Menu

Latest articles

Things that make you go hmmm: Do crypto key servers violate GDPR?
Gentoo hack caused by three rookie mistakes
Thunderbird gets its EFAIL patch
Chrome, Firefox pull invasive browser extension
Smashing Security #085: Doctor Who, Facebook patents, and Bob’s Burgers
Top 7 Most Popular and Best Cyber Forensics Tools

security update

security update

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in Exiv2.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Carole Cadwalladr takes us behind the scenes of the Cambridge Analytica investigation
The Pirate Bay is silently mining cryptocurrency without user consent
Welcome to a New Look for Threatpost
Navigating an Uncharted Future, Bug Bounty Hunters Seek Safe Harbors
ThreatList: Exploit Kits Still a Top Web-based Threat
ThreatList: Top Summer DDoS Trends
Newsmaker Interview: Marten Mickos on the Future of Bug Bounty

LinuxSecurity.com: The package git-annex before version 6.20180626-1 is vulnerable to multiple issues including arbitrary filesystem access and information disclosure.

LinuxSecurity.com: The package gitlab before version 11.0.1-1 is vulnerable to multiple issues including cross-site scripting and insufficient validation.

Want to beat facial recognition? Join the Insane Clown Posse
Elderly scam victims are too embarrassed to speak up
Samsung phones sending photos to contacts without permission
Going on vacation? Five things to do before you leave

You’ve set up an out-of-office auto-responder and packed your stuff, but have you done all of your “homework” before you rush out the front door for that well-deserved time off? The post Going on vacation? Five things to do before you leave appeared first on WeLiveSecurity

Facebook accidentally unblocks people
Someone else is reading your Gmails
Bill Clinton’s cyber-attack novel: The airport haxploit-blockbuster you knew it would be
NHS Developer Error Leads to Data Leak
Ransomware: Not dead, just getting a lot sneakier
‘Plane Hacker’ Roberts: I put a network sniffer on my truck to see what it was sharing. Holy crap!
Huawei enterprise comms kit has a TLS crypto bug
Hands up if you didn’t lose data in the Typeform breach

LinuxSecurity.com: Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program. For the stable distribution (stretch), this problem has been fixed in

LinuxSecurity.com: Several vulnerabilites have been discovered in Exiv2, a C++ library and a command line utility to manage image metadata which could result in denial of service or the execution of arbitrary code if a malformed file is parsed.

Samsung Investigates Claims of Spontaneous Texting of Images to Contacts

LinuxSecurity.com: libsoup could be made to crash if it received a specially crafted input.

LinuxSecurity.com: Two vulnerabilities affecting the cups printing server were found which can lead to arbitrary IPP command execution and denial of service.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2001

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1997

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1979

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1965

Four US govt agencies poke probe in Facebook following more ‘oops, we spilled your data’ shocks
More Federal Agencies Wrapped Up in Facebook Data Privacy Probe
Google Chrome update to label HTTP-only sites insecure within WEEKS
Typeform data breach exposes users of many websites
Tool scrubs hidden tracking data from printed documents
Immigrant identity thief and ICE lawyer gets four years
Britain’s tax authority reports takedown of record 20,000 fake sites

Her Majesty’s Revenue & Customs (HMRC) is “consistently the most abused government brand”, according to the National Cyber Security Centre (NCSC) The post Britain’s tax authority reports takedown of record 20,000 fake sites appeared first on WeLiveSecurity

HMRC: 29% Increase in Malicious Site Deactivations
Two-Fifths of UK CEOs See Cyber-Attacks as Inevitable
The difference between red team engagements and vulnerability assessments | Salted Hash Ep 34
‘Coding’ cockup blamed for NHS cough-up of confidential info against patients’ wishes
Facebook gave certain companies special access to customer data
Typeform data breach hits thousands of survey accounts
Budget hotel chain, UK political party, Monzo Bank, Patreon caught in Typeform database hack
Smash-hit game Fortnite is dangerous… for cheaters: Tools found laced with malware

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Quick look your right eyes and ears while using public WiFi network
Cryptocurrency users on Discord & Slack hit by MacOS malware

