Menu

Latest articles

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3854

LinuxSecurity.com: Several local side channel attacks and a denial of service via large Diffie-Hellman parameters were discovered in OpenSSL, a Secure Sockets Layer toolkit.

Facebook gave Amazon, Netflix, Spotify & others access to private user data

LinuxSecurity.com: An update that solves two vulnerabilities and has 11 fixes is now available. Description: Description: This update for salt fixes the following issues: – Crontab module fix: file attributes option missing (boo#1114824) – Fix git_pillar merging across multiple __env__ repositories (boo#1112874) – Bugfix: unable to detect os arch when RPM is not installed (boo#1114197) […]

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for the Linux Kernel 3.12.61-52_141 fixes one issue. The following security issue was fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.61-52_111 fixes several issues. The following security issues were fixed:

Patched Click2Gov Flaw Still Afflicting Local Govs
On the first day of Christmas, Microsoft gave to me… an emergency out-of-band security patch for IE

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. Description: Description: This update for ovmf fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for libnettle fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. Description: Description: This update for tiff fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for git fixes the following issues: Security issue fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for bluez fixes the following issues: Security issues fixed:

US told to appoint a damn Privacy Shield ombudsperson already or EU will take action
Hackers Succeed in NASA Mission, Lifting Thousands of Employee Records
Chill, it’s not WikiLeaks 2: Pile of EU diplomatic cables nicked by hackers
Threatpost Poll: Do You Hate Facebook?
NASA fears hackers may have stolen employee data

A probe launched immediately after the discovery of the suspected incident has yet to establish the scale of the potential damage The post NASA fears hackers may have stolen employee data appeared first on WeLiveSecurity

Serious Security: When cryptographic certificates attack
Facebook waited months before admitting privacy bug exposed millions of users’ unposted photos
Facebook Fights Back on Secret Data-Sharing Partnerships

LinuxSecurity.com: An update that solves three vulnerabilities and has four fixes is now available. Description: Description: This new package for go1.11 fixes the following issues: Security issues fixed: – CVE-2018-16873: Fixed a remote code execution in go get, when executed [More…] with the -u flag (bsc#1118897) with the -u flag (bsc#1118897) [More…] – CVE-2018-16874: Fixed […]

Snack-happy parrot shows insider threats come in all shapes and sizes
Instagram became the preferred tool in Russia’s propaganda war
SQLite creator fires back at Tencent’s bug hunters
How not to secure US missile defences
Stop the credential thieves before they stop your business

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3834

LinuxSecurity.com: Update to 2.7.5 bugfix release. Fix for CVE-2018-16876

Houston, we’ve had a problem: NASA fears internal server hacked, staff personal info swiped by miscreants
Russia-Linked Sofacy Debuts Fresh Zebrocy Malware Variant
American bloke hauls US govt into court after border cops ‘cuffed him, demanded he unlock his phone at airport’
After SamSam, Ryuk shows targeted ransomware is still evolving
German cybersecurity chief: Anyone have any evidence of Huawei naughtiness?

Risk Level: Very Low. Type: Trojan.

WordPress Targeted with Clever SEO Injection Malware
Target targeted: Five years on from a breach that shook the cybersecurity industry

In December 2013 news broke that Target suffered a breach that forced consumers and the cybersecurity community to question the security practices of retailers The post Target targeted: Five years on from a breach that shook the cybersecurity industry appeared first on WeLiveSecurity

Hidden Code in Memes Instruct Malware via Twitter
WSJ Webpage Defaced to Support PewDiePie
Newsmaker Interview: Troy Mursch on Top Botnet Trends

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Cybersecurity Trends 2019: Privacy and intrusion in the global village

With just days left in 2018, ESET experts offer their reflections in ‘Cybersecurity Trends 2019’ on themes that are set to figure prominently in the upcoming year The post Cybersecurity Trends 2019: Privacy and intrusion in the global village appeared first on WeLiveSecurity

Facebook photo API bug exposed users’ unpublished photos
Save the Children Hit by $1m BEC Scam
Cybercriminals Change Tactics to Outwit Machine-Learning Defense
Logitech flaw fixed after Project Zero disclosure
Twitter fixes bug that lets unauthorized apps get access to DMs
Sneaky phishing campaign beats two-factor authentication
Memes, messengers, and missiles: From Twitter to chat apps and weapons, security is ho-ho-hosed this Xmas
You better watch out, you better not cry. Better not pout, I’m telling you why: SQLite vuln fixes are coming to town

Risk Level: Very Low. Type: Trojan.

