Menu

Latest articles

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation (bsc#1118319). – CVE-2018-5848: Fixed an unsigned integer overflow in […]

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation (bsc#1118319). – CVE-2018-5848: Fixed an unsigned integer overflow in wmi_set_ie. […]

Risk Level: Very Low. Type: Trojan.

Automotive Security: It’s More Than Just What’s Under The Hood
Charming Kitten Iranian Espionage Campaign Thwarts 2FA
Influential cypherpunk and crypto-anarchist Tim May dies aged 67
PewDiePie Hackers Say They Launched Second Printer Siege
Facebook bug exposed private photos of 6.8M users to third-party developers
Hackers bypassed Gmail & Yahoo’s 2FA to target US officials
Personal & banking data of 120 million Brazilians leaked online
IT consultancy firm caught running ransomware decryption scam
Who’s watching you from an unmarked van while you shop in London? Cops with facial recog tech
The most popular passwords of 2018 revealed: Are yours on the list?

Besides the usual suspects among the worst of passwords, a handful of notable – but similarly poor – choices make their debuts The post The most popular passwords of 2018 revealed: Are yours on the list? appeared first on WeLiveSecurity

Worst passwords list is out, but this time we’re not scolding users
phpMyAdmin Releases Critical Software Update – Patch Your Sites Now!
Facebook bug exposed unposted photos of 6.8 million users
Former rave kingpin back in jail for bizarre bank heist
Fake face fools fones

LinuxSecurity.com: Updated packages are now available for Red Hat Gluster Storage 3.4 Web Administration on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: – Update to 2.14.1 – CVE-2018-19608 (#1656784) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2018-03 —- – Update to 2.14.0 Release notes:

PewDiePie fan hacker compromise 100,000 printers
Wicked scammers steal $1 million from Save the Children charity
Critical SQLite Flaw Leaves Millions of Apps Vulnerable to Hackers

LinuxSecurity.com: New upstream version 1.8.2. Fix low priority security issue with TLS: https://www.redhat.com/archives/libguestfs/2018-December/msg00047.html —- New upstream version 1.8.1. —- Rebase to new stable version 1.8.0. —- nbdkit metapackage should depend on versioned -server subpackage etc. —- New upstream version 1.6.3.

LinuxSecurity.com: Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644

LinuxSecurity.com: Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

LinuxSecurity.com: It was discovered there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack (CVE-2018-19208). References:

LinuxSecurity.com: – Buffer overflow using computed size of canvas element. (CVE-2018-12359) – Use-after-free when using focus(). (CVE-2018-12360) – Integer overflow in SwizzleData. (CVE-2018-12361)

LinuxSecurity.com: A buffer overflow and out-of-bounds read can occur in TextureStorage11 within the ANGLE graphics library, used for WebGL content. This results in a potentially exploitable crash (CVE-2018-17466). A use-after-free vulnerability can occur after deleting a selection

LinuxSecurity.com: Cache side-channel variant of the Bleichenbacher attack.(CVE-2018-12404) References: – https://bugs.mageia.org/show_bug.cgi?id=23972 – https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.36.6_release_notes

LinuxSecurity.com: A vulnerability in Scala could result in privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been found in SpamAssassin, the worst of which may lead to remote code execution.

LinuxSecurity.com: Multiple vulnerabilities have been found in CouchDB, the worst of which could lead to the remote execution of code.

Facebook could face billion dollar fine for data breaches

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

Blockchains should have ‘privacy by design’ for GDPR compliance
Fake Bomb Threat Emails Demanding Bitcoins Sparked Chaos Across US, Canada

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

Brazil bested by hackers, Virgin plugs hub bugs, and France surrenders… records
‘Bomb threat’ scammers linked to earlier sextortion campaign
Scumbag hackers lift $1m from children’s charity
Electric Vehicle Charging Stations Open to IoT Attacks
Stop us if you’ve heard this one: Facebook apologizes for bug leaking private photos
WordPress 5.0 Patched to Fix Serious Bugs
ZipRecruiter has been flying low: User email addresses exposed to unauthorised accounts
International email bomb hoax proves to be a spectacular failure

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Facebook Flaw Exposes Private Photos for 6.8M Users
Logitech Keystroke Injection Flaw Went Unaddressed for Months
Save the Children Federation Duped in $1M Scam
A critical bug in Microsoft left 400M accounts exposed
Nasty Android malware found stealing its victims’ PayPal funds
Apps on smartphones are selling and sharing our location data 24/7
PlayStation Classic hacked to become platform-free console
Google Plus hit by another breach – Data of 52.5M users exposed
Toyota’s PASTA- A car hacking tool to enhance automobile cybersecurity

Reading Time: ~2 min. Clemson Supercomputer Susceptible to Cryptojacking IT staff at Clemson University have been working to remove the recent introduction of a cryptominer on its supercomputer, known as Palmetto. As they compromised the system for the mining of Monero, the attackers’ ploy was only spotted due to spikes in computing power and rising operating […]

YouTube is reading text in users’ videos
Facebook has filed patents to predict our future locations
Kanye West tops the charts for year’s worst password pratfall
Rhode Island sues Google after latest Google+ API leak
Apache Misconfig Leaks Data on 120 Million Brazilians

LinuxSecurity.com: This update fixes libstdc++ std::future support on armel, which is necessary to get firefox-esr and thunderbird updates built on that architecture.

2018 – a year of data breaches in review
How to protect yourself as the threat of scam apps grows

As the threat of bogus apps continues, what can we do to protect ourselves against these fraudulent practices? The post How to protect yourself as the threat of scam apps grows appeared first on WeLiveSecurity

Update now! WordPress 5.0.1 release fixes seven flaws
US bitcoin bomb threat ransom scam looks like a hoax say FBI, cops
US elections watchdog says it’s OK to spend surplus campaign cash on cybersecurity gear
Bomb Threat Bitcoin Demands Cause Disruption, Evacuations
Fraudster convicted of online banking thefts using… whatever the hell this thing is
The fastest, most secure browser? Microsoft Edge apparently

security update

Grammarly Launches Public Bug Bounty Program
Unlocking Android phones with a 3D-printed head

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The package firefox before version 64.0-1 is vulnerable to multiple issues including arbitrary code execution, same-origin policy bypass and access restriction bypass.

Secure Critical Infrastructure Top of Mind for U.S.
Google Beefs Up Android Key Security for Mobile Apps
‘Exclusive swag’ up for grabs as GitLab flings bug bounty scheme open to world+dog
Border agents are copying travelers’ data, leaving it on USB drives
Shamoon Reappears, Poised for a New Wiper Attack
Supermicro: We told you the tampering claims were false

Reading Time: ~2 min. Virtual Private Networks (VPNs) are quickly becoming a fundamental necessity for staying safe online. From large corporations to family households, people are turning to VPNs to ensure their data is encrypted end to end. But as with any emerging technology, it’s easy to become overwhelmed with new and untested VPN options. […]

Update now! Microsoft and Adobe’s December 2018 Patch Tuesday is here
Taylor’s gonna spy, spy, spy, spy, spy… fans can’t shake cam off, shake cam off

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.