Menu

Category Archives: Security

Articles about security

Block blocked: Google to banish cryptominers from Chrome Web Store

LinuxSecurity.com: Multiple vulnerabilities were found in the rubygems package management framework, embedded in JRuby, a pure-Java implementation of the Ruby programming language.

LinuxSecurity.com: It was discovered that a race condition in beep (if configured as setuid via debconf) allows local privilege escalation. For the oldstable distribution (jessie), this problem has been fixed

U.S. DoD Hopes To Stamp Out Threats With Bug Bounty Program

security update

security update

Hacks Fifth Avenue: Crooks slurp bank cards from luxury chain Saks

LinuxSecurity.com: Several security issues were fixed in OpenJDK 8.

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

Report Shows Ransomware is the New Normal
Google Shuts Down URL Shortening Service & Acquires GIF Search Platform
Cloudflare Launches Publicly DNS-Over-HTTPS Service
Credit Card Data Swiped From 5M Saks, Lord & Taylor Customers
Phishing scam: Italian football club tricked into sending out €2m to crooks
Lord & Taylor & Saks customers payment cards stolen, sold on Dark Web

LinuxSecurity.com: Several security issues were fixed in Dovecot.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Irssi, a terminal-based IRC client which can result in denial of service. For the stable distribution (stretch), these problems have been fixed in

LinuxSecurity.com: Multiple vulnerabilities were found in rubygems, a package management framework for Ruby. CVE-2018-1000075

LinuxSecurity.com: James Davis discovered two issues in Django, a high-level Python web development framework, that can lead to a denial-of-service attack. An attacker with control on the input of the django.utils.html.urlize() function or django.utils.text.Truncator’s chars() and words() methods

Purism Librem 13: A Security-Focused Powerhouse of a Linux Laptop
How to configure multiple websites with Apache web server

LinuxSecurity.com: Two security vulnerabilities were discovered in the Z shell. CVE-2018-1071 Stack-based buffer overflow in the exec.c:hashcmd() function.

security update

security update

LinuxSecurity.com: CVE-2017-7651 A crafted CONNECT packet from an unauthenticated client could result in extraordinary memory consumption.

LinuxSecurity.com: Several vulnerabilities have been discovered in the Dovecot email server. The Common Vulnerabilities and Exposures project identifies the following issues:

US may screen social media of Immigrant & Non-Immigrant Visa Applicants

LinuxSecurity.com: Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in

LinuxSecurity.com: It was discovered that constructed ASN.1 types with a recursive definition could exceed the stack, potentially leading to a denial of service.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

MailChimp Bans ICO & Blockchain Marketing- Fundraisers Devastated

LinuxSecurity.com: libvncserver version through 0.9.11. does not sanitize msg.cct.length which may result in access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.

security update

security update

Any social media accounts to declare? US wants travelers to tell
Microsoft Fixes Bad Patch That Left Windows 7, Server 2008 Open to Attack

LinuxSecurity.com: An update that solves 19 vulnerabilities and has 16 fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: The system could be made to expose sensitive information.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 41 fixes is now available.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Hackers take over power billing records of Indian state; demand ransom
Flawed Meltdown patch by Microsoft makes Windows more vulnerable
Under Armour Reports Massive Breach of 150 Million MyFitnessPal Accounts
Under Armour says hackers stole 150 million MyFitnessPal user accounts
Drupal releases patch fixing “highly critical” flaw

The update plugs a security hole that exposes a million Drupal websites to attacks The post Drupal releases patch fixing “highly critical” flaw appeared first on WeLiveSecurity

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. City of Atlanta Faces Ransomware Roadblock In the past week, the city of Atlanta has been dealing […]

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: Alberto Garcia, Francisco Oca and Suleman Ali of Offensive Research discovered that the Xerces-C XML parser mishandles certain kinds of external DTD references, resulting in dereference of a NULL pointer while processing the path to the DTD. The bug allows for a denial of

Microsoft patches patch for Meltdown bug patch: Windows 7, Server 2008 rushed an emergency fix

LinuxSecurity.com: Wei Lei and Liu Yang of Nanyang Technological University discovered a stack-based buffer overflow in PHP5 when parsing a malformed HTTP response which can be exploited to cause a denial-of-service.