U.S. Ballistic Missile Defense System Rife with Security Holes
Twitter Draws Data Privacy Concerns with Two New Bugs

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation (bsc#1118319). – CVE-2018-5848: Fixed an unsigned integer overflow in […]

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation (bsc#1118319). – CVE-2018-5848: Fixed an unsigned integer overflow in wmi_set_ie. […]

Risk Level: Very Low. Type: Trojan.

Automotive Security: It’s More Than Just What’s Under The Hood
Charming Kitten Iranian Espionage Campaign Thwarts 2FA
Influential cypherpunk and crypto-anarchist Tim May dies aged 67
PewDiePie Hackers Say They Launched Second Printer Siege
Facebook bug exposed private photos of 6.8M users to third-party developers
Hackers bypassed Gmail & Yahoo’s 2FA to target US officials
Personal & banking data of 120 million Brazilians leaked online
IT consultancy firm caught running ransomware decryption scam
Who’s watching you from an unmarked van while you shop in London? Cops with facial recog tech
The most popular passwords of 2018 revealed: Are yours on the list?

Besides the usual suspects among the worst of passwords, a handful of notable – but similarly poor – choices make their debuts The post The most popular passwords of 2018 revealed: Are yours on the list? appeared first on WeLiveSecurity

Worst passwords list is out, but this time we’re not scolding users
phpMyAdmin Releases Critical Software Update – Patch Your Sites Now!
Facebook bug exposed unposted photos of 6.8 million users
Former rave kingpin back in jail for bizarre bank heist
Fake face fools fones

LinuxSecurity.com: Updated packages are now available for Red Hat Gluster Storage 3.4 Web Administration on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: – Update to 2.14.1 – CVE-2018-19608 (#1656784) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2018-03 —- – Update to 2.14.0 Release notes:

PewDiePie fan hacker compromise 100,000 printers
Wicked scammers steal $1 million from Save the Children charity
Critical SQLite Flaw Leaves Millions of Apps Vulnerable to Hackers

LinuxSecurity.com: New upstream version 1.8.2. Fix low priority security issue with TLS: https://www.redhat.com/archives/libguestfs/2018-December/msg00047.html —- New upstream version 1.8.1. —- Rebase to new stable version 1.8.0. —- nbdkit metapackage should depend on versioned -server subpackage etc. —- New upstream version 1.6.3.

LinuxSecurity.com: Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644

LinuxSecurity.com: Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

LinuxSecurity.com: It was discovered there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack (CVE-2018-19208). References:

LinuxSecurity.com: – Buffer overflow using computed size of canvas element. (CVE-2018-12359) – Use-after-free when using focus(). (CVE-2018-12360) – Integer overflow in SwizzleData. (CVE-2018-12361)

LinuxSecurity.com: A buffer overflow and out-of-bounds read can occur in TextureStorage11 within the ANGLE graphics library, used for WebGL content. This results in a potentially exploitable crash (CVE-2018-17466). A use-after-free vulnerability can occur after deleting a selection

LinuxSecurity.com: Cache side-channel variant of the Bleichenbacher attack.(CVE-2018-12404) References: – https://bugs.mageia.org/show_bug.cgi?id=23972 – https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.36.6_release_notes

LinuxSecurity.com: A vulnerability in Scala could result in privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been found in SpamAssassin, the worst of which may lead to remote code execution.

LinuxSecurity.com: Multiple vulnerabilities have been found in CouchDB, the worst of which could lead to the remote execution of code.

Facebook could face billion dollar fine for data breaches