Menu

Latest articles

LinuxSecurity.com: Several vulnerabilities have been discovered in mutt, a sophisticated text-based Mail User Agent, resulting in denial of service, stack-based buffer overflow, arbitrary command execution, and directory traversal

Facebook shuts off user data access for hundreds of thousands of apps
Smashing Security #089: Data breaches, ransomware, Bitcoin robberies, and typewriters
UK.gov ploughs cash into creaky police technology

LinuxSecurity.com: The security update of busybox announced as DLA-1445-1 introduced a regression due to an incomplete fix for CVE-2015-9261. It was no longer possible to decompress gzip archives which exceeded a certain file size.

Do you work in a regulated industry?
Cache of the Titans: Let’s take a closer look at Google’s own two-factor security keys
Drink this potion, Linux kernel, and tomorrow you’ll wake up with a WireGuard VPN driver
New Zealand school on naughty step after ransomware failure
Reddit hacked: Hackers steal complete copy of old database backup

LinuxSecurity.com: New blueman packages are available for Slackware 14.2 and -current to fix a security issue.

‘Unhackable’ Bitfi crypto-currency wallet maker will be shocked to find fingernails exist
DOJ Nabs Three FIN7 Cybercrime Suspects in Europe

security update

Bevy of Android Apps Harbor Hidden Malicious Windows Executables

LinuxSecurity.com: Several security issues were fixed in libmspack.

The End for Fin7: Feds cuff suspected super-crooks after $$$m stolen from 15m+ credit cards
SMS 2FA gave us sweet FA security, says Reddit: Hackers stole database backup of user account info, posts, messages
Reddit Breach Stems from SMS Two-Factor Authentication Breakdown

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Security critical patch update for OpenJDK (July CPU). See http://www.oracle.com/technetwork/security- advisory/cpujul2018-4258247.html#AppendixJAVA

LinuxSecurity.com: Security critical patch update for OpenJDK (July CPU). See http://www.oracle.com/technetwork/security- advisory/cpujul2018-4258247.html#AppendixJAVA

LinuxSecurity.com: # New upstream release 2.3 Fixes possible tag truncation security bug in AEAD API, see RHBZ#1602752 ## 2.3 – 2018-07-18 * SECURITY ISSUE: finalize_with_tag() allowed tag truncation by default which can allow tag forgery in some cases. The method now enforces the min_tag_length provided to the GCM constructor. * Added support for Python 3.7. […]

Risk Level: Very Low.

How a man hacked his victims’ SIM cards to steal millions of dollars
Amnesty International Targeted by Nation-State Spyware
Holy ship! UK’s Clarksons blames megahack on single point of pwnage
Android apps infected with umm… *Windows* malware
Alleged SIM-swap scammer nabbed for stealing $5m in Bitcoin
Staff dust off their typewriters after malware attack
Phone scam exploits Russian hacking fears
Steam Bans Developer After Outcry Over Cryptomining, Scam Items
High-schoolers’ data put up for sale after being scraped from surveys
HP offers rewards for hacking its printers

But don’t get too excited just yet: the first-of-its-kind bug bounty program for printers is invite-only for now The post HP offers rewards for hacking its printers appeared first on WeLiveSecurity

Mozilla still working on Firefox’s site isolation security revamp
New Spectre Variant Hits the Network
Clarksons says single user account to blame for data breach
Conversation hijacking attacks | Salted Hash Ep 38
Oooooh! Fashion! Yes, breach did contain 1 million+ records
UK cyber security boffins dispense Ubuntu 18.04 wisdom
Porn-warning security scam hooks you up to “Apple Care”

LinuxSecurity.com: Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may result in incorrect processing of HTTP/FTP, directory traversal, command injection, unintended socket creation or information disclosure.

Facebook Removes 17 Profiles Involved in Political Meddling
ThreatList: Business Email Compromises Way Up for Q2

LinuxSecurity.com: Security fix for CVE-2018-13988.

LinuxSecurity.com: Update zziplib to 0.13.69 version, fixes all known CVEs for the package.

Complex Malvertising Scheme Impacts Multiple Levels of Web Economy
HP Offers Up to $10,000 Rewards for Printer Bugs
Podcast: Why Bitcoin Miners Target Critical Infrastructure Networks
Please forgive me, I can’t stop robbing you: SamSam ransomware earns handlers $5.9m

LinuxSecurity.com: Denis Andzakovic discovered that network-manager-vpnc, a plugin to provide VPNC support for NetworkManager, is prone to a privilege escalation vulnerability. A newline character can be used to inject a

SamSam: The (almost) $6 million ransomware
NSA hasn’t closed security windows Snowden climbed through
Football team in trouble over unauthorized access to rivals’ videos
Leaky radio devices broadcast chipset data, discover researchers
Spectre chip weakness can be used to steal data remotely
OneDrive app for Android updated with fingerprint authentication

