Menu

Latest articles

Exposed: 157 GB of sensitive data from Tesla, GM, Toyota & others
US Intel Officials Share Their National Cybersecurity Concerns
Key takeaways from Singapore healthcare data breach

LinuxSecurity.com: The package networkmanager-vpnc before version 1.2.6-1 is vulnerable to privilege escalation.

LinuxSecurity.com: The package apache before version 2.4.34-1 is vulnerable to denial of service.

LinuxSecurity.com: The package znc before version 1.7.1-1 is vulnerable to multiple issues including privilege escalation and directory traversal.

DNS rebinding attack puts half a billion IoT devices at risk
The Fundamental Flaw in Security Awareness Programs
IoT hacker builds Huawei-based botnet, enslaves 18,000 devices in one day
LabCorp ransomed, 18k routers rooted, a new EXIF menace, and more

LinuxSecurity.com: Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program.

Microsoft: The Kremlin’s hackers are already sniffing, probing around America’s 2018 elections
Massive Malspam Campaign Finds a New Vector for FlawedAmmyy RAT
D-Link, Dasan Routers Under Attack In Yet Another Assault
Friday FYI: 9 out of 10 of website login attempts? Yeah, that’ll be hackers
Hackers attack Russian bank to steal $1m using an outdated router
Crypto gripes, election security, and mandatory cybersec school: Uncle Sam’s cyber task force emits todo list for govt
Newsmaker Interview: Troy Mursch on Why Cryptojacking Isn’t Going Away

LinuxSecurity.com: Update to 0.26.5 (CVE-2018-10887, CVE-2018-10888)

LinuxSecurity.com: This release fixes a directory and symbolic link traversal vulnerability in Archive::Zip::Archive Perl module that allows an attacker to writite into an arbitrary file accesible by a local user.

LinuxSecurity.com: An update for openstack-tripleo-heat-templates is now available for Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

GoogleUserContent CDN Hosting Images Infected with Malware
Doctor, doctor, I feel like my IoT-enabled vacuum cleaner is spying on me
ThreatList: A Ranking of Airports By Riskiest WiFi Networks
Chinese Hackers Mount Espionage Campaign During Trump-Putin Summit
Cybercrooks slurp nearly $1m from Russian bank after pwning router at regional branch
Top 10 vulnerable airports where your device can be hacked
Canada tackles malicious online advertising

Federal agency issues Notices of Violation to Datablocks and Sunlight Media for allegedly facilitating the installation of malware through online advertising The post Canada tackles malicious online advertising appeared first on WeLiveSecurity

UK’s Huawei handler dials back support for Chinese giant’s kit in critical infrastructure

LinuxSecurity.com: The dns-root-data update to 2017072601~deb8u2 broke dnsmasq’s init script, making dnsmasq no longer start when dns-root-data was installed.

Hackers hold 80,000 healthcare records to ransom
Roblox says hacker injected code that led to avatar’s gang rape
Millions of Health Records at Risk Following LabCorp Suspected Breach
Gov Slow to Address Urgent CNI Security Needs
White House Cybersecurity Strategy at a Crossroads
Basic email blunder exposed possible victims of child sexual abuse
Either my name, my password or my soul is invalid – but which?

Reading Time: ~2 min.Venmo’s Public Data Setting Shows All Researchers recently uncovered just how much data is available through the Venmo API, successfully tracking routines, high-volume transactions from vendors, and even monitoring relationships. Because Venmo’s privacy settings are set to public by default, many users have unknowingly contributed to the immense collection of user data […]

LinuxSecurity.com: The linux-base package has been updated to support the package of Linux 4.9 that was recently added to Debian 8. This resolves a dependency that was not satisfiable by the jessie and jessie-security suites.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: CVE-2015-1239 Fix for denial of service (process crash) via a crafted PDF.

ThreatList: Sizing Up The Scourge of Credential-Stuffing

security update

security update

Stealthy Malware Hidden in Images Takes to GoogleUserContent
IoT Robot Vacuum Vulnerabilities Let Hackers Spy on Victims
Declassified files reveal how pre-WW2 Brits smashed Russian crypto

LinuxSecurity.com: Update to 0.26.5 (CVE-2018-10887, CVE-2018-10888)

LinuxSecurity.com: This release fixes a directory and symbolic link traversal vulnerability in Archive::Zip::Archive Perl module that allows an attacker to writite into an arbitrary file accesible by a local user.

