Menu

Latest articles

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Innovative Phishing Tactic Makes Inroads Using Azure Blob
China’s clampdown on Tor pushes its hackers into foreign backyards
How a WhatsApp call could have taken over your phone
Google’s failure to disclose user data leak prompts closure of Google Plus
Critical Data-Loss Bug Identified in New Windows 10 Update
Hackers illegally selling stolen Fortnite accounts & botnets on Instagram
Four Critical Flaws Patched in Adobe Digital Edition
Worker perks flinger Sodexo pulls Engage website after malware smackdown
California outlaws poor default passwords in connected devices

The law is intended to help curb attacks that rely on weak, non-existent or publicly disclosed passwords that far too often ship with web-connected gadgets The post California outlaws poor default passwords in connected devices appeared first on WeLiveSecurity

Podcast: Key Takeaways For DevOps in BSIMM9
MSM-Next Bringing A6xx Performance Improvements, Fixes To The Linux Kernel
Heathrow Airport fined ?120,000 over USB data breach debacle
Google+ wakes up to what the rest of us already knew
291 records breached per second in first half of 2018
Cyber tormentor leaves a trail that lands him 17.5 years

LinuxSecurity.com: The package patch before version 2.7.6-3 is vulnerable to multiple issues including arbitrary command execution and denial of service.

Airport mislays world’s most expensive USB stick
Google and Microsoft boffins playing nicely together to stop replay attacks in their tracks
Google+ to shut down due to lack of adoption and privacy bug

Google has found no evidence of misuse of user information courtesy of a security glitch in the social platform’s API The post Google+ to shut down due to lack of adoption and privacy bug appeared first on WeLiveSecurity

US may have by far the world’s biggest military budget but it’s not showing in security

LinuxSecurity.com: Updates for rh-dotnetcore11-dotnetcore, and rh-dotnetcore10-dotnetcore are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

World’s largest CCTV maker leaves at least 9 million cameras open to public viewing
Rap for WhatsApp chat app chaps in phone-to-pwn security nap flap
It’s October 2018, and Microsoft Exchange can be pwned by a plucky eight-year-old… bug
Microsoft Patches Zero-Day Under Active Attack by APT

security update

security update

Payment-card-skimming Magecart strikes again: Zero out of five for infecting e-retail sites

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2846

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2898

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2892

New Ninth-Gen Intel CPUs Shield Against Some Spectre, Meltdown Variants
Chinese Super Micro ‘spy chip’ story gets even more strange as everyone doubles down
Slideshow: Intel from Virus Bulletin 2018

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several vulnerabilities were discovered in tinc, a Virtual Private Network (VPN) daemon. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: Several security issues were fixed in libxkbcommon.

MikroTik router vulnerability lets hackers bypass firewall to load malware undetected

Risk Level: Very Low. Type: Trojan.

It’s a cert: Hundreds of big sites still unprepared for starring role in that Chrome 70’s show
How Shared Pools of Cloud Computing Power Are Changing the Way Attackers Operate
Google+ Privacy Snafu Leaves a Cloud Over the Tech Landscape
ThreatList: Microsoft IIS Sees Triple-Digit Spike in Cyberattack Volume
Apple and Amazon hacked by China? Here’s what to do (even if it’s not true)

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2881

Microsoft hits the brakes on latest Windows 10 update – what to do
Magecart Group Targets Shopper Approved in Latest Attack
Don’t make us pay compensation for employee data breach, Morrisons begs UK court
Don’t fall for the Facebook ‘2nd friend request’ hoax
Blockchain: What is it, how it works and how it is being used in the market

A closer look at the technology that is rapidly growing in popularity The post Blockchain: What is it, how it works and how it is being used in the market appeared first on WeLiveSecurity

Hey Portal, what’s that Facebook device in my kitchen?
MikroTik vulnerability climbs up the severity scale, new attack permits root access
What is a Linux server and why does your business need one?
Google ramps up G Suite protections against government-backed attacks

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

California’s ban on weak default passwords isn’t going to fix IoT security

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft SQL Server Management Studio is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft SQL Server Management Studio is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft SQL Server Management Studio is prone to an information-disclosure vulnerability; fixes are available.

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

Google now minus Google Plus: Social mini-network faces axe in data leak bug drama

LinuxSecurity.com: Several vulnerabilities were discovered in tinc, a Virtual Private Network (VPN) daemon. The Common Vulnerabilities and Exposures project identifies the following problems:

SIEM, UBA, UEBA… If you’re suffering netsec acronym overload, then here’s our handy guide

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Google chose not to go public about bug that exposed Google Plus users’ data
Assassin’s Creed Odyssey suffers DDoS attack at launch
Department of Homeland Security and GCHQ back Apple and Amazon’s denials they were hacked by China
Unpatched routers bad, doubly unpatched routers worse – much, much worse!
Remember that lost memory stick from Heathrow Airport? The terrorist’s wet dream? So does the ICO
Most routers full of firmware flaws that leave users at risk

If you own a Wi-Fi router, it may well be riddled with security holes that expose you to a host of threats The post Most routers full of firmware flaws that leave users at risk appeared first on WeLiveSecurity

The Leading Linux Desktop Platform Issues Of 2018
Amazon employee shared email addresses with third-party seller
Which? That smart home camera? The one with the vulns? Really?
Attackers use voicemail hack to steal WhatsApp accounts
Phantom Secure CEO sold encrypted phones to drug cartels
Seven Russian cyberspies indicted for hacking, wire fraud, ID theft

LinuxSecurity.com: An update for rh-haproxy18-haproxy is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Fitbit data leads to arrest of 90-year-old in stepdaughter’s murder

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Intel’s commitment to making its stuff secure is called into question
PoC Attack Escalates MikroTik Router Bug to ‘As Bad As It Gets’

LinuxSecurity.com: Due to multiple vulnerabilities in various coders used by ImageMagick, Gentoo Linux now installs a policy.xml file which will restrict coder usage by default. [More…]

LinuxSecurity.com: A vulnerability in OpenSSH might allow remote attackers to determine valid usernames.

LinuxSecurity.com: Multiple vulnerabilities have been found in SoX, the worst of which may lead to a Denial of Service condition.

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 20 vulnerabilities is now available.

Why Facebook Loves Open-Source Firmware
Russia’s elite hacking unit has been silent, but busy
US Indicts 7 Russian Intel Officers for Hacking Anti-Doping Organizations

security update