Menu

Category Archives: Security

Articles about security

Jayden K Smith’s Facebook friendship request – not a hacker, it’s a hoax
Supermarkets and fishy perfumes

Recently I’ve been seeing lightly-revised versions of a longstanding hoax, says David Harley. Read more on supermarkets and fish perfumes. The post Supermarkets and fishy perfumes appeared first on WeLiveSecurity

Three million wrestling fans at risk after WWE leaves database unprotected
Petya ransomware developer releases master decryption key, giving hope for victims

security update

LinuxSecurity.com: A vulnerability in Gajim might allow remote attackers to intercept encrypted communications.

LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: update

LinuxSecurity.com: A vulnerability in RoundCube may allow authenticated users to bypass security restrictions.

LinuxSecurity.com: Multiple vulnerabilities have been found in VLC, the worst of which may allow remote attackers to execute arbitrary code.

SpyDealer Rooting Malware Steals Data From Android Devices

LinuxSecurity.com: Update to new ISC supported version 9.9.10.

LinuxSecurity.com: Update to new ISC supported version 9.9.10.

LinuxSecurity.com: Update to latest upstream release in order to fix CVE-2017-9735

LinuxSecurity.com: update

LinuxSecurity.com: Update to latest upstream release in order to fix CVE-2017-9735

LinuxSecurity.com: Update to latest upstream release in order to fix CVE-2017-9735

LinuxSecurity.com: This is new version with security fixes for CVE-2017-9468, CVE-2017-9469.

Prisoner Uses Drones and Cell Phones to Escape
CIA Implants Steal SSH Credentials From Linux & Windows Devices: WikiLeaks

LinuxSecurity.com: New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017

LinuxSecurity.com: Update to new ISC supported version 9.9.10-P2 including security fixes.

LinuxSecurity.com: Update to annulen-branch of qt5-qtwebkit, which contains a lot of security fixes. Drop-in replacement for the old unmaintained qt5-qtwebkit

LinuxSecurity.com: Update to new ISC supported version 9.9.10-P2 including security fixes.

Black Hat Survey: Security Pros Expect Major Breaches in Next Two Years

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available. An update that fixes 11 vulnerabilities is now available. An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has 14 fixes An update that solves two vulnerabilities and has 14 fixes An update that solves two vulnerabilities and has 14 fixes is now available. is now available.

LinuxSecurity.com: Clément Berthaux from Synaktiv discovered two vulnerabilities in BIND, a DNS server implementation. They allow an attacker to bypass TSIG authentication by sending crafted DNS packets to a server.

LinuxSecurity.com: A vulnerability has been found in GNOME applet for NetworkManager allowing local attackers to access the local filesystem.

LinuxSecurity.com: A vulnerability in feh might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in phpMyAdmin might allow remote attackers to bypass authentication.

LinuxSecurity.com: Multiple vulnerabilities have been found in JasPer, the worst of which could could allow an attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in virglrenderer, the worst of which could allow local guest OS users to cause a Denial of Service condition. [More…]

AA apologises, and confirms customers’ partial credit card data *was* exposed
Hard Rock, Loews Hotels Among Sabre Corp Hospitality Breach Victims
Authorities Shut Down Major Dark Web Child Porn Platform

Risk Level: Very Low. Type: Trojan, Worm.

Leaky WWE Database Exposes Personal Data of 3M Wrestling Fans
CopyCat Malware Made $1.5M by Infecting 14M Android Devices
Decryption Key to Original Petya Ransomware Released
Two suspects arrested in connection with WannaCry Android lookalikes
Massive WWE Database with 3 Million Records Exposed Online
Cloud computing security: This is where you’ll be spending the money
How to Achieve an Optimal Security Posture

LinuxSecurity.com: poppler could be made to crash or run programs as your login if it opened a specially crafted file.

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: An update that solves 17 vulnerabilities and has one errata An update that solves 17 vulnerabilities and has one errata An update that solves 17 vulnerabilities and has one errata is now available. is now available.

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. British Lawmakers’ Logins Targeted Over the last week, multiple parliament members and other lawmakers in the […]

Risk Level: Very Low. Type: Trojan.

security update

security update

Let’s Encrypt to Offer Wildcard Certificates in 2018

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service or the execution of arbitrary code.

