Menu

Latest articles

GDPR Suit Filed Against Amazon, Apple
2018’s Most Common Vulnerabilities Include Issues New and Old
How 2018 became Facebook’s worst year in privacy and security
North Korean Hackers Get Access To Chile’s ATM After Employee Falls For Fake Job Interview Over Skyp
The Iceman cometh, his smartwatch told the cops: Hitman jailed after gizmo links him to Brit gangland slayings

LinuxSecurity.com: **PHP version 7.2.14** (10 Jan 2019) **Core:** * Fixed bug php#77369 (memcpy with negative length via crafted DNS response). (Stas) * Fixed bug php#71041 (zend_signal_startup() needs ZEND_API). (Valentin V. Bartenev) * Fixed bug php#76046 (PHP generates “FE_FREE” opcode on the wrong line). (Nikita) **Date:** * Fixed bug php#77097 (DateTime::diff gives wrong diff when the

LinuxSecurity.com: Security fix for CVE-2018-20455 CVE-2018-20456 CVE-2018-20457 CVE-2018-20458 CVE-2018-20459 CVE-2018-20460 CVE-2018-20461 through rebase to 3.2.0

Google Play Removes Malicious Malware-Ridden Apps

security update

US midterms barely over when Russians came knocking on our servers (again), Democrats claim
Fallout EK Retools for a Fresh New 2019 Look
Ingenious! The Android malware which only triggers if you’re moving
Threatpost News Wrap Podcast For Jan. 18
Critical, Unpatched Cisco Flaw Leaves Small Business Networks Wide Open

Risk Level: Very Low. Type: Trojan.

Reading Time: ~2 min. Texas Town Brought to a Halt by Ransomware Several days ago the town of Del Rio, Texas, fell victim to a ransomware attack that knocked most of the town’s major systems offline. While the town’s IT department quickly worked to isolate the infection, remaining departments were forced to switch to hand-written […]

Get 3 Years of NordVPN Service for Just $2.99 Per Month – Deal Alert
Twitter Android Glitch Exposed Private Tweets for Years
Watch as hackers take over a construction crane
Malware can fully compromise building control systems
Cryptopia cryptocurrency exchange hacked; suffers “significant losses”
Bug bounty: Hack Tesla Model 3 to win your own Model 3
The Pirate Bay malware can empty your Cryptocurrency wallet
Microsoft partner portal ‘exposes ‘every’ support request filed worldwide’ today
Two men charged with hacking into SEC in stock-trading scheme

The hacking duo is believed to have exploited a software flaw and compromised several SEC workstations with malware in order to take early peeks at financial disclosures The post Two men charged with hacking into SEC in stock-trading scheme appeared first on WeLiveSecurity

Vast data-berg washes up 1.16 billion pwned records
Google cracks down on access to your Android phone and SMS data
Did you know you can see the ad boxes Facebook sorts us into?
The 773 Million Record “Collection #1” Data Breach
There’s a simple reason why your new smart TV was so affordable: It’s collecting and selling your da
15+ Password Cracking Techniques Used By Hackers 2019
YouTube bans dangerous and harmful pranks and challenges
I used to be a dull John Doe. Thanks to Huawei, I’m now James Bond!
Microsoft blue biz bug bounty bonanza beckons
Old bugs, new bugs, red bugs … yes, it’s Oracle mega-update day again
Got a Drupal-powered website? You may want to get patching now…
Twitter. Android. Private tweets. Pick two… Account bug unlocked padlocked accounts
Microsoft Launches Azure DevOps Bug Bounty Program
Apple CEO Demands Federal Data Privacy Legislation

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Top GP: Medical app Your.MD’s data security wasn’t my remit
Cyber-Jackpot: 773M Credentials Dumped on the Dark Web
773 million records with emails & plain text passwords leaked online
The Collection #1 data breach – what you need to do about it
773 million email IDs, 21 million passwords for anyone to see in massive data dump

The vast dossier of stolen login details appears to have been gathered from data stolen in many breaches The post 773 million email IDs, 21 million passwords for anyone to see in massive data dump appeared first on WeLiveSecurity

Microsoft font gives away forgery in bankruptcy case
Email crooks swindle woman out of $150K from home sale
Cryptomining Malware Uninstalls Cloud Security Products
Magecart hits hundreds of websites via ad supply chain hijack
Change your password! VoIP provider leaves huge database exposed online
New Year’s resolutions: Routing done right

As another thing to improve this year, you may want to route your focus on a device that is the nerve center of your network and, if poorly secured, the epicenter of much potential trouble The post New Year’s resolutions: Routing done right appeared first on WeLiveSecurity

Two charged with hacking company filings out of SEC’s EDGAR system
Happy Thursday! 770 MEEELLLION email addresses and passwords found in yuge data breach
As the Government Shutdown Drags on, Security Risks Intensify
Oracle Java Card updated for IoT applications

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.

