Menu

Latest articles

YouTuber reveals iPhone XS passcode bypass bug exposing contacts/photos

LinuxSecurity.com: CVE-2017-7653 As invalid UTF-8 strings are not correctly checked, an attacker could

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

Hacky hack on whack ‘Hacky Hack Hack’ Mac chaps hack attack rap cut some slack

LinuxSecurity.com: Multiple security issues were discovered in Python: ElementTree failed to initialise Expat’s hash salt, two denial of service issues were found in difflib and poplib and a buffer overflow in PyString_DecodeEscape.

Big Facebook breach: 50 million accounts affected
Facebook Data Breach Impacts Almost 50 Million Accounts
Facebook hacked: Hackers steal access tokens of 50 million accounts
Another Linux Kernel Bug Surfaces, Allowing Root Access

LinuxSecurity.com: This release fixes a heap-based buffer over-read when parsing a mallformed BSON document (CVE-2018-16790).

LinuxSecurity.com: Changes since 10.1.8.16: === v 10.1.9.6 handle legacy external message recipients * [XSS] Updated known HTML5 events * Better IPV6 support * UI support for protocol-only entries v 10.1.9.5

LinuxSecurity.com: Security fix for CVE-2018-10897

LinuxSecurity.com: This release fixes a heap-based buffer over-read when parsing a mallformed BSON document (CVE-2018-16790).

Facebook: Up to 90 million addicts’ accounts slurped by hackers, no thanks to crappy code
iPhone XS Passcode Bypass Hack Exposes Contacts, Photos
Demonoid goes offline with owner missing in action for last two months
Zuckerberg’s Facebook page? I’ll livestream its deletion, says hacker
Health insurer Bupa fined £175k after staffer tried to sell customer data on dark web souk
WhatsApp cofounder: “I sold my users’ privacy”
Android App Verification Issues Pave Way For Phishing Attacks
Australian teen who hacked into Apple and stole 90 GB of files avoids jail
Android password managers vulnerable to phishing apps
VirusTotal slips on biz suit, says Google’s daddy will help the search for nasties

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Power to the people! Google backtracks (a bit) on forced Chrome logins
Who’s behind DDoS attacks at UK universities?

The timing of the attacks suggests that many attempts to take the networks offline may not necessarily be perpetrated by organized cybercriminal gangs The post Who’s behind DDoS attacks at UK universities? appeared first on WeLiveSecurity

Robocallers slapped with huge fines for using spoofed phone numbers
Majority of Orgs Failing to Make Machine Learning Fair, Safe & Balanced
Critical Linux Kernel Flaw Gives Root Access to Attackers
BLK-MQ To Support Runtime Power Management With Linux 4.20~5.0
Come to the National Information Security Conference (NISC), 10-12 October 2018

Reading Time: ~2 min.Firefox Vulnerability Leads to Crash A new denial-of-service (DoS) attack has been created with the ability to cause desktop versions of the browser Firefox to freeze or crash. Upon visiting sites where the malicious script is present, the user’s browser forces download requests for a massive junk file that can cause the […]

Oslo clever clogs craft code to scan di mavens and snare dodgy staff

LinuxSecurity.com: Several security issues were fixed in Mutt.

Your specialist subject? The bleedin’ obvious… Feds warn of RDP woe
Resident evil: Inside a UEFI rootkit used to spy on govts, made by you-know-who (hi, Russia)
DEF CON hackers’ dossier on US voting machine security is just as grim as feared

LinuxSecurity.com: CVE-2018-14404 Fix of a NULL pointer dereference which might result in a crash and thus in a denial of service.

LinuxSecurity.com: Multiple security issues were discovered in Python: ElementTree failed to initialise Expat’s hash salt, two denial of service issues were found in difflib and poplib and the shutil module was affected by a command injection vulnerability.

Perimeter Defenses are Dead, So Now What?

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

ThreatList: Hackers Turn to Python as Attack Coding Language of Choice
Sunny Cali goes ballistic, this ransomware is atrocious. Even our IT bill will be something quite ferocious

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty), Red Hat OpenStack Platform 9.0 (Mitaka), Red Hat OpenStack Platform 10.0 (Newton), Red Hat OpenStack Platform 12.0 (Pike), and Red Hat OpenStack Platform 13.0 (Queens).

