Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: Two vulnerabilities were discovered in Libtasn1, a library to manage ASN.1 structures, allowing a remote attacker to cause a denial of service against an application using the Libtasn1 library.

LinuxSecurity.com: An update that solves two vulnerabilities and has 17 fixes is now available.

LinuxSecurity.com: Security fix for CVE-2017-17969 (from Debian)

LinuxSecurity.com: Security fix for CVE-2018-6381

LinuxSecurity.com: This update includes a rebase from 8.0.47 to 8.0.49.

LinuxSecurity.com: This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error […]

Hotspot Shield Vulnerability Could Reveal ‘Juicy’ Info About Users, Researcher Claims

Risk Level: Very Low. Type: Trojan.

WordPress update stopped WordPress automatic updates from working. So update now
UK-led police operation quashes Luminosity Link RAT

The investigation showed that the tool, which required little technical knowledge to deploy, had over 8,600 users in 78 countries. Victims are believed to be in the thousands. The post UK-led police operation quashes Luminosity Link RAT appeared first on WeLiveSecurity

LinuxSecurity.com: Security fixes for CVE-2017-17485 and CVE-2018-5968.

Boffins crack smartphone location tracking – even if you’ve turned off the GPS
Abusing X.509 Digital Certificates for Covert Data Exchange
Hacking suspect Lauri Love wins landmark appeal against US extradition
Australian cops to enter kindergartens to teach kids not to cyber
Malware Exploiting Spectre, Meltdown Flaws Emerges
Beware the looming Google Chrome HTTPS certificate apocalypse!
Uber quits GitHub for in-house code after 2016 data breach
Registrar Namecheap let miscreants slap spam, malware on customers’ web domains willy-nilly

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to mitigate the speculative side channel attack known as Spectre variant 2.

Amazon explained ‘Key’ crack before it shipped fix, says hacker who found the hole
Web analytics outfit Mixpanel slurped surfers’ passwords

LinuxSecurity.com: It was discovered that mpv, a media player, was vulnerable to remote code execution attacks. An attacker could craft a malicious web page that, when used as an argument in mpv, could execute arbitrary code in the host of the mpv user.

Who doesn’t like a good mobile game? Especially a free one! They allow you to blow off steam while fine-tuning your skills, competing with others or maybe even winning bragging rights among friends. Free games can be fun to play, yet there are some common-sense guidelines to make sure these apps don’t surprise you with […]

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Leaky Amazon S3 Bucket Exposes Personal Data of 12,000 Social Media Influencers
Adobe: Two critical Flash security bugs fixed for the price of one
All Ledger hardware wallets vulnerable to man in the middle attack
MacUpdate Hacked to Distribute Mac Cryptocurrency Miner
Cisco Issues New Patches for Critical Firewall Software Vulnerability
One year later, the UK’s Active Cyber Defence is seeing good results
Security hole meant Grammarly would fix your typos, but let snoopers read your private writings
FBI warns of email scams claiming to be from Bureau

Another template attempts to scare, rather than thrill, the recipients. Upon learning that “your IP address and other identifying information were used to commit multiple online crimes”, the mark is urged to contact the sender by phone immediately. The post FBI warns of email scams claiming to be from Bureau appeared first on WeLiveSecurity

Spectre and Meltdown | Salted Hash Ep 17
How I Got Paid $0 From the Uber Security Bug Bounty
Why cops won’t need a warrant to pull the data off your autonomous car
Open source turns 20 years old, looks to attract normal people
Think you have a tracker on your phone? Learn how to make your device more resilient

While it certainly doesn’t hurt to ask for help from local law enforcement, know that even major cities may not have the expertise or the bandwidth to investigate compromised mobile devices. The most important objective is to take steps to make sure you’re safe. Ask for help, but do not wait for others to help […]

LinuxSecurity.com: ClamAV 0.99.3 recommended for all ClamAV users. Please see details below: 1. ClamAV UAF (use-after-free) Vulnerabilities (CVE-2017-12374) ————————————————————— The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could

