Menu

Latest articles

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Paris Hilton’s hacker sentenced to 57 months in prison
Severe Keyboard Flaws in LG Smartphones Allow Remote Code Execution
Patch now! Microsoft and Adobe release critical security updates
Georgia Governor Vetoes Controversial Hack-Back Bill
Smashing Security #077: Why Paris Hilton doesn’t use iCloud, lottery hacking, and Facebook dating
Inside fake Interac transfer and tax refund SMS phishing

It’s tax season in Canada and scammers are using fake tax refund forms to lure victims into supplying their personal information via phishing pages The post Inside fake Interac transfer and tax refund SMS phishing appeared first on WeLiveSecurity

Spyware uses malicious adult games to infect Android & Window devices
Drupe app removed from Google Play store after photos and messages leaked publicly
Critical bug in 7-Zip – make sure you’re up to date!
Trial set for Latvian accused of running malware operation
Equifax Update Clarifies Breach Details to SEC
Uber car software detected woman before fatal crash but failed to stop
Mingis on Tech: Reflections on RSA 2018
Google cracks down on election meddling advertisers
Could this be the end of password re-use?
Cryptomining with JavaScript in an Excel spreadsheet
Every major OS maker misread Intel’s docs. Now their kernels can be hijacked or crashed
Second wave of Spectre-like CPU security flaws won’t be fixed for a while
Mirai botnet cost you $13.50 per infected thing, say boffins

LinuxSecurity.com: On May 8, fixes for CVE-2018-1087 and CVE-2018-8897 were released in linuxkernel version 4.4.0-124.148. These CVEs are both related to the way thatthe linux kernel handles certain interrupt and exception instructions. Ifan interrupt or exception instruction (INT3, SYSCALL, etc.) is immediatelypreceded by a MOV SS or POP SS instruction, the resulting interrupt will [More…]

It’s 2018, and a webpage can still pwn your Windows PC – and apps can escape Hyper-V

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Red Hat smitten by secure enclaves ‘cos some sysadmins are evil
Copenhagen city’s bicycle sharing system hacked; 1,800 bikes affected
May Patch Tuesday Fixes Two Bugs Under Active Attack
Sierra Wireless Patches Critical Vulns in Range of Wireless Routers
NSA sought data on 534 MILLION phone calls in 2017
Russian hackers sent death threats to US army wives posing as ISIS: Report

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low.

Risk Level: Very Low. Type: Worm.

Adobe Patches Critical Bugs In Flash Player, Creative Cloud
“Equi-Facts”: Equifax Clarifies the Numbers for Its Massive Breach
FBI: Cyber-Fraud Losses Rise to Reach $1.4B
400 popular Drupal based websites hacked to mine cryptocurrency
Bad guys have something new to play with! Microsoft Excel adds support for JavaScript
Pentagon orders military exchanges to pull Chinese smartphones over security risks
Most Industrial Networks Vulnerable to Attack
Budget Android manufacturer Blu settles with FTC over privacy fiasco

LinuxSecurity.com: Harry Sintonen discovered that wget, a network utility to retrieve files from the web, does not properly handle ‘rn’ from continuation lines while parsing the Set-Cookie HTTP header. A malicious web server could use this flaw to inject arbitrary cookies to the cookie jar file, adding

The Man on the Train: Caught with his phishing loot
Cloud security: The skills gap is delaying cloud migration
Countdown to the GDPR deadline: Are you ready? | Salted Hash Ep 28
Tuesday review – the hot 21 stories of the week
Equifax reveals full horror of that monstrous cyber-heist of its servers
Android P to improve users’ network privacy

security update

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.

Hacking charge dropped against Nova Scotia teen who slurped public records from the web
Download Kali Linux 2018.2 with new security features

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

That Drupal bug you were told to patch weeks ago? Cryptominers hope you haven’t bothered
Romanian Hackers Extradited to U.S. over $18M Vishing Scam
Variant of SynAck Malware Adopts Doppelgänging Technique

LinuxSecurity.com: Several security issues were fixed in the kernel.

Reading Time: ~3 min.As the EU’s General Data Protection Regulation (GDPR) edges closer, we’re looking back on the five most significant stories during the lead up to its implementation. Read about GDPR’s impact on data security and find out how to get prepared with five steps to compliance. What aspect of GDPR will have the […]

Asylo Open-Source Framework Tackles TEEs for Cloud
Cryptojacking Campaign Exploits Drupal Bug, Over 400 Websites Attacked
Cyberwar: Greek & Turkish hackers target each other’s media outlets
Lenovo Patches Arbitrary Code Execution Flaw
Tech support scams and the call of the void

The importance of providing the best possible after-sales service to customers The post Tech support scams and the call of the void appeared first on WeLiveSecurity

Report: China’s Intelligence Apparatus Linked to Previously Unconnected Threat Groups
Linux Kernel Hardens Sound Drivers Against Spectre V1 Vulnerability
Password re-use is dangerous, right? So what about stopping it with password-sharing?
Russia blocks 50 VPNs & Anonymizers amid Telegram crack down

security update

LinuxSecurity.com: An XML external entity expansion vulnerability was discovered in the DataImportHandler of Solr, a search server based on Lucene, which could result in information disclosure.

Abbott to fix critical vulnerabilities in 350,000 ICDs & Pacemakers
Vulnerabilities on the Rise?
A GEORGIA HACKING BILL GETS CYBERSECURITY ALL WRONG
Man hacked 200 firms & sold data of millions of users on dark web

LinuxSecurity.com: – fix stack-based buffer overflow in utils.c:checkmailpath() (CVE-2018-1100) – fix stack-based buffer overflow in gen_matches_files() (CVE-2018-1083) – fix stack-based buffer overflow in exec.c:hashcmd() (CVE-2018-1071)

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.