Menu

Category Archives: Security

Articles about security

Most FTSE 100 boards kept in the dark about cyber resilience plans
Northern Irish Parliament Hit by Brute Force Attack
World Backup Day: Saving the day by saving data

World Backup Day, celebrated annually on March 31, is a timely reminder of the importance of taking effective measures that can make all the difference when a data loss incident strikes. It is also a good time to pause and reflect on the rising tide of threats that organizations, notably those operating in critical industries, […]

Privacy activists to UK plod: Wanna slurp folks’ phone records? Come back with a warrant
Cyberattack disrupted Baltimore emergency responders
How a boobytrapped QR code can trick iOS 11 into taking you to a malicious website
Monero cryptocurrency: Malware’s rising star

Bitcoin gets all the press these days when it comes to cryptocurrency but the gap in market capitalization is narrowing. The post Monero cryptocurrency: Malware’s rising star appeared first on WeLiveSecurity

Be wary when scanning QR codes with iOS 11’s camera app

Boobytrapped QR code can trick iOS 11 into taking you to a malicious website The post Be wary when scanning QR codes with iOS 11’s camera app appeared first on WeLiveSecurity

Intel shrugs off ‘new’ side-channel attacks on branch prediction units and SGX
Microsoft’s Windows 7 Meltdown fixes from January, February made PCs MORE INSECURE

LinuxSecurity.com: Jesse Schwartzentruber discovered a use-after-free vulnerability in Firefox, which could be exploited to trigger an application crash or arbitrary code execution.

security update

Hackers pwn Baltimore’s 911 system?! Quick, someone call 91– doh!

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: It was discovered that a use-after-free in the compositor of Firefox can result in the execution of arbitrary code. For the oldstable distribution (jessie), this problem has been fixed

Alleged Mastermind Behind Carbanak Crime Gang Arrested

LinuxSecurity.com: An update that solves 9 vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

Did the FBI engineer its iPhone encryption court showdown with Apple to force a precedent? Yes and no, say DoJ auditors

security update

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0592

Facebook Cracks Down On Data Misuse With Expanded Bug Bounty Program
GoScanSSH Malware Targets SSH Servers, But Avoids Military and .GOV Systems
Hackers spread password stealer malware from YouTube comment section

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: A vulnerability in PLIB may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in BusyBox, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: It was discovered that there was an issue in the irssi IRC client where certain nick names could result in out-of-bounds access when printing theme strings.

LinuxSecurity.com: It was discovered that there was a heap corruption vulnerability in the net-snmp framework which exchanges server management information in a network.

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The package bchunk before version 1.2.2-4 is vulnerable to denial of service.

Exploit kit development has gone to sh$t… ever since Adobe Flash was kicked to the curb
US government gets its hand on $15,000 iPhone cracking device
US Cops Using Dead Suspects’ Fingerprints to Unlock iPhones
The Last Windows XP Security White Paper

Using the strategies and procedures we present in our paper could help prevent an attacker from taking control of your computer The post The Last Windows XP Security White Paper appeared first on WeLiveSecurity

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

Why IoT security should keep you up at night
Oil & gas industry in Middle East found lagging in security

The oil and gas industry is the target of as much as one-half of all cyberattacks in the Middle East The post Oil & gas industry in Middle East found lagging in security appeared first on WeLiveSecurity

GCHQ’s infosec crew plans to ‘scale up’ Web Check to improve uk.gov site security
Police arrest members of billion-dollar banking cybercrime gang
Cash-machine-draining €1bn cybercrime kingpin suspect cuffed by plod
Police arrest members of cybercrime gang

ATM jackpot gang is thought to have infiltrated over 100 financial firms in 40 countries costing banks more than one billion dollars. The post Police arrest members of cybercrime gang appeared first on WeLiveSecurity

How a QR code can fool iOS 11’s Camera app into opening evil.com rather than nice.co.uk

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Richard Zhu and Huzaifa Sidhpurwala discovered that an out-of-bounds memory write when playing Vorbis media files could result in the execution of arbitrary code.

