Menu

Latest articles

WannaCry-hero Hutchins’ trial date set, Microsoft readies Google’s Spectre V2 fix for Windows 10, Coinhive axed, and more

LinuxSecurity.com: gdm 3.30.3 release. – Screen lock bypass fix (when timed login is enabled) (CVE-2019-3825) – Translation updates

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: fix for CVE-2018-5704 (RHBZ 1534844)

LinuxSecurity.com: Restrict default configuration to localhost.

LinuxSecurity.com: fix for CVE-2018-5704 (RHBZ 1534844)

LinuxSecurity.com: This release fixes various buffer overflows when parsing or processing damaged Waveform audio and BMP image files.

LinuxSecurity.com: Restrict default configuration to localhost.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

When the bits hit the FAN: US military accused of knackering Russian trolls, news org’s IT gear amid midterm elections

security update

security update

security update

security update

Adobe Patches Critical ColdFusion Vulnerability With Active Exploit

Type: Vulnerability. WinRAR is prone to multiple security vulnerabilities; fixes are available.

19-year-old ethical hacker is a millionaire now; thanks to his skills
Podcast: RSA Conference 2019 Preview
Did you hear the one about Cisco routers using strcpy insecurely for login authentication? Makes you go AAAAA-AAAAAAAA *segfault*

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 5 fixes is now available.

The Momo Challenge urban legend – what on earth is going on?
Necurs Botnet Evolves to Hide in the Shadows, with New Payloads
Dow Jones’ high-risk screening watchlist data exposed online

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 33 fixes is now available.

After last year’s sexism shambles, 2019’s RSA infosec event has upped its inclusivity game

LinuxSecurity.com: A vulnerability was discovered in uw-imap, the University of Washington IMAP Toolkit, that might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a

Data-tracking Chrome flaw triggered by viewing PDFs
For sale: iPhone hacking tool, one previous (not very careful) owner
Disgruntled dev blames crypto-wallet for losing cryptocoins
Latest container exploit (runc) can be blocked by SELinux
A year in review: 2018 Product Security Risk Report

Reading Time: ~2 min. Fake Apex Legends App Spreads Malware As the popularity of the latest free-to-play battle royale pushes ever higher, malicious Apex Legends apps have been spotted in the Google Play store with upwards of 100,000 downloads. The fake apps typically offer free in-game currency, or free downloads for an already free game, while […]

Dow Jones Watchlist of risky businesses exposed on public server

LinuxSecurity.com: Garming Sam reported an out-of-bounds read in the ldb_wildcard_compare() function of ldb, a LDAP-like embedded database, resulting in denial of service.

Spot the cyber-crims before they spot your data: Find out more in this here webinar – free for every Reg reader

LinuxSecurity.com: Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform various Cross-Side Scripting (XSS) and PHP injections attacks, delete files, leak potentially sensitive data, create posts of unauthorized types, or

The “Momo challenge” – why it’s time to stop the hype [VIDEO]

security update

Reading Time: ~6 min. This is the third of a three-part report on the state of three malware categories: miners, ransomware and information stealers. Ransomware is any malware that holds your data ransom. These days it usually involves encrypting a victim’s data before asking for cash (typically cryptocurrency) to decrypt it. Ransomware ruled the malware world since […]

Surprise, surprise, yet another cryptocurrency creator collared, hit with $6 million fraud rap

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

In the cloud, things aren’t always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel

Reading Time: ~5 min. The landscape of digital security is rapidly shifting, and even the largest tech giants are scrambling to keep up with new data regulations and cybersecurity threats. Small to medium-sized businesses (SMBs) are often left out of these important conversations, leaving themselves — and their users — vulnerable. In an effort to […]

Qbot malware’s back, and latest strain relies on Visual Basic script to slip into target machines
Coinhive to Mine Its Last Monero in March
Coinhive, the in-browser cryptomining service beloved by hackers, is dead
A video about cybersecurity threats that doesn’t feature any computers

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

Coinhive cryptocurrency miner to call it a day next week

The service became notorious for its use by ne’er-do-wells looking to make a quick buck by hijacking the processing power of victim machines to generate virtual money The post Coinhive cryptocurrency miner to call it a day next week appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in GD.

Cisco Fixes Critical Flaw in Wireless VPN, Firewall Routers
Thunderclap: Apple Macs at risk from malicious Thunderbolt peripherals
US House and Senate debate new data privacy law

LinuxSecurity.com: ultiple vulnerabilities have been discovered in SoX (Sound eXchange), a sound processing program: CVE-2017-15370

US pushed Russian troll factory offline during US midterm elections
Businesses warned of malware spread via LinkedIn job offers

LinuxSecurity.com: An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several vulnerabilities were found in QEMU, a fast processor emulator: CVE-2018-12617

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Smashing Security #117: SWATs on a plane

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Risk Level: Very Low. Type: Trojan.

Web hacker ‘Alfabeto Virtual’ thrown in the clink for 3 months by US judge who wanted to ‘send a message’
Intel: Let’s talk about SGX, baby. Let’s talk about 2U and me. Let’s talk about all the good things, and the bad…
Friendly reminder to Drupal admins: Secure your sh!t before latest RCE-holes get you

LinuxSecurity.com: An update that solves two vulnerabilities and has four fixes is now available.

Card-Skimming Scripts Hide Behind Google Analytics, Angular
Ring Doorbell Flaw Opens Door to Spying
Cisco Patches High-Severity Webex Vulnerability For Third Time
Thunderclap Flaws Shatter Peripheral Security

LinuxSecurity.com: An information leak issue was discovered in phpMyAdmin. An attacker can read any file on the server that the web server’s user can access. This is related to the mysql.allow_local_infile PHP

LinuxSecurity.com: A regression was introduced in the previous chromium security update. The browser would always crash when launched in headless mode. This update fixes this problem.

Running Elasticsearch 1.4.2 or earlier? There’s targeted malware going for your boxen
‘Highly critical’ bug exposes unpatched Drupal sites to attacks

Worse, attackers have already been spotted targeting the flaw to deliver cryptocurrency miners and other payloads The post ‘Highly critical’ bug exposes unpatched Drupal sites to attacks appeared first on WeLiveSecurity

Bronze Union APT Updates Remote Access Trojans in Fresh Wave of Attacks

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 7 fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 7 fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

Nvidia patches eight security flaws in graphics products
Researchers break e-signatures in 22 common PDF viewers
Police bust their own radio shop manager for dodgy software updates
Millions of utilities customers’ passwords stored in plain text
How to spot if your password was stolen in a security breach

Following the revelation that a list containing millions of stolen usernames and passwords had appeared online, we tell you a few different ways to find out if your credentials were stolen in that—or any other—security breach The post How to spot if your password was stolen in a security breach appeared first on WeLiveSecurity

Protect you and your biz by learning the tricks of cyber criminals’ trade at SANS London in March
Ready for another fright? Spectre flaws in today’s computer chips can be exploited to hide, run stealthy malware

LinuxSecurity.com: New openssl packages are available for Slackware 14.2 to fix a security issue.

LinuxSecurity.com: Security fix for CVE-2018-16741,CVE-2018-16744,CVE-2018-16745

Thunder, thunder, thunder… Thunderclap: Feel the magic, hear the roar, macOS, Windows pwnage tools are loose
Up up and Huawei in my beautiful buffoon: Trump sparks panic by tying tech kit ban, charges to China trade negotiations