Menu

Latest articles

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: The system could be made to expose sensitive information.

Victoria’s educational apps-for-students let creeps contact kids

LinuxSecurity.com: Side channel execution mitigations were added to QEMU.

security update

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Microsoft, Google: We’ve found a fourth data-leaking Meltdown-Spectre CPU hole
Multilingual malware hits Android devices for phishing & cryptomining

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in privilege escalation.

Facebook conspiracy theories after Android app tries to “get root”
Penetration tester pokes six holes in Dell EMC’s RecoverPoint products
High-end router flinger DrayTek admits to zero day in bunch of Vigor kit
See me speak at the Sunny Side Up Security breakfast event in London next month
Wicked Botnet Uses Passel of Exploits to Target IoT
Greenwich uni fined £120k: Hole in computing school site leaked 20k people’s data
Best Security Podcast: “Smashing Security” up for top award
Cybersecurity training still neglected by many employers

While training employees will not guarantee complete cyber safety for companies, it could go a long way to making workers more cyber-aware The post Cybersecurity training still neglected by many employers appeared first on WeLiveSecurity

Real-time cellphone location data leaked for all major US carriers
Chrome drops ‘secure’ label for HTTPS websites
Syrian Electronic Army Members Indicted for Conspiracy

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

You are not alone; The Pirate Bay is down around the world

LinuxSecurity.com: The package libcurl-gnutls before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package libcurl-compat before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package lib32-libcurl-compat before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package lib32-curl before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Someone hacked California’s live congressional debate to run gay porn

Advance notification for upcoming end-of-life for Debian 8

security update

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1414

Hurdles Remain After Senate Votes To Restore Net Neutrality
Latin American ‘Biñeros’ Bond Over Fraudulent Purchase Scheme
WiFi hacker- 10 best Android & Desktop WiFi hacking apps free download
Tech Talk: As GDPR looms, companies rush to comply
2018: Scariest Year of Evil Things on the Internet
California Teen Arrested for Phishing Teachers to Change Grades

LinuxSecurity.com: Security update for CVE-2017-17723, CVE-2017-17725, CVE-2018-5772

LinuxSecurity.com: Security update for CVE-2017-17723, CVE-2017-17725, CVE-2018-5772

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Misconfigured Reverse Proxy Servers Spill Credentials
RedDawn Espionage Campaign Shows Mobile APTs on the Rise
BYOD Threats Exposed: 61% of UK SMEs Suffer Cyber-Attacks
New Research Seeks to Shorten Attack Dwell Time
Signal bugs, car hack antics, the Adobe flaw you may have missed, and much more

security update

Threatpost News Wrap Podcast for May 18

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Updated collectd packages are now available for Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of

LinuxSecurity.com: An update for sensu is now available for Red Hat OpenStack Platform 10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Hans Jerry Illikainen discovered a type conversion vulnerability in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played.

Tracking firm caught leaking realtime location data of US Mobile users
TeleGrab Malware Steals Telegram Desktop Messaging Sessions, Steam Credentials
Critical Linux Flaw Opens the Door to Full Root Access
WinstarNssmMiner Monero mining malware crashes PC upon detection
Suspected Syrian Electronic Army hackers indicted for conspiracy and identity theft
Senate votes to restore net neutrality… but don’t get your hopes up
Open source code is ubiquitous and so are many vulnerabilities

One-third of audited codebases that contain Apache Struts suffer from the same vulnerability that facilitated the Equifax hack a year ago The post Open source code is ubiquitous and so are many vulnerabilities appeared first on WeLiveSecurity

ZipperDown catches 170,000 iOS apps with their pants down
DHS Unveils National Cybersecurity Risk Strategy
IT Pros Worried About IoT But Not Prepared to Secure It
Tech Talk: Prepping for GDPR
Don’t invest! The ICO scam that doesn’t want your money

LinuxSecurity.com: The package curl before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.

Man faces up to 35 years in prison for helping hackers evade detection by anti-virus software

Reading Time: ~2 min.Chili’s Restaurant Reveals Payment Card Breach In the last week, officials have discovered a data breach that affects an unknown number of the chain’s 1,600 restaurants across the country. It is believed that the breach could affect customers who visited the restaurant between March and April of this year, and likely includes […]

LocationDumb: Phone tracker foul-up exposes world+dog to tracking
Meet MEWKit, a tricky phishing attack draining Ethereum wallets

security update

LinuxSecurity.com: The package zathura-pdf-mupdf before version 0.3.3-3 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Fake Fortnite Apps for Android Spread Spyware, Cryptominers
‘Voice-Squatting’ Turns Alexa, Google Home into Silent Spies

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5 and Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5 and Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The package runc before version 1.0.0rc5+19+g69663f0b-1 is vulnerable to privilege escalation.

LinuxSecurity.com: An update is now available for Red Hat JBoss Data Grid. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Securus firm that lets US Cops track cellphone users has been hacked
Cisco Warns of Three Critical Bugs in Digital Network Architecture Platform
One Year After WannaCry: A Fundamentally Changed Threat Landscape
The Dark Overlord: Suspected hacking group member arrested in Serbia
Podcast: The Evolution of Deception Technology
RIG EK Still Makes Waves, This Time with a Stealthy Backdoor
Phishing Spy Campaign Targets Top Mideast Officials
Mexico’s Banking System Sees $18M Siphoned Off in Phantom Transactions
Biometrics: Better than your mother’s maiden name. Good luck changing your body if your info is stolen

LinuxSecurity.com: New upstream bugfix release, includes security fix for CVE-2017-18266

Suspected member of The Dark Overlord arrested in Serbia

The Dark Overlord, known for a number of breaches and cyber-extortion campaigns in the last two years, is believed to have made US$275,000 from various schemes The post Suspected member of The Dark Overlord arrested in Serbia appeared first on WeLiveSecurity