Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: Multiple vulnerabilities have been found in FreeType, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: An out-of-bounds data access in minicom might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Wireshark, the worst of which allows remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A vulnerability in PCRE library allows remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A vulnerability in Pidgin might allow remote attackers to execute arbitrary code.

Hackers can steal large amount of data using router’s LEDs
Why you must patch the new Linux sudo security hole
Botnets overshadowed by ransomware (in media)

Regardless of how prominent and effective ransomware appears to be, it is not the most dangerous form of malware. The post Botnets overshadowed by ransomware (in media) appeared first on WeLiveSecurity

See a real attack on a virtual network in this free webinar by Nehemiah Security
Mingis on Tech: The alphabet soup of mobile device management
UK cops arrest man picked out by automatic facial recognition software
Trends 2017: Ransomware of Things

Welcome to the Ransomware of Things, where all connected devices are at risk of being compromised, locked and held to ransom by cybercriminals. The post Trends 2017: Ransomware of Things appeared first on WeLiveSecurity

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to run programs as an administrator.

LinuxSecurity.com: The system could be made to run programs as an administrator.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

How The Intercept might have helped unmasked Reality Winner to the NSA
Curiosity Kills Security When it Comes to Phishing
IBM Backup Bug Gets Workaround Fix After Nine Months of Exposure

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Several security issues were fixed in Puppet.

Risk Level: Very Low. Type: Trojan.

Google Fixes 30 Vulnerabilities, Five High Severity, in Chrome 59
NSA’s EternalBlue Exploit Ported to Windows 10
Neuroanatomy of Facial Processing Decoded – by Reading Minds of Monkeys
Federal Contractor Caught Leaking Classified NSA Documents to News Outlet
Turla’s watering hole campaign: An updated Firefox extension abusing Instagram

The Turla espionage group is still using watering hole techniques to redirect potentially interesting victims to their C&C infrastructure. The post Turla’s watering hole campaign: An updated Firefox extension abusing Instagram appeared first on WeLiveSecurity

CIA’s Pandemic Toolkit
Hackers leak 8 unaired episodes of ABC’s Steve Harvey’s Funderdome TV series
British Airways blames IT meltdown on human error
QakBot trojan triggers Active Directory lockouts while seeking to drain bank accounts

LinuxSecurity.com: A vulnerability in a bundled copy of PuTTY in FileZilla might allow remote attackers to execute arbitrary code or cause a denial of service. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in MuPDF, the worst of which allows remote attackers to cause a Denial of Service condition or have other unspecified impact. [More…]

LinuxSecurity.com: A vulnerability has been found in Libtirpc and RPCBind which may allow a remote attacker to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in ImageWorsener, the worst of which allows remote attackers to cause a Denial of Service condition or have other unspecified impact. [More…]

LinuxSecurity.com: Multiple vulnerabilities in D-Bus might allow an attacker to overwrite files with a fixed filename in arbitrary directories or conduct a symlink attack. [More…]

LinuxSecurity.com: A vulnerability in Git might allow remote attackers to bypass security restrictions.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which may allow a remote attacker to cause a Denial of Service or gain elevated privileges from a guest VM. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Shadow, the worst of which might allow privilege escalation.

LinuxSecurity.com: Gentoo’s MUNGE ebuilds are vulnerable to privilege escalation due to improper permissions.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents

LinuxSecurity.com: Update to 4.12 (#1456190)

QakBot Returns, Locking Out Active Directory Accounts
Top Tips on How to Land a Well-Paid Job in Cyber Security
40,000 Subdomains Tied to RIG Exploit Kit Shut Down
53 Percent of Enterprise Flash Installs are Outdated

LinuxSecurity.com: Security fix for CVE-2017-7494

LinuxSecurity.com: Update to latest stable release, include fixes for gnutls and gtk-vnc compatibility.

