Menu

Latest articles

Huawei Router Flaw Leaks Default Credential Status

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

U.S. Indicts China-Backed Duo for Massive, Years-Long Spy Campaign
Drones shut down major international airport

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Amazon Sends 1,700 Alexa Voice Recordings to a Random Person
Facebook Admits Giving Partners Access to Messages
Microsoft IE Zero Day Gets Emergency Patch
Microsoft issues emergency fix for Internet Explorer zero-day

Details are sparse about a security hole that Microsoft said is being exploited in targeted attacks The post Microsoft issues emergency fix for Internet Explorer zero-day appeared first on WeLiveSecurity

Here is a list of top 25 worst passwords of 2018
Hacker found using Twitter memes to spread malware
Pro-PewDiePie messages appear on hacked Wall Street Journal website
Chinese hackers reportedly stole secret US Navy data
France next up behind Britain, Netherlands to pummel Uber with €400k fine over 2016 breach
Spooked by a speaking security camera? Polite hacker tells owner how to fix his IoT security
Facebook denies sharing private messages without user knowledge
Most home routers lack simple Linux OS hardening security
Glitter bomb engineer exacts revenge on parcel thieves
Facebook defends giving tech giants access to extensive user data
Mayday! NASA Warns Employees of Personal Information Breach
Phone repair shop employees accused of stealing nude photos
London’s Gatwick airport suspends all flights after ‘multiple’ reports of drones
Holiday online shopping special tips

Some useful advice for staying safe while hunting for bargains in this holiday season The post Holiday online shopping special tips appeared first on WeLiveSecurity

Facebook’s Rough History of Failed User Revolts
NASA suffers data breach – Staff’s personal data stolen
Smashing Security #109: Grinches target Amazon and Reddit, stealing Christmas from the poor

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3854

LinuxSecurity.com: Several local side channel attacks and a denial of service via large Diffie-Hellman parameters were discovered in OpenSSL, a Secure Sockets Layer toolkit.

Facebook gave Amazon, Netflix, Spotify & others access to private user data

LinuxSecurity.com: An update that solves two vulnerabilities and has 11 fixes is now available. Description: Description: This update for salt fixes the following issues: – Crontab module fix: file attributes option missing (boo#1114824) – Fix git_pillar merging across multiple __env__ repositories (boo#1112874) – Bugfix: unable to detect os arch when RPM is not installed (boo#1114197) […]

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for the Linux Kernel 3.12.61-52_141 fixes one issue. The following security issue was fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.61-52_111 fixes several issues. The following security issues were fixed:

Patched Click2Gov Flaw Still Afflicting Local Govs
On the first day of Christmas, Microsoft gave to me… an emergency out-of-band security patch for IE

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. Description: Description: This update for ovmf fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for libnettle fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. Description: Description: This update for tiff fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for git fixes the following issues: Security issue fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for bluez fixes the following issues: Security issues fixed:

US told to appoint a damn Privacy Shield ombudsperson already or EU will take action
Hackers Succeed in NASA Mission, Lifting Thousands of Employee Records
Chill, it’s not WikiLeaks 2: Pile of EU diplomatic cables nicked by hackers
Threatpost Poll: Do You Hate Facebook?
NASA fears hackers may have stolen employee data

A probe launched immediately after the discovery of the suspected incident has yet to establish the scale of the potential damage The post NASA fears hackers may have stolen employee data appeared first on WeLiveSecurity

Serious Security: When cryptographic certificates attack
Facebook waited months before admitting privacy bug exposed millions of users’ unposted photos
Facebook Fights Back on Secret Data-Sharing Partnerships

LinuxSecurity.com: An update that solves three vulnerabilities and has four fixes is now available. Description: Description: This new package for go1.11 fixes the following issues: Security issues fixed: – CVE-2018-16873: Fixed a remote code execution in go get, when executed [More…] with the -u flag (bsc#1118897) with the -u flag (bsc#1118897) [More…] – CVE-2018-16874: Fixed […]

Snack-happy parrot shows insider threats come in all shapes and sizes
Instagram became the preferred tool in Russia’s propaganda war
SQLite creator fires back at Tencent’s bug hunters
How not to secure US missile defences
Stop the credential thieves before they stop your business

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3834

LinuxSecurity.com: Update to 2.7.5 bugfix release. Fix for CVE-2018-16876

Houston, we’ve had a problem: NASA fears internal server hacked, staff personal info swiped by miscreants
Russia-Linked Sofacy Debuts Fresh Zebrocy Malware Variant
American bloke hauls US govt into court after border cops ‘cuffed him, demanded he unlock his phone at airport’
After SamSam, Ryuk shows targeted ransomware is still evolving
German cybersecurity chief: Anyone have any evidence of Huawei naughtiness?

Risk Level: Very Low. Type: Trojan.

WordPress Targeted with Clever SEO Injection Malware
Target targeted: Five years on from a breach that shook the cybersecurity industry

In December 2013 news broke that Target suffered a breach that forced consumers and the cybersecurity community to question the security practices of retailers The post Target targeted: Five years on from a breach that shook the cybersecurity industry appeared first on WeLiveSecurity

Hidden Code in Memes Instruct Malware via Twitter
WSJ Webpage Defaced to Support PewDiePie
Newsmaker Interview: Troy Mursch on Top Botnet Trends

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Cybersecurity Trends 2019: Privacy and intrusion in the global village

With just days left in 2018, ESET experts offer their reflections in ‘Cybersecurity Trends 2019’ on themes that are set to figure prominently in the upcoming year The post Cybersecurity Trends 2019: Privacy and intrusion in the global village appeared first on WeLiveSecurity

Facebook photo API bug exposed users’ unpublished photos
Save the Children Hit by $1m BEC Scam
Cybercriminals Change Tactics to Outwit Machine-Learning Defense
Logitech flaw fixed after Project Zero disclosure
Twitter fixes bug that lets unauthorized apps get access to DMs
Sneaky phishing campaign beats two-factor authentication
Memes, messengers, and missiles: From Twitter to chat apps and weapons, security is ho-ho-hosed this Xmas
You better watch out, you better not cry. Better not pout, I’m telling you why: SQLite vuln fixes are coming to town

Risk Level: Very Low. Type: Trojan.

U.S. Ballistic Missile Defense System Rife with Security Holes
Twitter Draws Data Privacy Concerns with Two New Bugs

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation (bsc#1118319). – CVE-2018-5848: Fixed an unsigned integer overflow in […]

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation (bsc#1118319). – CVE-2018-5848: Fixed an unsigned integer overflow in wmi_set_ie. […]

Risk Level: Very Low. Type: Trojan.

Automotive Security: It’s More Than Just What’s Under The Hood
Charming Kitten Iranian Espionage Campaign Thwarts 2FA
Influential cypherpunk and crypto-anarchist Tim May dies aged 67
PewDiePie Hackers Say They Launched Second Printer Siege
Facebook bug exposed private photos of 6.8M users to third-party developers