Menu

Category Archives: Security

Articles about security

Google Discloses Another ‘High Severity’ Microsoft Bug
New Phishing Scam Targets Digital Payment and Online Banking Users

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This update prevents `python-cjson` from crashing when attempting to parseheavily nested JSON structures (which could be exploited for denial of servicepurposes, against any application that uses `python-cjson` to parse arbitraryinput).

LinuxSecurity.com: memory leak when destroying guest without PT devices [XSA-207] (#1422492) updatepatches for XSA-208 after upstream revision (no functional change) —- Qemu:net: mcf_fec: infinite loop while receiving data in mcf_fec_receive[CVE-2016-9776] Qemu: audio: memory leakage in ac97 [CVE-2017-5525] (#1414111)Qemu: audio: memory leakage in es1370 device [CVE-2017-5526] (#1414211) oobaccess in cirrus bitblt copy [XSA-208, CVE-2017-2615] (#1418243)

LinuxSecurity.com: This update prevents `python-cjson` from crashing when attempting to parseheavily nested JSON structures (which could be exploited for denial of servicepurposes, against any application that uses `python-cjson` to parse arbitraryinput).

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Fix for CVE-2017-5495

LinuxSecurity.com: Security fix for CVE-2017-2616

LinuxSecurity.com: Update to 0.7.10

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Evolved Version of MongoDB Ransomware Caught Targeting MySQL Databases
Katie Moussouris on Bug Bounty Programs, Hack the Army, and Wassenaar
NHS patient letters meant for GPs went undelivered for years
Google Releases E2EMail to Open Source
DNS attacks: How they try to direct you to fake pages

ESET’s Josep Albors looks at how DNS attacks will try and direct you to fake pages. The post DNS attacks: How they try to direct you to fake pages appeared first on WeLiveSecurity

New prison law will let mobile networks deploy IMSI catchers
Necurs Botnet Learns New DDoS Trick
Don’t panic about SHA-1—fix it
What IT must do now that Cloudflare leaked user data
D-Link resolves enterprise switch hacker risk
Google’s Project Zero reveals another Microsoft flaw
Git fscked by SHA-1 collision? Not so fast, says Linus Torvalds

security update

Movie night? Nope. It’s a fake iTunes receipt from phishers targeting Apple users
Saudi-Iran: Proxy Wars Escalate To Direct Cyber Attacks

security update

Change.org sends password reset email after CloudBleed bug

security update

Cellebrite Can Now Unlock, Extract Data From iPhone 6 and 6 Plus
Was Your Google Account Unexpectedly Signed Out Today? Company Explains Why
Netflix Debuts ‘Stethoscope’ Open-Source Security Tool
Malware Lets a Drone Steal Data by Watching a Computer’s Blinking LED
UK cops can keep millions of mugshots of innocent folks on file
NSA snoops told: Get your checkbooks and pens ready for a cyber-weapon shopping spree
Don’t worry about Privacy Shield, it’s fine. Really. I promise, says US trade watchdog head
Researchers Uncover New Leads Behind Shamoon2
Facebook goes down; comes back with suspicious account activity alert

security update

Google Researchers Successfully Broke SHA-1 Web Security Tool

Emergency Services Lines DDoS’d in Texas Officials have sentenced a cybercriminal who manipulated a bug via the Twitter app to continuously dial 911, which spread to several hundred individuals across multiple states. By tweeting out a malicious link to his followers, anyone who clicked on it was subjected to an endless loop of dialing the […]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Latest stable upstream release, includes security fix for CVE-2017-5593

LinuxSecurity.com: WARNING: Please note that this update comes with a slightly different syntax ofsesman.ini file, so if you edited this file by hand, you may need to look at the.rpmnew file and merge any required changes by hand. This release also createsthree files in /etc/xrdp directory if they don’t already exist or are empty: -rsakeys.ini […]

LinuxSecurity.com: Latest stable upstream release, includes security fix for CVE-2017-5593

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Mysterious Gmail account lockouts prompt hack fears
Threatpost News Wrap, February 24, 2017
Uber Sued by Google’s Waymo for Stealing its Self-Driving Car Technology
Cloudflare Bug Leaks Sensitive Data
Debugging a kernel in QEMU/libvirt – Part II
It’s raining. It’s pouring. This fake weather app is stealing your credentials
British man arrested after 900,000 broadband routers knocked offline in Germany
Ransomware ‘customer support’ chat reveals criminals’ ruthlessness
CloudFlare Blames Internal Faults for Memory and Client Data Leakage
South Korea targeted by cyberspies (again). Kim, got something to say?
Cloudbleed: Big web brands leaked crypto keys, personal secrets thanks to Cloudflare bug
Someone from China is Distributing Mirai Malware Through Windows Botnet
Policy Experts Push To Make Vulnerability Equities Process Law
I was authorized to trash my employer’s network, sysadmin tells court
US ‘security’ biz trio Sentinel Labs, Vir2us, SpyChatter accused of lying about certification

security update

BitTorrent distribution sites dropping crypto-ransomware on macOS
Google kills SHA-1 with successful collision attack
‘First ever’ SHA-1 hash collision calculated. All it took were five clever brains… and 6,610 years of processor time
Breaking and protecting devops tool chains
Bruce Schneier and the call for “public service technologists”
First Practical SHA-1 Collision Attack Arrives

LinuxSecurity.com: An update for python-oslo-middleware is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This release fixes pcregrep multi-line matching with –only-matching option, acrash when JIT-compiling some patterns (CVE-2017-6004) and a possible bufferoverflow when formatting a pcregrep error message.

LinuxSecurity.com: it was found that KDE plasma does not honor the setting for prompting whenexecuting executable files on the desktop. This update resolves this issue.

LinuxSecurity.com: Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627,CVE-2017-5628.

LinuxSecurity.com: Update to the latest version, fixes a security issue.

LinuxSecurity.com: Security fix for CVE-2016-8745

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: it was found that KDE plasma does not honor the setting for prompting whenexecuting executable files on the desktop. This update resolves this issue.

LinuxSecurity.com: Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627,CVE-2017-5628.

LinuxSecurity.com: Update to the latest version, fixes a security issue.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Risk Level: Very Low. Type: Trojan.

Ex-employees sued for £15m over data slurpage ordered to pay up just £2
10 Powerful But Not Yet Promoted Antivirus for PC, Mac, Android, iPhone
Barely 1% of Android users are running Nougat, as Apple shows how to update devices properly
Impact of New Linux Kernel DCCP Vulnerability Limited
Smashing Security #009: False flags and hacker clues
Java, Python FTP Injection Attacks Bypass Firewalls
Destructive Mac ransomware spread as cracks to pirate commercial software
Publicly Disclosed Windows Vulnerabilities Await Patches
Released Android malware source code used to run a banking botnet

ESET researchers have discovered a new variant of botnet-forming Android banking malware based on source code made public a couple of months ago. The post Released Android malware source code used to run a banking botnet appeared first on WeLiveSecurity

Deutsche Telekom hack suspect arrested at London airport
At death’s door for years, widely used SHA1 function is now dead
Linux’s decade-old flaw: Major distros move to patch serious kernel bug
Salted Hash: RSAC 2017 Recap
How to scrub your private data from ‘people finder’ sites