South Korea says mystery hackers cracked advanced weapons servers
$24m in fun bux stolen from crypto-mogul. Now he fires off huge fraud charge. Like, RICO, say?
Smashing Security #111: When rivals hack, and ‘extreme’ baby monitors

Risk Level: Very Low. Type: Trojan.

Threatpost Survey Says: 2FA is Just Fine, But Go Ahead and Kill SMS
Millions of Oklahoma Gov Files Exposed by Wide-Open Server
Exploring the economic realities of cybersecurity insurance | Salted Hash Ep 43

LinuxSecurity.com: Several security issues were fixed in libcaca.

Lowjax city: Researchers crack open notorious Fancy Bear rootkit
U.S. Issues Multiple Charges For 2016 SEC Hack
Fortnite Hacked Via Insecure Single Sign-On
Magecart Returns with Advertising Library Tactic
Car and almost $1m on offer for Tesla Model 3 hacks

The electric car maker is raising the ante in automotive security, putting one of its swanky models as a target at a hacking contest The post Car and almost $1m on offer for Tesla Model 3 hacks appeared first on WeLiveSecurity

Epic’s Fortnite fail: Ancient UT2004 server used for login-stealing proof-of-concept
VOIPO Database Exposes Millions of Texts, Call Logs
Microsoft sends a raft of Windows 10 patches out into the Windows Update ocean
Are you sure those WhatsApp messages are meant for you?
Intel patches another security flaw in SGX technology
Beware buying Fortnite’s V-Bucks, you could be funding organised crime
Firms fined $1M for SingHealth data security breach
UK Banks Finally Issue New Cards After Ticketmaster Breach
Feds can’t force you to unlock your phone with finger or face, says judge

LinuxSecurity.com: This update fixes CVE-2018-20685 (the first “variant”) and backports several fixes to unbreak ECDSA authentication from PKCS#11, certificate authentication and so on.

LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).

LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).

LinuxSecurity.com: Patch for CVE-2016-10091

EDGAR Wrong: Ukrainians hacked SEC, stole docs for inside trading, says Uncle Sam

LinuxSecurity.com: Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation. A local attacker could possibly use this issue to perform a cache-timing attack and recover private ECDSA keys (CVE-2018-0495). References:

LinuxSecurity.com: A heap use-after-free vulnerability in the server code of the file transfer extension, which can result in remote code execution. This attack appears to be exploitable via network connectivity (CVE-2018-6307).

LinuxSecurity.com: It was observed that URL’s which gets downloaded via “–log=” attribute stores sensitive information. This update fixes that. References: – https://bugs.mageia.org/show_bug.cgi?id=24112

IDenticard Zero-Days Allow Corporate Building Access, Location Recon
‘It’s like they took a rug and covered it up’: Flight booking web app used by scores of airlines still vuln to attack – claim
Data Breach Roundup: U.S. Healthcare, Cryptopia, SingHealth and Experian

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

security update

security update

LinuxSecurity.com: Several issues in wireshark, a tool that captures and analyzes packets off the wire, have been found by different people. These are basically issues with length checks or invalid memory access in

LinuxSecurity.com: libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (CVE-2018-15127) SL7 x86_64 libvncserver-0.9.9-13.el7_6.i686.rpm libvncserver-0.9.9-13.el7_6.x86_64.rpm libvncserver-debuginfo-0.9.9-13.el7_6.i686.rpm libvncserver-debuginfo-0.9.9-13.el7_6.x86_64.rpm libvncserver-devel-0.9.9-13.el7_6.i686.rpm [More…]

Judge: Law Enforcement Can’t Force Suspects to Unlock iPhones with FaceID
ThreatList: $1.7M is the Average Cost of a Cyber-Attack