Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: * various security fixes (https://github.com/glpi-project/glpi/issues/2475, https://github.com/glpi-project/glpi/issues/2476, https://github.com/glpi- project/glpi/issues/2492), * fix regressions on self service portal: * self-service users should not be auto assigned as tech * type and category fields are not selectable

LinuxSecurity.com: Update to 2.48 Fixes various security issues, see http://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for more info.

LinuxSecurity.com: Update to 5.2.24: fixes XSS vulnerability CVE-2017-11503.

LinuxSecurity.com: Apache HTTP Server could be made to crash or leak sensitive information if it received specially crafted network traffic.

Will The Real Security Community Please Stand Up

LinuxSecurity.com: * various security fixes (https://github.com/glpi-project/glpi/issues/2475, https://github.com/glpi-project/glpi/issues/2476, https://github.com/glpi- project/glpi/issues/2492), * fix regressions on self service portal: * self-service users should not be auto assigned as tech * type and category fields are not selectable

LinuxSecurity.com: Update to 2.48 Fixes various security issues, see http://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for more info.

Hackers hijack central Cardiff billboard to display swastikas and more…
HBO hackers upload Games of Thrones episodes & other data on their site
True random numbers are here – what that means for data centers
Long Live Gopher: The Techies Keeping the Text-Driven Internet Alive

LinuxSecurity.com: A denial of service vulnerability was discovered in Varnish, a state of the art, high-performance web accelerator. Specially crafted HTTP requests can cause the Varnish daemon to assert and restart, clearing the cache in the process.

LinuxSecurity.com: New gnupg packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

security update

Legislation Proposed to Secure Connected IoT Devices
Email prankster tricks White House officials

LinuxSecurity.com: Fixes CVE-2017-11671. Fixed bugs (http://gcc.gnu.org/PRNNNNN): 31468, 43434, 45053, 49244, 50345, 53915, 56469, 60818, 60992, 61636, 61729, 62045, 64238, 65542, 65705, 65972, 66295, 66669, 67353, 67440, 68163, 68491, 68972, 69264, 69699, 69804, 69823, 69953, 70601, 70844, 70878, 71294, 71310, 71444, 71458, 71510, 71778, 71838, 72775, 73650, 75964, 76731, 77333, 77563, 77728, 77850,

LinuxSecurity.com: Fixes CVE-2017-11671. Fixed bugs (http://gcc.gnu.org/PRNNNNN): 31468, 43434, 45053, 49244, 50345, 53915, 56469, 60818, 60992, 61636, 61729, 62045, 64238, 65542, 65705, 65972, 66295, 66669, 67353, 67440, 68163, 68491, 68972, 69264, 69699, 69804, 69823, 69953, 70601, 70844, 70878, 71294, 71310, 71444, 71458, 71510, 71778, 71838, 72775, 73650, 75964, 76731, 77333, 77563, 77728, 77850,

LinuxSecurity.com: Fixes CVE-2017-11671. Fixed bugs (http://gcc.gnu.org/PRNNNNN): 31468, 43434, 45053, 49244, 50345, 53915, 56469, 60818, 60992, 61636, 61729, 62045, 64238, 65542, 65705, 65972, 66295, 66669, 67353, 67440, 68163, 68491, 68972, 69264, 69699, 69804, 69823, 69953, 70601, 70844, 70878, 71294, 71310, 71444, 71458, 71510, 71778, 71838, 72775, 73650, 75964, 76731, 77333, 77563, 77728, 77850,

LinuxSecurity.com: New version, security fix for CVE-2017-1000381.

LinuxSecurity.com: V1.0 final release —- bump runc commit —- Update to latest release candidate

LinuxSecurity.com: Fix for multiple CVEs

LinuxSecurity.com: Security fix for CVE-2017-7525

LinuxSecurity.com: Fix for multiple CVEs

Amazon Halts Sale of Android Blu Phone Amid Spyware Concerns
Breach at Third Party Contractor Affects 18,000 Anthem Members
Svpeng Android Banking Trojan Tweaked with Keylogger Feature
Popular Chrome extension hacked to deliver adware
Hackers could install malware on your Amazon Echo to secretly ‘wiretap’ you
Dutch Police Nabs Romanian Gang for Stealing $590K worth of iPhones
Trojan found pre-installed on Android phones being sold on Amazon
Pharmaceutical Giant Still Feeling NotPetya’s Sting

LinuxSecurity.com: New version, security fix for CVE-2017-1000381.

Copyfish Browser Extension Hijacked to Spew Spam
Why you should view torrents as a threat

Despite their popularity among users, torrents are a very risky “business”. Apart from the obvious legal trouble you could face for violating the copyright of musicians, filmmakers or software developers, there are security issues as well. The post Why you should view torrents as a threat appeared first on WeLiveSecurity

Def Con hackers showed how easily voting machines can be hacked
‘Real people’ do not want secure communications, claims UK Home Secretary Amber Rudd
How are you going to protect the next generation of your Mobile Applications?

LinuxSecurity.com: A security issues were fixed in Bash.

