Menu

Latest articles

LinuxSecurity.com: Several vulnerabilities were discovered in qemu, a fast processor emulator. CVE-2017-15038

Fraudsters Claim To Hack Two Canadian Banks

LinuxSecurity.com: Etienne Stalmans discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability exploitable via specially crafted submodule names in a .gitmodules file.

SEVered Attack Extracts the Memory of AMD-Encrypted VMs

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1726

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1669

Sonic Tone Attacks Damage Hard Disk Drives, Crashes OS

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Google Patches reCAPTCHA Bypass
GCHQ bod tells privacy advocates: Most of our work is making sure we operate within the law
Brazilian Banking Trojan Communicates Via Microsoft SQL Server
Hackers demand $1m ransom after stealing data from 2 Canadian banks
Despite Ringeader’s Arrest, Cobalt Group Still Active
BCC is hard, OK? Quite a lot of orgs blurted your email addresses in GDPR mailouts

LinuxSecurity.com: Batik could be made to expose sensitive information if it received a specially crafted XML.

UNICEF now using cryptocurrency mining for fundraising

So far in 2018, the NGO has launched two charity campaigns with the aim of raising funds through cryptocurrency mining. The post UNICEF now using cryptocurrency mining for fundraising appeared first on WeLiveSecurity

Are your Android apps sending unencrypted data?
Wayback Machine ‘unarchives’ spying website
Watch thieves steal keyless Mercedes within 23 seconds
Your Firefox account can now be secured with 2FA
Papua New Guinea to ban Facebook for a month
Inside Microsoft’s Azure Sphere hardware for secure IoT
Ex-staffer of UK.gov dept bags payout after boss blabbed medical info to colleagues
Two Canadian banks warn attackers may have stolen customer data

Simplii Financial and Bank of Montreal are believed to have suffered a twin attack that was soon followed by blackmail threats The post Two Canadian banks warn attackers may have stolen customer data appeared first on WeLiveSecurity

ISP popped router ports, saving customers the trouble of making themselves hackable
Softbank’s ‘Pepper’ robot is a security joke
10 years prison for man who hacked 200 firms & sold data on Dark Web

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Scammers raid man’s bank account while he waits on hold to fraud hotline

Criminals have set their sights on customers of a bank that has been struggling with a switchover to a new computer platform The post Scammers raid man’s bank account while he waits on hold to fraud hotline appeared first on WeLiveSecurity

Singapore ISP Leaves 1,000 Routers Open to Attack
This Chrome extension reveals if your password has been breached
Man arrested for possession of 58 terabytes of child sexual abuse material

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

Privacy International Launches GDPR Probe into Data Companies
Clear Linux Exploring Support For Windows WSL
GDPR latest: Fraudsters posing as banks in data protection emails phishing scam
One in Three HCOs Hit by Cyber-Attack
Hacker jailed for selling personal data on dark web

Grant West used popular food app Just Eat to gain access to thousands of emails and passwords The post Hacker jailed for selling personal data on dark web appeared first on WeLiveSecurity

FBI to World+Dog: Please, try turning it off and turning it back on
15 years prison for man who hired attackers to DDoS his ex-employer
Starbucks site slurped, Z-Wave locks clocked, mad Mac Monero mining malware and much more
Cola-Cola breach: ex-employee stole hard drive with 8,000 workers’ data
GDPR Oddsmakers: Who, Where, When Will Enforcement Hit First?
Xenotime Attack Group Expands Activity
Ghostery’s goofy GDPR gaffe – someone’s in trouble come Monday!

LinuxSecurity.com: CVE-2017-18248 It was found that by submitting a print job with an invalid username, the CUPS server can be crashed, when D-Bus support is enabled (which

FBI: Protect yourself from VPNFilter malware; reboot your router now

LinuxSecurity.com: Security fix for CVE-2018-10536 CVE-2018-10537 CVE-2018-10538 CVE-2018-10539 CVE-2018-10540

security update

New cryptojacking malware hits Mac devices
Hackers deface Airport screens in Iran with anti-government messages
Starbucks site slurped, Comcast keys clocked, mad Mac Monero mining malware and much more

LinuxSecurity.com: The gitlab security update announced as DSA-4206-1 caused regressions when creating merge requests (returning 500 Internal Server Errors) due to an issue in the patch to address CVE-2017-0920. Updated packages are now available to correct this issue.

Most Expensive Data Breaches Start with Third Parties: Report
Report: Hacker group behind Trisis Malware expanding Activity in Middle East

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Ming: CVE-2018-7866

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Gabriel Corona discovered that xdg-utils, a set of tools for desktop environment integration, is vulnerable to argument injection attacks. If the environment variable BROWSER in the victim host has a “%s” and the victim opens a link crafted by an attacker with xdg-open, the malicious

Epyc fail? We can defeat AMD’s virtual machine encryption, say boffins

Type: Vulnerability. Adobe Acrobat and Reader are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to an arbitrary code-execution vulnerability; fixes are available.

Millions of IoT Devices Vulnerable to Z-Wave Downgrade Attacks, Researchers Claim
Pet Trackers Open to MITM Attacks, Interception
Hundreds of Android devices shipped with pre-installed malware

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.