Menu

Latest articles

Google logins make JavaScript mandatory, Huawei China spy shock, Mac malware, Iran gets new Stuxnet, and more

LinuxSecurity.com: Updated java-1.8.0-openjdk packages fix security vulnerabilities: Incorrect handling of unsigned attributes in singed Jar manifests (Security, 8194534) (CVE-2018-3136).

LinuxSecurity.com: The updated packages fix security vulnerabilities: It was found that the GnuTLS implementation of HMAC-SHA-256 and HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and

LinuxSecurity.com: This update provides virtualbox 5.2.20 and fixes the following security vulnerabilities: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This

LinuxSecurity.com: Updated mediawiki packages fix security vulnerabilities: ‘$wgRateLimits’ entry for ‘user’ overrides ‘newbie’ (CVE-2018-0503). When a log event is (partially) hidden Special:Redirect/logid can link

LinuxSecurity.com: Updated gitolite package fixes security vulnerability: Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been

LinuxSecurity.com: Updated mbedtls package fixes security vulnerabilities: Fixed a vulnerability in the TLS ciphersuites based on use of CBC and SHA-384 in DTLS/TLS 1.0 to 1.2, that allowed an active network attacker to partially recover the plaintext of messages under certains conditions

LinuxSecurity.com: Dancer2 0.206000 addresses several potential security issues. There is a potential RCE with regards to Storable. Dancer2 adds session ID validation to the session engine so that session backends based on Storable can reject malformed session IDs that may lead to exploitation of the RCE. Parsing requests now uses HTTP::Entity::Parser which reduces the amount […]

LinuxSecurity.com: The python-cryptography and python-cryptography-vectors packages have been updated to version 2.3.1 and fixes the following security issue: The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to

LinuxSecurity.com: Updated axis packages fix security vulnerability: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services (CVE-2018-8032).

LinuxSecurity.com: Updated lighttpd package fixes security vulnerabilities: Potential path traversal with specific configs or in some use cases in mod_alias.

LinuxSecurity.com: Updated dnsmasq packages fix a security issue Upstream dnsmasq run as nobody user which could lead to security issue if multiple services run as this same user.

Giant ransomware bundle threatens to make malware attacks easier for crooks
Shipbuilder, defense contractor Austal reveals data breach

LinuxSecurity.com: Several vulnerabilities have been discovered in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following problems:

security update

Feds accuse Chinese firm of stealing trade secrets of US tech giant
30 spies dead after Iran cracked CIA comms network with, er, Google search – new claim
Facebook Blames Malicious Extensions in Breach of 81K Private Messages
PortSmash attack punches hole in Intel’s Hyper-Thread CPUs, leaves with crypto keys
Web domain owners paid EasyDNS to cloak their contact info from sight. It was blabbed via public Whois anyway

LinuxSecurity.com: Several security issues were fixed in curl.

LinuxSecurity.com: tzdata upstream released version 2018g. Notables changes since 2018e (previous version available in jessie)

Cisco Security Appliance Zero-Day Found Actively Exploited in the Wild
ThreatList: Fewer Big DDoS Attacks in Q3, Overall Rate Holds Steady
Another day, another update, another iPhone lockscreen bypass
Popular browsers made to cough up browsing history
Antimalware Day: The evolution of malicious code

Celebrated annually on November 3, Antimalware Day is an opportunity to recognize the work of cybersecurity professionals The post Antimalware Day: The evolution of malicious code appeared first on WeLiveSecurity

Google’s stealthy sign-in sentry can pick up pilfered passwords

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2018-5179

What’s that? SSH can still use RC4? Not for much longer, promise
Report reveals one-dimensional support for two-factor authentication
BBC micro:bit vendor Kitronik says customers’ deets nicked, fingers Magecart malware
I know what you’re thinking: Outsource or in-source IT security? I’ve worked both sides, so here’s my advice…

Reading Time: ~2 min.DemonBot Botnet Gaining Traction DemonBot, while not the most sophisticated botnet discovered to date, has seen a significant rise in usage over the last week. With the ability to take control of Hadoop cloud frameworks, DemonBot has been using the platform to carry out DDoS attacks across the globe. By exploiting Hadoop’s […]

security update

Yi IoT Home Camera Riddled with Code-Execution Vulnerabilities
GDPR’s First 150 Days Impact on the U.S.

LinuxSecurity.com: The package linux-lts before version 4.14.75-1 is vulnerable to denial of service.

LinuxSecurity.com: The package linux before version 4.18.13.arch1-1 is vulnerable to denial of service.

