Menu

Latest articles

LinuxSecurity.com: A vulnerability in the HTML_QuickForm package has been found which potentially allows remote code execution. References: – https://bugs.mageia.org/show_bug.cgi?id=24185

LinuxSecurity.com: It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service (CVE-2018-20544). It was discovered that libcaca incorrectly handled certain images. An

LinuxSecurity.com: An issue has been found in PowerDNS Recursor where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua (CVE-2019-3806).

Risk Level: Very Low. Type: Trojan.

ThreatList: Credential-Sniffing Phishing Attacks Erupted in 2018
Passwords at risk for users who fall for Eileen’s cousin’s voicemail
Colour us shocked: Google in €50m GDPR fine appeal bombshell
Bit-and-Piece DDoS Method Emerges to Torment ISPs
DarkHydrus Phishery tool spreading malware using Google Drive
Malicious apps deploy Anubis banking trojan using motion detection
World’s favourite open-source PDF interpreter needs patching (again)
Bomb threat spam may stem from GoDaddy DNS weakness
Can you spot the phish? Take Google’s test

Everybody loves quizzes. So why not take this one and hone your phish-spotting prowess? The post Can you spot the phish? Take Google’s test appeared first on WeLiveSecurity

Supreme Court won’t consider case against defamatory reviews on Yelp
How to stop a hacker home invasion! [VIDEO]
Update now! Apple releases first 2019 iOS and macOS patches
“Proceed with caution”: Microsoft browser says Mail Online is untrustworthy
Nasty security bug found and fixed in Linux apt
New ransomware strain is locking up Bitcoin mining rigs in China
Sky Go app security failure exposes customers to snooping, data theft
Tech sector meekly waves arms in another bid to get Oz to amend its crypto-busting laws
Hadoop coop thrown for loop by malware snoop n’ scoop troop? Oh poop

LinuxSecurity.com: Security fix for CVE-2018-20551, CVE-2018-20481, CVE-2018-20650 and CVE-2018-18897.

LinuxSecurity.com: – xattr: strip credentials from any URL that is stored (CVE-2018-20483)

LinuxSecurity.com: Security fix for CVE-2019-5010 in Python. Anaconda is joined because an unrelated fix was done there that allowed to remove a workaround in Python.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

8-year-old ‘scared to death’ after hacked Nest security camera warns of missile attack
Smashing Security #112: Payroll scams, gold coin heists, web giants spanked

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

As netizens, devs scream bloody murder over Chrome ad-block block, Googlers insist: It’s not set in stone (yet)
Fake broadband ISP support scammers accidentally cough up IP address to Deadpool in card phish gone wrong

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Redaman Spams Russian Banking Customers with Rotating Tactics
Google faces another GDPR probe – this time in the land of meatballs and flat-pack furniture
Malware in Ad-Based Images Targets Mac Users
Monero: Cybercrime’s Top Choice for Mining Malware
Poisoned PEAR. PHP extension repository download infected for up to six months

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Got a Nest security camera? Enable two-step verification now
6 Signs of Successful Threat Hunting
‘Chaos’ iPhone X Attack Alleges Remote Jailbreak
Popular free Android VPN apps on Play Store contain malware
U.S. Gov Issues Urgent Warning of DNS Hijacking Attacks
100 million online bets exposed by leaky database

Reading Time: ~3 min. Fitness trackers and other digital wearables have unlocked a new era of convenience and engagement in consumer health. Beyond general fitness trackers, you can find wearables for a variety of purposes; some help diabetics, some monitor for seizure activity, and some can aid in senior citizens’ health and quality of life. […]

Black hats are great for language diversity, says Eugene Kaspersky
PewDiePie-spammers and whale-flingers exploit hole in Atlas game
Former employee blamed for hack of WordPress plugin maker

The plugin’s users are recommended to change their passwords on WPML’s website following havoc reportedly wrought by a disgruntled ex-employee The post Former employee blamed for hack of WordPress plugin maker appeared first on WeLiveSecurity

