Menu

Latest articles

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: The package thunderbird before version 60.0-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

LinuxSecurity.com: Chris Coulson discovered a use-after-free flaw in the GNOME Display Manager, triggerable by an unprivileged user via a specially crafted sequence of D-Bus method calls, leading to denial of service or potentially the execution of arbitrary code.

New Variant of KeyPass Ransomware Discovered
Blue Team Village, DEF CON 2018 | Salted Hash Ep 43
Black Hat 2018: IoT Security Issues Will Lead to Legal ‘Feeding Frenzy’
GoDaddy Leaks ‘Map of the Internet’ via Amazon S3 Cloud Bucket Misconfig

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

DEF CON 2018: ‘Man in the Disk’ Attack Surface Affects All Android Phones
How a cryptocurrency-destroying bug almost didn’t get reported
Black Hat Video Exclusive: Mobile APTs Redefining Phishing Attacks
US voting systems: Full of holes, loaded with pop music, and hacked by an 11-year-old
DEF CON 2018: Voting Hacks Prompt Push Back from Election Officials, Vendors

LinuxSecurity.com: Multiple vulnerabilities have been discovered in various parsers of Blender, a 3D modeller/ renderer. Malformed .blend model files and malformed multimedia files (AVI, BMP, HDR, CIN, IRIS, PNG, TIFF) may result in the execution of arbitrary code.

Can cramming code with bugs make it more secure? Some think so

Unbeknownst to exploit writers, the seemingly mouth-watering bugs would be bogus and non-exploitable The post Can cramming code with bugs make it more secure? Some think so appeared first on WeLiveSecurity

Siri is listening to you, but she’s NOT spying, says Apple
Feds indict 12 for allegedly buying iPhones on other people’s dimes
In-flight satellite comms vulnerable to remote attack, researcher finds

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 9 fixes is now available.

Security breach in the White House’s Situation Room
PGA of America Struck By Ransomware
#DEFCON DHS Says Collaboration Needed for Secure Infrastructure and Elections
#DEFCON Government Attacks and Surveillance Continue to Increase
Criminal justice software code could send you to jail and there’s nothing you can do about it
Hackers can manipulate Police body cam footages
Prank ‘Give me a raise!’ email nearly lands sysadmin with dismissal
Former NSA top hacker names the filthy four of nation-state hacking
Black Hat: Protecting Industrial Control System

Aiming to protect critical infrastructure against attacks The post Black Hat: Protecting Industrial Control System appeared first on WeLiveSecurity

UK cyber cops: Infosec pros could help us divert teens from ‘dark side’
DEF CON 2018: Critical Bug Opens Millions of HP OfficeJet Printers to Attack
DEF CON 2018: Apple 0-Day (Re)Opens Door to ‘Synthetic’ Mouse-Click Attack
The Enigma of AI & Cybersecurity
NSA Brings Nation-State Details to DEF CON
#DEFCON L0pht Reunite to Find Security Unimproved
DEF CON 2018: Hacking Medical Protocols to Change Vital Signs

security update

security update

LinuxSecurity.com: rebase to 8.37.0 ———————- – few fixes and enhancements handling journal input – now requires librelp at least 1.2.16, adding support for setting address to bind – various other rsyslog core bugfixes and stability fixes

LinuxSecurity.com: – update to 2.56.x

LinuxSecurity.com: – update to 2.56.x

DEF CON 2018: Telltale URLs Leak PII to Dozens of Third Parties

LinuxSecurity.com: New upstream version 0.7alpha. Fixes CVE-2018-14679 libmspack: off-by-one error in the CHM PMGI/PMGL chunk number validity checks

Cyber Criminals selling Bitcoin ATM Malware on Dark Web
Snap code snatched, Pentagon bans bands, pacemakers cracked, etc
Blue Team village, Deffcon 2018 | Salted Hash Ep. 43

LinuxSecurity.com: New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

PGA Golf Championship hit with Bitcoin ransomware
The off-brand ‘military-grade’ x86 processors, in the library, with the root-granting ‘backdoor’
Chris Valasek and Charlie Miller: How to Secure Autonomous Vehicles
Sensitive data on 31,000 GoDaddy servers exposed online

LinuxSecurity.com: Two vulnerabilities have been found in the PostgreSQL database system: CVE-2018-10915

LinuxSecurity.com: It was discovered that the PatternSyntaxException class in the Concurrency component of OpenJDK, an implementation of the Oracle Java platform could result in denial of service via excessive memory consumption.

LinuxSecurity.com: Various vulnerabilities leading to denial of service or possible unspecified other impacts were discovered in sam2p, an utility to convert raster images to EPS, PDF, and other formats.

Hackers phish Butlin’s holiday camp chain, access customers’ personal data
Black Hat 2018: Voice Authentication is Broken, Researchers Say
Hi-de-Hack! Redcoats red-faced as Butlin’s holiday camp admits data breach hit 34,000
Congresscritters want answers on Tillerson’s rm -rf /opt/gov/infosec
How one man could have hacked every Mac developer (73% of them, anyway)
Comcast Xfinity web flaws exposed customer data
15,000-strong army of Twitter robots found spreading cryptocurrency spam

LinuxSecurity.com: Several security issues were fixed in the kernel.

Over 20 Flaws Discovered in Popular Healthcare Software
#BHUSA: Politics and Cyber-Defense Are Colliding
Off-colour tweet earns Google’s Spectre whizz a midnight eviction from Caesars and DEF CON

Reading Time: ~2 min.Chipmaker Production Halts After WannaCry Attack A recent WannaCry attack at a Taiwanese chip manufacturerhas brought production to a standstill and threatens delays for new Apple products yet to be released. The manufacturer has announced that after two days their systems are clear and production is able to continue, blaming their own […]

Black Hat 2018: With Healthcare Security Flaws, Safety’s Increasingly at Stake
Facebook ‘regrets’ balloons and confetti triggered by earthquake posts
Hackers can cook people alive using sat-comms ‘microwave oven’ death rays – claim
Encryption doesn’t stop him or her or you… from working out what Thing 1 is up to
Spec-exec CPU bugs sweep hacking Oscars – and John McAfee’s in there like a bullet
Can we talk about the little backdoors in data center servers, please?
Say what you will about self-driving cars – the security is looking ‘OK’

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: Java applications could be made to use excessive memory.

LinuxSecurity.com: Java applications could be made to use excessive memory.

You can’t always trust those mobile payment gadgets as far as you can throw them – bugs found by infosec duo
Kaspersky VPN blabbed domain names of visited websites – and gave me a $0 reward, says chap
Understanding TRITON and the Missing Final Stage of the Attack

security update

Crims hacked accounts, got phones, resold them – and the Feds reckon they’ve nabbed ’em
Oh, fore putt’s sake: Golf org PGA bunkered up by ransomware attack just days before tournament
Black Hat 2018: Widespread Critical Flaws Found in Smart-City Gear
Black Hat 2018: Stealthy Kernel Attack Flies Under Windows Mitigation Radar
Hacking For Sport: A Journey in Reverse Engineering a Toshiba Wireless SD Card
New WhatsApp flaws let attackers hack chats to spread fake news
New Actor DarkHydrus Targets Middle East with Open-Source Phishing
Discover which dangers lurk ahead – at Sophos’ ‘See the Future’ event
Google to warn companies targeted in government-backed attacks
Black Hat 2018: Cortana Flaw Allowed Takeover of Locked Windows 10 Device
Attackers grab hold of PGA of America files, demand ransom

The golf association is said to have had little success with restoring access to its files so far The post Attackers grab hold of PGA of America files, demand ransom appeared first on WeLiveSecurity