Menu

Category Archives: Security

Articles about security

Equifax’s disastrous Struts patching blunder: THOUSANDS of other orgs did it too
Cloud Security Error Exposes Half a Million Voters’ Personal Information
You lost your ballpoint pen, Slack? Why’s your Linux version unsigned?
Night Vision Enabled Security Cameras Secretly Transfer Your Data

LinuxSecurity.com: An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two fixes is now available. fixes is now available.

CCleaner targeted top tech companies in attempt to lift IP

Risk Level: Very Low. Type: Trojan.

security update

Smashing Security podcast #043: Backups – a necessary evil?
Orland-whoa! Chap cops to masterminding $100m Microsoft piracy racket

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

security update

FedEx: TNT NotPetya infection blew a $300m hole in our numbers

LinuxSecurity.com: Update to upstream release 1.25.6

More than three dozen schools call off classes after ‘cyber terrorist’ threat
Viacom cloud config goof exposed Paramount Pictures, Comedy Central, MTV, and more
What Triggers HTTPS Chrome Browser Warnings?
Malware Steals Data From Air-Gapped Network via Security Cameras

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Deep-Learning PassGAN Tool Improves Password Guessing

With global ransomware attacks, such as WannaCry and not-Petya, making big headlines this year, it seems the unwelcomed scourge of ransomware isn’t going away any time soon. While large-scale attacks like these are most known for their ability to devastate companies and even whole countries, the often under-reported victim is the average home user. We […]

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

The laws that are ruining the Internet
Pirate Bay digs itself a new hole: Mining alt-coin in slurper browsers
5 Ways to Secure Wi-Fi Networks
First ever crypto-mining Chrome extension discovered
Cloud-Focused Firms Earn High Marks for Software Security in BSIMM8 Report
Manage access control using Redis Bitfields

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

iOS 11 Update includes Patches for Eight Vulnerabilities

security update

security update

LinuxSecurity.com: new upstream release —- * heap overflow in libwpd

LinuxSecurity.com: Rebase to the latest upstream version 2.0.14. This update contains security fix for CVS -2017-1000050.

LinuxSecurity.com: Update to version 1.3.0, see https://nih.at/libzip/NEWS.html for details. —- This update backports security fix for CVE-2017-14107.

LinuxSecurity.com: Security fix for CVE-2017-13735

Equifax Suffered Earlier Breach in March
Red Alert 2.0: New Android banking trojan can block and log incoming calls from banks

As a CISO, I think the cybersecurity community is beginning to realize that the threats we face as security professionals are consistently evolving, and, more importantly, that we must evolve just as quickly to combat them. Recent data collected by the Webroot® Threat Intelligence Platform on the acceleration of phishing attacks and the maturation of new, […]

Risks Limited With Latest Apache Bug, Optionsbleed

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

Misleading headlines about Equifax’s *earlier* hack
APNIC-sponsored proposal could vastly improve DNS resilience against DDoS
The Pirate Bay hijacked users’ CPU power to secretly mine cryptocurrency Monero
Safer but not immune: Cloud lessons from the Equifax breach
Heads roll, as it’s revealed Equifax’s IT team knew about web app vulnerability

Risk Level: Very Low. Type: Trojan.

Attackers Use Undocumented MS Office Feature to Leak System Profile Data

security update

Pirate Bay Spotted Hosting Monero Cryptocurrency Miner

LinuxSecurity.com: Multiple vulnerabilities have been found in cURL, the worst of which may allow attackers to bypass intended restrictions.

LinuxSecurity.com: A vulnerability in SquirrelMail might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in module File::Path for Perl allows local attackers to set arbitrary mode values on arbitrary files bypassing security restrictions. [More…]

LinuxSecurity.com: Gentoo’s GIMPS ebuilds are vulnerable to privilege escalation due to improper permissions. A local attacker could use it to gain root privileges. [More…]

LinuxSecurity.com: A command injection vulnerability in Git may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A command injection vulnerability in Subversion may allow remote attackers to execute arbitrary code.

Google Chrome Will Mark FTP Resources As “Not Secure”
IDG Contributor Network: From equanimity to Equifax
CCleaner Software Hacked with Backdoor; 2 Million Users Infected
The Pirate Bay website quietly runs a cryptocurrency miner on visitors’ PCs, gobbling up CPU cycles

LinuxSecurity.com: GDK-PixBuf could be made to crash or run programs as your login if it opened a specially crafted file.

CCleaner, distributed by anti-virus firm Avast, contained malicious backdoor

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

security update

The Pirate Bay Caught Running Cryptocurrency Mining Script

LinuxSecurity.com: Multiple vulnerabilities have been found in GDK-PixBuf, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: A vulnerability in Kpathsea allows remote attackers to execute arbitrary commands by manipulating the -tex option from mpost program.

LinuxSecurity.com: A vulnerability in Supervisor might allow remote attackers to execute arbitrary code. [More…]

LinuxSecurity.com: A vulnerability in chkrootkit may allow local users to gain root privileges.

LinuxSecurity.com: A vulnerability in mod_gnutls allows remote attackers to spoof clients via crafted certificates.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebkitGTK+, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Binutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

Equifax confirms up to 400,000 UK consumers at risk after data breach
Alaska Voter Database Exposed Online
Guess what happened after VEVO told its hackers to ‘f**k off’…

security update

Fitbit’ Fitness Tracker Devices Leak Personal Data: Researchers
Android Apps Infected with ExpensiveWall Malware Downloaded 21M Times
OurMine hacks video hosting service Vevo; leaks 3.12TB data online
LinkedIn Phishing Scam Steals Gmail Credentials Through Google Docs

security update

Rogue WordPress Plugin Allowed Spam Injection

German Voting Software Raises Concerns With German elections only a couple weeks away, researchers have been working to determine how secure the voting systems really are. Per a recent study, the software being used contains multiple vulnerabilities that could lead to devastating results if the election is compromised. Meanwhile, the software creator maintains there is […]

Chrome will automatically block annoying autoplay videos