Menu

Category Archives: Security

Articles about security

BitGrail cryptocurrency exchange hacked; $160 million in Nano stolen

Risk Level: Very Low. Type: Trojan.

U.K. and U.S. Government Websites Among Thousands Infected by Cryptocurrency Miner
Until last week, you could pwn KDE Linux desktop with a USB stick
See that over Heathrow? It’s not an airliner – it’s a Predator drone
Washington State Marijuana Tracking System Hacked to Steal Route Data
US and UK government websites hijacked to mine cryptocurrency on visitors’ machines

If undetected by a user’s security solution or content- or ad-blocker, the script ran in the background unbeknown to the user until the webpage was closed. A number of the affected websites, including that of the ICO, were also offline for hours in the aftermath of the attack. The post US and UK government websites […]

Uh-oh. How just inserting a USB drive can pwn a Linux box
Cryakl ransomware antidote released after servers seized

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

Managing open-source mobile security and privacy for activists worldwide | Salted Hash Ep 18
All HTTP websites to soon be marked as ‘not secure’ by Google Chrome

LinuxSecurity.com: It was discovered that there was an input validation vulnerability in the librsvg renderer library that could result in data being leaked to remote attackers via a specially-crafted file.

LinuxSecurity.com: Chris Navarrete from Fortinet’s FortiGuard Labs discovered that Audacity, a multi-track audio editor, contains a vulnerability such that a .wav file with a crafted FORMATCHUNK structure (many channels) can result in

If you haven’t already killed Lotus Notes, IBM just gave you the perfect reason to do it now, fast
Government websites hijacked by cryptomining plugin

LinuxSecurity.com: Multiple vulnerabilities have been found in VirtualBox, the worst of which could allow an attacker to take control of VirtualBox.

Winter Olympics website downed by cyber attack

LinuxSecurity.com: Jonas Klempel discovered that, when parsing the AIA-Extension field of a client certificate, Apache Tomcat Native did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the

security update

Turns out Equifax breach was way bigger than initially thought
UK ICO, USCourts.gov… Thousands of websites hijacked by hidden crypto-mining code after popular plugin hacked
Apple’ iBoot Baseband Code for Various iPhone Models Leaked on GitHub

security update

LinuxSecurity.com: It was discovered that the uwsgi_expand_path function in utils.c in Unbit uWSGI, an application container server, has a stack-based buffer overflow via a large directory length that can cause a denial-of-service (application crash) or stack corruption.

Cyber Attack Disrupts Winter Olympics Website During Opening Ceremony

security update

LinuxSecurity.com: Meh Chang discovered a buffer overflow flaw in a utility function used in the SMTP listener of Exim, a mail transport agent. A remote attacker can take advantage of this flaw to cause a denial of service, or potentially the execution of arbitrary code via a specially crafted

LinuxSecurity.com: Meh Chang discovered a buffer overflow flaw in a utility function used in the SMTP listener of Exim, a mail transport agent. A remote attacker can take advantage of this flaw to cause a denial of service, or potentially the execution of arbitrary code via a specially crafted

LinuxSecurity.com: Security fix for CVE-2017-15698

LinuxSecurity.com: PostgreSQL could be made to expose sensitive information.

LinuxSecurity.com: The package clamav before version 0.99.3-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 70 fixes is now available.

Russian scientists caught using nuclear facility supercomputer to mine Bitcoin
Why Linux is better than Windows or macOS for security
Hackers Get Linux Running On Switch And Claim Nintendo Can’t Patch The Exploit
Dark Web’s largest cybercrime group indicted after stealing $530M
NSA code backported, crims cuffed, leaky AWS S3 buckets, and more

LinuxSecurity.com: Lalith Rallabhandi discovered that OmniAuth, a Ruby library for implementing multi-provider authentication in web applications, mishandled and leaked sensitive information. An attacker with access to the callback environment, such as in the case of a crafted web

LinuxSecurity.com: The package plasma-workspace before version 5.12.0-1 is vulnerable to arbitrary command execution.

LinuxSecurity.com: The package plasma-workspace before version 5.12.0-1 is vulnerable to arbitrary command execution.

