes the latest upstream release of mod_http2, version 1.10.16. This includes a security fix (CVE-2018-1302): When an HTTP/2 stream was destroyed after being handled, mod_http2 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerabilty hard to trigger in usual […]

New macOS malware aims at infecting devices with malicious macros
Delta, Sears Breaches Blamed on Malware Attack Against a Third-Party Chat Service

LinuxSecurity.com: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) (CVE-2018-5146) SL6 x86_64 libvorbis-1.2.3-5.el6_9.1.i686.rpm libvorbis-1.2.3-5.el6_9.1.x86_64.rpm libvorbis-debuginfo-1.2.3-5.el6_9.1.i686.rpm libvorbis-debuginfo-1.2.3-5.el6_9.1.x86_64.rpm libvorbis-devel-1.2.3-5.el6_9.1.i686.rpm libvorbis-devel-1.2.3-5.el6_9.1.x86_64.rpm i386 libvorbis-1.2.3 [More…]

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

security update

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libvorbis is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Bot-ched security: Chat system hacked to slurp hundreds of thousands of Delta Air Lines, Sears customers’ bank cards

Reading Time: ~3 min.When WannaCry ransomware spread throughout the world last year by exploiting vulnerabilities for which there were patches, we security “pundits” stepped up the call to patch, as we always do. In a post on LinkedIn Greg Thompson, Vice President of Global Operational Risk & Governance at Scotiabank expressed his frustration with the […]

You are not alone; The Pirate Bay is down once again

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Mark Zuckerberg admits Facebook scans user private messages
Rarog Trojan ‘Easy Entry’ For New Cryptomining Crooks, Report Warns
1.5 BEEELLION sensitive files found exposed online dwarf Panama Papers leak
Don’t want to alarm you, but defence bods think North Korea could nuke UK ‘within a few years’
Saks and Lord & Taylor stores suffer data breach exposing five million bank cards

Cybercriminals are believed to have stolen information for more than five million credit and debit cards that shoppers had used at dozens of Saks Fifth Avenue, Saks Off 5th and Lord & Taylor stores mainly in the United States between May 2017 and March 2018. The post Saks and Lord & Taylor stores suffer data […]

Beware ad slingers thinly disguised as security apps

ESET researchers have analyzed a newly discovered set of apps on Google Play, Google’s official Android app store, that pose as security applications. Instead of security, all they provide is unwanted ads and ineffective pseudo-security. The post Beware ad slingers thinly disguised as security apps appeared first on WeLiveSecurity

Find out who is leaking your secrets, with help from invisible zero-width characters
Gosh, these ‘hacker’ nerds are only getting more sophisticated
Smashing Security #072: Why are firms so cr*p with our private data?
US spanks EU businesses in race to detect p0wned servers
Brain monitor had remote code execution and DoS flaw

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

They forked this one up: Microsoft modifies open-source code, blows hole in Windows Defender
Facebook Bolsters Privacy Measures With New Data Access Restrictions

LinuxSecurity.com: The package drupal before version 8.5.1-1 is vulnerable to arbitrary code execution.

security update

security update

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Intel Tells Remote Keyboard Users to Delete App After Critical Bug Found
Cyber security developments: Keeping safe and up to date

LinuxSecurity.com: An update that fixes one vulnerability is now available.

White House Lags Far Behind on Email Security Benchmark
No, Panera Bread Doesn’t Take Security Seriously
Intel Halts Spectre Fixes On Older Chips, Citing Limited Ecosystem Support
Mainstream Live Chat widgets leaking personal details of employees
Insecure SCADA Systems Blamed in Rash of Pipeline Data Network Attacks
Why you might want to tell Facebook you now live in Europe
Don’t blame Panera Bread’s security guy just because he used to work at Equifax
Google banishes cryptocurrency mining extensions from Chrome Web Store

The tech giant is taking the measure after a rise in malicious browser extensions that mine digital money by hijacking the processing power of users’ computers. The clampdown follows Google’s recent move to stop serving any and all adverts promoting virtual currencies and initial coin offerings. The post Google banishes cryptocurrency mining extensions from Chrome […]

Magento sites hacked with cryptominers & credential stealing malware
The 5 IT security actions to take now based on 2018 Trends

Implementing the five actions described in this article can help reduce your organization’s cyber risk and bolster its security defenses The post The 5 IT security actions to take now based on 2018 Trends appeared first on WeLiveSecurity

Facebook Expands Bug Bounty Amid Spiraling Privacy Scandal
Saks, Lord & Taylor Payment Card Breach Affects 5 Million
GoScanSSH Malware Avoids US Military, South Korea Targets

LinuxSecurity.com: Multiple vulnerabilities have been found in glibc, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were discovered in libxslt, the worst of which may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: Michal Kedzior found two vulnerabilities in LDAP Account Manager, a web front-end for LDAP directories. CVE-2018-8763

Intel admits a load of its CPUs have Spectre v2 flaw that can’t be fixed

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Hold the phone: Mystery fake cell towers spotted slurping comms around Washington DC

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, unauthorized access, sandbox bypass or HTTP header injection.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

security update

Furious gunwoman opens fire at YouTube HQ, three people shot

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Gay dating app Grindr shared user HIV & location data with third-parties
Do(ug)h! Half-baked security at Panera Bread spills customer data
Mad March Meltdown! Microsoft’s patch for a patch for a patch may need another patch

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several security issues were fixed in the kernel.

How to delete your Facebook data in bulk with this Chrome extension

Risk Level: Very Low. Type: Trojan.

Badmins: Magento shops brute-forced to scrape card deets and install cryptominers
Google’s April Android Security Bulletin Warns of 9 Critical Bugs
Panera Bread Slammed After Keeping Massive Data Leak Quiet For Eight Months
New Android Malware Stealing Data from Popular Messenger Apps
Lazarus KillDisks Central American casino

The Lazarus Group gained notoriety especially after cyber-sabotage against Sony Pictures Entertainment in 2014. Fast forward to late 2017 and the group continues to deploy its malicious tools, including disk-wiping malware known as KillDisk, to attack a number of targets. The post Lazarus KillDisks Central American casino appeared first on WeLiveSecurity

Panera Bread’s half-baked security
One solution to wreck privacy-hating websites: Flood them with bogus info using browser tools

LinuxSecurity.com: It was discovered that there was a local privilege escalation vulnerability in beep, an “advanced PC speaker beeper”. For Debian 7 “Wheezy”, this issue has been fixed in beep version

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Streaming site 123movies has been shut down; here are its alternatives