LinuxSecurity.com: – update to 1.8.20p2 – added sudo package to dnf/yum protected packages —- – update to 1.8.20p1 – fixes CVE-2017-1000367

LinuxSecurity.com: Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c

LinuxSecurity.com: fix insufficient escaping of user-supplied data (CVE-2017-7692)

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069 —- Security fix for CVE-2017-5055, CVE-2017-5054, CVE-2017-5052, CVE-2017-5056, CVE-2017-5053

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069 —- Security fix for CVE-2017-5055, CVE-2017-5054, CVE-2017-5052, CVE-2017-5056, CVE-2017-5053

LinuxSecurity.com: fix insufficient escaping of user-supplied data (CVE-2017-7692)

48% of U.S. Firms Using IoT Devices Suffered Security Breaches – Survey

Risk Level: Very Low. Type: Trojan.

Hackers Leak First 8 Episodes of Steve Harvey’s “Funderdome” TV Show
Don’t let politicians use the excuse of murderous assholes to scapegoat the internet
Google will Now Pay Hackers $200,000 for Reporting Bugs in Android
Trends 2017: Fewer vulnerabilities are being reported, but are we any safer?

Fewer vulnerabilities are being reported, but are we any safer? In this short video, we take a look at why it’s still a problem. The post Trends 2017: Fewer vulnerabilities are being reported, but are we any safer? appeared first on WeLiveSecurity

Bid farewell to your browsing data in the stock Android browsers – for better privacy

LinuxSecurity.com: The cPanel Security Team reported a time of check to time of use (TOCTTOU) race condition flaw in File::Path, a core module from Perl to create or remove directory trees. An attacker can take advantage of this flaw to set the mode on an attacker-chosen file to a attacker-chosen

security update

LinuxSecurity.com: Security fixes for CVE-2017-9078 CVE-2017-9079

LinuxSecurity.com: Security fixes for CVE-2017-9078 CVE-2017-9079

Australian Pedophile Arrested as Philippine Cybersex Ring Busted
Man Accidentally Destroyed Production Database on First Day of His Job
Hackers Behind Jaff Ransomware Selling Victims’ Data on Dark Web
Jaff Malware Probe Uncovers Link to Cybercrime Marketplace
Phishing Campaigns Follow Trends

security update

security update

EternalBlue Exploit Spreading Gh0st RAT, Nitol

LinuxSecurity.com: Several vulnerabilities were discovered in NSS, a set of cryptographic libraries, which may result in denial of service or information disclosure.

LinuxSecurity.com: It was discovered that Zookeeper, a service for maintaining configuration information, didn’t restrict access to the computationally expensive wchp/wchc commands which could result in denial of service by elevated CPU consumption.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: OpenLDAP could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: Several security issues were fixed in libsndfile.

‘Fireball’ Malware Infected 250 Million Mac and Windows Devices
Fireball malware’s flames infect a quarter of a BILLION computers

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Hackers Blackmail Surgery Patients Hackers have begun contacting victims of a March data leak that exposed […]

SSH Configuration on Nexpose Servers Allowed Weak Encryption Algorithms
“Good hackers” took over billboard to send security warning
Wikileaks reveals pandemic malware for Windows developed by the CIA
OneLogin data breach may have compromised encrypted information

The OneLogin breach once again highlights the importance of how companies protect their encrypted data. The post OneLogin data breach may have compromised encrypted information appeared first on WeLiveSecurity

Threatpost News Wrap, June 2, 2017
WikiLeaks Dumps CIA Patient Zero Windows Implant
IDG Contributor Network: Choose your devsecops team wisely: Your apps depend on it
Fireball Malware Infects 250 Million Computers Worldwide
Infosecurity Europe: 10 interesting talking points

Just weeks after one of the largest global ransomware attacks in history, Infosecurity Europe returns for its 22nd installment. The post Infosecurity Europe: 10 interesting talking points appeared first on WeLiveSecurity

Silk Road founder Ross Ulbricht loses appeal for new trial
Biker group charged with hacking hundreds of Jeeps, motorcycles in crime spree
Watch this webinar to learn about email security threats
US defense contractor secures Amazon S3 bucket after leaving sensitive data publicly exposed

LinuxSecurity.com: An update that solves two vulnerabilities and has 5 fixes An update that solves two vulnerabilities and has 5 fixes An update that solves two vulnerabilities and has 5 fixes is now available. is now available.