LinuxSecurity.com: Several security issues were fixed in Thunderbird.

LinuxSecurity.com: It was discovered that jabberd2, a Jabber instant messenger server, allowed anonymous SASL connections, even if disabled in the configuration.

CopyCat Malware Infected 14M Android Devices, Rooted 8M, in 2016
Google Patches Critical ‘Broadpwn’ Bug in July Security Update
Thousands of NZ Airport Passengers forced to surrender device password
Two hackers arrested after a decade of selling malware
All you need to know about the move from SHA-1 to SHA-2

For the past two years, I’ve been busy helping Public Key Infrastructure (PKI) customers prepare for and move to SHA-2, the set of cryptographic hash functions that have succeeded SHA-1. Last year, moving to SHA-2 ahead of the global deadline was a nice-to-do preparatory step. This year, now that the migration deadline has passed, it’s required.Many digital-certificate-consuming […]

Everything you need to know about the latest variant of Petya

The latest global cyberattack, detected by ESET as Win32 / Diskcoder.C, considered a variant of Petya, once again highlights the reality outdated systems and insufficient security solutions are still widespread. The post Everything you need to know about the latest variant of Petya appeared first on WeLiveSecurity

Last month’s malware outbreak cost this household company £100 million

LinuxSecurity.com: An update that solves 16 vulnerabilities and has two fixes An update that solves 16 vulnerabilities and has two fixes An update that solves 16 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Smashing Security #032: The iPhone 8, a data breach at the AA, and a mystery no show
Dark Web Marketplace AlphaBay Down; Users Fear Scam

LinuxSecurity.com: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 —- Update to 10.1.

LinuxSecurity.com: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 —- Update to 10.1.

LinuxSecurity.com: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 —- Update to 10.1.

LinuxSecurity.com: **Horde_Image 2.5.1** * [mjr] SECURITY: Fix more potential places for command injections. —- **Horde_Image 2.5.0** * [mjr] **SECURITY**: Prevent DOS attack by preventing an infinite loop in certain conditions (CVE-2017-9773, reported by Fariskhi Vidyan). * [mjr] **SECURITY**: Prevent RCE attacks by properly sanitizing shell arguments (CVE-2017-9774, reported by Fariskhi

LinuxSecurity.com: CVE-2017-9604 kmail: Send Later with Delay bypasses OpenPGP

LinuxSecurity.com: Security fix for CVE-2017-9604

LinuxSecurity.com: Security fix for CVE-2016-7968

Threat Actors Target Chinese Language News Sites
Critical Vulnerabilities Found in Pre-Installed Dell Software

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes is now available. is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has 12 fixes is An update that solves 6 vulnerabilities and has 12 fixes is An update that solves 6 vulnerabilities and has 12 fixes is now available. now available.

Libgcrypt ‘Sliding Right’ Attack Allows Recovery of RSA-1024 Keys
Judge: Facebook can Track Browsing Activity Even When You Log Out
Servers associated with NotPetya attack seized by Ukrainian Police
Google and Apple should do more to fight phone scammers, says researcher
Major cryptocurrency exchange hacked – customers’ Bitcoin and Ethereum accounts plundered
GnuPG crypto library cracked, look for patches
Tor Browser 7.0.2 is released

LinuxSecurity.com: Multiple vulnerabilities have been found in IcedTea, the worst of which may allow execution of arbitrary code.

Risk Level: Very Low. Type: Trojan.

Teen Charged for Selling Malware Used in DDoS Attacks
Hackers Steal Billions in S.Korean Won by Hacking 4th Largest Bitcoin Exchange
Kaspersky Willing to Share Its Source Code with US Govt
13GB Data of Automobile Insurance Giant AA Exposed Online
A Man-in-the-Middle Attack against a Password Reset System
HTTPS Certificate Revocation is broken, and it’s time for some new tools
With a single wiretap order, US authorities listened in on 3.3 million phone calls
Yes – despite what it says – AA customer credit card data was exposed
Analysis of TeleBots’ cunning backdoor

This article reveals details about the initial infection vector that was used during the DiskCoder.C outbreak. The post Analysis of TeleBots’ cunning backdoor appeared first on WeLiveSecurity

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]