Menu

Latest articles

Google’s private browsing doesn’t keep your searches anonymous
More data joy: Email scammers are buying marks’ info from legit biz intelligence firms
Chrome 71 stomps on abusive advertising
Ukraine: We Blocked Major Russian Attack on Judiciary
#BHEU: How Google Aurora Attacks Changed the Consciousness of Cybersecurity
Brits’ DNA data sent to military base after ‘foreign’ hack attacks – report
Pencil manufacturers rejoice: Oz government doesn’t like e-voting
Smashing Security #107: Sextorting the US army, and a Touch ID scam
It’s December 2018, and a rogue application can still tell your Apple Mac: I’m your El Capitan now
Talk about a GAN-do attitude… AI software bots can see through your text CAPTCHAs
Adobe Flash zero-day exploit… leveraging ActiveX… embedded in Office Doc… BINGO!
White House Facial Recognition Pilot Raises Privacy Alarms

LinuxSecurity.com: An update for openstack-neutron is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: It was discovered that the ghostscript /invalidaccess checks fail under certain conditions. An attacker could possibly exploit this to bypass the – -dSAFER protection and, for example, execute arbitrary shell commands via a specially crafted PostScript document. (CVE-2018-16509) SL6 x86_64 ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-8.70-24.el6_10.2.x86_64.rpm ghostscript- [More…]

LinuxSecurity.com: ghostscript: incomplete fix for CVE-2018-16509 (CVE-2018-16863) Bug Fix(es): * Previously, the flushpage operator has been removed as part of a major clean-up of a non-standard operator. However, flushpage has been found to be used in a few specific use cases. With this update, it has been re- added to support those use cases. SL7 […]

Adobe Flash Zero-Day Leveraged Via Office Docs in Campaign
Kubernetes Flaw is a “Huge Deal,” Lays Open Cloud Deployments
Adobe Patches Zero-Day Vulnerability in Flash Player
It looked like a Citrix ShareFile phishing attack, but wasn’t
The Dark Side of the ForSSHe

ESET researchers discovered a set of previously undocumented Linux malware families based on OpenSSH. In the white paper, “The Dark Side of the ForSSHe”, they release analysis of 21 malware families to improve the prevention, detection and remediation of such threats The post The Dark Side of the ForSSHe appeared first on WeLiveSecurity

Estonian ex-foreign sec urges governments: Get cosy with the private sector on cybersecurity
Kubernetes cloud computing bug could rain data for attackers
Quora.com admits data breach affecting 100 million accounts
Now you, too, can snoop on mobe users from 3G to 5G with a Raspberry Pi and €1,100 of gizmos
Those are NOT your grandchildren! FTC warns of new scam
Coalition and Labor strike deal on encryption legislation
Facebook Exposes Nonprofits to Donors-and Hackers
Could adult content ban spell the end for Tumblr?
Google Chrome 71 Touts 43 Fixes, Fights Ad Abuse
Windows 10 version 1809 is incompatible with Morphisec anti-malware
GOPwned: Republicans fall victim to email hack
1-800-Flowers Becomes Latest Payment Breach Victim

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

He’s not cracked RSA-1024 encryption, he’s a very naughty Belarusian ransomware middleman

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform release 3.5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform release 3.6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Google Patches 11 Critical RCE Android Vulnerabilities
Quora Breach Exposes a Wealth of Info on 100M Users
Bleichenbacher’s CAT puts another scratch in TLS
Quora hack leaves details of 100 million accounts exposed
AirDrop an unwanted nude pic and you could face stiff penalties
Quora hacked: Personal data of 100 million users stolen
Zoom patches serious video conferencing bug
‘Iceman’ hacker charged with running drone-smuggling ring from jail
Marriott sued hours after announcing data breach
Magecart Group Ups Ante: Now Goes After Admin Credentials
Yet another mega-leak: 100 million Quora accounts compromised by system invaders

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Malware since 2017: Auction giant Sotheby’s Home hit by Magecart attack
Customers baffled as Citrix forces password changes for document-slinging Sharefile outfit

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Some HTML emails can trick messagelib into opening a new browser window when displaying said email as HTML. This happens even if the option to allow the HTML emails to access remote servers is disabled in KMail settings. This means that the owners of the servers referred in the email can see in their […]

Lawsuit Claims Pegasus Spyware Helped Saudis Spy on Khashoggi
Container code cluster-fact: There’s a hole in Kubernetes that lets miscreants cause havoc

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Fitness-tracking apps caught misusing Touch ID to steal money from iPhone users
Czech yourself, Russia! Prague says its foreign ministry was hacked for more than a year

LinuxSecurity.com: Several security issues were fixed in Perl.

Digitize and automate your customer agreement process for financial transactions. Download this free OneSpan guide.
Private data of more than 82 million US citizens left exposed

LinuxSecurity.com: Several security issues were fixed in Perl.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may lead to arbitrary code execution.

LinuxSecurity.com: A vulnerability in Nagios allows local users to escalate privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in ConnMan, the worst of which could result in the remote execution of code.

LinuxSecurity.com: Multiple vulnerabilities have been found in PHP, the worst of which could result in a Denial of Service condition.

Chris Vickery on the Marriott Breach and a Rash of Recent High-Profile Hacks

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

U.S. Military Members Catfished and Hooked for Thousands of Dollars
Lenovo Ordered to Pay $7.3M in Superfish Fiasco
iOS Fitness Apps Robbing Money From Apple Victims
YouTuber PewDiePie Promoted Via 50K Hacked Printers
Moscow’s cable car service shuts down in 2 days after ransomware attack
Someone hacked 50,000 printers to promote PewDiePie YouTube channel
Indian police & Microsoft busts tech support scam centers
Marriott hotel data breach: Sensitive data of 500 million guests stolen
Dunkin Donuts Perks loyalty data breach: Change your password
Feds charge 2 Iranian hackers behind SamSam ransomware attacks
Gang sentenced for installing card skimmers on gas pumps & stealing data
Dell resets all customer passwords after security breach
FBI & Google shut down largest-ever Ad fraud scheme ‘3VE’
Lenovo to pay $7.3m for installing adware in 750,000 laptops
Wanna save yourself against NotPetya? Try this one little Windows tweak
Scam iOS apps promise fitness, steal money instead

Fitness-tracking apps use dodgy in-app payments to steal money from unaware iPhone and iPad users The post Scam iOS apps promise fitness, steal money instead appeared first on WeLiveSecurity

Printers pulled into 9100 port attack spew PewDiePie propaganda
Router attack exploits UPnP and NSA malware to target PCs
Microsoft cracks down on tech support scams, 16 call centers raided
Faster fuzzing ferrets out 42 fresh zero-day flaws
CyberwarCon – focusing on the impact of cyber-badness

A welcome return to the hacker conferences of yesteryear The post CyberwarCon – focusing on the impact of cyber-badness appeared first on WeLiveSecurity

LinuxSecurity.com: An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low. Type: Trojan.