Menu

Latest articles

Beware buying Fortnite’s V-Bucks, you could be funding organised crime
Firms fined $1M for SingHealth data security breach
UK Banks Finally Issue New Cards After Ticketmaster Breach
Feds can’t force you to unlock your phone with finger or face, says judge

LinuxSecurity.com: This update fixes CVE-2018-20685 (the first “variant”) and backports several fixes to unbreak ECDSA authentication from PKCS#11, certificate authentication and so on.

LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).

LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).

LinuxSecurity.com: Patch for CVE-2016-10091

EDGAR Wrong: Ukrainians hacked SEC, stole docs for inside trading, says Uncle Sam

LinuxSecurity.com: Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation. A local attacker could possibly use this issue to perform a cache-timing attack and recover private ECDSA keys (CVE-2018-0495). References:

LinuxSecurity.com: A heap use-after-free vulnerability in the server code of the file transfer extension, which can result in remote code execution. This attack appears to be exploitable via network connectivity (CVE-2018-6307).

LinuxSecurity.com: It was observed that URL’s which gets downloaded via “–log=” attribute stores sensitive information. This update fixes that. References: – https://bugs.mageia.org/show_bug.cgi?id=24112

IDenticard Zero-Days Allow Corporate Building Access, Location Recon
‘It’s like they took a rug and covered it up’: Flight booking web app used by scores of airlines still vuln to attack – claim
Data Breach Roundup: U.S. Healthcare, Cryptopia, SingHealth and Experian

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

security update

security update

LinuxSecurity.com: Several issues in wireshark, a tool that captures and analyzes packets off the wire, have been found by different people. These are basically issues with length checks or invalid memory access in

LinuxSecurity.com: libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (CVE-2018-15127) SL7 x86_64 libvncserver-0.9.9-13.el7_6.i686.rpm libvncserver-0.9.9-13.el7_6.x86_64.rpm libvncserver-debuginfo-0.9.9-13.el7_6.i686.rpm libvncserver-debuginfo-0.9.9-13.el7_6.x86_64.rpm libvncserver-devel-0.9.9-13.el7_6.i686.rpm [More…]

Judge: Law Enforcement Can’t Force Suspects to Unlock iPhones with FaceID
ThreatList: $1.7M is the Average Cost of a Cyber-Attack

LinuxSecurity.com: Several security issues were fixed in libcaca.

Yes, you can remotely hack … building site cranes. Wait, what?
Man whose DDoS attacks took down entire country’s Internet jailed
8 million users installed 9 adware apps from Play Store
What makes a cybercriminal?

Forget balaclavas or hoodies, these cybercriminals are hiding in plain sight The post What makes a cybercriminal? appeared first on WeLiveSecurity

Reading Time: ~2 min. For many MSPs, integrating their security solution with their remote monitoring and management (RMM) and professional service automation (PSA) platforms is essential for doing business. Together, these platforms help lower the cost of keeping up with each client, ensuring profitable margins for a healthy, growing business. For true providers of IT […]

Windows 7 users get fix for latest updating woe
Blockchain burglar returns some of $1m crypto-swag
Facebook to start fact-checking fake news in the UK

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2019:0049

Is fake-news sharing driven by age, not politics?

LinuxSecurity.com: An update for libvncserver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Want to get rich from bug bounties? You’re better off exterminating roaches for a living

LinuxSecurity.com: The v4.19.14 stable update contains important fixes across the tree.

Oh, SSH, IT please see this: Malicious servers can fsck with your PC’s files during scp slurps
A city in Texas is using paper after suffering ransomware attack

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

This must be some kind of mistake. IT managers axed, CEO and others’ wallets lightened in patient hack aftermath
Cops told: No, you can’t have a warrant to force a big bunch of people to unlock their phones by fingerprint, face scans
Popular Web-Hosting Platform Bluehost Riddled with Flaws, Researcher Claims
Intel’s Software Guard caught asleep at its post: Patch out now for SGX give-me-admin hole

security update

Threatpost Poll: Can We Fix 2FA?
Hack Allows Escape of Play-with-Docker Containers

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

British TV viewers targeted by email fraudsters
Ryuk Hauls in $3.7M in ‘Earnings,’ Adds TrickBot to the Attack Mix
Mozilla Kills Default Support for Adobe Flash in Firefox 69
RBS reissues punters with new bank cards after Ticketmaster breach
Goddamn the Pusher man: Nominet kicks out domain name hijack bid
Shutdown hits government websites as certificates begin to expire
Poland may consider Huawei ban amid ‘spy’ arrests – reports
Data Exposed in OXO, Amazon and MongoDB Leaks
Nissan EV app password reset prompts user panic

LinuxSecurity.com: An update for systemd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

CES: Smart cities and the challenge of securing the neighborhood

In our final report from CES we take a look at smart city initiatives The post CES: Smart cities and the challenge of securing the neighborhood appeared first on WeLiveSecurity

Podcast: Emotet Grows With Fast-Evolving Tactics
10 years for Boston Children’s Hospital attacker
New Linux Systemd security holes uncovered
Governments need to embrace AI for the good of the people
USB-C Authentication sounds great, so why are people worried?
Facebook exec gets SWATted
The DDoS attacker rescued by a Disney cruise ship is sentenced to over 10 years in prison
Brit hacker hired by Liberian telco to nobble rival now behind bars

LinuxSecurity.com: New zsh packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is now available.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: The Qualys Research Labs discovered multiple vulnerabilities in systemd-journald. Two memory corruption flaws, via attacker-controlled alloca()s (CVE-2018-16864, CVE-2018-16865) and an out-of-bounds read flaw leading to an information leak (CVE-2018-16866), could allow an attacker to

LinuxSecurity.com: The package python2-django before version 1.11.18-1 is vulnerable to content spoofing.

LinuxSecurity.com: The package python-django before version 2.1.5-1 is vulnerable to content spoofing.

security update

LinuxSecurity.com: Due to kernel issue there is a way to reuse start_time of a process. This allows to duplicate process authorized by polkit. This update mitigates polkit issue #75 (slowfork): https://gitlab.freedesktop.org/polkit/polkit/issues/75

It only takes a Skype Call to Unlock an Android Handset
Kaspersky tipped off US about the contractor who stole NSA data
9 million users installed 85 adware infected apps from Play Store
Aussie govt emergency service hacked to send fake warning alerts
WhatsApp Gold Scam is Back with Malware Payload
Hacker ‘BestBuy’ sentenced to prison for operating Mirai DDoS botnet
Facebook staff discussed cashing in on user data, reports say

LinuxSecurity.com: An integer underflow was discovered in the CAF demuxer of the VLC media player. For the stable distribution (stretch), this problem has been fixed in

Facebooker swatted, Kaspersky snares an NSA thief, NASA server exposed, and more

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: Resolves CVE-2018-16869