Menu

Latest articles

Facebook fined $11m for misleading users about how data will be used
Texas Instruments flicks Armis’ Bluetooth chip vuln off its shoulder
Google admits Google Plus hit by *another* privacy flaw, speeds up site’s closure
GlobeImposter ransomware victims find themselves abandoned by their extortionists
Latest Google+ flaw leads Chocolate Factory to shut down site early

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Women in Cyber Take the Spotlight
Did you know that iOS ad clicks cost more than Android? These scammers did

LinuxSecurity.com: Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: The EXIF module was susceptible to denial of service/information disclosure when parsing malformed images, the Apache module allowed cross-site-scripting via the body of a

Nice phone account you have there – shame if something were to happen to it: Samsung fixes ID-theft flaws
Google Accelerates Google+ Shutdown After New Bug Discovered
Sextortion Emails Force Payment via GandCrab Ransomware

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

Risk Level: Very Low. Type: Trojan.

Old-School Bagle Worm Spotted in Modern Spam Campaigns
Volkswagen Giveaway Scam Peddles Ad Networks
Privacy, security fears about ID cards? UK.gov’s digital bod has one simple solution: ‘Get over it’
Next Generation Dark Markets? Think Amazon or eBay for criminals

The “evolution” of these markets is making cybercrime easier than ever before The post Next Generation Dark Markets? Think Amazon or eBay for criminals appeared first on WeLiveSecurity

Massive botnet chews through 20,000 WordPress sites
Android click fraud apps mimic Apple iPhones to boost revenue
Microsoft’s gutting Edge and stuffing it with Chromium
235 members of dark web money counterfeiting gang busted
Security News This Week: Did Quora Get Hacked? Top Answer: Yes
Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
Microsoft calls for laws on facial recognition, issues principles

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: It was discovered that there was a XSS injection vulnerability in the LXML HTML/XSS manipulation library for Python. LXML did not remove “javascript:” URLs that used escaping such as

LinuxSecurity.com: An update for rh-git218-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service (CVE-2018-1336). The defaults settings for the CORS filter are insecure and enable

LinuxSecurity.com: An update that fixes 27 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

DuckDuckGo study claims Google Incognito searches are not private
Hackers conducting botnet attacks through 20k hacked WordPress sites
Another MongoDB database exposes personal data of 66M users
Days After Massive Breach, Marriott Customers Await Details

security update

22 malware infected apps on Play Store found draining phone’s battery

LinuxSecurity.com: Use after free flaw enabling arbitrary code execution. (CVE-2018-15982) Insecure Library Loading (DLL hijacking) flaw enabling privilege escalation. (CVE-2018-15983)

LinuxSecurity.com: The HTML thumbnailer was incorrectly accessing some content of remote URLs listed in HTML files. This meant that the owners of the servers referred in HTML files in your system could have seen in their access logs your IP address every time the thumbnailer tried to create the thumbnail (CVE-2018-19120).

GDPR Implementation Slow but Improving
Addresses and Names of Customers Exposed by Bethesda in Support Tickets
Linux 4.19.8 Released With BLK-MQ Fix To The Recent Data Corruption Bug
6 Critical Website Elements You Need to Review
415,000 routers infected by cryptomining malware – Prime target MikroTik
New AI tool aims to make CAPTCHA a thing of the past
Bethesda blunders, IRS sounds the alarm, China ransomware, and more
In case you’re not already sick of Spectre… Boffins demo Speculator tool for sniffing out data-leaking CPU holes
Identity stolen because of the Marriott breach? Come and claim your new passport
‘Say hello to my little vacuum cleaner!’ US drug squad puts spycams in cleaner’s kit
ThreatList: Gift Card-Themed BEC Holiday Scams Spike
Linux.org domain hacked, plastered with trolling, filth and anti-transgender vandalism

security update

Type: Vulnerability. Adobe Flash Player is prone to an unspecified remote code-execution vulnerability; fixes are available.

Australia Anti-Encryption Law Triggers Sweeping Backlash
TA505 Crooks are Now Targeting US Retailers with Personalized Campaigns

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Reading Time: ~2 min. Touch ID Used to Scam Apple Users Two apps were recently removed from the Apple App Store after several users reported being charged large sums of money after installing the app and scanning their fingerprint. Both apps were fitness-related and had users scan their fingerprint immediately so they could monitor calories or […]

Brit bomb hoax teen who fantasised about being a notorious hacker cops 3 years in jail
Using Fuzzing to Mine for Zero-Days
Three years in jail for teenager who spammed out school bomb threats
Microsoft Calls For Facial Recognition Tech Regulation

LinuxSecurity.com: An update that fixes one vulnerability is now available.

UK Supreme Court considers whether spy court should be immune to legal probes

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves 7 vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Flash zero-day exploit spotted – patch now!
Kids’ VTech tablets vulnerable to eavesdropping hackers
Unencrypted medical data leads to 12-state litigation
Hacker-besieged DNA data tucked away under military care
Australia now has encryption-busting laws as Labor capitulates
The path to cloud security goes through integration
Wow, what a lovely early Christmas present for Australians: A crypto-busting super-snoop law passes just in time

security update

LinuxSecurity.com: A vulnerability in EDE could result in privilege escalation.

LinuxSecurity.com: The package jupyter-notebook before version 5.7.2-1 is vulnerable to cross-site scripting.

LinuxSecurity.com: It was discovered that incorrect processing of very high UIDs in Policykit, a framework for managing administrative policies and privileges, could result in authentication bypass.

LinuxSecurity.com: Several security issues were fixed in OpenSSL.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3760

Infected WordPress Sites Are Attacking Other WordPress Sites

LinuxSecurity.com: Several security issues were fixed in SpamAssassin.

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Facebook Defends Data Policies On Heels of Incriminating Internal Docs
UK spies: You know how we said bulk device hacking would be used sparingly? Well, things have ‘evolved’…
DanaBot evolves beyond banking Trojan with new spam-sending capability

ESET research shows that DanaBot operators have been expanding the malware’s scope and possibly cooperating with another criminal group The post DanaBot evolves beyond banking Trojan with new spam-sending capability appeared first on WeLiveSecurity

Windows 10 security question: How do miscreants use these for post-hack persistence?
Malicious Chrome extension which sloppily spied on academics believed to originate from North Korea
Facebook staff’s private emails published by fake news inquiry
Patch now (if you can!): Latest Android update fixes clutch of RCE flaws