LinuxSecurity.com: The package go-pie before version 1.9.4-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package go before version 1.9.4-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 44 fixes is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

Russian nuclear scientists arrested for allegedly hijacking supercomputer to mine Bitcoins
Ruskie boffins blasted for using nuke bomb lab’s supercomputer to mine crypto-rubles

Type: Vulnerability. Microsoft Internet Information Services is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Adobe Flash Player is prone to an unspecified remote code-execution vulnerability; fixes are available.

Cisco Confirms Critical Firewall Software Bug Is Under Attack

LinuxSecurity.com: Mailman could be made to run arbitrary code.

Lenovo Warns Critical WiFi Vulnerability Impacts Dozens of ThinkPad Models

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

New Tech Support Scam Freezes Chrome, Firefox & Brave Browser
Corpse! of! Yahoo! drags! emails! of! the! dead! case! to! US! Supreme! Court!
Apple’s iOS source code leak – what you need to know

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Security fix for CVE-2017-15698

How will WPA3 improve WiFi security?

This is aimed at improving security at the time of the handshake, which is when the key is being exchanged. As a result, WPA3 is poised to provide robust security even if short or weak passwords are used, i.e. those that don’t contain a combination of letters, numbers and symbols. The post How will WPA3 […]

LinuxSecurity.com: simplesamlphp, an authentication and federation application has been found vulnerable to Cross Site Scripting (XSS), signature validation byepass and using insecure connection charset.

LinuxSecurity.com: The mailman package has a Cross-site scripting (XSS) vulnerability in the web UI before 2.1.26 which allows remote attackers to inject arbitrary web script or HTML via a user-options URL

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. New Variant of Scarab Ransomware With a few interesting changes to the original Scarab ransomware, Scarabey is […]

VMware sticks finger in Meltdown/Spectre dike for virtual appliances
Wish you could log into someone’s Netgear box without a password? Summon a &genie=1

LinuxSecurity.com: A regression was detected in the previously issued fix for CVE-2018-6360. The patch released with DSA 4105-1 broke the feature of invoking mpv with raw YouTube ids. This update fixes this functionality issue. For reference, the relevant part of the original advisory text follows.

LinuxSecurity.com: An update that solves two vulnerabilities and has 17 fixes is now available.

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Apple Downplays Impact of iBoot Source Code Leak

security update

security update

Insurance Customers’ Personal Data Exposed Due to Misconfigured NAS Server
Now that’s taking the p… Sewage plant ‘hacked’ to craft crypto-coins

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 68 fixes is now available.

LinuxSecurity.com: Several security issues were fixed in Django.

LinuxSecurity.com: Security fixes for CVE-2017-17485 and CVE-2018-5968.

From July, Chrome will name and shame insecure HTTP websites
Gojdue Variant Eludes Microsoft, Google Cloud Protection, Researchers Say
Global cybercrime behemoth busted, 36 people indicted

According to US authorities, the enterprise aimed at becoming the premier destination for the buying and selling of stolen payment card data and forged identification documents. It is believed that the losses that the Infraud Organization had intended to cause were north of $2.2 billion. The post Global cybercrime behemoth busted, 36 people indicted appeared […]

LinuxSecurity.com: An update is now available for Red Hat JBoss Core Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

12 Common Threat Intelligence Use Cases
Swisscom data breach exposes 800,000 customers
DDoS attacks: How an 18-year-old got arrested for trying to knock out systems
CyberThreat18: 2 days of bughunting, techie chat and code lockdown
Apple’s top-secret iBoot firmware source code spills onto GitHub for some insane reason
Intel adopts Orwellian irony with call for fast Meltdown-Spectre action after slow patch delivery
New strife for Strava: Location privacy feature can be made transparent
PSA: If your security starts and ends with bug bounties, you’re gonna have a bad time
Unlucky 13 collared by cops hunting cyber-crew who stole up to $2.2bn
Smashing Security #064: So just a ‘teeny tiny’ security issue then?
Google Expands Play Marketplace Bug Bounty Program

LinuxSecurity.com: It was discovered that the webhook validation of Anymail, a Django email backends for multiple ESPs, is prone to a timing attack. A remote attacker can take advantage of this flaw to obtain a WEBHOOK_AUTHORIZATION secret and post arbitrary email tracking events.

security update

LinuxSecurity.com: A vulnerabilities has been found in the PostgreSQL database system: CVE-2018-1053

Type: Vulnerability. Adobe Flash Player is prone to an remote code-execution vulnerability; fixes are available.