Menu

Category Archives: Security

Articles about security

Hackers can take over Car Wash, trap you and smash your vehicle
ShadowBrokers Remain an Enigma
How DevOps and cloud will speed up security

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Google Study Quantifies Ransomware Profits
CowerSnail Backdoor Targeting Windows Devices
APT Group Uses Catfish Technique To Ensnare Victims
Black Hat speaker denied entry to US in another needless hit to security research

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-7018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7018), [CVE-2017-7030](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7030), [CVE-2017-7034](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7034), [CVE-2017-7037](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7037),

LinuxSecurity.com: ## 2.8.25 (2017-07-17) * security #23507 [Security] validate empty passwords again (xabbuh) * bug #23526 [HttpFoundation] Set meta refresh time to 0 in RedirectResponse content (jnvsor) * bug #23540 Disable inlining deprecated services (alekitto) * bug #23468 [DI] Handle root namespace in service definitions (ro0NL) * bug #23256 [Security] Fix authentication.failure event

LinuxSecurity.com: – Upgrade to upstream v3.0.15 release. See upstream ChangeLog for details (in freeradius-doc subpackage). – Resolves: Bug#1471848 CVE-2017-10978 freeradius: Out-of-bounds read/write due to improper output buffer size check in make_secret() – Resolves: Bug#1471860 CVE-2017-10983 freeradius: Out-of-bounds read in

LinuxSecurity.com: This update fixes multiple security vulnerabilities (CVE-2017-7515, CVE-2017-9775, CVE-2017-9776, CVE-2017-9865).

LinuxSecurity.com: Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129

LinuxSecurity.com: * Bump to 1.8.3 * Security fix for CVE-2017-8932 * add support for 28+bit OIDs in asn1

Homograph attacks: Don’t believe everything you see

A homograph attack is what happens when attackers register domains that are similar to the originals, with valid certificates. The post Homograph attacks: Don’t believe everything you see appeared first on WeLiveSecurity

Black Hat 2017 industrial hacking: The song remains the same

If industry frameworks are to inform and secure the critical infrastructure writ large, here at Black Hat there a lot of people punching holes in them, and in simple ways. The post Black Hat 2017 industrial hacking: The song remains the same appeared first on WeLiveSecurity

Black Hat 2017: Non-standard hacking platforms reign supreme

This year at Black Hat, tiny automated hacking platforms are everywhere, loaded with tasty purpose-built tools that can be used to break into your systems. The post Black Hat 2017: Non-standard hacking platforms reign supreme appeared first on WeLiveSecurity

Android Sypware Still Collects PII Despite Outcry

Risk Level: Very Low. Type: Trojan.

Smashing Security #035: Up the Roomba with mandatory Chinese spyware
Vulnerable Radiation Monitoring Devices Won’t Be Patched
China arrests 11 hackers for infecting 250M devices with Fireball malware

security update

security update

security update

Italian Banking Giant UniCredit Hacked; 400,000 Customers Impacted
Stop blaming users for security misses
Facebook Security Boss: Empathy, Inclusion Must Come to Security

LinuxSecurity.com: This release fixes a use-after-free in replaceChild() call.

LinuxSecurity.com: * CVE-2017-7718: cirrus: OOB read access issue (bz #1443443) * CVE-2016-9603: cirrus: heap buffer overflow via vnc connection (bz #1432040) * CVE-2017-7377: 9pfs: fix file descriptor leak (bz #1437872) * CVE-2017-7980: cirrus: OOB r/w access issues in bitblt (bz #1444372) * CVE-2017-8112: vmw_pvscsi: infinite loop in pvscsi_log2 (bz #1445622) * CVE-2017-8309: audio: host memory […]

LinuxSecurity.com: Multiple vulnerabilities were found in in qemu, a fast processor emulator: CVE-2017-9310

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in sandbox bypass, use of insecure cryptography, side channel attacks, information disclosure, the execution of arbitrary code, denial of service or

LinuxSecurity.com: Fix CVE-2017-11368 (remote triggerable assertion failure in krb5kdc)

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. Debian follows the extended support releases (ESR) of Thunderbird.

LinuxSecurity.com: This release fixes a use-after-free in replaceChild() call.

EVERY app offered by alternative Android app market redirected to malware
FruitFly Mac malware – FBI investigating hundreds of infections, say researchers
6 billion records hacked in 2017 so far; ransomware victims paid $25 million
'Jump boxes' and SAWs improve security, if you set them up right

A jump box is a secure computer that all admins first connect to before launching any administrative task or use as an origination point to connect to other servers or untrusted environments. Over the last few years, with malicious hackers and malware infesting nearly every enterprise network at will, security admins have been looking for […]

Post Quantum Cryptography
Windows SMB Zero Day to Be Disclosed During DEF CON
Adobe to Completely Disable Flash Player by 2020
Is it safe to store corporate information on Google Drive (or similar services)?