LinuxSecurity.com: It was discovered that there was a cross-site scripting (XSS) vulnerability in phpldapadmin, a web-based interface for administering LDAP servers. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: OpenJDK: Improper field access checks (Hotspot, 8199226) (CVE-2018-3169) * OpenJDK: Incomplete enforcement of the trustURLCodebase restriction (JNDI, 8199177) (CVE-2018-3149) * OpenJDK: Incorrect handling of unsigned attributes in signed Jar manifests (Security, 8194534) (CVE-2018-3136) * OpenJDK: Leak of sensitive header data via HTTP redirect (Networking, 8196902) (CVE-2018-3139) * OpenJ [More…]

Radisson Hotel Group reveals breach of rewards site
Utilities, Energy Sector Attacked Mainly Via IT, Not ICS
PoC Exploit Compromises Microsoft Live Accounts via Subdomain Hijacking
Eurostar resets customers’ passwords after accounts breached
Two Zero-Day Bugs Open Millions of Wireless Access Points to Attack
IT Wi-Fi kit bit by TI chip slip: Wireless gateways open to hijacking via BleedingBit chipset vuln
Smashing Security #102: Ethical dilemmas, Girl Scouts, and porn-loving US officials
New AI system DARKMENTION will detect upcoming cyberattacks from dark web
Passcodes are protected by Fifth Amendment, says court
Facebook is still approving fake political ads
Update now! Apple releases security fixes for iOS, MacOS, Safari, others
US indicts alleged Chinese spies for hacking aerospace companies
RoboCops: AI on the rise in policing to predict crime and uncover lies
Feds: Chinese spies orchestrated massive hack that stole aviation secrets
Spooking the C-Suite: The Ephemeral Specter of Third-Party Cyber-Risk
GDPR Alert as Average ICO Fines Double in a Year
Welcome back, ‘ping of death’, it has been… a few months. Now it’s Apple’s turn to do the patching
£220k fines for dodgy dialling duo who didn’t do due dil on data

LinuxSecurity.com: Various security issues were discovered in the poppler PDF rendering shared library.

This one weird trick turns your Google Home Hub into a doorstop
Nice work if you can get it: GandCrab ransomware nets millions even though it has been broken
US government charges two Chinese spies over jet engine blueprint theft

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for xorg-x11-server is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: This is the One-Month notification for the retirement of Red Hat Enterprise Linux 7.3 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.3.

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

Spooky miasmic gas bricks hospital iPhones (mwah ha ha ha)
Apple Fixes Multiple macOS, iOS Bugs Including a Quirky FaceTime Vulnerability
Kraken Ransomware Upgrades Distribution with RaaS Model
Post-breach, Cathay Pacific hit by group action by UK law firm
How one man could have taken over any business on Facebook

LinuxSecurity.com: Several security issues were fixed in curl.

Growing pains: Skills gap meets expanding threat surface

The need to defend a growing threat surface highlights the widening cybersecurity skills gap The post Growing pains: Skills gap meets expanding threat surface appeared first on WeLiveSecurity

Yes, you should update your iPhone to iOS 12.1, but its lock screen is *still* unsafe
Google’s stealthy reCAPTCHA v3 detects humans – no questions asked
Crypto exchange collapses, victims accuse it of exit scam
Five ways to make Halloween less cyber-scary for kids

How can we help kids avoid security horrors and stay safe from rogue online “neighbors” at Halloween and thereafter? The post Five ways to make Halloween less cyber-scary for kids appeared first on WeLiveSecurity

LinuxSecurity.com: The package gitlab before version 11.4.3-1 is vulnerable to multiple issues including arbitrary code execution, cross-site request forgery, cross-site scripting and information disclosure.

Check this out: Radisson Hotel Group ‘fesses up to ‘security incident’
Mirai author fined $8.6million, gets 6 months house arrest

LinuxSecurity.com: Updated glusterfs packages that fix multiple security issues and bugs are now available for Red Hat Gluster Storage 3.4 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Updated glusterfs packages that fix multiple security issues and bugs are now available for Red Hat Gluster Storage 3.4 on Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

Apple emits its much-anticipated updates to Mac, AppleTV, and iOS
Square, PayPal POS Hardware Open to Multiple Attack Vectors
Employee infects US govt network with malware after visiting 9,000 porn sites

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

Google Updates reCAPTCHA: No More Boxes to Check
Signal App’s New Privacy Feature Conceals Sender ID from Metadata
ThreatList: Dead Web Apps Haunt 70 Percent of FT 500 Firms
Alleged SWATter will plead guilty to dozens of serious new federal charges
Gov worker visits 9k porn sites without protection, spreads infection

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Snakes in the grass! Malicious code slithers into Python PyPI repository

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

China hijacking internet traffic using BGP, claim researchers