Menu

Category Archives: Security

Articles about security

Raw sockets backdoor gives attackers complete control of some Linux servers
Hands up who HASN’T sued Intel over Spectre, Meltdown chip flaws

security update

security update

LinuxSecurity.com: Several vulnerabilities have been discovered in Quagga, a routing daemon. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Krzysztof Sieluzycki discovered that the notifier for removable devices in the KDE Plasma workspace performed insufficient sanitisation of FAT/VFAT volume labels, which could result in the execution of arbitrary shell commands if a removable device with a malformed disk label is

LinuxSecurity.com: BIND, a DNS server implementation, was found to be vulnerable to a denial of service flaw was found in the handling of DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an

119,000 FedEx users​ ​passports, security ID & driving licenses exposed

security update

Mueller bombshell: 13 Russian ‘troll factory’ staffers charged with allegedly meddling in US presidential election
Apple Rushes Fix for Latest ‘Text Bomb’ Bug As Abuse Spreads

LinuxSecurity.com: The package irssi before version 1.1.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: Talosintelligence discovered a command injection vulnerability in the gplotMakeOutput function of leptonlib. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary

New IoT Botnet DoubleDoor Bypass Firewall to Drop Backdoor
Hackers who stole $300 million, hacked Citibank & Nasdaq are jailed
PM urged to protect data flows post-Brexit ahead of Munich speech
US forms dedicated office to help avert cyberattacks at infrastructure

The vulnerability of critical infrastructure, including energy grids, to cyberattacks has been a growing concern worldwide. Many nations have been scrambling to improve their defenses vis-à-vis threats faced by services that are critical to the continuity of our daily lives. The post US forms dedicated office to help avert cyberattacks at infrastructure appeared first on […]

UK.gov: Psst. Belgium. Buy these Typhoon fighter jets from us, will you?

LinuxSecurity.com: An update that solves 10 vulnerabilities and has three fixes is now available.

LinuxSecurity.com: An update that solves 16 vulnerabilities and has 12 fixes is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Winter Olympics Disrupted by Malware Attack The Winter Olympics are in full swing, and cybercriminals seem to […]

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Russians behind bars in US after nicking $300m+ in credit-card hacks
Techno-senator tells Tinder to hook up its app with better security

LinuxSecurity.com: Several security issues were fixed in Quagga.

Former ICE top lawyer raided US govt database to steal aliens’ identities
Facebook wants you to install a VPN app accused of spying on users

LinuxSecurity.com: Several vulnerabilities have been discovered in Quagga, a routing daemon. The Common Vulnerabilities and Exposures project identifies the following issues:

Intel Expands Bug Bounty Program Post-Spectre and Meltdown

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

security update

That terrifying ‘unfixable’ Microsoft Skype security flaw: THE TRUTH

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: – CVE-2018-1055 Remote arbitrary file disclosure vulnerability via WEBSERVICE formula

LinuxSecurity.com: Updated AppStream metadata

LinuxSecurity.com: This is an update to Mozilla’s CA certificates list version 2.22, which has been published as part of Mozilla NSS 3.35. For additional details, please refer to the NSS 3.35 release notes: https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.35_release_notes

Reported Critical Vulnerabilities In Microsoft Software On the Rise
Word-based Malware Attack Doesn’t Use Macros
How a Bitcoin phishing gang made $50 million with the help of Google AdWords
Hackers use Google Ads to steal $50 million of Bitcoin
Dell EMC squashes pair of VMAX virtual appliance bugs
Smashing Security #065: Cryptominomania, Poppy, and your Amazon Alexa
Essex black hat behind Cryptex and reFUD gets two years behind bars
Concerns about data breaches hitting all-time high

A record-high proportion of organizations worldwide (67%) said that they had been breached at some point, up from 56% in the report’s previous edition. The post Concerns about data breaches hitting all-time high appeared first on WeLiveSecurity

With Intel’s updated bug bounty program, you could earn big bucks for finding the next Meltdown
A potent botnet is exploiting a critical router bug that may never be fixed
Unsecured server exposed thousands of FedEx customer records
Hack the Air Force 2.0 uncovers over 100 vulnerabilities
Adding Encryption To printk()
Managing open-source mobile security and privacy for activists worldwide
You’ve heard the advice before: Whether you’re in the office or on the road, a VPN is one of the bes
Android ransomware in 2017: Innovative infiltration and rougher extortion

Ransomware in 2017 saw users and businesses across the globe trying to cope with campaigns such as Petya and WannaCryptor. Not to be outdone, Android ransomware had a year full of innovative infiltration and rougher extortion as highlighted by the latest ESET research whitepaper. The post Android ransomware in 2017: Innovative infiltration and rougher extortion […]

UK names and shames Russia as source of NotPetya
PCI Council and X9 Committee to combine PIN security standards

LinuxSecurity.com: It was discovered that jackson-databind, a Java library used to parse JSON and other data formats, did not properly validate user input before attempting deserialization. This allowed an attacker to perform code execution by providing maliciously crafted input.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

Hate to ruin your day, but… Boffins cook up fresh Meltdown, Spectre CPU design flaw exploits
Lazarus Group is back, targeting Banks & Bitcoin users with phishing scam

LinuxSecurity.com: Two vulnerabilities were discovered in the libraries of the Vorbis audio compression codec, which could result in denial of service or the execution of arbitrary code if a malformed media file is processed.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor: CVE-2017-17563

US govt staffers use personal gear on work networks, handle biz docs on the reg – study
Dell EMC Patches Critical Flaws in VMAX Enterprise Storage Systems
Hua-no-wei! NSA, FBI, CIA bosses put Chinese mobe makers on blast
Crypto-gurus: Which idiots told the FBI that Feds-only backdoors in encryption are possible?
Researchers Find New Twists In ‘Olympic Destroyer’ Malware

LinuxSecurity.com: An update is now available for Red Hat JBoss Fuse and Red Hat JBoss A-MQ. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Three in hospital after NSA cops open fire on campus ram-raid SUV

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.