LinuxSecurity.com: – Fix Side Channel Based ECDSA Key Extraction (CVE-2018-12437) (PR #408) – Fix potential stack overflow when DER flexi-decoding (CVE-2018-0739) (PR #373) – Fix two-key 3DES (PR #390) – Fix accelerated CTR mode (PR #359) – Fix Fortuna PRNG (PR #363) – Fix compilation on platforms where cc doesn’t point to gcc (PR #382) […]

LinuxSecurity.com: Fix heap memory corruption, CVE-2017-17833

LinuxSecurity.com: Linux 4.9 has been packaged for Debian 8 as linux-4.9. This provides a supported upgrade path for systems that currently use kernel packages from the “jessie-backports” suite.

LinuxSecurity.com: Linux 4.9 has been packaged for Debian 8 as linux-4.9. This provides a supported upgrade path for systems that currently use kernel packages from the “jessie-backports” suite.

GangWang GPS Navigation Attack Leads Unsuspecting Drivers Astray
How Cyber Insurance Changes the Conversation Around Risk
Brit tech forges alliance to improve cyber security as MPs moan over ‘acute scarcity’ of experts
Hackers automate the laundering of money via Clash of Clans
Adobe on internal systems security hole: Panic not. It isn’t critical
Ubisoft Games Hit by Massive DDoS Attacks
America’s largest diagnostics service LabCorp suffers massive data breach

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Google slapped with €4.34bn fine by EU over antitrust violations

Tech giant has 90 days to comply with ruling or faces further penalties over ‘anti-competitive’ practices The post Google slapped with €4.34bn fine by EU over antitrust violations appeared first on WeLiveSecurity

LinuxSecurity.com: An update for fluentd is now available for Red Hat OpenStack Platform 13.0 Operational Tools for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Critical Authentication Flaws in Cisco Policy Suite Patched
Venmo users: time to hide your drug deals and excessive pizza consumption

LinuxSecurity.com: This is the Six-Month notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.

Cloud Security: Lessons Learned from Intrusion Prevention Systems
US Vote-Counting Computers Had Flaw, Allowed Hackers Access
US Orgs Overly Optimistic About Cyber-Readiness
Google hit with $5.1b fine in EU’s Android antitrust case
Privacy Advocates Say Kelsey Smith Act Gives Police Too Much Power

LinuxSecurity.com: unzip and untar target tasks in ant allows the extraction of files outside the target directory. A crafted zip or tar file submitted to an Ant build could create or overwrite arbitrary files with the

Microsoft offers up to $100,000 to identity bug finders
Automated money-laundering scheme found in free-to-play games
British Airways cancelled flights at Heathrow after ‘IT system issue’

Thousands of British Airways passengers left stranded at Heathrow airport following incident The post British Airways cancelled flights at Heathrow after ‘IT system issue’ appeared first on WeLiveSecurity

Smashing Security #087: How Russia hacked the US election
Airbus UK infosec gros fromage: Yep, we work with arch-rivals Boeing

LinuxSecurity.com: Jeriko One discovered two vulnerabilities in the ZNC IRC bouncer which could result in privilege escalation or denial of service. For the stable distribution (stretch), these problems have been fixed in

LinuxSecurity.com: A use-after-free was discovered in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played.

Bloke accused of netting $5m on inside info about Lattice Semiconductor

LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: CVE-2018-11439 Fix for a heap-based buffer over-read via a crafted audio file.

security update

security update

Who’s leaving Amazon S3 buckets open online now? Cybercroooks, US election autodialers
Will this biz be poutine up the cash? Hackers demand dosh to not leak stolen patient records
ThreatList: Popular Apps Get Enterprise Blacklisted
Thousands of U.S. Voter Personal Records Leaked by Robocall Firm

LinuxSecurity.com: New release (1:12.2.6-1) Security fix for CVE-2018-1128 Security fix for CVE-2018-1129 Security fix for CVE-2018-10861

Mingis on Tech: The blockchain evolution, from services…to smartphones

LinuxSecurity.com: The package curl before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package libcurl-gnutls before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package libcurl-compat before version 7.61.0-1 is vulnerable to arbitrary code execution.