Menu

Category Archives: Security

Articles about security

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Someone is touting a mobile, PC spyware platform called Dark Caracal to governments
Intel Says Firmware Fixes for Spectre and Meltdown Affecting Newer Chips
Researcher reports how to hack Facebook account with Oculus Integration
Less than 10% of Gmail users have enabled two-factor authentication
F-35 ‘incomparable’ to Harrier jump jet, top test pilot tells El Reg
Virtual Reality (VR) Porn App Exposed Personal Data of 20k Users
Google fuels up Chromecast Wi-Fi flooding fix
And Oracle E-biz suite makes 3: Package also vulnerable to exploit used by crytpo-currency miner
CES 2018 cybersecurity: Now in every single ‘whatchamacallit’

Not content anymore to just have a bed made of soft plushy stuff, now you can adjust everything about the bed, from electronically sitting up in bed to the lighting surrounding your nap: connected digital technology everywhere. The post CES 2018 cybersecurity: Now in every single ‘whatchamacallit’ appeared first on WeLiveSecurity

The first lawsuits to save net neutrality have been filed
Trends 2018: Personal data in the new age of technology and legislation

The depth of data collected from our online habits could easily allow profiles to be constructed, showing what may be considered extremely personal interests, drawing on information that we don’t realize someone is collecting. The post Trends 2018: Personal data in the new age of technology and legislation appeared first on WeLiveSecurity

Smashing Security #061: Fallout over Hawaii missile false alarm
VTech fondleslabs for kids ‘still vulnerable’ despite sanctions
Mozilla edict: ‘Web-accessible’ features need ‘secure contexts’
North Korea’s finest spent 2017 distributing RATs, wipers, and phish
Industrial systems scrambling to catch up with Meltdown, Spectre

LinuxSecurity.com: – Update to 52.5.3 – Patched for mozilla bug-1427870 (spectre mitigation)

LinuxSecurity.com: Security fix for CVE-2018-5702 (Mitigate dns rebinding attacks against daemon)

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: – Update to 52.5.3 – Patched for mozilla bug-1427870 (spectre mitigation)

New macOS malware hijacks DNS settings and takes screenshots
Attackers Use Microsoft Office Vulnerabilities to Spread Zyklon Malware

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

Who’s using 2FA? Sweet FA. Less than 1 in 10 Gmail users enable two-factor authentication

LinuxSecurity.com: It was discovered that multiple encryption key classes in the Librariescomponent of OpenJDK did not properly synchronize access to their internaldata. This could possibly cause a multi-threaded Java application to applyweak encryption to data because of the use of a key that was zeroed out.(CVE-2018-2579)Note: If the web browser plug-in provided by the icedtea-web […]

Oracle Ships 237 Fixes in Latest Critical Patch Update

security update

HTML5 may as well stand for Hey, Track Me Longtime 5. Ads can use it to fingerprint netizens
New Android Malware records audio, video & steals WhatsApp messages

Type: Vulnerability. Multiple CPU Hardwares are prone to an information-disclosure vulnerability; fixes are available.

Potent Skygofree Malware Packs ‘Never-Before-Seen’ Features

LinuxSecurity.com: Rebase `osc` and `osc-source_validator` to new versions for security fixes for CVE-2017-9274

LinuxSecurity.com: Rebase `osc` and `osc-source_validator` to new versions for security fixes for CVE-2017-9274

Mozilla Joins U.S. Attorneys General In Bid to Restore Net Neutrality
4 Malicious Chrome Extensions Put 500k Users at Risk of Click Fraud
Former Santander bank manager pleads guilty to computer misuse crimes
Fighting cyber attacks with nuclear weapons
Carphone Warehouse faces hefty fine for 2015 breach

The attackers gained access to a range of customer data such as names, addresses, phone numbers, dates of birth, and marital status. Making matters worse, the historical payment card details of some 18,000 customers were also compromised. The post Carphone Warehouse faces hefty fine for 2015 breach appeared first on WeLiveSecurity

Hawaii’s missile alert agency keeps its password on a Post-it note
Mental Models & Security: Thinking Like a Hacker
Android security: This newly discovered snooping tool has remarkable spying abilities
Spectre and Meltdown patches causing trouble as realistic attacks get closer
Biggest vuln bombshell in forever and storage industry still umms and errs over patches
CES 2018: Blockchain will solve everything