Hurrah! TLS 1.3 is here. Now to implement it and put it into software
Android Malware in QR Reader apps on Play Store downloaded 500k times
Political ad campaign biz AggregateIQ exposes tools, DB logins online

LinuxSecurity.com: slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution (CVE-2018-8088) SL7 noarch slf4j-1.7.4-4.el7_4.noarch.rpm slf4j-javadoc-1.7.4-4.el7_4.noarch.rpm slf4j-manual-1.7.4-4.el7_4.noarch.rpm – Scientific Linux Development Team

Sanny Malware Updates Delivery Method

LinuxSecurity.com: Bas van Schaik and Kevin Backhouse discovered a stack-based buffer overflow vulnerability in librelp, a library providing reliable event logging over the network, triggered while checking x509 certificates from a peer. A remote attacker able to connect to rsyslog can take

LinuxSecurity.com: An update for slf4j is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

ATM hacker behind $1 billion malware heists arrested in Spain

LinuxSecurity.com: The package thunderbird before version 52.7.0-1 is vulnerable to multiple issues including arbitrary code execution and access restriction bypass.

Facebook Woes Continue as FTC Opens Data Privacy Probe
FBI: Iranian Firm Stole Data In Massive Spear Phishing Campaign
UK.gov unveils cyber security export strategy – only thing missing is the strategy
Mozilla Tests DNS over HTTPS: Meets Some Privacy Pushback
Critical Infrastructure Interview with David Harley

WeLiveSecurity sat down with David Harley to get a better understanding of Critical Infrastructure and the role he has played in the area throughout his career. The post Critical Infrastructure Interview with David Harley appeared first on WeLiveSecurity

Facebook collected users’ call and SMS logs with “their permission”

LinuxSecurity.com: An update for rh-ruby23-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-mysql57-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

YouTube isn’t for kids

LinuxSecurity.com: An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ruby24-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Why Spectre demands more elegantly coded software

LinuxSecurity.com: An update for rh-ruby22-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-maven35-slf4j is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

We need to go deeper: Meltdown and Spectre flaws will force security further down the stack
Hey Siri! Read me this locked iPhone’s hidden messages…
Tumblr troll-ban follows February indictments

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Daniel P. Berrange and Peter Krempa of Red Hat discovered a flaw in libvirt, a virtualization API. A lack of restriction for the amount of data read by QEMU Monitor socket can lead to a denial of service by exhaustion of memory resources.

Five year old vulnerability used for Monero mining on Linux servers

security update

LinuxSecurity.com: Wojciech Regu?a discovered that Freeplane, a program for working with mind maps, was affected by a XML External Entity (XXE) vulnerability in its mindmap loader that could compromise a user’s machine by opening a specially crafted mind map file.

Microsoft to lock out Windows RDP clients if they are not patched against hijack bug
9 Iranian hackers charged with hacking universities & stealing secrets

LinuxSecurity.com: Samba could be made to crash if it received specially crafted input.

LinuxSecurity.com: An update that solves 10 vulnerabilities and has 70 fixes is now available.

Guccifer 2.0 outed, Kaspersky slammed, Oz radio hacker in the slammer, and more

LinuxSecurity.com: An update that fixes one vulnerability is now available.

World celebrates, cyber-snoops cry as TLS 1.3 internet crypto approved
Elon Musk deletes Tesla & Space X Facebook pages for #DeleteFacebook
Senate Gives Nod To Controversial Cross-Border Data Access Bill
Nine Iranians accused of cyber-swiping 30TB+ of blueprints from unis, biz on Tehran’s orders

security update

security update

LinuxSecurity.com: Sharutils could be made to execute arbitrary code if it opened a specially crafted file.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: It was discovered that there was a server-side request forgery exploit in adminer, a web-based database administration tool. Adminer allowed unauthenticated connections to be initiated to arbitrary

On Dark Web Your Facebook ID is worth $5.20 & Gmail ID just $1
A Closer Look at APT Group Sofacy’s Latest Targets
Ransomware Attack Cripples Several Atlanta City Systems
British doctor says his laptop was hacked & led to Aleppo hospital airstrike
Guccifer 2.0’s schoolboy error reveals he’s hacking from Moscow

LinuxSecurity.com: Cure53 discovered that in SimpleSAMLphp, in rare circumstances an invalid signature on the SAML 2.0 HTTP Redirect binding could be considered valid.

City of Atlanta computers held hostage in ransomware attack

City officials confirm that Atlanta is dealing with a cyberattack that has locked down some internal systems and is holding them hostage using ransomware The post City of Atlanta computers held hostage in ransomware attack appeared first on WeLiveSecurity