Menu

Latest articles

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in Python.

Critical WordPress Flaw Grants Admin Access to Any Registered Site User
Lock-Screen Bypass Bug Quietly Patched in Handsets

Reading Time: ~2 min.Infowars Online Site Compromised by MageCart Attack Earlier this week, a security researcher found payment card-stealing scripts running on the Infowars online site. The scripts managed to stay active for nearly 24 hours. At least 1,600 users of the site may have been affected during this period, though many were returning customers […]

How to rob an ATM? Let me count the ways…
BlackBerry absorbs Operation Cleaver beaver Cylance into threat detection unit
Judge asks if Alexa is witness to a double murder
‘Unjustifiably excessive’: Not even London cops can follow law with their rubbish gang database
Hacking MiSafes’ smartwatches for kids is child’s play
AI-generated ‘skeleton keys’ fool fingerprint scanners
Cloud security: The essential checklist
Where to implant my employee microchip? I have the ideal location
MIT to Oz: Crypto-busting laws risk banning security tests

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

Super Micro chief bean counter: Bloomberg’s ‘unwarranted hardware hacking article’ has slowed our server sales

LinuxSecurity.com: A flaw was found in gdal up to version 2.3.0. A Heap-buffer-overflow in GTiffOddBitsBand::IReadBlock. A flaw was found in gdal. A Heap-buffer-overflow in NITFRasterBand::Unpack.

LinuxSecurity.com: There is a possible XSS vulnerability in Rack. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`.Applications that expect the scheme to be limited to “http” or “https” and do not escape the return value could be vulnerable to an XSS attack (CVE-2018-16471).

LinuxSecurity.com: An important vulnerability in Adobe Flash Player 31.0.0.122 and earlier versions. Successful exploitation could lead to information disclosure. (CVE-2018-15978) References:

LinuxSecurity.com: Updated php-pear-CAS packages fix security vulnerabilities: An XSS vulnerabilities has been fixed for proxy mode. References: – https://bugs.mageia.org/show_bug.cgi?id=23833

LinuxSecurity.com: It was discovered that incorrect connection setup in the server for Teeworlds, an online multi-player platform 2D shooter, could result in denial of service via forged connection packets (rendering all game server slots occupied) (CVE-2018-18541). This update fixes it.

LinuxSecurity.com: A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database (CVE-2018-1058).

LinuxSecurity.com: A NULL pointer dereference flaw was found in the way patch processed patch files. An attacker could potentially use this flaw to crash patch by tricking it into processing crafted patches (CVE-2018-6951). A double-free flaw was found in the way the patch utility processed

LinuxSecurity.com: It was discovered that Mutt incorrectly handled certain requests. An attacker could possibly use this to execute arbitrary code (CVE-2018-14350, CVE-2018-14352, CVE-2018-14354, CVE-2018-14359, CVE-2018-14358, CVE-2018-14353 ,CVE-2018-14357).

tRat Emerges as New Pet for APT Group TA505
Up to three million kids’ GPS watches can be tracked by parents… and any miscreant: Flaws spill pick-and-choose catalog for perverts

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Dynamics 365 is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to an information-disclosure vulnerability; fixes are available.

John McAfee is ‘liable’ for 2012 death of Belize neighbour, rules court
Thought you deleted your iPhone photos? Hackers find a way to get them back
Managing the Risk of IT-OT Convergence

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Connected Wristwatch Allows Hackers to Stalk, Spy On Children
Ahead of Black Friday, Rash of Malware Families Takes Aim at Holiday Shoppers
20% of MageCart-compromised merchants get reinfected within days
Download Malwarebytes Today and Protect Your Data for Free
Security researchers bypass encryption on self-encrypting drives

Industry standard specification does not guarantee the safety of the self-encrypting drives despite verification The post Security researchers bypass encryption on self-encrypting drives appeared first on WeLiveSecurity

Reading Time: ~3 min.What business owners and MSPs should know about the year’s biggest online retail holiday It’s no secret that Black Friday and Cyber Monday are marked by an uptick in online shopping. Cyber Monday 2017 marked the single largest day of online sales to date, with reported sales figures upwards of $6.5 billion. […]

Official Google Twitter account hacked in Bitcoin scam
DARPA uses a remote island to stage a cyberattack on the US power grid
France: Let’s make the internet safer! US: ‘How about NO?!’
Dutch Film Boss Sacked After 19m BEC Loss
2018 on Track to Be One of the Worst Ever for Data Breaches
Cyber criminals abuse US Postal Service Informed Delivery for ID theft
Employees’ cybersecurity habits worsen, survey finds

Almost all young people recycle their passwords, often doing so across work and personal accounts The post Employees’ cybersecurity habits worsen, survey finds appeared first on WeLiveSecurity

The threat to your org’s data lies betwixt chair and keyboard. Join us live on the internet for expert advice on tackling issue
US China-watcher warns against Middle Kingdom tech dominance

LinuxSecurity.com: Several security issues were mitigated in the Linux kernel.

CISA’s Palace: Congress backs new cybersecurity nerve-center for cyber-America’s cyber-future
Steganography – cool cybersecurity trick or dangerous risk? [VIDEO]
Smashing Security #104: The world’s most evil phishing test, and cyborgs in the workplace

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash or run programs as an administrator.

Bitcoin Giveaway Scam Balloons, with Google the Latest Victim
Pwn2Own Trifecta: Galaxy S9, iPhone X and Xiaomi Mi6 Fall to Hackers
Another Meltdown, Spectre security scare: Data-leaking holes riddle Intel, AMD, Arm chips
Did you by chance hack OPM back in 2015? Good news, your password probably still works!

security update

LinuxSecurity.com: PostgreSQL could be made to run SQL statements as the administrator.

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Type: Vulnerability. Microsoft Dynamics 365 is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Skype for Business and Lync are prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Core is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Get 90% Off Your First Year of RemotePC, Up To 50 Computers for $6.95

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several security issues were fixed in Python.

Siemens Patches Firewall Flaw That Put Operations at Risk

Risk Level: Very Low. Type: Trojan.

Just because you’re paranoid doesn’t mean hackers aren’t going to nuke your employer into the ground tomorrow
Apple says nothing as Apple ID accounts mysteriously locked down
WordPress GDPR Compliance plugin hacked to spread backdoor
You are not alone; social media giant Facebook is down
Cloudflare Launches Android and iOS version of 1.1.1.1 DNS Service
Will good prevail over bad as bots battle for the internet?
Headmaster caught mining cryptocurrency at school; gets fired
Man who conducted DDoS attacks on Sony, Xbox & EA pleads guilty
Vulnerability in Drone giant DJI exposed users’ photos & other sensitive data
Russian exploit developer publicly disclosed VirtualBox zero-day vulnerability
Want to hack an ATM for free cash? It’s as easy as Windows XP
HTTP/3: Come for the speed, stay for the security
Support wouldn’t change his password, so he mailed them a bomb
Oz telcos’ club asks: Why the hell do Australia Post, rando councils, or Taxi Services Commission want comms metadata?
Microsoft update breaks Calendar and Mail on Windows 10 phones
Scumbag who phoned in a Call of Duty ‘swatting’ that ended in death pleads guilty to dozens of criminal charges
It’s November 2018, and Microsoft’s super-secure Edge browser can be pwned eight different ways by a web page