Menu

Latest articles

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or bypass of the same-origin policy.

Smashing Security #108: Hoaxes, Huawei and chatbots – with Mikko Hyppönen
UK white hats blacklisted by Cisco Talos after smart security code stumbles

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com:

Supermicro says independent investigation found no spy chips on its motherboards
It is with a heavy heart that we must inform you hackers are targeting ‘nuclear, defense, energy, financial’ biz
Android Trojan Targets PayPal Users

LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or bypass of the same-origin policy.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Azure Pack is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Dynamics NAV is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft PowerPoint is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a memory corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a heap-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to an information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: USN-3837-1 introduced a regression in poppler.

ThreatList: Holiday Spam, the Perfect Seasonal Gift for Criminals
Bulk surveillance is always bad, say human rights orgs appealing against top Euro court
Britain approved £2.5m of snooping kit exports to thoroughly snuggly regime in Saudi Arabia
Operation Sharpshooter Takes Aim at Global Critical Assets
Super Micro Says Its Gear Wasn’t Bugged By Chinese Spies
Bad news for scammers. Huawei executive Meng Wanzhou has been released on bail
Supply Chain Security: Managing a Complex Risk Profile
Samsung fixes flaws that could have let attackers hijack your account
Google+ to power down early after second security hole found
Text CAPTCHAs easily beaten by neural networks
Phones are selling location data from “trusted” apps
New Google+ Breach Will Lead to Early Service Shutdown
Equifax breach was ‘entirely preventable’ had it used basic security measures, says House report
Ticketmaster tells customer it’s not at fault for site’s Magecart malware pwnage

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

It’s December of 2018 and, to hell with it, just patch your stuff

LinuxSecurity.com: Firefox could be made to crash or run programs as your login if it opened a malicious website.

Facebook Fined $11.3M for Privacy Violations
Zero-Day Bug Fixed by Microsoft in December Patch Tuesday
Equifax how-it-was-mega-hacked damning dossier lands, in all of its infuriating glory

security update

25% of NHS trusts have zilch, zip, zero staff who are versed in security

LinuxSecurity.com: pixman could be made to crash or run programs if it processed specially crafted instructions.

Data Privacy Issues Trigger Soul Searching in Tech Industry
Cobalt Group Pushes Revamped ThreadKit Malware

LinuxSecurity.com: pixman could be made to crash or run programs if it processed specially crafted instructions.

LinuxSecurity.com: The package openssl-1.0 before version 1.0.2.q-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package lib32-openssl-1.0 before version 1.0.2.q-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package lib32-openssl before version 1:1.1.1.a-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package openssl before version 1.1.1.a-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package texlive-bin before version 2018.48691-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package wireshark-cli before version 2.6.5-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package chromium before version 71.0.3578.80-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, information disclosure and insufficient validation.

LinuxSecurity.com: CUPS could be made to expose sensitive information.

LinuxSecurity.com: lxml could allow cross-site scripting (XSS) attacks.

LinuxSecurity.com: lxml could allow cross-site scripting (XSS) attacks.

LinuxSecurity.com: This is the one-Month notification for the retirement of Red Hat Enterprise Linux 6.6 Telco Update Service (TUS). This notification applies only to those customers subscribed to the Telco Update Service (TUS) channel for Red Hat Enterprise Linux 6.6.

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 7.3 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.3.

LinuxSecurity.com: This is the one-Month notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.

Adobe December 2018 Security Update Fixes Reader, Acrobat
Biometrics: Security Solution or Issue?
Google+ to shut earlier as new bug exposed data of 52.5 million users

There is no evidence that the flaw was misused during the six days it was alive, said the tech giant The post Google+ to shut earlier as new bug exposed data of 52.5 million users appeared first on WeLiveSecurity

Linux.org Redirected to NSFW Page Spewing Racial Epithets
Android Trojan steals money from PayPal accounts even with 2FA on

ESET researchers discovered a new Android Trojan using a novel Accessibility-abusing technique that targets the official PayPal app, and is capable of bypassing PayPal’s two-factor authentication The post Android Trojan steals money from PayPal accounts even with 2FA on appeared first on WeLiveSecurity

Lenovo tells Asia-Pacific staff: Work lappy with your unencrypted data on it has been nicked
Dark web goldmine busted by Europol
Teen SWATter who had 400 schools evacuated lands 3 years in jail