Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

Uber dismissive about security flaw that lets hackers bypass its 2FA

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: It was discovered that Smarty, a PHP template engine, was vulnerable to code-injection attacks. An attacker was able to craft a filename in comments that could lead to arbitrary code execution on the host running Smarty.

‘WHAT THE F*CK IS GOING ON?’ Linus Torvalds explodes at Intel spinning Spectre fix as a security feature
Popular Sonic the HedgeHog Apps at Risk of Leaking User Data to Unverified Servers

security update

LinuxSecurity.com: An update for java-1.6.0-sun is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several security issues were fixed in GIMP.

Evrial Info-Stealing Trojan Modifies Addresses to Steal Cryptocurrency

From Facebook to LinkedIn, social media is flat-out rife with phishing attacks. You’ve probably encountered one before… Do fake Oakley sunglasses sales ring a bell? Phishing attacks attempt to steal your most private information, posing major risks to your online safety. It’s more pressing than ever to have a trained eye to spot and avoid […]

Google Denies Using Google Arts & Culture App to Collect Selfie Data
Get 29% Off This 6-Sheet Micro-Cut Paper and Credit Card Shredder
Up to 40,000 OnePlus customers potentially hit by credit card hack

The breach put at risk ‘only’ the customers who entered their payment data on oneplus.net between the middle of November 2017 and January 11, 2018. Those who paid with previously saved credit card details or via PayPal are believed to be out of harm’s way. The post Up to 40,000 OnePlus customers potentially hit by […]

The people you call when you’ve had a breach | Salted Hash Ep 15
How To Keep Yourself Safe During Online Gaming
UK Army chief: Russia could totally pwn us with cable-cutting and hax0rs
HMRC dev support team cc blurtfest: Over 1,400 email addresses blabbed

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The Reg visits London Met Police’s digital and electronics forensics labs
World Economic Forum: Cyberthreats rising in prominence in global risk landscape

The latest survey marks a shift from optimism regarding technological risks in the previous years. The heightened levels of worry come on the back of an escalation in cybersecurity threats, which, as noted by the WEF, are growing in prevalence and in disruptive potential alike. The post World Economic Forum: Cyberthreats rising in prominence in […]

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Dridex redux, with FTP serving the nasties
Smut site fingered as ‘source’ of a million US net neutrality comments
Meltdown/Spectre week three: World still knee-deep in something nasty
China flaunts quantum key distribution in-SPAAACE by securing videoconference
Sweatcoin App Pays You Cryptocurrency To Get Fit
Hacker Infects Gas Pumps with Code to Cheat Customers

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: It was discovered that PHP5 was vulnerable to a reflected cross-site scripting (XSS) attack on the PHAR 404 error page by manipulating the URI of a request for a .phar file. This issue is only exploitable if the web server is configured to handle phar files using PHP5.

Android Malware in gaming apps on Play Store downloaded 4 million times
Crackas with Attitude’ hacker posed as CIA Chief to access secret data
State-Sponsored Malware Campaign Hits Users Across 21 Countries
Rogue Chrome, Firefox Extensions Hijack Browsers; Prevent Easy Removal
Mozilla mandates that new Firefox features rely on encrypted connections
Unlocked: The hidden love note on the grave of America’s first crypto power-couple

“How to buy Bitcoin” dominated Google how-to searches in 2017, ranking third overall. With the hype surrounding cryptocurrency at a palpably all-time high, now is a better time than ever to cover the essentials of keeping cryptocurrencies safe. If you are just getting into the crypto space or you’ve known what ‘HODL’ means for a […]

Opponents Vow to Continue the Fight after Trump Reauthorizes Domestic Spying Law
America restarts dodgy spying program – just as classified surveillance abuse memo emerges
OnePlus website hacked; credit card data of 40,000 users stolen

security update

OnePlus Confirms Credit Card Breach Impacted Up to 40,000 Customers

Type: Vulnerability. Microsoft Office for MAC is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

New Dridex Variant Emerges With An FTP Twist
Apple Preps ChaiOS iMessage Bug Fix for Next Week
Facebook Hacking Android Malware GhostTeam Found in 53 Play Store Apps

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any questions? Just ask. Hospital Pays Ransom to Restore Systems, Despite Having Backups In the first cyberattack of 2018 to hit […]

There are other, legal ways to nab Microsoft emails, privacy groups remind Supremes
Man Admits to Directing DDoS Attacks Across the US

LinuxSecurity.com: It was discovered that there was a denial-of-service attack in the libgd2 image library. A corrupt file could have exploited a signedness confusion leading to an infinite loop.

LinuxSecurity.com: It was discovered that there was an injection vulnerability in the rsync file-copying tool. For Debian 7 “Wheezy”, this issue has been fixed in rsync version

Are mobile devices insecure by nature?

Granted, not all that glitters is gold, and mobiles also come with some drawbacks in terms of the protection of information. There are a number of risks that users may face when trying to secure their information on mobiles and tablets. The post Are mobile devices insecure by nature? appeared first on WeLiveSecurity

Delve into the hidden corners of security at CyberThreat18

LinuxSecurity.com: The cPanel Security Team discovered that awstats, a log file analyzer, was vulnerable to path traversal attacks. A remote unauthenticated attacker could leverage that to perform arbitrary code execution.

Two things will survive a nuclear holocaust: Cockroaches and crafty URLs like ғасеьоок.com

security update

LinuxSecurity.com: Tavis Ormandy discovered a vulnerability in the Transmission BitTorrent client; insecure RPC handling between the Transmission daemon and the client interface(s) may result in the execution of arbitrary code if a user visits a malicious website while Transmission is running.

LinuxSecurity.com: The package bind before version 9.11.2.P1-1 is vulnerable to denial of service.

LinuxSecurity.com: The package perl-xml-libxml before version 2.0130-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package transmission-cli before version 2.92-8 is vulnerable to arbitrary command execution.

LinuxSecurity.com: The package nrpe before version 3.2.1-3 is vulnerable to arbitrary command execution.

LinuxSecurity.com: The package irssi before version 1.0.6-1 is vulnerable to denial of service.

You get a lawsuit! And you get a lawsuit! And you! Now Apple sued over CPU security flaws
Sprawling Mobile Espionage Campaign Targets Android Devices

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Fix permissions on rootsh log directory to limit it to root.

Sad-sack Anon calling himself ‘Mr Cunnilingus’ online is busted for DDoSing ex-bosses
6 years jail time for ‘one of the largest’ dark web drug dealer
Google Awards Record $112,500 Bounty for Android Exploit Chain

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0094

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0093

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0093

LinuxSecurity.com:

LinuxSecurity.com: This is new version of irssi. It contains security fixes for CVE-2018-5205 CVE-2018-5206 CVE-2018-5207 CVE-2018-5208 .

LinuxSecurity.com: – Resolves: #1510351 – CVE-2017-14992 – built docker @projectatomic/docker-1.13.1 commit 584d391 – built docker-novolume-plugin commit 385ec70 – built rhel-push-plugin commit af9107b – built docker-lvm-plugin commit 8647404 – built docker-runc @projectatomic/docker-1.13.1 commit 1c91122 – built docker-containerd @projectatomic/docker-1.13.1 commit 62a9c60 – built

chaiOS “Text Bomb” Can Freeze & Crash Your iPhone

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.