Microsoft Windows RCE Flaw Gets Temporary Micropatch
RogueRobin Malware Uses Google Drive as C2 Channel
Google fined $57m for data protection violations
Hijacked Nest cam broadcasts bogus warning about incoming missiles
White-listing Azure cloud connections to grease your Office 365 wheels? About that…

LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: Multiple vulnerabilities were found in the journald component of systemd which can lead to a crash or code execution. CVE-2018-16864

Build the wall… around your DNS settings, US govt IT staff urged by Homeland Security amid domain hijackings

LinuxSecurity.com: Fix for CVE-2019-5885 Upgrade notes available at https://github.com/matrix- org/synapse/blob/v0.34.0/UPGRADE.rst#upgrading-to-v0340 – Note this continues to use Python 2.

Plug in your iPhone, iPad, iPod, fire up the App Store: You have new Apple patches to install

LinuxSecurity.com: Several vulnerabilities have been resolved in libjpeg-turbo, Debian’s default JPEG implemenation. CVE-2016-3616

Wow, fancy that. Web ad giant Google to block ad-blockers in Chrome. For safety, apparently
Heads up: Debian’s package manager is APT for root-level malware injection… Fix out now to thwart MITM hijacks
En garde! ‘Cyber-war has begun’ – and France will hack first, its defence sec declares
How Web Apps Can Turn Browser Extensions Into Backdoors
French diplomat: Spies gonna spy – there aren’t any magical cyberspace laws that can prevent it
Google Fined $57M in Largest GDPR Slap Yet
Looks like Uncle Sam has pulled its finger out and appointed a Privacy Shield ombudsperson
Adobe Issues Unscheduled Updates for Experience Manager Platform
Google fined €50 million for violating EU data privacy rules

France’s data protection watchdog issues the first major penalty under the EU’s new privacy regime The post Google fined €50 million for violating EU data privacy rules appeared first on WeLiveSecurity

Stalk my pals on social media and you’ll know that the next words out of my mouth will be banana hammock
Email security does not end with your password

A strong password is a great start, but there are more ways to make sure that your email is as secure as possible The post Email security does not end with your password appeared first on WeLiveSecurity

Rogue websites can turn vulnerable browser extensions into back doors
Bicycle-riding hitman convicted with Garmin GPS watch location data
Get in the bin: Let’s Encrypt gives admins until February 13 to switch off TLS-SNI-01
WhatsApp fights the spread of deadly fake news with recipient limit

LinuxSecurity.com: It was discovered that aria2 (the lightweight command-line download utility) can store passed user credentials in a log file when using the –log option. This might allow local users to obtain sensitive information by reading this file.

DNC targeted by Russian hackers beyond 2018 midterms, it claims

security update

Twitter exposed some Android users’ protected tweets, and didn’t notice for over four years
Angry ex-employee blamed for hack of WordPress plugin developer, and email to customers warning of security hole
Twitter bug may have exposed private tweets of Android users for years

If you use Twitter for Android and want your tweets to be private, you may want to play safe and review your settings The post Twitter bug may have exposed private tweets of Android users for years appeared first on WeLiveSecurity

Is the Ten Year Challenge a Facebook scam???
Twitter bug exposed some Android private tweets to public view
Attackers used a LinkedIn job ad and Skype call to breach bank’s defences
Learn how Starbucks combats credential stuffing & account takeover (ATO)
State agency exposes 3TB of data, including FBI info and remote logins
Websites can steal browser data via extensions APIs
Tim Cook demands a way for users to delete their personal data

LinuxSecurity.com: admin: Prevent access if any authentication agent isn’t available

Twitter bug exposed private tweets of Android users to public for years
New ransomware steals PayPal data with phishing link in ransom note

LinuxSecurity.com: Fix for use after free in affile_dw_reap

LinuxSecurity.com: libssh versions 0.6 and above have an authentication bypass vulnerability in the server code. By presenting the server an SSH2_MSG_USERAUTH_SUCCESS message in place of the SSH2_MSG_USERAUTH_REQUEST message which the server would expect to initiate authentication, the attacker could successfully authentciate

Serious Security: What 2000 years of cryptography can teach us
DDoS sueball, felonious fonts, leaky Android file manager, blundering building security, etc etc