Menu

Category Archives: Security

Articles about security

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst with a passion for all things security. Any questions? Just ask. Researchers Find Major Security Flaws in Modern Processors Newly discovered bugs, Meltdown and Spectre, exploit critical flaws in the architecture […]

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, information leaks, privilege escalation or the execution of arbitrary code.

Woo-yay, Meltdown CPU fixes are here. Now, Spectre flaws will haunt tech industry for years

It can be daunting to step into the often unfamiliar world of security, where you can at times be inundated with technical jargon (and where you face real consequences for making the wrong decision). Employing an MSP or MSSP is oftentimes in best interest of small and medium businesses (SMBs). In a study performed by […]

LinuxSecurity.com: Multiple researchers have discovered a vulnerability in Intel processors, enabling an attacker controlling an unprivileged process to read memory from arbitrary addresses, including from the kernel and all other processes running on the system.

LinuxSecurity.com: An industry-wide issue was found in the way many modern microprocessordesigns have implemented speculative execution of instructions (a commonlyused performance optimization). There are three primary variants of theissue which differ in the way the speculative execution can be exploited.Variant CVE-2017-5715 triggers the speculative execution by utilizingbranch target injection. It relies on the presence of […]

LinuxSecurity.com: An update for microcode_ctl is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0023

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0029

Microsoft patches Windows to cool off Intel’s Meltdown – wait, antivirus? Slow your roll

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0030

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0008

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0013

Private Details of 240,000 DHS Employees Accessed after Data Breach
Vendors Share Patch Updates on Spectre and Meltdown Mitigation Efforts
Top 7 Cyber Forensic Tools
Bogus security apps in the Google Play store stole users’ info and tracked their location
US Homeland Security breach compromised personal info of 200,000+ staff
ESET Research: Wauchos now headed for extinction?

As Wauchos was sold on underground forums, there were various monetization schemes. One of them was to use the form grabber plugin to steal passwords for online accounts. The post ESET Research: Wauchos now headed for extinction? appeared first on WeLiveSecurity

New Android Malware Disguised as Uber App

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 13 fixes is An update that solves 5 vulnerabilities and has 13 fixes is An update that solves 5 vulnerabilities and has 13 fixes is now available. now available.

LinuxSecurity.com: An update that solves 17 vulnerabilities and has 13 fixes An update that solves 17 vulnerabilities and has 13 fixes An update that solves 17 vulnerabilities and has 13 fixes is now available. is now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 26 fixes is An update that solves 5 vulnerabilities and has 26 fixes is An update that solves 5 vulnerabilities and has 26 fixes is now available. now available.

32% off Kidde Carbon Monoxide Alarm with Display and 10 Year Battery – Deal Alert

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0014

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0012

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0007

Spectre? Meltdown? F*CKWIT? Calm down and make yourself some tea

LinuxSecurity.com: It was discovered that there were two vulnerabilities in the imagemagick image manipulation program: CVE-2017-1000445: A null pointer dereference in the MagickCore

Meltdown, Spectre: The password theft bugs at the heart of Intel CPUs

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for linux-firmware is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for linux-firmware is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

We translated Intel’s crap attempt to spin its way out of CPU security bug PR nightmare
Smashing Security podcast #059: An intro to Bitcoin and Blockchain

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Apple macOS so secure some apps can’t be easily deleted
Today’s CPU vulnerability: what you need to know
Attention, vSphere VDP backup admins: There is a little remote root hole you need to patch…
Intel In Security Hot Seat Over Reported CPU Design Flaw

LinuxSecurity.com: Upstream announcement: Welcome to **phpMyAdmin 4.7.7**, a regular maintenance release containing bug fixes and a security fix. The security vulnerability is a XSRF/CSRF flaw; you can read more at https://www.phpmyadmin.net/security/PMASA-2017-9/ As a result of this, we recommend all users upgrade immediately. A CVE-ID has been requested but not yet

The F*CKWIT Intel chip flaw. Ready yourself for patches
Security Flaws in GPS Trackers Puts Millions of Devices’ Data at Risk
Multiple Intel Processors Generations Hit by Serious Security Flaw
Teen girl facing up to 10 years for sending nude selfie
Bug-finders’ scheme: Tick-tock, this tech’s tested by flaws.. but who the heck do you tell?

