Menu

Latest articles

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes 15 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Thought two-factor auth completely locks down Office 365? Not quite
US drug cops snared crooks with pre-cracked BlackBerry mobes – and that’s just the start
Scam alert: No, hackers don’t have webcam vids of you enjoying p0rno. Don’t give them any $$s

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.

You are not alone; Instagram is down for many

Reading Time: ~2 min.Ticketmaster Snafu Only Tip of the Iceberg After last month’s Ticketmaster breach, a follow-up investigation found it to be part of a larger payment card compromising campaign affecting more than 800 online retail sites worldwide. The cause of the breach appears to stem from the third-party breaches of several Ticketmaster suppliers, which […]

Indictment bombshell: ‘Kremlin intel agents’ hacked, leaked Hillary’s emails same day Trump asked Russia for help
Justice Department Indicts 12 Russian Nationals Tied to 2016 Election Hacking

LinuxSecurity.com: gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification (CVE-2018-12020) SL6 x86_64 gnupg2-2.0.14-9.el6_10.x86_64.rpm gnupg2-debuginfo-2.0.14-9.el6_10.x86_64.rpm gnupg2-smime-2.0.14-9.el6_10.x86_64.rpm i386 gnupg2-2.0.14-9.el6_10.i686.rpm gnupg2-debuginfo-2.0.14-9.el6_10.i686.rpm gnupg2-smim [More…]

LinuxSecurity.com: Red Hat JBoss Core Services Pack Apache Server 2.4.29 packages are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Red Hat JBoss Core Services Pack Apache Server 2.4.29 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Red Hat JBoss Core Services Pack Apache Server 2.4.29 packages are now available. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

Indian iPhone Spy Campaign Used Fake MDM Platform

Risk Level: Very Low. Type: Trojan.

ThreatList: Bug Bounty Payouts Increase Six Percent for Critical Vulnerabilities
Sextortionists Shift Scare Tactics to Include Legit Passwords
It pays to know your enemies: Sophos webinar gives you the cybercrime lowdown
Unsanctioned Apps Invite Fox into Cybersecurity Hen House
Spectre bug protection forcing Chrome to use 10 to 13% more RAM
Bogus Mobile Device Management system used to hack iPhones in India
Sextortion scam knows your password, but don’t fall for it
Ukraine claims it blocked VPNFilter attack at chemical plant
Facebook ordered to let grieving mother in to dead daughter’s account
Linux, malware and data breaches – what can we learn? [VIDEO]

LinuxSecurity.com: It was discovered that there was a symlink attack in the Cinnamon desktop environment. An attacker could overwrite an arbitrary file on the filesystem via

Risk Level: Very Low. Type: Trojan.

Google’s ghost busters: We can scare off Spectre haunting Chrome tabs

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2112

Now Pushing Malware: NPM package dev logins slurped by hacked tool popular with coders
Hacker Compromises Air Force Captain to Steal Sensitive Drone Info
“Bitcoins for cash in bags” trader gets 12 months in prison
Dark web marketplace found selling access to airport’s security system
Cisco Patches High-Severity Bug in VoIP Phones
ThreatList: 6-Year-Old Dorkbot Banking Malware Resurfaces as Big Threat
Chrome Now Features Site Isolation to Defend Against Spectre
Timehop data breach is worse than they initially said
Average cost of a data breach exceeds $3.8 million, claims report
Ransomware is so 2017, it’s all cryptomining now among the script kiddies

LinuxSecurity.com: Update to upstream version 9.4.11. Fixes CVE-2017-7656, CVE-2017-7657, CVE-2017-7658, CVE-2018-12538.

Palo Alto Networks rattles tin, wants $1.5bn for, er, stuff and things
Insights Security Hardening Rules

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Facebook fined over data privacy scandal

Social media giant fined in the UK for failing to protect users’ personal information and for a lack of transparency The post Facebook fined over data privacy scandal appeared first on WeLiveSecurity

Not All Hacks Are Created Equal
This Is How Much a ‘Mega Breach’ Really Costs
Hacker Exploits 2-Year Old Router Issue To Steal Sensitive US Military Data
Smashing Security #086: Elon Musk submarine scams and 2FA bypass
What can $10 stretch to these days? Lunch… or access to international airport security systems
Trends 2018: Doing time for cybercrime

Law enforcement and malware research join forces to take down cybercriminals The post Trends 2018: Doing time for cybercrime appeared first on WeLiveSecurity

Who’s Reading Your Gmail Messages?
Stolen Taiwanese Certs Used in Malware Campaign
Asian Countries Frequent Targets of APT Attacks
Cost of UK Data Breaches Rises to ?2.7m
Your Google phone will soon screen nuisance calls
Facebook doesn’t want to eradicate fake news. If it did they’d kick out InfoWars
Hackers break into newswire services, trade on what they find
Default router password leads to spilled military secrets

LinuxSecurity.com: It was discovered that there was a discovered a path traversal flaw in ruby-sprockets, a Rack-based asset packaging system. A remote attacker could take advantage of this flaw to read arbitrary files outside an application’s root directory via “file://” requests.

Snakes on a plane! (Stuffed inside a hard drive)

LinuxSecurity.com: New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Ticketmaster breach ‘part of massive card-skimming campaign’
Tim? Larry? We need to talk about smartphones and privacy
Timehop admits to more data leakage, details GDPR danger
FBI for the Apple guy: Bloke accused of stealing car kit collared

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2113

Like my new wheels? All I did was squash a bug, and they gave me $72k

LinuxSecurity.com: An update for gnupg2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for gnupg2 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Ticketmaster Breach: Just One Part of a Wide-Ranging Campaign

Type: Vulnerability. Microsoft Access is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Skype for Business and Lync are prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Skype for Business and Lync are prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a security-bypass vulnerability; fixes are available.