Menu

Latest articles

LinuxSecurity.com: Fixes **CVE-2017-11332**, **CVE-2017-11358**, and **CVE-2017-11359**. —- **Prevents division by zero in `src/ao.c`** This bug is hard to reproduce, depending on the HW configuration or installed OS parts. For me, it can be reproduced only in `mock`. In this update, error message should be displayed instead of SIGFPE.

LinuxSecurity.com: Security critical patch update for OpenJDK (July CPU). See http://www.oracle.com/technetwork/security- advisory/cpujul2018-4258247.html#AppendixJAVA

LinuxSecurity.com: upstream security fix release

LinuxSecurity.com: **PHP version 7.2.8** (19 Jul 2018) **Core:** * Fixed bug php#76534 (PHP hangs on ‘illegal string offset on string references with an error handler). (Laruence) * Fixed bug php#76520 (Object creation leaks memory when executed over HTTP). (Nikita) * Fixed bug php#76502 (Chain of mixed exceptions and errors does not serialize properly). (Nikita) **Date:** […]

Flaw in Swann smart security cameras allows access to user’s live stream
364 inmates hacked prison tablets to steal almost $225,000
5 Ways Small Security Teams Can Defend Like Fortune 500 Companies
This new cryptomining malware targets business PCs and servers
FBI boss: We went to the moon, why can’t we have crypto backdoors? – and more this week

LinuxSecurity.com: It was discovered that there was a denial of service vulnerability in policykit-1, a framework for managing administrative policies and privileges.

LinuxSecurity.com: The package libextractor before version 1.7-1 is vulnerable to denial of service.

LinuxSecurity.com: The package wesnoth before version 1.14.4-1 is vulnerable to arbitrary code execution.

security update

ICO hacked: Hackers steal $8 million from KICKICO Blockchain network

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to fix security issues.

FELIXROOT Backdoor Resurfaces in Environmental Spam Campaign

security update

Security Glitch in IoT Camera Enabled Remote Monitoring

LinuxSecurity.com: The fix for arbitrary code execution documented in CVE-2017-17458 was incomplete in the previous upload. A more exhaustive change was implemented upstream and completely disables non-Mercurial subrepositories unless users changed the subrepos.allowed setting.

LinuxSecurity.com: USN-3722-1 introduced a regression in ClamAV.

LinuxSecurity.com: A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: A security update is now available for Red Hat Single Sign-On 7.2 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low. Type: Trojan.

Spectre attack variant can be remotely mounted to extract sensitive data
Font of pwnage: Crims poison well with crypto-jacking code, trickles into PDF editor app
“Simple trick” floors home security camera, gives anyone access
Your essential guide to what sysadmins really mean
Google takes on Yubico with its own security key, Titan
Help us bring a smile to a sysadmin’s dial…
Threatpost News Wrap Podcast For July 27
Google wants you to beef up your account security with its own hardware token

The company credits hardware-based two-factor authentication with practically eliminating the problem of phishing attacks that have targeted its own employees of late The post Google wants you to beef up your account security with its own hardware token appeared first on WeLiveSecurity

Our FREE #SysAdminDay gift means you need NEVER code in Python again!
Nerves jangled by new ransomware attack on shipping giant
Shock Land Rover Discovery: Sellers could meddle with connected cars if not unbound
Virginian Bank Robbed Twice in Eight Months
COSCO Hit by Suspected Ransomware
Wyden urges government agencies to ditch Flash
How to Find Trustworthy Tools and Software for Your Business

LinuxSecurity.com: The security update of mailman announced as DLA-1442-1 introduced a regression due to an incomplete fix for CVE-2018-13796 that broke the admin and listinfo overview pages.

LinuxSecurity.com: Security researchers identified two software analysis methods that, if used for malicious purposes, have the potential to improperly gather sensitive data from multiple types of computing devices with different vendors’ processors and operating systems.