LinuxSecurity.com: Jason Crain discovered a overflow vulnerability in the poppler PDF rendering library. For Debian 7 “Wheezy”, this issue has been fixed in poppler version

Opera browser updated to stop crypto-currency mining
Ransomware to hit cloud computing in 2018, predicts MIT
Critical Flaw Reported In phpMyAdmin Lets Attackers Damage Databases
Driving Open Standards in a Fragmented Networking Landscape
Security catch-up: Nigerian prince email ring cops collar … Louisiana OAP?
Now is the best time to craft your breach response

Taking time to think logically and deliberately about your assets can help you determine what needs to be secured. Preparing for the worst can help you see the best course of action to prevent those emergencies in the present. The post Now is the best time to craft your breach response appeared first on WeLiveSecurity

LinuxSecurity.com: An update for eap7-jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 7.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Brazil says it has bagged Royal Navy flagship HMS Ocean for £84m
Shopped in Forever 21? There was bank-card-slurping malware in it for, like, forever
Code for Satori malware posted on Pastebin
MacOS LPE Exploit Gives Attackers Root Access
VMware Issues 3 Critical Patches for vSphere Data Protection
Kernel-memory-leaking Intel processor design flaw forces Linux, Windows redesign
The mysterious case of the Linux Page Table Isolation patches
Forever 21 Says PoS Systems Exposed Customer Data for 8 Months
A desperate YouTube moderator scam spam
Iranians resist internet censorship amid deadly street protests
Automatic autofill of your username and password? Not a good idea
15-year-old Unpatched Root Access Bug found in Apple’s macOS
Multiple-guess quiz will make Brit fliers safer, hopes drone-maker DJI

LinuxSecurity.com: It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for CIP Safety, IWARP_MPA, NetBIOS, Profinet I/O and AMQP, which result in denial of dervice or the

Smartphone sensors can leak the four-digit PIN code to hackers
Reddit user leaks alleged Game of Thrones Season 8 script pages
2017’s Top hacks and data breaches

security update

You are not alone, WhatsApp is down for many

LinuxSecurity.com: Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service (application crash) or potentially the execution of arbitrary code if malformed files are opened.

Nintendo Switch Hacked to Run Pirated Games
Snowden Explains Why Telegram Messenger App is Unsafe

security update

LinuxSecurity.com: Update to 1.9.9. This release addresses security vulnerabilities discovered by Cure53. Details can be found in the Security Audit Report: https://enigmail.net/ download/other/Enigmail%20Pentest%20Report%20by%20Cure53%20-%20Excerpt.pdf

LinuxSecurity.com: A vulnerability has been discovered in Asterisk, an open source PBX and telephony toolkit, which may result in resource exhaustion and denial of service.

PS4 Jailbreak possible with newly identified exploit
Victim of Swatting: Police kills Innocent man after Call of Duty gamer prank call

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Asterisk, an open source PBX and telephony toolkit, which may result in denial of service, information disclosure and potentially the execution of arbitrary code.

How Classical Cryptography Will Survive Quantum Computers

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

security update

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service, information disclosure or spoofing of sender’s email addresses.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

security update

Chrome Extension with 105,000 installs is a Cryptocurrency Miner

LinuxSecurity.com: Update to 1.9.9. This release addresses security vulnerabilities discovered by Cure53. Details can be found in the Security Audit Report: https://enigmail.net/ download/other/Enigmail%20Pentest%20Report%20by%20Cure53%20-%20Excerpt.pdf

LinuxSecurity.com: Update to 0.8.3, fixing CVE-2017-15612 and CVE-2017-16876

LinuxSecurity.com: A vulnerability was found in the Mercurial version control system which could lead to remote arbitrary code execution.

Bitcoin exchange hit by DDoS attack after kidnapping of its official (Updated)