With this update, Microsoft is bringing a feature for Android users that has been available on iOS devices for quite a while now The post OneDrive app for Android updated with fingerprint authentication appeared first on WeLiveSecurity

UK CNP Fraud Drops as Banks Fight Back
Idaho Inmates Hack Tablets for Extra Credits
Automating Kernel Exploitation for Better Flaw Remediation
Steam game Abstractism pulled after cryptomining accusations
Cryptojacking for beginners – what you need to know
Dixons Carphone: Yeah, so, about that hack we said hit 1.2m records? Multiply that by 8.3
Dixons Carphone admits hack far bigger than originally thought
Inmates hack tablets for free credits prison

The nature of the vulnerability hasn’t been disclosed, but is said to have already been identified and fixed The post Inmates hack tablets for free credits prison appeared first on WeLiveSecurity

LinuxSecurity.com: New file packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New seamonkey packages are available for Slackware 14.2 and -current to fix security issues.

Australians almost immune from ransomware, topping lists for data safety
Pentagon ‘do not buy’ list says нет to Russia, 不要 to Chinese code
Updated AZORult Spyware Comes with Sophisticated New Techniques

security update

LinuxSecurity.com: Several security issues were fixed in MySQL.

LinuxSecurity.com: yum-utils: reposync: improper path validation may lead to directory traversal (CVE-2018-10897) SL6 noarch yum-plugin-aliases-1.1.30-42.el6_10.noarch.rpm yum-plugin-changelog-1.1.30-42.el6_10.noarch.rpm yum-plugin-ovl-1.1.30-42.el6_10.noarch.rpm yum-plugin-security-1.1.30-42.el6_10.noarch.rpm yum-plugin-tmprepo-1.1.30-42.el6_10.noarch.rpm yum-plugin-verify-1.1.30-42.e [More…]

LinuxSecurity.com: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) (CVE-2018-2952) SL6 x86_64 java-1.7.0-openjdk-1.7.0.191-2.6.15.4.el6_10.x86_64.rpm java-1.7.0-openjdk-debuginfo-1.7.0.191-2.6.15.4.el6_10.x86_64.rpm java-1.7.0-openjdk-devel-1.7.0.191-2.6.15.4.el6_10.x86_64.rpm java-1.7.0-openjdk-demo-1.7.0.191-2.6.15.4.el6_10.x86_64.rpm [More…]

Connected Car Apps Open Privacy Hole For Used Car Owners

LinuxSecurity.com: yum-utils: reposync: improper path validation may lead to directory traversal (CVE-2018-10897) SL7 noarch yum-plugin-aliases-1.1.31-46.el7_5.noarch.rpm yum-plugin-changelog-1.1.31-46.el7_5.noarch.rpm yum-plugin-ovl-1.1.31-46.el7_5.noarch.rpm yum-plugin-tmprepo-1.1.31-46.el7_5.noarch.rpm yum-plugin-verify-1.1.31-46.el7_5.noarch.rpm yum-plugin-versionlock-1.1.31-46.el7 [More…]

LinuxSecurity.com: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) (CVE-2018-2952) SL7 x86_64 java-1.7.0-openjdk-1.7.0.191-2.6.15.4.el7_5.x86_64.rpm java-1.7.0-openjdk-debuginfo-1.7.0.191-2.6.15.4.el7_5.x86_64.rpm java-1.7.0-openjdk-headless-1.7.0.191-2.6.15.4.el7_5.x86_64.rpm java-1.7.0-openjdk-accessibility-1.7.0.191-2.6.15.4.el7_5.x86_64. [More…]

LinuxSecurity.com: CVE-2018-14339 CVE-2018-14340 CVE-2018-14341

Jailhouse Tablets Allow Inmates to Steal Thousands of Dollars in Credits
DMARC Compliance Lacking in 28 Percent of .Gov Agencies
New York Times profiles one of its own security experts
How hack on 10,000 WordPress sites was used to launch an epic malvertising campaign
Prison inmates hacked tablets to earn $225,000 in credits
Parasite HTTP RAT loaded with advanced detection evasion capability
1.4 million online fashion shoppers exposed after data breach at UK ecommerce provider
Prisoners exploit tablet vulnerability to steal nearly $225K
Social media rumors lead to PepsiCo lawsuit
Google bans Android miners from Play Store
Russian Hacking Campaign Targeted US Utilities
‘Fancy Bear’ Targets Democratic Sen. Claire McCaskill
Phishing problems: 3.2M emails blocked in a month | Salted Hash Ep 37

LinuxSecurity.com: The host name verification in Tomcat when using TLS with the WebSocket client was missing. It is now enabled by default. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: Two vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following issues.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.

The Pirate Bay alternatives (2018) in wake of Cryptomining scandal

LinuxSecurity.com: A heap-based buffer overflow in cURL might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ZNC, the worst of which could result in privilege escalation.

LinuxSecurity.com: Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine.