Menu

Latest articles

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions or unsafe redirects. More information can be found in the upstream advisory at

security update

LinuxSecurity.com: – https://www.drupal.org/project/drupal/releases/7.59 – https://www.drupal.org/SA-CORE-2018-004

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Red Hat Single Sign-On 7.2.2 is now available for download from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: It was found that the Quassel IRC client was vulnerable to a remote code execution vulnerability due to insufficient checks in the deserializer code.

Android users hit by ZooPark malware stealing data & recording calls
Security Holes Make Home Routers Vulnerable
Hackers Leverage GDPR to Target Airbnb Customers

LinuxSecurity.com: This update includes the changes in tzdata 2018e for the Perl bindings. For the list of changes, see DLA-1371-1. For Debian 7 “Wheezy”, these problems have been fixed in version

LinuxSecurity.com: This update includes the changes in tzdata 2018e. Notable changes are: – North Korea switches back to +09 on 2018-05-05.

Serious Security: The GLitch “row hammering” attack
Cookie code compromise caper caught and crumbled

LinuxSecurity.com: Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Report: Intel Facing New Spectre-Like Security Flaws
Pr0nbot is Back – and Evading Twitter Censors
Abbott Addresses Life-Threatening Flaw in a Half-Million Pacemakers
Breakthrough pushes Quantum Key Distribution beyond 500km
Anti-theft software LoJack hijacked by Russian Fancy Bear group
The Pentagon bans Huawei and ZTE smartphone sales at military bases worldwide
A bug stored Twitter passwords in plain text so change your password
Twitter advises all users to change passwords after glitch

A bug exposed the passwords of an undisclosed number of users in plain text within Twitter’s internal systems The post Twitter advises all users to change passwords after glitch appeared first on WeLiveSecurity

Tech companies resist government hacking back and backdoors
What to do after a data breach: 5 steps to minimize risk
UK Phisher Pleads Guilty to Just Eat Scam
Yes, you should change your Twitter password – but don’t panic
Half a million pacemakers need a security patch
How to secure SaaS: Understanding the cloud’s security layers
Google rolls out .app domains with built-in HTTPS

The move is part of the company’s HTTPS-everywhere vision for the internet The post Google rolls out .app domains with built-in HTTPS appeared first on WeLiveSecurity

Penetrate the mind of the cyber criminal at SANS London July 2018

Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Cyberattack Shuts Down Mexico Central Bank Within the past week, several payment systems associated […]

Twitter admits to password storage blunder – change your password now!

Reading Time: ~1 min.Our most recent release of the DNS Protection agent provided customers with added features and enhancements designed to improve the overall product experience and its capabilities delivered to end users. We revamped the network detection functionality to improve accuracy and speed for roaming and off-site clients who frequently change networks. We also […]

Fresh fright of data-spilling Spectre CPU design flaws haunt Intel
It’s World (Terrible) Password (Advice) Day!
4chan hackers tried changing voting results of NASA student challenge
Twitter Urges Users to Change Passwords Due to Glitch
European Space Agency wants in on quantum comms satellites
Twitter: No big deal, but everyone needs to change their password

security update

Hurry up patching those Oracle bugs: Attackers aren’t waiting
MassMiner Takes a Kitchen-Sink Approach to Cryptomining
Phone Maker BLU Settles with FTC Over Unauthorized User Data Extraction
A Look Inside: Bug Bounties and Pen Testing

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Kitty Cryptomining Malware Cashes in on Drupalgeddon 2.0
Scammers bought Twitter ads to run verified badge phishing scam
Facebook’s getting a clear history button
Critical Cisco WebEx Bug Allows Remote Code Execution
Google and Amazon put an end to censorship-dodging domain fronting
Kitty malware gets its claws into Drupal websites to mine Monero
Poker tournaments disrupted after DDoS attacks on Americas Cardroom

LinuxSecurity.com: It was discovered that jackson-databind, a Java library used to parse JSON and other data formats, improperly validated user input prior to deserializing because of an incomplete fix for CVE-2017-7525.

Using Docker and Windows Server Containers? There’s a patch for that
Firms running Cisco WebEx are told to update their software… again!

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

Recycling is a must, but why would you reuse your password?

World Password Day, celebrated on the first Thursday of every May, is a timely reminder of the fact that our passwords are the key to a wealth of personal information about us. The post Recycling is a must, but why would you reuse your password? appeared first on WeLiveSecurity

Free Speech Advocates Blast Amazon Over Threats Against Signal
Facebook fires engineer accused of stalking women
Fedora 28 “Cutting Edge” Linux Distro Released With New Features
A critical security flaw in popular industrial software put power plants at risk
Boutique Shops Offering Rewards Points Pop Up on the Dark Web

LinuxSecurity.com: An update for rh-php70-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for go-toolset-7 and go-toolset-7-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Quit WebEx now if you want to live! (Bad bugs, not killer slideware)
Goodbye Cambridge Analytica, hello Emerdata?
Oracle Access Manager is a terrible doorman: Get patching this bug

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: A buffer overflow in Python might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability was discovered in hesiod which may allow remote attackers to gain root privileges.

LinuxSecurity.com: Two vulnerabilities were found in the Quassel IRC client, which could result in the execution of arbitrary code or denial of service. Note that you need to restart the ‘quasselcore’ service after upgrading

Smashing Security #076: Spying phones, hacked ski lifts, and World Password Day

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

security update

security update

Hacktivists, Tech Giants Protest Georgia’s ‘Hack-Back’ Bill
Fancy that, Fancy Bear: LoJack anti-laptop theft tool caught phoning home to the Kremlin

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

What’s so special about the SamSam ransomware? [VIDEO]
Medical devices vulnerable to KRACK Wi-Fi attacks
FacexWorm malware steals cryptocurrency & Facebook credentials
Facebook Introduces ‘Clear History’ Option Amid Data Scandal
Vlad that’s over: Remote code flaws in Schneider Electric apps whacked
Schneider Electric Patches Critical RCE Vulnerability
Hands off! Arm pitches tamper-resistant Cortex-M35-P CPU cores

LinuxSecurity.com: An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

Volkswagen and Audi car infotainment systems hacked remotely

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Virtualization 4 Management Agent for RHEL 7 and Red Hat Virtualization Manager 4.1. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

WiFi or Ethernet: Which is faster and which is safer?

There is a lot of debate about WiFi speeds and whether they can offer higher potential speeds than a cable connection, but in practice Ethernet connections turn out to be not only faster but also safer. The post WiFi or Ethernet: Which is faster and which is safer? appeared first on WeLiveSecurity