Menu

Category Archives: Security

Articles about security

Russia could chop vital undersea web cables, warns Brit military chief

LinuxSecurity.com: An erlang TLS server configured with cipher suites using RSA key exchange, may be vulnerable to an Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) against RSA, which when exploited, may result in plaintext recovery of encrypted messages and/or a Man-in-the-middle (MiTM)

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Brit film board proposed as overlord of online pr0nz age checks
Is source code inspection a security risk? Maybe not, experts say

LinuxSecurity.com: Update to 0.18.6

LinuxSecurity.com: USN-3509-1 introduced a regression in the Linux kernel for Ubuntu 16.04 LTS.

LinuxSecurity.com: USN-3509-2 introduced a regression in the Linux HWE kernel for Ubuntu 14.04 LTS.

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any questions? Just ask. NC County Crippled by Ransomware Attack Recently, a county in North Carolina was the target of a […]

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 11.0 (Ocata). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Synaptics Says Claims of a Keylogger in HP Laptops are False

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Man gets friend kidnapped to steal $1.8 million worth of Ethereum

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Satellite 5.8 and Red Hat Satellite 5.8 ELS. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: libxml2 could be made to crash or run arbitrary code if it opened a specially crafted file.

Permissions Flaw Found on Azure AD Connect

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

85 Credential-Stealing Apps Found on Google Play Store
19-Year-Old ROBOT Flaw Resurfaces to Haunt Popular Websites
Fox-IT reveals hackers hijacked its DNS records, spied on clients’ files
Cybersecurity Trends 2018: The costs of connection

To help the reader navigate through the maze of such threats, ESET’s thought leaders have zeroed in on several areas that top the priority list in our exercise in looking forward. The post Cybersecurity Trends 2018: The costs of connection appeared first on WeLiveSecurity

The Mirai botnet: three men plead guilty after weaponizing the Internet of Things

LinuxSecurity.com: An update for go-toolset-7 and go-toolset-7-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

UK.gov delays biometrics strategy again – but cops will STILL USE the tech
NIST Releases New Cybersecurity Framework Draft
Smashing Security podcast #057: Mikko – live from the sauna – talks Bitcoin security

LinuxSecurity.com: The package quagga before version 1.2.2-1 is vulnerable to denial of service.

LinuxSecurity.com: The package qt5-webengine before version 5.10.0-1 is vulnerable to multiple issues including arbitrary code execution, cross-site scripting, access restriction bypass, content spoofing and information disclosure.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

OK, OK, MIRA-I DID IT: Botnet-building compsci kid comes clean

LinuxSecurity.com: An update that solves three vulnerabilities and has three An update that solves three vulnerabilities and has three An update that solves three vulnerabilities and has three fixes is now available. fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Hackers behind Mirai botnet & DYN DDoS attacks plead guilty
19-Year-Old TLS Vulnerability Weakens Modern Website Crypto

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office Outlook is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: An update for eap7-jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 7.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: A regression was added by the patch introduced in version 0.5.0-2+deb7u2 to fix CVE-2017-16927: xrdp-sesman started to segfault in libscp. For Debian 7 “Wheezy”, these problems have been fixed in version

LinuxSecurity.com: An update for rh-java-common-lucene5 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-java-common-lucene is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Fix to directory traversal attacks (CVE-2017-17042).

LinuxSecurity.com: Update to 2.1 —- Update to 2.0, Initial support for aarch64 images and associated SBCs

Banker jailed for helping criminals who stole millions using Dridex malware
Barclays employee sentenced for aiding Dridex money launderers
Memes: the explanation of nearly everything – including computer viruses

We still don’t have a solid scientific theory of memes; nonetheless, they already allow us to understand why certain things happen the way they do. Memes are “alive”; they reproduce, mutate, and evolve according to Darwinian laws. The post Memes: the explanation of nearly everything – including computer viruses appeared first on WeLiveSecurity

File with 1.4 Billion Hacked and Leaked Passwords Found on the Dark Web
Newly Revealed Flaw in Intel Processors Allows Undetectable Malware
Australian airport hack was ‘a near miss’ says government’s cybersecurity expert
One per cent of all websites probably p0wned each year, say boffins
Up to ‘ONE BEEELLION’ vid-stream gawpers toil in crypto-coin mines
Put down the eggnog, it’s Patch Tuesday: Fix Windows boxes ASAP
Intel to slap hardware lock on Management Engine code to thwart downgrade attacks
I, Robot? Aiiiee, ROBOT! RSA TLS crypto attack pwns Facebook, PayPal, 27 of 100 top domains

Risk Level: Very Low. Type: Trojan.

Tenable’s response to folks upset at AWOL features: A 150-emails-a-minute spam storm
It’s time to patch your Microsoft and Adobe software again against vulnerabilities
What is the cyber kill chain?
Kaspersky dragged into US govt’s trashcan as weaponized blockchain agile devops mulled
Microsoft December Patch Tuesday Update Fixes 34 Bugs
Argy-bargy Argies barge into Starbucks Wi-Fi with alt-coin discharges

security update

Sophisticated ‘MoneyTaker’ group stole millions from Russian & US banks
New Spider Ransomware Comes With 96-Hour Deadline

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2017:3402

Bitfinex cryptocurrency exchange hit by massive DDoS attacks​
Brrr! It’s a snow day and someone has pwned the chuffin’ school heating
Cryptocurrency in kilowatt hours: Counting the costs of anonymous transactions

The energy costs are not the only charges in a transaction: the bitcoin network itself levies a charge which, according to a blog from Valve, the gaming provider behind the Steam network, has skyrocketed from $0.20 in 2016 to $20 per transaction today The post Cryptocurrency in kilowatt hours: Counting the costs of anonymous transactions […]

This Fidget spinner app is sending other apps data to Chinese server

It has been a turbulent year of devastating ransomware attacks (e.g. NotPetya) and gut-wrenching breaches (e.g. Equifax). Undoubtedly, the question on everyone’s mind is, “what’s in store for us in the New Year?” Webroot’s top 10 cybersecurity predictions for 2018 covers everything from ransomware and breaches to mobile, cryptocurrency, and government.We’ve grouped our predictions to […]

Watch: How to Pick a Lock
Dyn Inc. DDoS anniversary, and the truth about the Reaper botnet

LinuxSecurity.com: Fix omapi SD leak (#1523547)