Menu

Category Archives: Security

Articles about security

Free Certs Come With a Cost
Want to a hack a Myspace account? They’ve made it shockingly easy

LinuxSecurity.com: The 4.11.10 update contains a number of important fixes across the tree

Unix: How random is random?
White House released voter-fraud commenters’ sensitive personal information
Want to kill your IT security team? Put the top hacker in charge

LinuxSecurity.com: Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize function

LinuxSecurity.com: CVE-2017-1000381: c-ares NAPTR parser out of bounds access

Malware installs Signal as part of scheme to steal Mac users’ banking credentials

LinuxSecurity.com: – CVE-2017-1000083: Evince command injection vulnerability in CBT handler (#1468488)

LinuxSecurity.com: File /etc/sysconfig/httpd is ghosted now —- Version update —- Security fix for CVE-2017-3167 CVE-2017-3169 CVE-2017-7659 CVE-2017-7668 CVE-2017-7679

LinuxSecurity.com: This update updates QtWebEngine to the 5.9.1 release, a security and bugfix release from the 5.9 branch. QtWebEngine 5.9.1 is part of the Qt 5.9.1 release, but only the QtWebEngine component is included in this update. The update fixes the following security issues in QtWebEngine 5.9.0: CVE-2017-5070, CVE-2017-5071, CVE-2017-5075, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078,

LinuxSecurity.com: New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017

Giveaway: Download Millions of Free Microsoft E-books

LinuxSecurity.com: Jeffrey Altman, Viktor Dukhovni, and Nicolas Williams reported that Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos, trusts metadata taken from the unauthenticated plaintext (Ticket), rather than the authenticated and encrypted KDC response. A

security update

security update

security update

security update

You can buy password stealing malware ‘Ovidiy Stealer’ for $7

LinuxSecurity.com: Samba could allow unintended access to network services.

LinuxSecurity.com: Heimdal could allow unintended access to network services.

LinuxSecurity.com: Clément Berthaux from Synaktiv discovered a signature forgery vulnerability in knot, an authoritative-only DNS server. This vulnerability allows an attacker to bypass TSIG authentication by sending crafted DNS packets to a server.

LinuxSecurity.com: Felix Wilhelm discovered that the Evince document viewer made insecure use of tar when opening tar comic book archives (CBT). Opening a malicious CBT archive could result in the execution of arbitrary code. This update disables the CBT format entirely

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize function

LinuxSecurity.com: – Update to 1.1.12 – Fix Cross-site Scripting (XSS) issue with link.php (CVE-2017-10970) Release notes: https://www.cacti.net/release_notes.php?version=1.1.11 Release notes: https://www.cacti.net/release_notes.php?version=1.1.12

Risk Level: Very Low. Type: Trojan.

Gandi hosting’ logins breached; 751 domains diverted to malware site
OSX/Dok malware hits Macs; bypasses Apple’ Gatekeeper
Crooks Stealing Data From ATMs Using Infrared
Kerberos bypass, login theft bug slain by Microsoft, Linux slingers
Black Hat to Host Discussion on Diversity

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: New mariadb packages are available for Slackware 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes is now available. is now available.

NemucodAES Ransomware, Kovter Click-Fraud Malware Spreading in Same Campaigns
Siemens Patches Authentication Bypass Flaw in SiPass Server
Beware bogus ‘WhatsApp subscription ending’ emails and texts

You ultimately decide what links you click on, and whether you hand over your passwords and payment card details. Always think twice, because the wrong decision could prove costly. The post Beware bogus ‘WhatsApp subscription ending’ emails and texts appeared first on WeLiveSecurity

AlphaBay Marketplace busted; admin commits suicide in prison
Cisco Patches Publicly Disclosed SNMP Vulnerabilities in IOS, IOS XE
U.S Bans Kaspersky Software For Links To Russia
Dark Web Child Pornographer Avoids Jail Due To Asperger Syndrome 
Threatpost News Wrap, July 14, 2017
Experts Warn Too Often AWS S3 Buckets Are Misconfigured, Leak Data

LinuxSecurity.com: – Update to 1.1.12 – Fix Cross-site Scripting (XSS) issue with link.php (CVE-2017-10970) Release notes: https://www.cacti.net/release_notes.php?version=1.1.11 Release notes: https://www.cacti.net/release_notes.php?version=1.1.12

LinuxSecurity.com: updated to 2.6.1 (security bugfix release)

LinuxSecurity.com: New upstream release fixing moderate security issue CVE-2017-7526.

Patching: Your questions answered

How do patches work? Could the Microsoft patch have stopped WannaCryptor? All your questions answered. The post Patching: Your questions answered appeared first on WeLiveSecurity

How Active Intrusion Detection Can Seek and Block Attacks

LinuxSecurity.com: – CVE-2017-1000083: Evince command injection vulnerability in CBT handler (#1468488)

LinuxSecurity.com: https://github.com/libexpat/libexpat/blob/R_2_2_1/expat/Changes

LinuxSecurity.com: – Update to 1.1.12 – Fix Cross-site Scripting (XSS) issue with link.php (CVE-2017-10970) Release notes: https://www.cacti.net/release_notes.php?version=1.1.11 Release notes: https://www.cacti.net/release_notes.php?version=1.1.12

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: updated to 2.6.1 (security bugfix release)

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Verizon Call Logs Found Exposed Online Over the past month, researchers have been learning more about […]

CIA Highrise Android Malware Spies On SMS Messages: WikiLeaks

security update

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Beware – “Fake Tor Browser Rodeo” Scamming Unsuspecting Users
Scanner Shows EternalBlue Vulnerability Unpatched on Thousands of Machines
Attackers Using Automated Scans to Takeover WordPress Installs

LinuxSecurity.com: An integer overflow has been found in the HTTP range module of Nginx, a high-performance web and reverse proxy server, which may result in information disclosure.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Google Changes How it Analyzes Misbehaving Mobile Apps
Microsoft’ Calibri font hinges Pakistan’s entire government
Bupa warns health insurance information exposed by rogue employee

LinuxSecurity.com: Evince could be made run programs as your login if it opened a specially crafted file.

Are you looking at me? Welcome to the world of facial recognition
What is new in OpenSSH 7.4 (in RHEL 7.4)?
Hackers able to turbo-charge DJI drones way beyond what’s legal

LinuxSecurity.com: Updated to the latest version; Security fix for CVE-2017-10788

The Magala trojan makes its money dishonestly by clicking on ads in your browser

LinuxSecurity.com: An update that solves 15 vulnerabilities and has 162 fixes An update that solves 15 vulnerabilities and has 162 fixes An update that solves 15 vulnerabilities and has 162 fixes is now available. is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

14 Million Verizon Customer Records Exposed

security update

security update

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Third Party Exposes 14 Million Verizon Customer Records
New Point-of-Sale Malware LockPoS Hitches Ride with FlokiBot
LeakerLocker Android Ransomware: Pay or Your Data Will Be Leaked
Uber Patches Authentication Bypass Vulnerability on Custom SSO Solution
SAP Patches High-Risk Flaws in SAP POS, Host Agent
Trump Hotels’ Booking System Hacked, Credit Card Data Stolen
Industrial control security practitioners worry about threats … for a reason

Recent research from the SANS Institute confirms that security of industrial control systems is increasingly seen and understood to be a serious issue. The post Industrial control security practitioners worry about threats … for a reason appeared first on WeLiveSecurity