Menu

Latest articles

security update

LinuxSecurity.com: It was discovered that Wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for PCP, ADB, NBAP, UMTS MAC, IEEE 802.11, SIGCOMP, LDSS, GSM A DTAP and Q.931, which result in denial of service or the execution of arbitrary code.

LinuxSecurity.com: The redmine security update announced as DSA-4191-1 caused regressions with multi-value fields while doing queries on project issues due to an bug in the patch to address CVE-2017-15569. Updated packages are now available to correct this issue.

Steam fixes 10-year-old critical remote code execution vulnerability

LinuxSecurity.com: CVE-2016-9396

LinuxSecurity.com: Security fix for CVE-2016-5003, CVE-2016-5002

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1780

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1779

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1777

Ticketfly, Major Concert Venues Still Offline After Hack

LinuxSecurity.com: Man Yue Mo, Lars Krapf and Pierre Ernst discovered that Batik, a toolkit for processing SVG images, did not properly validate its input. This would allow an attacker to cause a denial-of-service, mount cross-site scripting attacks, or access restricted files on the

A Spectre flaw solution, Cloudflare blips, a bank cyber-heist in Canada, and more in infosec land

LinuxSecurity.com: It was discovered that Zookeeper, a service for maintaining configuration information, enforced no authentication/authorisation when a server attempts to join a Zookeeper quorum.

LinuxSecurity.com: New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

Researchers Warn of Microsoft Zero-Day RCE Bug
Browser Side-Channel Flaw De-Anonymizes Facebook Data
Stingray phone stalker tech used near White House, SS7 abused to steal US citizens’ data – just Friday things
Visa card payment network goes down across Europe
Public Google Groups Leaking Sensitive Data at Thousands of Orgs
Sonic & Ultra signals can be used to crash Windows, Linux & hard drives
An acoustic attack can bluescreen your Windows computer

Security researchers have demonstrated how attackers could cause physical damage to hard drives, and cause PCs to crash, just by playing sounds through a computer’s speaker. The post An acoustic attack can bluescreen your Windows computer appeared first on WeLiveSecurity

Trends 2018: Critical infrastructure attacks on the rise

Healthcare sectors, critical manufacturing, food production and transportation also said to be targets for cybercriminals The post Trends 2018: Critical infrastructure attacks on the rise appeared first on WeLiveSecurity

OMG, that’s downright Wicked: Botnet authors twist corpse of Mirai into new threats
Brit bank TSB facepalms at critical mass as users report receiving letters meant for other people
Ticketfly website hacked & offline after hacker leaks customer data
Honda, Universal Music Group Expose Sensitive Data in Misconfig Blunders

LinuxSecurity.com: xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003) SL7 noarch xmlrpc-client-3.1.3-9.el7_5.noarch.rpm xmlrpc-common-3.1.3-9.el7_5.noarch.rpm xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm xmlrpc-server-3.1.3-9.el7_5.noarch.rpm – Scientific Linux Development Team

Your F-35s need spare bits? Computer says we’ll have you sorted in… a couple of years

LinuxSecurity.com: Upstream security fixes related to .gitmodules handling. From the [upstream announcement](https://public-inbox.org/git/xmqqy3g2flb6.fsf@gitster- ct.c.googlers.com/): “` * Submodule “names” come from the untrusted .gitmodules file, but we blindly append them to $GIT_DIR/modules to create our on-disk repo paths. This means you can do bad things by putting “../” into the

Artist rigs up Google Assistant to (sometimes) fire a gun on command

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service. CVE-2018-1093

LinuxSecurity.com: Upstream security fixes related to .gitmodules handling. From the [upstream announcement](https://public-inbox.org/git/xmqqy3g2flb6.fsf@gitster- ct.c.googlers.com/): “` * Submodule “names” come from the untrusted .gitmodules file, but we blindly append them to $GIT_DIR/modules to create our on-disk repo paths. This means you can do bad things by putting “../” into the

Doctor sues patient for $1m over bad online reviews
World Cup scams: how to avoid an own goal

Whether travelling to enjoy the matches in person, or watching from home, fans should be on the lookout for foul play The post World Cup scams: how to avoid an own goal appeared first on WeLiveSecurity

SpamCannibal comes back to life, starts spam-blocking everyone
Europol sets up EU-wide team to fight dark web crime

Embedded within the agency’s European Cybercrime Centre (EC3), the new team will also work together with law enforcement globally in an effort to reduce the size of the underground illegal economy The post Europol sets up EU-wide team to fight dark web crime appeared first on WeLiveSecurity

More curious, less cautious: Protecting kids online

How we can help protect a generation for which digital is the way of the world? The post More curious, less cautious: Protecting kids online appeared first on WeLiveSecurity

An advert against online privacy

Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Mercedes Keyless Entry Leads to Car Theft It was discovered this week that criminals […]

LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.