LinuxSecurity.com: libvirt: Resource exhaustion via qemuMonitorIORead() method (CVE-2018-5748) * libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent (CVE-2018-1064) SL6 x86_64 libvirt-0.10.2-64.el6.x86_64.rpm libvirt-client-0.10.2-64.el6.i686.rpm libvirt-client-0.10.2-64.el6.x86_64.rpm libvirt-debuginfo-0.10.2-64.el6.i686.rpm libvirt-debuginfo-0.10.2-64.el6.x86_64.rpm [More…]

LinuxSecurity.com: glibc: Buffer overflow in glob with GLOB_TILDE (CVE-2017-15670) * glibc: Buffer overflow during unescaping of user names with the ~ operator (CVE-2017-15804) SL6 x86_64 glibc-2.12-1.212.el6.i686.rpm glibc-2.12-1.212.el6.x86_64.rpm glibc-common-2.12-1.212.el6.x86_64.rpm glibc-debuginfo-2.12-1.212.el6.i686.rpm glibc-debuginfo-2.12-1.212.el6.x86_64.rpm glibc-debuginfo- [More…]

LinuxSecurity.com: samba: Null pointer indirection in printer server process (CVE-2018-1050) SL6 x86_64 libsmbclient-3.6.23-51.el6.i686.rpm libsmbclient-3.6.23-51.el6.x86_64.rpm samba-client-3.6.23-51.el6.x86_64.rpm samba-common-3.6.23-51.el6.i686.rpm samba-common-3.6.23-51.el6.x86_64.rpm samba-debuginfo-3.6.23-51.el6.i686.rpm samba-debuginfo-3.6.23-51.el6.x86_64.rpm samba-winb [More…]

LinuxSecurity.com: zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c (CVE-2018-1083) * zsh: buffer overflow when scanning very long directory paths for symbolic links (CVE-2014-10072) * zsh: buffer overrun in symlinks (CVE-2017-18206) * zsh: buffer overflow in utils.c:checkmailpath() can lead to local arbitrary code execution (CVE-2018-1100) SL6 x86_64 zsh-4.3.11-8.el6.x86_64.rpm [More…]

Risk Level: Very Low.

Fake Bitcoin exchange traps drug dealers on the dark web
Dr Symantec offers quick and painless checkup for VPNFilter menace on routers
Android devices since 2012 vulnerable to RAMpage vulnerability
The principle of least privilege: A strategy of limiting access to what is essential

The principle of least privilege is a security strategy applicable to different areas, which is based on the idea of only granting those permissions that are necessary for the performance of a certain activity The post The principle of least privilege: A strategy of limiting access to what is essential appeared first on WeLiveSecurity

Phishing Cited by SMBs as Top Attack Threat
Natural Language Processing Fights Social Engineers
Brave adds Tor to reinvent anonymous browsing
Second former Equifax staffer charged with insider trading
Boffins want to stop Network Time Protocol’s time-travelling exploits
Surveys-as-a-service outfit Typeform spilled a backup in May

security update

Bug Bounty Programs Turn Attention to Data Abuse
MacOS Malware Targets Cryptocurrency Community on Slack, Discord
Hackers steal millions of customers’ data from Adidas US website
Adidas US Website Hit by Data Breach
The 6 Worst Insider Attacks of 2018 – So Far

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes is now available.

Gentoo Linux on Github hacked; repositories modified
Ticketmaster Breach Discovered in April, Says Bank
Cyber-Attacks Caused 18 Days of NHS Downtime
Rowhammer returns, Spectre fix unfixed, Wireguard makes a new friend, and much more

LinuxSecurity.com: CVE-2017-7651 fix to avoid extraordinary memory consumption by crafted CONNECT packet from unauthenticated client

LinuxSecurity.com: CVE-2017-12872 / CVE-2017-12868 The (1) Htpasswd authentication source in the authcrypt module and (2)

LinuxSecurity.com: An update that fixes one vulnerability is now available.

And that’s now all three LTE protocol layers with annoying security flaws
Worse than Equifax: Personal records of 340M people leaked online
EFF Sues to Repeal Controversial Online Sex Trafficking FOSTA Law