Menu

Latest articles

You’ve Invested in an Email Security Solution… Why your Email may be in Danger, Regardless
RSA Conference 2019: BEC Scammer Gang Takes Aim at Boy Scouts, Other Nonprofts
RSA Conference 2019: How to Be Better, on Trust, AI and IoT
FBI boss: Never mind Russia and social media, China ransacks US biz for blueprints, secrets at ‘surprisingly’ huge scale
Adi Shamir visa snub: US govt slammed after the S in RSA blocked from his own RSA conf

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Companies are flying blind on cybersecurity
RSAC 2019: Joomla! Mail Flaw Exploited to Create Mass Phishing Infrastructure
Payment processors remain phishers’ favorites

The latest report from the Anti-Phishing Working Group offers a mixed bag of findings about the phishing landscape in 2018 The post Payment processors remain phishers’ favorites appeared first on WeLiveSecurity

RSAC 2019: Most Consumers Say ‘No’ to Cumbersome Data Privacy Practices
Comcast security nightmare: default ‘0000’ PIN on everybody’s account
Update now! Critical Adobe ColdFusion flaw now being exploited
Huawei opens Brussels code-check office: Hey! EU’ve got our guide – love Huawei
RSAC 2019: Picking Apart the Foreshadow Attack
Linux and Open Source FAQs: Common Myths and Misconceptions Addressed
New & Improved LinuxSecurity Site Coming Soon!
As Trump and Kim Met, North Korean Hackers Hit Over 100 Targets in U.S. and Ally Nations
Hackers have started attacks on Cisco RV110, RV130, and RV215 routers
Revealed: Facebooks global lobbying against data privacy laws

LinuxSecurity.com: An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rhvm-appliance is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for vdsm is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Windows IoT Core exploitable via ethernet
RSAC 2019: Malicious Emailed URLs See Triple-Digit Increase
RSAC 2019: Microsoft Zero-Day Allows Exploits to Sneak Past Sandboxes
How to address IoT’s two biggest challenges: data and security
Find QuadrigaCX’s missing $190 million, and you could win a $100,000 bounty
Apple gets bug for free, while HackerOne declares first $1m bug hunter
That’s a nice ski speaker you’ve got there. Shame if it got pwned
Bad news: Google drops macOS zero-day after Apple misses bug deadline. Good news: It’s fiddly to exploit
SPOILER alert, literally: Intel CPUs afflicted with simple data-spewing spec-exec vulnerability
BSides SF 2019: Remote-Root Bug in Logitech Harmony Hub Patched and Explained

LinuxSecurity.com: Vulnerabilities have been discovered in nss, the Mozilla Network Security Service library.

Alphabet snoop: If you’re OK with Google-spawned Chronicle, hold on, hold on, dipping into your intranet traffic, wait, wait
Oh no Xi didn’t?! China’s hackers nick naval tech blueprints, diddle with foreign elections to boost trade – new claim
Teen Becomes First to Earn $1M in Bug Bounties with HackerOne
When 2FA means sweet FA privacy: Facebook admits it slurps mobe numbers for more than just profile security

LinuxSecurity.com: An update that solves 8 vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

Smart Ski Helmet Headphone Flaws Leak Personal, GPS Data

LinuxSecurity.com: One of the fixes in USN-3885-1 was incomplete.

LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

McAfee: Oops, our bad. Sharpshooter malware was the Norks’ Lazarus Group the whole time
Project Zero Discloses High-Severity Apple macOS Flaw
Armor Games admits all its users’ deets slurped in mega breach as site moves to repair chink
RSAC 2019: 58% of Orgs Have Unfilled Cyber Positions

LinuxSecurity.com: This is the six-month notification for the retirement of Red Hat Enterprise Linux 7.4 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.4.

Teen earns US$1 million in bug bounties

A ‘white hat’ from Argentina has come a long way since winning his first reward of US$50 in 2016 The post Teen earns US$1 million in bug bounties appeared first on WeLiveSecurity

Container Escape Hack Targets Vulnerable Linux Kernel
TikTok to pay record fine for collecting children’s data
Is a Facebookcoin in the works?
YouTube disables comments on millions of videos of children
Anomaly in pen-test tool made malware servers visible
RSAC 2019: An Antidote for Tech Gone Wrong
Visitor Kiosk Access Systems Riddled with Bugs

LinuxSecurity.com: The package file before version 5.36-1 is vulnerable to multiple issues including information disclosure and denial of service.

LinuxSecurity.com: The package lib32-openssl-1.0 before version 1.0.2.r-1 is vulnerable to information disclosure.

LinuxSecurity.com: The package openssl-1.0 before version 1.0.2.r-1 is vulnerable to information disclosure.

LinuxSecurity.com: The package gdm before version 3.30.3-1 is vulnerable to access restriction bypass.

LinuxSecurity.com: The package pcre before version 8.43-1 is vulnerable to denial of service.

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 6.4 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.4.

Ah, this military GPS system looks shoddy but expensive. Shall we try to break it?
RSAC 2019: New Operation Sharpshooter Data Reveals Higher Complexity, Scope

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: The package chromium before version 72.0.3626.121-1 is vulnerable to arbitrary code execution.

How the Dark Web Data Bazaar Fuels Enterprise Attacks

LinuxSecurity.com: Update to 4.01. Fixes lots of security bugs (and non-security bugs).

LinuxSecurity.com: It was found that a security update (DSA-4387-1) of OpenSSH, an implementation of the SSH protocol suite, was incomplete. This update did not completely fix CVE-2019-6111, an arbitrary file overwrite vulnerability in the scp client implementing the SCP protocol.

iPhone hacking tool Cellebrite being sold on eBay
Cellular networks flaws expose 4G & 5G devices to IMSI capturing attacks
WannaCry-hero Hutchins’ trial date set, Microsoft readies Google’s Spectre V2 fix for Windows 10, Coinhive axed, and more

LinuxSecurity.com: gdm 3.30.3 release. – Screen lock bypass fix (when timed login is enabled) (CVE-2019-3825) – Translation updates

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: fix for CVE-2018-5704 (RHBZ 1534844)

LinuxSecurity.com: Restrict default configuration to localhost.

LinuxSecurity.com: fix for CVE-2018-5704 (RHBZ 1534844)

LinuxSecurity.com: This release fixes various buffer overflows when parsing or processing damaged Waveform audio and BMP image files.

LinuxSecurity.com: Restrict default configuration to localhost.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

When the bits hit the FAN: US military accused of knackering Russian trolls, news org’s IT gear amid midterm elections

security update

security update

security update

security update

Adobe Patches Critical ColdFusion Vulnerability With Active Exploit

Type: Vulnerability. WinRAR is prone to multiple security vulnerabilities; fixes are available.

19-year-old ethical hacker is a millionaire now; thanks to his skills
Podcast: RSA Conference 2019 Preview
Did you hear the one about Cisco routers using strcpy insecurely for login authentication? Makes you go AAAAA-AAAAAAAA *segfault*

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 5 fixes is now available.

The Momo Challenge urban legend – what on earth is going on?
Necurs Botnet Evolves to Hide in the Shadows, with New Payloads
Dow Jones’ high-risk screening watchlist data exposed online

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 33 fixes is now available.