LinuxSecurity.com: Tyler Bohan of Talos discovered that FreeRDP, a free implementation of the Remote Desktop Protocol (RDP), contained several vulnerabilities that allowed a malicious remote server or a man-in-the-middle to either cause a DoS by forcibly terminating the client, or execute

HBO Hacked – Upcoming Game of Thrones Episodes and Data Leaked
Dutch police share list of identified, active, and arrested Hansa vendors and buyers
ShieldFS Can Detect Ransomware, Recover Files

LinuxSecurity.com: USN 3366-1 introduced a regression in OpenJDK 8.

Voting Machines Hacked with Ease at DEF CON
Android Banking Trojan Svpeng Adds Keylogger
Airborne Drones can be hijacked using $15 BBC’ Micro:bit
DEF CON attendees make short work of electronic voting machines

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Hackers steal information on 400,000 customers of Italy’s biggest bank
Microsoft Releases Outlook and Office Click-to-Run Patches
Feds Seize BTC-E exchange website – CoinBase suffers DDoS attacks
‘Ghost Telephonist’ Attack Exploits 4G LTE Flaw to Hijack Phone Numbers
Pre-installed Trojan in Cheap Android Devices Steal Data, Intercept Chats

LinuxSecurity.com: Several security issues were fixed in Apache HTTP Server.

LinuxSecurity.com: Update to latest snapshot that contains fixes for the latest Talos discovered CVEs.

LinuxSecurity.com: Update to latest snapshot that contains fixes for the latest Talos discovered CVEs.

LinuxSecurity.com: Fix for multiple CVEs

This past May, Webroot surveyed more than 600 IT decision-makers at medium-sized companies (with between 100 and 499 employees) in the U.S., U.K., and Australia. The survey focused on how these small businesses perceived new threats facing their organizations. Were they prepared to manage fallout and recovery process after a cyberattack? Did they understand the […]

How Google Shrunk The Android Attack Surface

LinuxSecurity.com: Several security issues were fixed in NSS.

Risk Level: Very Low. Type: Trojan.

security update

security update

For hackers at Defcon hacking US voting machines was a piece of cake
iOS VPN apps removed from Apple’s Chinese App Store
Apple has removed all major VPN apps from Chinese App Store
Healthcare Clinic Suffers Ransomware Attack; 300K Patients Impacted

LinuxSecurity.com: Update to 5.2.24: fixes XSS vulnerability CVE-2017-11503.

LinuxSecurity.com: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).

LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.57, which includes additional changes, such as performance improvements, bug fixes, new features, and possibly incompatible

LinuxSecurity.com: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).

LinuxSecurity.com: In DSA 3918 Thunderbird was upgraded to the latest ESR series. This update upgrades Enigmail, the OpenPGP extention for Thunderbird, to version 1.9.8.1 to restore full compatibility.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Wikileaks Exposes CIA’ 3 Linux/macOS Malware- Aeris, Achilles, SeaPea
Watch: Hackers take over Tesla Model X; control brakes and doors
Privacy Isn’t Dead. It’s More Popular Than Ever
‘SambaCry’ malware scum return with a Windows encore
How a Bug in an Obscure Chip Exposed a Billion Smartphones to Hackers
Car wash security flaws let hackers ‘physically attack’ people

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Mac Backdoor Just Discovered, Active For Years Researchers have only recently discovered a previously undetectable backdoor […]

How A Coffee Machine Infected Factory Computers with Ransomware

LinuxSecurity.com: New squashfs-tools packages are available for Slackware 14.2 and -current to fix security issues.

Bringing behavioral game theory to security defenses
Simple tips to keep your devices secure when you travel
Watch: Researcher hacking, unlocking a smart gun with $15 magnets
Update your phone: Avoid being Pwned by bug residing in WiFi chip
BTC-e exchange’ owner arrested over money laundering accusation

LinuxSecurity.com: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).

LinuxSecurity.com: An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available.

Are smartphones threatening the security of our IoT devices?

The number of IoT devices is set to surpass 20 billion by 2020. We take a look at how connected things threaten our security as cybercriminals exploit weaknesses in the smartphones that control them. The post Are smartphones threatening the security of our IoT devices? appeared first on WeLiveSecurity

BlackHat: FBI Talks Avalanche Botnet Takedown
Shorting-For-Profit Viable Business Model For Security Community
Black Hat: Hacking the firmware, the next frontier

Trick the firmware and you have access to the whole system. Here at Black Hat, there are a lot of people doing just that. The post Black Hat: Hacking the firmware, the next frontier appeared first on WeLiveSecurity

ESET’s Anton Cherepanov picks up Pwnie for Best Backdoor

Anton Cherepanov, a malware researcher at ESET, has picked up a Pwnie Award for Best Backdoor at this year’s ceremony at Black Hat USA 2017 in Las Vegas. The post ESET’s Anton Cherepanov picks up Pwnie for Best Backdoor appeared first on WeLiveSecurity

11 arrested in Chinese Fireball malware investigation

Risk Level: Very Low. Type: Trojan.

Attack Uses Docker Containers To Hide, Persist, Plant Malware