Menu

Latest articles

LinuxSecurity.com: The package libcurl-compat before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-libcurl-compat before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-curl before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: Several security issues were fixed in PolicyKit.

LabCorp Investigates a Potential Breach that Could Affect Millions
Woman charged for hacking & leaking private pictures of Selena Gomez
So long and thanks for all the fixes: ERPScan left out of credits on Oracle bug-bash list
Oracle Sets All-Time Record with July Critical Patch Update
Microsoft Bounty Program Offers Payouts for Identity Service Bugs
Smaller Nation State Attacks: A Growing Cyber Menace
Brit watchdog fines child sex abuse inquiry £200k over mass email blunder
Could semantic icons replace passwords and PINs?
SPECTRE Variant 1 scanning tool
21-year-old spy tool developer faces prison
£200,000 fine for exposing possible child abuse victims in classic Cc/Bcc email blunder
Elon Musk retracts vile Twitter accusation against cave rescuer
Call records breach let users feel like Movistars (with everyone watching who they’re talking to)
Time to Yank Cybercrime into the Light
Russian National Vulnerability Database Operation Raises Suspicions
“Astoundingly stupid” Kodak (not really) Bitcoin miner bites the dust
Business email compromise scams have netted $12.5 billion, says FBI

LinuxSecurity.com: A vulnerability was discovered in WordPress, a web blogging tool. It allowed remote attackers with specific roles to execute arbitrary code.

PayPal’s pal Venmo spaffs your pals’ payments – and yours
Microsoft to pay new bounties for identity services holes

LinuxSecurity.com: A vulnerability in tqdm could allow remote attackers to execute arbitrary code.

security update

Blood test biz LabCorp pulls plug on systems over hacker fears

LinuxSecurity.com: Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in various parsers of Blender, a 3D modeller/ renderer. Malformed .blend model files and malformed multimedia files (AVI, BMP, HDR, CIN, IRIS, PNG, TIFF) may result in the execution of arbitrary code.

Scumbag confesses in court: LuminosityLink creepware was my baby

LinuxSecurity.com: New mutt packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

800K Patient Records At Issue in ProCare Health Snafu
Peer-to-Peer Crypto-Exchanges: A Haven for Money Laundering

security update

US voting systems (in Oregon) potentially could be hacked (11 years ago) by anybody (in tech support)
Recent Andariel Group ActiveX Attacks Point to Future Targets
Millions of Telefonica customers’ data exposed after security breach

LinuxSecurity.com: gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification (CVE-2018-12020) SL7 x86_64 gnupg2-2.0.22-5.el7_5.x86_64.rpm gnupg2-debuginfo-2.0.22-5.el7_5.x86_64.rpm gnupg2-smime-2.0.22-5.el7_5.x86_64.rpm gnupg2-2.0.22-5.el7_5.src.rpm – Scientific Linux Development Team

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Look, what’s that over there? Sophos nips Windows DNS DLL false positive in the bud
Luminosity RAT author pleads guilty to creating & selling hacking tool
Russia’s national vulnerability database is a bit like the Soviet Union – sparse and slow
DDoS Attacks Get Bigger, Smarter and More Diverse
How to spoof someone’s GPS navigation to send them the wrong way
How to Teach Your Employees About Cybersecurity
Yar, thar she blows: Corp-cash-stealing email whaling attacks now a $12.5bn industry
A deep dive down the Vermin RAThole

ESET researchers have analyzed remote access tools cybercriminals have been using in an ongoing espionage campaign to systematically spy on Ukrainian government institutions and exfiltrate data from their systems The post A deep dive down the Vermin RAThole appeared first on WeLiveSecurity

Trump wants to work with Russia on infosec. Security experts: lol no
“Red Alert” Warning on US Cyber-Attacks, Now at “Critical Point”
Russia Fends Off 25 Million Cyber-Attacks During World Cup
Guy jailed for refusing to unlock phones

Reading Time: ~3 min.While one-click shopping on Amazon (or Webroot.com, for that matter) seems super easy when you’re the consumer, there are a lot of complex strategies and processes going on behind the scenes. We chat with Cathy Ondrak, product owner for Webroot.com, to get a glimpse behind the curtain. In her role, Cathy works […]

Twitter shutters accounts linked to US election hacking

LinuxSecurity.com: The package thunderbird before version 52.9.1-1 is vulnerable to multiple issues including arbitrary code execution, cross-site request forgery and information disclosure.

