Menu

Category Archives: Security

Articles about security

Researcher: DJI RCE-holes offered me $500 after I found Heartbleed etc on its servers
Mr. Robot: Now we know where Tyrell was hiding

Since nothing is what is seems, it’s hard to be sure who was really behind the attacks shown in the series. The world still believes fsociety was responsible (and they themselves do too, to an extent), but the truth is that there is a group in the shadows that is pulling all the strings. The […]

Ransomware Attack Involving Scarab Malware Sends Over 12M Emails in 6 Hours
Boffins craft perfect ‘head generator’ to beat facial recognition

LinuxSecurity.com: New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Surprise: Android apps are riddled with trackers
Open source nameserver used by millions needs patching
Chinese IT security bods accused of siphoning US GPS, biz blueprints
Uber, quit shoveling money into the fire for one second and explain that hack – US senators

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Bulletproof Coffee lacks bulletproof security: Nerd brain juice biz hacked, cards gulped
Deleting anyone’s Facebook photo, a bug that earned researcher $10,000
That $10,000 Facebook bug: Photos shafted, addicts screwed by polls
Barracuda gobbled up by private equity sharks
Imgur Confirms 2014 Breach of 1.7 Million User Accounts

LinuxSecurity.com: Berkeley DB could be made to expose sensitive information.

LinuxSecurity.com: Berkeley DB could be made to expose sensitive information.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash or run programs as an administrator.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash or run programs as an administrator.

LinuxSecurity.com: Samba could be made to expose sensitive information over the network.

LinuxSecurity.com: formail could be made to crash or run programs if it processed specially crafted mail.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Hackers can Exploit Load Planning Software to Capsize Balance of Large Vessels
Researchers Convert Human Bacteria into World’s Tiniest Tape Recorder
What keeps IT administrators up at night? Ransomware, for one | Salted Hash Ep 8
Newly Published Exploit Code Used to Spread Mirai Variant
Looking for scrubs? Nah, NHS wants white hats – the infosec techie kind
Don’t shame idiots about their idiotically weak passwords
Facebook flaw allowed unauthorised users to delete any photo
Imgur hackers stole 1.7 million email addresses and passwords

LinuxSecurity.com: An update for samba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for samba is now available for Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6 and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

.GIF garage Imgur plugs 1.7 million-subscriber creds breach
Exim-ergency! Unix mailer has RCE, DoS vulnerabilities
Anonymous Muslim Group Confusing ISIS with Porn and Fake News

LinuxSecurity.com: An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is now available. now available.

Fake Symantec Blog Caught Spreading Proton macOS Malware

LinuxSecurity.com: An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now available. fixes is now available.

Imgur was hacked in 2014; affecting 1.7M users

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

“ProtonMail Contacts” world’s first encrypted contacts manager is here

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: An update that solves 33 vulnerabilities and has 7 fixes is An update that solves 33 vulnerabilities and has 7 fixes is An update that solves 33 vulnerabilities and has 7 fixes is now available. now available.

security update

security update

LinuxSecurity.com: An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now available. fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

MS Office’ Default Function Can Be Used to Create Self-Replicating Malware

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan, Worm.

Blockchain Wallet CoinPouch Hacked; Verge Coins Stolen
SAML Post-Intrusion Attack Mirrors ‘Golden Ticket’
Seek ‘passion’ and tech skills will follow, say recruiting security chiefs
New reality in European banking looming large: the lowdown

At the heart of the regulation is the requirement for banks to allow licensed third-party providers (TPPs) of financial services to access securely their customer-account data, as long as the customer has given their prior consent. The post New reality in European banking looming large: the lowdown appeared first on WeLiveSecurity

UK emergency crews get 4G smartmobes as monkeys attempt to emerge from Reg’s butt
EU’s data protection bods join the party to investigate Uber breach
‘Treat infosec fails like plane crashes’ – but hopefully with less death and twisted metal
Busy Browsers attract Black Friday Burglars

Just as in past decades when cash drawers and bank vaults were targeted for theft, today’s e-shops and online banks have fallen under the scope of cybercriminals. Their “digital-focus” is just an evolutionary step beyond robbing stagecoaches in the Wild West, and banks in the 20th century. The post Busy Browsers attract Black Friday Burglars […]

Linus Torvalds on security: ‘Do no harm, don’t break users’
Firefox to warn users who visit p0wned sites

LinuxSecurity.com: An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two fixes is now available. fixes is now available.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in impersonation of Kerberos services, denial of service, sandbox bypass or HTTP header injection.

LinuxSecurity.com: Two vulnerabilities were discovered in the Open Ticket Request System which could result in disclosure of database credentials or the execution of arbitrary shell commands by logged-in agents.

Alleged HBO hacker identified, charged and indicted

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

security update

Firefox to collaborate with HaveIBeenPwned to alert users on data breach

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: update to 9.5.10, per release notes http://www.postgresql.org/docs/9.5/static/release-9-5-10.html

LinuxSecurity.com: Tobias Schneider discovered that libspring-ldap-java, a Java library for Spring-based applications using the Lightweight Directory Access Protocol, would under some circumstances allow authentication with a correct username but an arbitrary password.

LinuxSecurity.com: update to 9.6.6 per release notes: https://www.postgresql.org/docs/9.6/static/release-9-6-6.html

LinuxSecurity.com: An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two fixes is now available. fixes is now available.

Tips for Making Your Business Secure from Digital Crimes
Royal Navy destroyer leaves Middle East due to propeller problems
‘Data is the new oil’: F-Secure man on cartels, disinformation and IoT
World’s top websites record all your browsing movements
Smartphone adoption among older Americans continues growth spurt

Some three-quarters of users up to 34 years of age reported that they “definitely” or “probably” use their phone too much. Almost half (47 percent) of all ages said they make a conscious effort to pare back their mobile phone time, most commonly by keeping their devices in their bag or pocket or by switching […]

US indicts alleged culprit of HBO hack-and-extort campaign

Between approximately July 23 and 29, Mesri reportedly engaged in his blackmail campaign. After the TV network didn’t pay the required $6 million in digital cryptocurrency, he began leaking portions of the stolen data on July 30. The post US indicts alleged culprit of HBO hack-and-extort campaign appeared first on WeLiveSecurity

To fix Intel’s firmware fiasco, wait for Christmas Eve or 2018
Samba needs two patches, unless you’re happy for SMB servers to dance for evildoers
Devs working to stop Go math error bugging crypto software
Smashing Security podcast #053: Game of Thrones, a major Amazon cloud leak, and web tracking gone crazy

LinuxSecurity.com: An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

security update

security update

3 Cybersecurity Predictions for 2018
HP to Patch Bug Impacting 50 Enterprise Printer Models

Risk Level: Very Low. Type: Trojan.