LinuxSecurity.com: This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error […]

LinuxSecurity.com: Security fix for CVE-2017-17969 (from Debian)

Cops find ATM spewing cash, car with dodgy plates, stack of $20 bills and hacking kit inside
X.509 metadata can carry information through the firewall
T-Mobile US let hackers nick my phone number, drain my crypto-wallets, cries man who lost $20k
Grammarly Patches Chrome Extension Bug That Exposed Users’ Docs
Authorities shut down Luminosity RAT used by buyers in 78 countries

security update

Don’t worry, it’ll be all Reich! Googler saves Grammarly nazis from hacker invasion
Covert Data Channel in TLS Dodges Network Perimeter Protection
New Monero Crypto Mining Botnet Leverages Android Debugging Tool

LinuxSecurity.com: It was discovered that an XHR/AJAX call did not properly encode user input in the “dokuwiki” wiki platform. This resulted in a reflected file download vulnerability.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Lauri Love judgment: Extradition would be ‘oppressive’ and breach forum bar
GCHQ unit claims it has ‘objectively’ made the UK a less desirable target to cybercrims
Lauri Love won’t be extradited to the United States to face hacking charges
British Hacker Lauri Love will not be extradited to the United States
It’s time to say ‘Welcome to dumpsville Adobe Flash’, as new unpatched flaw exploited by criminals

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

Accused Brit hacker Lauri Love will NOT be extradited to America

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Vulnerabilities reached a historic peak in 2017

In 2017, the number of vulnerabilities smashed records set in previous years. According to CVE Details, more than 14,600 vulnerabilities were reported in 2017, compared to 6447 in 2016. The post Vulnerabilities reached a historic peak in 2017 appeared first on WeLiveSecurity

Russian-monitoring Shetlands radar station was nearly sold off
Knock, knock. Who’s there? Another Amazon Key door-lock hack

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: ‘landave’ discovered a heap-based buffer overflow vulnerability in the NCompress::NShrink::CDecoder::CodeReal method in p7zip, a 7zr file archiver with high compression ratio. A remote attacker can take advantage of this flaw to cause a denial-of-service or, potentially the

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Internet Crime Complaint Center Impersonated for Malware & Phishing Scam
BeeToken’s ICO Hit by Phishing Scam; $1M worth of Ethereum Stolen
Spectre shenanigans, Nork hackers upgrade, bad WD drives and more
Japanese boy arrested for developing cryptocurrency stealing malware
JenX Botnet Has Grand Theft Auto Hook
New Western Digital My Cloud Bugs Give Local Attackers Root on NAS Devices
139 Malware Samples Identified that Exploit Meltdown & Spectre Flaws
Get 3 Years of NordVPN Service for Just $2.75 Per Month

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Multiple Dutch Banks Fall Victim to Week-long Cyberattack String Over the last week, several of the largest […]

Bluetooth ‘Panty Buster’ smart mock-cock fails penetration test
Fileless WannaMine Cryptojacking Malware Using NSA Exploit
On the NHS tech team? Weep at ugly WannaCry post-mortem, smile as Health dept outlines plan
Critical Infrastructure More Vulnerable Than Ever Before
GDPR: These are the organisations which are least prepared
Meltdown-Spectre: Malware is already being tested by attackers
A giant botnet is forcing Windows servers to mine cryptocurrency
What is microsegmentation? How getting granular improves network security
How to eliminate the default route for greater security
Smart, Smarter… Dumbest…

While the evolution of new smartphones creates more possibilities for the user, these new devices also creates more possibilities for hackers. The post Smart, Smarter… Dumbest… appeared first on WeLiveSecurity

Venture into the security thickets at CyberThreat18
Hey, you know what the internet needs? Yup, more industrial control systems for kids to hack
New Monero mining malware infected 500K PCs by using 2 NSA exploits

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0262