‘007’ code helps stop Spectre exploits before they exist
21-year-old woman charged with hacking Selena Gomez
Revealed in detail: World powers stuff spyware kit, how-to guides in dodgy nations’ pockets

LinuxSecurity.com: A timing attack was discovered in the function for CSRF token validation of the “Ruby rack protection” framework. For the stable distribution (stretch), this problem has been fixed in

Irish fella accused of being Silk Road admin ‘Libertas’ hauled to US
No Evidence of GandCrab Leveraging SMB Exploit – Yet

security update

security update

Sad Nav: How a cheap GPS spoofer gizmo can tell drivers to get lost

LinuxSecurity.com: The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo

LinuxSecurity.com: – Security fix for CVE-2017-9258, CVE-2017-9259, CVE-2017-9260

Newsmaker Interview: Bruce Schneier on ‘Going Dark’ and the Crypto Arms Race
Kremlin hacking crew went on a ‘Roman Holiday’ – researchers
New sextortion scheme uses victims’ real password for blackmailing
DanaBot Trojan Targets Bank Customers In Phishing Scam
IoT search engine exposes passwords of over 30,000 vulnerable DVRs
Road navigation systems can be spoofed using $223 equipment
Who is the weakest link in software security?
A highly targeted malware campaign is spying on 13 iPhones in India
Facebook refuses to remove fake news, but will demote it
Twitter pops a lot of famous people’s follower bubbles
Free eBook: If your friend was put in charge of a cyber budget, what advice would you give them?
Irishman extradited to the US to face charges relating to Silk Road

Gary Davis accused of working as an administrator for the notorious dark web marketplace appears in a federal court in New York The post Irishman extradited to the US to face charges relating to Silk Road appeared first on WeLiveSecurity

Major International Airport System Access Sold for $10 on Dark Web
Western E-Tailers Set to Lose Nearly $19bn to Fraud
GandCrab Ransomware Continues to Evolve But Can’t Spread Via SMB Shares Yet
USB Restricted Mode in iOS 11.4.1 now available to all iPhone users
Ex-Apple engineer charged with stealing self-driving car secrets
GitHub to Pythonistas: Let us save you from vulnerable code

LinuxSecurity.com: CVE-2015-1854 A flaw was found while doing authorization of modrdn operations. An unauthenticated attacker able to issue an ldapmodrdn call to

LinuxSecurity.com: It was discovered that there were two issues in znc, a modular IRC bouncer: * There was insufficient validation of lines coming from the network

Australia’s Airport Security Threatened by Hack
FBI: Email Account Compromise Losses Reach $12B
Russian intelligence officers indicted in DNC hacking

LinuxSecurity.com: Security fix for CVE-2018-8009 —- Version update to 2.7.6. Fixes many open CVEs and bugs.

LinuxSecurity.com: Update to 4.9.7 security release. https://wordpress.org/news/2018/07/wordpress-4-9-7-security-and-maintenance- release/

LinuxSecurity.com: Update to Sprockets 3.7.2. Fixes CVE-2018-3760: https://access.redhat.com/security/cve/cve-2018-3760

security update

LinuxSecurity.com: Several vulnerabilities were discovered in CUPS, the Common UNIX Printing System. These issues have been identified with the following CVE ids: CVE-2018-4180

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.

Timehop Reveals More Personal Data Was Breached
WordPress Sites Targeted in World Cup-Themed Spam Scam
Hope for Hutchins, Navy sinks contractor, there’s another Russian hacking scandal, and more

LinuxSecurity.com: Multiple vulnerabilities were found in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.