Animal abuse website hacked; thousands of users exposed

LinuxSecurity.com: memcached version prior to 1.4.37 contains an Integer Overflow vulnerability that can result in data corruption and deadlocks. This attack is exploitable via network connectivity to the memcached service.

LinuxSecurity.com: It was discovered that constructed ASN.1 types with a recursive definition could exceed the stack, potentially leading to a denial of service.

Why you shouldn’t trust a stranger’s VPN: Plenty leak your IP addresses

security update

Drupal Issues Highly Critical Patch: Over 1M Sites Vulnerable
Boeing production plant hit by malware, apparently WannaCry ransomware
Too many IoT smartphone apps making life easy for online criminals

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or information disclosure.

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Thunderbird, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: An update for openstack-tripleo-common and openstack-tripleo-heat-templates is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Fauxpersky Keylogger Malware Stealing Passwords from Windows PCs
Popular VPNs Leaking Your Real IP Address Through WebRTC Leak
WannaCryptor said to reappear, hitting Boeing’s computers

The notorious ransomware prompted fears that aircraft production could be impacted The post WannaCryptor said to reappear, hitting Boeing’s computers appeared first on WeLiveSecurity

Pingu Cleans Up: Subscription scam on Google Play

The game was uploaded to Google Play and attempted to trick users into unwittingly signing up for a weekly paid subscription The post Pingu Cleans Up: Subscription scam on Google Play appeared first on WeLiveSecurity

Creaking protocols are threat to EU’s telecom infrastructure security

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

As predicted, more branch prediction processor attacks are discovered
World Backup Day: Banks having each other’s back

As World Backup Day reminds us, robust backups are integral to healthy information security practices of any organization. This is doubly true for those operating in critical sectors. The post World Backup Day: Banks having each other’s back appeared first on WeLiveSecurity

Lizard Squad member jailed after offering DDoS-for-hire attack service
Train to be a top cybercrime fighter at SANS London June 2018
Egg on Cisco’s face: Three critical software bugs to fix over Easter
Facebook to extend bug bounty to cover data leakage, sever ties to data brokers

LinuxSecurity.com: Jasper Mattsson found a remote code execution vulnerability in the Drupal content management system. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being completely compromised.

security update

It’s baaack – WannaCry nasty soars through Boeing’s computers
HiddenMiner Android Monero Mining Malware Cause Device Failure
Smashing Security #071: Pony-tailed pundit ponders privacy problems
Police arrest teens in connection with spammed-out school bomb threats

LinuxSecurity.com: A remote code execution vulnerability has been found in Drupal, a fully-featured content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2018-002

Firefox users can now ‘isolate their Facebook identity’ from the rest of the web

The brazen theft of cryptocurrency has been an ongoing issue for years now, mostly affecting exchanges and users who fail to store their private keys securely. But what about scams purporting to be giving free cryptocurrency away? It seems a little ridiculous, but there is a serious problem with this new incarnation of the classic […]

Cisco Patches Two Critical RCE Bugs in IOS XE Software

LinuxSecurity.com: An update that solves 19 vulnerabilities and has 12 fixes is now available.

security update

security update

Running Drupal? You need to patch, patch, patch right now!

LinuxSecurity.com: This update includes the changes in tzdata 2018d. Notable changes are: – Palestine started Daylight Saving Time (DST) on March 24, rather than on March 31st.

LinuxSecurity.com: This update includes the changes in tzdata 2018d for the Perl bindings. For the list of changes, see DLA-1323-1. For Debian 7 “Wheezy”, these problems have been fixed in version

LinuxSecurity.com: An update for sensu is now available for Red Hat OpenStack Platform 12.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

3-month old flaw in iPhone camera app takes users to phishing sites

LinuxSecurity.com: Various security issues were discovered in Graphicsmagick, a collection of image processing tools. CVE-2017-18219

Baltimore’ 911 CAD system hacked; remained suspended for 17 hours

Risk Level: Very Low. Type: Trojan.

Bad Microsoft Meltdown Patch Made Some Windows Systems Less Secure
GoScanSSH Malware Targets Linux Servers
Internet of insecure Things: Software still riddled with security holes