The first obvious candidate was banking, a sector that has been hard at work trying to implement blockchain to secure the vast troves of digital transactions that happen every microsecond of every day. The post CES 2018: Blockchain will solve everything appeared first on WeLiveSecurity

Wanna motivate staff to be more secure? Don’t bother bribing ’em
Another round of click-fraud extensions pulled from Chrome Store
Beware! A new bug can crash iOS and macOS with a single text message

LinuxSecurity.com: Multiple vulnerabilities have been found in rsync, the worst of which could allow remote attackers to bypass access restrictions.

BIND comes apart thanks to ancient denial-of-service vuln

security update

Hospital injects $60,000 into crims’ coffers to cure malware infection

LinuxSecurity.com: An update for microcode_ctl is now available for Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red

LinuxSecurity.com: The Check Point Research Team discovered that the XBMC media center allows arbitrary file write when a malicious subtitle file is downloaded in zip format. This update requires the new dependency libboost-regex1.49.

LinuxSecurity.com: An update for linux-firmware is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions, and Red Hat Enterprise Linux 7.3

LinuxSecurity.com: Jayachandran Palanisamy of Cygate AB reported that BIND, a DNS server implementation, was improperly sequencing cleanup operations, leading in some cases to a use-after-free error, triggering an assertion failure and crash in named.

Google Chrome Once Again Target of Malicious Extensions

LinuxSecurity.com: An update that solves 14 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Transmission could be made to run arbitraty code.

LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Lenovo Patches Networking OS Vulnerability Dating Back to 2004
BlackWallet hacked: Hackers replace DNS server, steal $400k in Stellar

security update

LinuxSecurity.com: Qtpass password generation had a bug where only a 1000 different passwords where possible https://github.com/IJHack/QtPass/issues/338 —- Upstream release

LinuxSecurity.com: Qtpass password generation had a bug where only a 1000 different passwords where possible https://github.com/IJHack/QtPass/issues/338

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves 7 vulnerabilities and has three fixes is now available.

Risk Level: Very Low. Type: Trojan.

Android snoopware Skygofree can pilfer WhatsApp messages
New BitTorrent Flaw Puts Linux & Windows devices at risk of hacking
UK’s Just Eat faces probe after woman tweets chat-up texts from ‘delivery guy’
Smart card forwarding with Fedora
Scammers and jobhunters

It’s easier to have scruples about how you earn your living when you’re not one of millions of people chasing just a few thousand jobs. The post Scammers and jobhunters appeared first on WeLiveSecurity

New Mirai botnet species ‘Okiru’ hunts for ARC-based kit
Congress Renews Warrantless Surveillance-And Makes It Even Worse
The “Doublespeak” of Responsible Encryption
Wi-Fi Alliance announces WPA3 to secure modern networks
How I’ve captured all passwords trying to ssh into my server
Cybersecurity quiz winners rewarded with malware-infected USB sticks

LinuxSecurity.com: This release does a complete update of the CA list. This includes removing the StartCom and WoSign certificates to as they are now untrusted by the major browser vendors.

LinuxSecurity.com: New kernel packages are available for Slackware 14.0 and 14.2 to fix security issues.

LinuxSecurity.com: A vulnerability has been discovered in GraphicsMagick, a collection of image processing tools, which may result in a denial of service.

Canada charges chap alleged to run stolen data-mart Leakedsource
Bad benchmarks bedevil boffins’ infosec efforts
Operator of hacked password service Leakedsource.com arrested

LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Police distributed malware infected USBs as cybersecurity quiz prizes

LinuxSecurity.com: It was discovered that multiple integer overflows in the GIF image loader in the GDK Pixbuf library may result in denial of service and potentially the execution of arbitrary code if a malformed image file is opened.

security update

LinuxSecurity.com: Several security issues were fixed in GDK-PixBuf.

Now Meltdown patches are making industrial control systems lurch

LinuxSecurity.com: David Sopas discovered that Kohana, a PHP framework, was vulnerable to a Cross-site scripting (XSS) attack that allowed remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection mechanism in system/classes/Kohana/Security.php. This issue

OnePlus denies checkout page hack amid credit card fraud reports