When it comes to protecting corporate information, some doubt whether or not the cloud is the best option. We look at all the security services available. The post Is it safe to store corporate information on Google Drive (or similar services)? appeared first on WeLiveSecurity

Linux file manager flaw leaves security “Bad Taste”
Pathetic patching leaves over 70,000 Memcached servers still up for grabs
A Clever New Tool Shuts Down Ransomware Before It’s Too Late
Black Hat 2017: Hacking the physical world

Cameron Camp, in attendance at this year’s Black Hat in Las Vegas, takes a closer look at attacks against physical infrastructure. The post Black Hat 2017: Hacking the physical world appeared first on WeLiveSecurity

Relax: Microsoft is NOT Killing Paint App

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Academia’s Role in Security Skills Gap Examined
Watch Security Researcher As She Hacks ATM by Drilling a Hole
Novel Attack Tricks Servers to Cache, Expose Personal Data
FBI’s Surveillance Van Sold on eBay for US $18,700

LinuxSecurity.com: This update includes the latest stable release of _Apache Subversion_, version **1.9.6**. ### User-visible changes: #### Client-side bugfixes: * cp/mv: improve error message when target is an unversioned dir * merge: reduce memory usage with large amounts of mergeinfo ([issue 4667](https://issues.apache.org/jira/browse/SVN-4667)) #### Server-side

Social engineering and ransomware

Social engineering may play a vital part in persuading a victim to open a malicious executable or website, says ESET’s David Harley on social engineering and ransomware. The post Social engineering and ransomware appeared first on WeLiveSecurity

Black Hat USA 2017 Preview
Malware found lurking behind every app at alternative Android store

ESET researchers have discovered an Android app store distributing malware on a mass scale. The post Malware found lurking behind every app at alternative Android store appeared first on WeLiveSecurity

Writing Windows or Linux apps? Microsoft just launched a cloud-powered bug hunter to find the flaws
£20 million cybersecurity programme to train teenagers set to launch in UK

A new £20 million cybersecurity programme to train teenagers will be launched in the UK this autumn, as part of the government’s plans to address the skills gap. The post £20 million cybersecurity programme to train teenagers set to launch in UK appeared first on WeLiveSecurity

Spiderman pleads guilty to knocking 900,000 German broadband routers offline
18-year-old arrested after reporting dumb bug in public transport e-ticket system
Variant of Surveillance Malware Fruitfly Targeting Mac Users
A massive trove of highly critical data of Swedish citizens leaked online

LinuxSecurity.com: Fix CVE-2017-11368 (remote triggerable assertion failure in krb5kdc)

LinuxSecurity.com: librsvg 2.40.18 release, fixing CVE-2017-11464 (division-by-zero in the Gaussian blur code). For details, see https://mail.gnome.org/archives/ftp-release- list/2017-July/msg00078.html

security update

Casino Becomes Victim of Data Hack—courtesy Fish Tank

Type: Vulnerability. Adobe Flash Player is prone to multiple remote code-execution vulnerabilities; fixes are available.

Hacker Admits to Mirai Attack Against Deutsche Telekom
Veritaseum Hack: Another Ethereum ICO Hacked; Loses $8.4 Million
A US Firm Will Install Microchips in Employees
macOS Fruitfly Backdoor Analysis Renders New Spying Capabilities
70,000 Memcached Servers Can Be Hacked Using Eight-Month-Old Flaws

LinuxSecurity.com: Heimdal could allow unintended access to network services.

88% feel vulnerable to data threats

Thales Group has announced the results of its 2017 data threat report, showing that the number of global data breaches has increased from 2016. The post 88% feel vulnerable to data threats appeared first on WeLiveSecurity

Going to Black Hat? Bring your (marketing) wallet

This year at Black Hat, it will be incumbent upon newer vendors to make sensational claims to gain market share from established vendor, says Cameron Camp. The post Going to Black Hat? Bring your (marketing) wallet appeared first on WeLiveSecurity

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Risk Level: Very Low. Type: Trojan.

Online criminals clone UK university’s website to phish for cash

LinuxSecurity.com: A heap-based buffer underflow flaw was discovered in catdoc, a text extractor for MS-Office files, which may lead to denial of service (application crash) or have unspecified other impact, if a specially crafted file is processed.

security update

Google’ ‘Play Protect’ Ensures Maximum Security For Android Devices

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: It was discovered that Atril, the MATE document viewer, made insecure use of tar when opening tar comic book archives (CBT). Opening a malicious CBT archive could result in the execution of arbitrary code. This update disables the CBT format entirely.

Tor Public Bug Bounty Program: Earn Up To $4000
Watch a Homemade Robot Crack a Safe in Just 15 Minutes
Scammers demand Bitcoin in DDoS extortion scheme, deliver empty threats
Fake Adobe Flash Player App Infects Android Devices with Banking Malware

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: New seamonkey packages are available for Slackware 14.2 and -current to fix security issues.

WikiLeaks Release Documents on How CIA Uses 5 Different Malware

LinuxSecurity.com: Update to upstream version 1.3.1.

LinuxSecurity.com: New upstream release: 2.4.5

LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is now available. now available.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.

Trickbot Malware Now Targets US Banks
Motivation Mystery Behind WannaCry, ExPetr
Your Old Phone Number Can Be Used To Hack Facebook Account