LinuxSecurity.com: Applications using Oslo middleware could be made to expose sensitiveinformation.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service: CVE-2017-11613

LinuxSecurity.com: The Qualys Research Labs discovered multiple vulnerabilities in procps, a set of command line and full screen utilities for browsing procfs. The Common Vulnerabilities and Exposures project identifies the following problems:

ICANN Launches GDPR Lawsuit to Clarify the Future of WHOIS

LinuxSecurity.com: Several security issues were fixed in libytnef.

LinuxSecurity.com: An update for xmlrpc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Nocturnal Stealer Lets Low-Skilled Cybercrooks Harvest Sensitive Info
Paris Police Arrests Alleged Vevo Hackers
Huawei Patches Four Server Bugs Rated High Severity

LinuxSecurity.com: xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003) SL6 noarch xmlrpc3-client-3.0-4.17.el6_9.noarch.rpm xmlrpc3-common-3.0-4.17.el6_9.noarch.rpm xmlrpc3-client-devel-3.0-4.17.el6_9.noarch.rpm xmlrpc3-common-devel-3.0-4.17.el6_9.noarch.rpm xmlrpc3-javadoc-3.0-4.17.el6_9.noarch.rpm xmlrpc3-server-3.0-4.17.el6_9.noarch.rpm [More…]

We found 1 good reason to get the iOS 11.4 update – rogue message handling
Podcast: How Cities Can Be Security Smart
How to set up 2FA on eBay – go do it now!
These Chrome extensions & Android apps collect your Facebook data
European Commission “doesn’t plan to comply with GDPR” – well, sort of

LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Hoax alert! Starbucks is NOT inviting you to test its shatterproof windows
Apple’s iOS 11.4 security update arrives in an iCloud of silence
Acoustic attacks can blue-screen computers
Nuisance call bosses, get your wallets ready!
Smashing Security #080: Country bans Facebook, eavesdropping Alexa, and PornHub VPN
Court says ‘nyet’ to Kaspersky’s US govt computer ban appeal
Forget VPNfilter – here’s BACKLASH, a networking hack from way, way back
Yahoo hacker involved in 500 million accounts breach jailed for 5 years
Law forcing Feds to get warrants for email slurping is sneaked into US military budget

security update

security update

Bug In Git Opens Developer Systems Up to Attack
Botnet Operators Team Up To Leverage IcedID, Trickbot Trojans
Inmates pirated movies from computers they build with spare parts
Yahoo! merc! hacker! Karim! Baratov! gets! five! years! in! the! clink!

LinuxSecurity.com: Several security issues were fixed in the kernel.

Yahoo Hacker Sentenced; Coke Opens Up a Can of Data Breach
SpamCannibal blacklist service reanimated by squatters, claims every IP address is spammy
Git security vulnerability could lead to an attack of the (repo) clones
Google Patches 34 Browser Bugs in Chrome 67, Adds Spectre Fixes
Multiple Internet-Connected BMW vehicles vulnerable to getting hacked
Hidden Cobra Strikes Again with Custom RAT, SMB Malware

LinuxSecurity.com: Several vulnerabilities have been found in the Apache HTTPD server. CVE-2017-15710

An acoustic attack can blue screen your Windows computer
Jail for the man who helped Russia hack Yahoo’s email accounts
California tests digital license plates. Is tracking cars next?
Despacito YouTube video hack – teenagers charged
An Industry In Transition: Key Tech Trends In 2018
FBI to all router users: Reboot now to neuter Russia’s VPNFilter malware
Facebook to be blocked in Papua New Guinea for one month
Tor exit node admin acquitted of aiding terrorism
Facebook battles tiny startup over privacy accusations
See me speak at the Cloud Security Summit in London
Have you heard about ransomware? Now’s the time to ask: Are you covered?

LinuxSecurity.com: Git contains multiple vulnerabilities that allow for the remote execution of arbitrary code.

FBI fingers North Korea for two malware strains

LinuxSecurity.com: The package strongswan before version 5.6.2-2 is vulnerable to denial of service.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: The package wireshark-cli before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package wireshark-common before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package wireshark-qt before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package wireshark-gtk before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,