Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: An update for httpd24, httpd24-curl, httpd24-httpd, httpd24-mod_auth_kerb, and httpd24-nghttp2 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Reaper malware outshines Mirai; hits millions of IoT devices worldwide
Microsoft’ New Feature to Protect Windows 10 from Ransomware

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Latest Sofacy Campaign Targeting Security Researchers
DHS Alert on Dragonfly APT Contains IOCs, Rules Likely to Trigger False Positives
FBI failed to break into nearly 7000 mobiles due to encryption
Fake cryptocurrency trading apps on Google Play

With all the hype around cryptocurrencies, cybercriminals are trying to grab whatever new opportunity they can – be it hijacking users’ computing power to mine cryptocurrencies via browsers or by compromising unpatched machines, or various scam schemes utilizing phishing websites and fake apps. The post Fake cryptocurrency trading apps on Google Play appeared first on […]

Google: This surge in Chrome HTTPS traffic shows how much safer you now are online
Hackers target security researchers with malware-laden document

LinuxSecurity.com: An update for rh-nodejs4, rh-nodejs4-node-gyp, and rh-nodejs4-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Multiple vulnerabilities have been found in Dnsmasq, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenJPEG, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in the PCRE Library, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Go, the worst of which may result in the execution of arbitrary commands.

TODAY IS 22nd Oct 2017, AND IT’S CAPS LOCK DAY
US warns of ongoing attacks on energy firms and critical infrastructure

security update

Found a flaw in a popular Android app? Google might give you $1000
New Magniber Ransomware Targets South Korea, Asia Pacific
Your Browser Could Be Mining Cryptocurrency For a Stranger

LinuxSecurity.com: An update that solves 8 vulnerabilities and has three fixes An update that solves 8 vulnerabilities and has three fixes An update that solves 8 vulnerabilities and has three fixes is now available. is now available.

A plethora of patches, Kaspersky hits back, new hope for Wannacry Brit hero – and more
Hackers infect Mac users with Proton malware using Elmedia Player

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata An update that solves 8 vulnerabilities and has one errata An update that solves 8 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

security update

security update

LinuxSecurity.com: Two unspecified vulnerabilities were discovered in OpenJFX, a rich client application platform for Java. For the stable distribution (stretch), these problems have been fixed in

Malware hidden in vid app is so nasty, victims should wipe their Macs
‘IOTroop’ Botnet Could Dwarf Mirai in Size and Devastation, Says Researcher

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.58, which includes additional changes, such as performance improvements, bug fixes, new features, and possibly incompatible

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Google might block embedded cryptocurrency mining with new Chrome feature
Necurs-Based DDE Attacks Now Spreading Locky Ransomware
Canada’s Spy Agency Releases its Cyber-Defense Tool for Public
Threatpost News Wrap, Oct. 20, 2017
Top tips to keep cybercriminals out of your home

Better security of your internet router is one of the simplest ways in which you can cyber-safeguard your home, and the technology you keep there. The post Top tips to keep cybercriminals out of your home appeared first on WeLiveSecurity

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Cisco Warns 69 Products Impacted by KRACK

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Your data will get hacked anyway so you might as well give up protecting it
Canadian spooks release their own malware detection tool

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Swedish Trains Schedule Gets Derailed by Cyber Attack In the last week, several computer systems belonging […]

Hack apps, attack code drawbacks for cash stacks, Google yaks

LinuxSecurity.com: Liao Xinxi discovered that jackson-databind, a Java library used to parse JSON and other data formats, did not properly validate user input before attemtping deserialization. This allowed an attacker to perform code execution by providing maliciously crafted input.

LinuxSecurity.com: An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one errata is now available. errata is now available.

Make America late again: US ‘lags’ China in IT security bug reporting

security update

OSX/Proton spreading again through supply-chain attack

Our researchers noticed that the makers of the Elmedia Player software have been distributing a version of their app trojanized with the OSX/Proton malware. The post OSX/Proton spreading again through supply-chain attack appeared first on WeLiveSecurity

Russian Hacker Exploits GTA 5 PC Mod to Install Cryptocurrency Miner

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Google Play Bounty Promises $1,000 Rewards for Flaws in Popular Apps

LinuxSecurity.com: Fix CVE-2017-2887

LinuxSecurity.com: Daniel P. Berrange reported that Libvirt, a virtualisation abstraction library, does not properly handle the default_tls_x509_verify (and related) parameters in qemu.conf when setting up TLS clients and servers in QEMU, resulting in TLS clients for character devices and disk devices

Hackers Take Aim at SSH Keys in New Attacks
Android Apps Infected with Sockbot Malware Turn Devices into Botnet
Google Advanced Protection Trades Ease-of-Use for Security

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

YouTube sin-bins account of KRACK WPA2 researcher

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Malware in firmware: how to exploit a false sense of security

When thinking about security we generally take risk into account. It is well known that risk is a composition of likelihood and potential impact. The post Malware in firmware: how to exploit a false sense of security appeared first on WeLiveSecurity

Adobe patches zero-day vulnerability used to plant gov’t spying software
The Flawed System Behind the Krack Wi-Fi Meltdown
Yes, British F-35 engines must be sent to Turkey for overhaul
Canadian SMBs: The importance of a stable foundation

You always build from the ground up, and every small-medium business (SMB) must build a strong foundation with their management team. The post Canadian SMBs: The importance of a stable foundation appeared first on WeLiveSecurity

LinuxSecurity.com: It was discovered that YADIFA, an authoritative DNS server, did not sufficiently check its input. This allowed a remote attacker to cause a denial-of-service by forcing the daemon to enter an infinite loop.

Stealth web crypto-cash miner Coin Hive back to the drawing board as blockers move in
EU: No encryption backdoors but, eh, let’s help each other crack that crypto, oui? Ja?
What is blockchain? Get up to speed with this video primer
US-CERT study predicts machine learning, transport systems to become security risks
You’re doing open source wrong, Microsoft tsk-tsk-tsks at Google: Chrome security fixes made public too early

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.