Well, well, well. Crime does pay: Ransomware creeps let off with community service

Reading Time: ~2 min.Paired Bluetooth Devices Vulnerable to Man-in-the-Middle Attacks A new vulnerability has been discovered that would allow an attacker to easily view the traffic sent between two Bluetooth-paired devices. The core of the vulnerability relies on the attacker’s device being within wireless range of both devices in the process of being paired. Signals […]

LinuxSecurity.com: Busybox, utility programs for small and embedded systems, was affected by several security vulnerabilities. The Common Vulnerabilities and Exposures project identifies the following issues.

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2018-4117

Boffins: Mixed-signal silicon can SCREAM your secrets to all

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

How to (slowly) steal secrets over the network from chip security holes: NetSpectre summoned
Identity theft protection firm LifeLock may have exposed user email addresses

LinuxSecurity.com: CVE-2018-11319 The improper handling of search for configuration files might be exploited for arbitrary code execution via a malicious gcc plugin.

Highly Sophisticated Parasite RAT Emerges on the Dark Web
Oh no, what a rough blow: Cosco at a lossco over ransomware tossco
Bugs in Samsung IoT Hub Leave Smart Home Open To Attack

LinuxSecurity.com: An update for ceph is now available for Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2241

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2252

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2242

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2240

COSCO’s American Operations Hit With Crippling Ransomware Attack
Sen. Wyden Urges Government Ban on Adobe Flash
Chrome now flags HTTP sites as “not secure”

This is bad news for many websites that have yet to embrace encrypted connections The post Chrome now flags HTTP sites as “not secure” appeared first on WeLiveSecurity

LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

Fake banking apps on Google Play leak stolen credit card data

Fraudsters are using bogus apps to convince users of three Indian banks to divulge their personal data The post Fake banking apps on Google Play leak stolen credit card data appeared first on WeLiveSecurity

Senator calls on US Government to start killing Flash now
Malware targeting cash machines fetches top dollar on dark web

LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

HTTP versus HTTPS – what’s all the fuss? [VIDEO]
8 types of malware and how to recognize them
DHS Officials: Hundreds of US Utility Victims Infiltrated by Russian Hackers
Regional Virginia Bank Falls Victim to Coordinated $2.4M ATM Heist
More browser extensions and apps caught spying on users
Man accused of tricking men into involuntary porn
Twitter boots 143K bad apps, throttles developer access to API
Would a bill banning bots do more harm than good?
Bigamists have no right to privacy on Facebook

LinuxSecurity.com: The package jenkins before version 2.133-1 is vulnerable to multiple issues including access restriction bypass, arbitrary filesystem access, cross-site scripting and information disclosure.

I saw what you did…or did I?

It might seem legit but there are several reasons why you should not always hit the panic button when someone claims to have your email password The post I saw what you did…or did I? appeared first on WeLiveSecurity

Popular Android/iOS Apps & Extensions Collecting “Highly Personal” User data
Sen. Ron Wyden: Adobe Flash is doomed, why is Uncle Sam still using it?

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Smashing Security #088: PayPal’s Venmo app even makes your drug purchases public
Skills That a ‘Next-Level’ Pentester Should Have

security update

security update

LinuxSecurity.com: This update includes the latest upstream release, **httpd 2.4.34**, with multiple bug fixes and enhancements. See http://www.apache.org/dist/httpd/CHANGES_2.4.34 for more information on the changes in this version. A security vulnerability is addressed in this update: * `mod_md`: DoS via Coredumps on specially crafted requests (CVE-2018-8011)

New variant of Kronos banking trojan spotted using Tor network
Pinterest Browser Extension Injects Unwanted Code into 5K Websites
US Homeland Security warns of latest hacker craze – ERP pwnage
Hey you smart, well-paid devs. Stop clicking on those phishing links and bringing in malware muck on your shoes
Facebook Security Exec Calls for Tightened Data Privacy

LinuxSecurity.com: New version of dcraw is available 9.28.0 Security fix for CVE-2018-5801

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2251

Risk Level: Very Low. Type: Trojan, Worm.

Intel Smart Sound Tech Vulnerable to Three High-Severity Bugs
Podcast: The Industrial World is Facing a Security Crisis