Local-Privilege Escalation Flaw in Linux Kernel Allows Root Access
Cryptojacking – coming to a server-laptop-phone near you (and how to stop it)
Weakness in Apple MDM Tool Allows Access to Sensitive Corporate Info
Looking after the corporate Apple mobile fleet? Beware: MDM onboarding is ‘insecure’
Trump’s axing of cyber czar role has left gaping holes in US defence
Cisco coughs up baker’s dozen of vulns and other security nasties
Linux Readying Spectre V2 Userspace-Userspace Protection
Mirai Authors Escape Jail Time – But Here Are 7 Other Criminal Hackers Who Didn’t
Malware steals passwords from 6.4 million SHEIN customers
Firefox Monitor starts tracking breached email addresses
Spotify offers playlists tailored to your DNA
Malware hits fashion giant SHEIN; 6.42 million online shoppers affected
Uber to dole out $148m settlement among US states over breach it paid $100k to bury
LoJax: First UEFI rootkit found in the wild, courtesy of the Sednit group

ESET researchers have shown that the Sednit operators used different components of the LoJax malware to target a few government organizations in the Balkans as well as in Central and Eastern Europe The post LoJax: First UEFI rootkit found in the wild, courtesy of the Sednit group appeared first on WeLiveSecurity

Smashing Security #097: Dash cam surveillance, robocall plague, and Zoho woe
Fancy Bear still Putin out new modules for VPNFilter malware
‘Mutagen Astronomy’ Linux kernel vulnerability sighted

LinuxSecurity.com: HylaFAX+ 5.6.1 vulnerabilities (18 Sep 2018)

LinuxSecurity.com: Security fix for CVE-2018-16435

Boffins bypass password protection with pilfering by phony programs
2018 Has Been Open Season on Open Source Supply Chains
Pain spotting: Russia’s Aeroflot Docker server lands internal source code, config files on public internet

LinuxSecurity.com: The 4.18.9 stable update contains a number of important fixes across the tree. —- The 4.18.8 update contains a number of important fixes across the tree

LinuxSecurity.com: Fix for CVE-2018-14630

LinuxSecurity.com: Fixed 2.1.0 update, includes security fixes and added performance fix

LinuxSecurity.com: Security fix for CVE-2017-5950.

VPNFilter’s Arsenal Expands With Newly Discovered Modules
Google Vows Privacy Changes in Chrome Browser After User Backlash
Banking trojan found in call recorder app on Play Store – stole over €10,000
Almost Every Major Free VPN Service is a Glorified Data Farm
Finally, a fix for the encrypted web’s Achilles’ heel
Twitter patches bug that may have spilled users’ private messages

The flaw affected one of the platform’s APIs between May 2017 and September 10 of this year, when it was patched “within hours” The post Twitter patches bug that may have spilled users’ private messages appeared first on WeLiveSecurity

Security Technologies: FORTIFY_SOURCE
Can’t read my, can’t read my… broker face: Premium Credit back online a week after cyber attack
Defending your company from cyberattack

ESET CTO Juraj Malcho outlines some of the ways in which organizations can reduce their cybersecurity risk The post Defending your company from cyberattack appeared first on WeLiveSecurity

Microsoft is killing passwords one announcement at a time
Domain flub leaves 30 million customers high and dry
The Sony hacker indictment: 5 lessons for IT security
Vulnerable open source component adoption skyrockets in the enterprise
French cybersecurity agency open sources security hardened CLIP OS
Google actually listens to users, hands back cookies and rethinks Chrome auto sign-in
Facebook scolds police for using fake accounts to snoop on citizens
Millions of Twitter DMs may have been exposed by year-long bug
Canadian security boss ain’t afraid of no Huawei, sees no reason for ban
Malware steals passwords from SHEIN, 6.4 million customers impacted

LinuxSecurity.com: Red Hat OpenShift Container Platform release 3.6.173.0.130 is now available with updates to packages that fix one security issue and several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Multiple vulnerabilities were found in the CPython interpreter which can cause denial of service, information gain, and arbitrary code execution.

NSA dev in the clink for 5.5 years after letting Kaspersky, allegedly Russia slurp US exploits

LinuxSecurity.com: Multiple vulnerabilities were found in the CPython interpreter which can cause denial of service, information gain, and arbitrary code execution.

While the UN laughed at Trump, hackers chortled at the UN’s lousy web application security

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,