Menu

Latest articles

City of London Police Takes Cybercrime Fight to Businesses
A Quarter of UK CNI Firms Have Suffered Cyber-Attack Outages
Firefox isn’t adding ads, it’s ‘sponsored content’

LinuxSecurity.com: Update to 1.8.8

North Korea’s antivirus software whitelisted mystery malware

LinuxSecurity.com: Red Hat Mobile Application Platform 4.6.0 Release – Container Images 2. Description: Red Hat Mobile Application Platform (RHMAP) 4.6.0 consists of three main components:

AWS sends noise to Signal: You can’t use our servers to beat censors
Scammers using Google Maps to skirt link-shortener crackdown
A cryptocurrency platform exposed sensitive data of 25,000 users
Millions of Home Fiber Routers Vulnerable to Complete Takeover
Samples of SiliVaccine Offer Rare Peek Inside North Korea’s Antivirus Software
Volkswagen Cars Open To Remote Hacking, Researchers Warn

Risk Level: Very Low. Type: Trojan, Worm.

Google Maps open redirect flaw abused by scammers
Twitter sold user data to Cambridge Analytica’s Aleksandr Kogan
Surveillance watchdog learns that old domains never die
Tens of Thousands of Malicious Apps Using Facebook APIs
Researchers find critical security flaws in popular car models
The hacker who broke into jail and had to stay for 7 years
GravityRAT malware evades detection and targets users in India
Controlling children’s use of technology: a preventive measure or an invasion of privacy?

How to use parental control apps to protect children and the fine line that exists between controlling the use of technology and invasion of privacy The post Controlling children’s use of technology: a preventive measure or an invasion of privacy? appeared first on WeLiveSecurity

Cyber Security Breaches Survey 2018
North Korea Ramps Up ‘Operation GhostSecret’ Cyber Espionage Campaign
Defending against mobile technology threats | Salted Hash Ep 24

Reading Time: ~3 min.Text messages are now a common way for people to engage with brands and services, with many now preferring texts over email. But today’s scammers have taken a liking to text messages or smishing, too, and are now targeting victims with text message scams sent via shortcodes instead of traditional email-based phishing […]

Bitcoin hijackers found at least one sucker for scam Chrome extension
USB Sticks Can Trigger BSOD – Even on a Locked Device
KRACK Vulnerability Puts Medical Devices At Risk
Failbreak: Bloke gets seven years in the clink for trying to hack his friend out of jail
Someone hacked this highway sign & defaced it with “Hail Hitler” text
Updated GravityRAT Malware Adds Advanced AV Detection
Brit healthcare system inks Windows 10 install pact with Microsoft
Firewalls: What They Are & Why You Need Them
NIST Updates Cybersecurity Framework to Tackle Supply Chain Threats, Vulnerability Disclosure and More
Online poker site bombarded by DDoS attacks, pauses tournaments
Twitter Sold Data To Cambridge Analytica-Linked Company
Man jailed for hacking County jail’s records to get friend released early
This test will tell you how likely you are to fall for fraud

The questionnaire measures a range of personality traits to distinguish people who are more prone to taking the bait than others. The post This test will tell you how likely you are to fall for fraud appeared first on WeLiveSecurity

Hacker who almost sprung a prisoner out of jail is himself imprisoned for seven years
Google adds SSO verification check to G Suite
YouTube snags millions of bad videos, but is it getting the right ones?

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

DNA in genealogy database leads to arrest of suspected serial killer
No, Mark Zuckerberg isn’t messaging you about winning a Facebook lottery
Cloud Misconceptions Are Pervasive Across Enterprises
Why Hackers Love Healthcare
GDPR may well kill enterprise blockchain databases

LinuxSecurity.com: An update for openvswitch is now available for Fast Datapath for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Thailand seizes server linked to North Korean attack gang

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.4. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Umm, Oracle – about that patch? It might not be very sticky …

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Serious vulnerabilities were found in the libvorbis library, commonly used to encode and decode audio in OGG containers. 2017-14633

LinuxSecurity.com: Security fix for [CVE-2018-10194](https://access.redhat.com/security/cve/cve-2018-10194).

LinuxSecurity.com: Updated Boost libraries are available that fix compatibility with CUDA 9.x compilers and fix a possible integer overflow in Boost.Regex.

LinuxSecurity.com: Information leak via crafted user-supplied CDROM [XSA-258] (#1571867) x86: PV guest may crash Xen with XPTI [XSA-259] (#1571878)

LinuxSecurity.com: Security fix for CVE-2018-1088 (Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled)

security update

security update

security update

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.1. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

How to Transfer Data from Android to iPhone
Should we open source election software?
Despite Risks, Nearly Half of IT Execs Don’t Rethink Cybersecurity after an Attack

LinuxSecurity.com: This is an update to the latest upstream release, which disables the UDP port by default (CVE-2018-1000115).

LinuxSecurity.com: It was discovered that gunicorn, an event-based HTTP/WSGI server was susceptible to HTTP Response splitting. For the oldstable distribution (jessie), this problem has been fixed

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, execution of arbitrary code or bypass of JAR signature validation.

LinuxSecurity.com: CVE-2018-7033 An issue that could be used for SQL Injection attacks against SlurmDBD has been fixed.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the image loading library for Simple DirectMedia Layer 1.2, which could result in denial of service or the execution of arbitrary code if malformed image files are opened.

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

New Phishing Attack Targets 550M Email Users Worldwide
Most federal IT contractors don’t protect emails from fraud
Windows USB-stick-of-death, router bugs resurrected, and more

LinuxSecurity.com: It has been discovered that Tor, a connection-based low-latency anonymous communication system, contains a protocol-list handling bug that could be used to remotely crash directory authorities with a null-pointer exception (TROVE-2018-001).

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2018-6056

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

security update

LinuxSecurity.com: This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. — https://www.genivia.com/advisory.html

LinuxSecurity.com: The v4.16.4 update contains fixes across the tree

LinuxSecurity.com: Update to newer release of Tika including security fixes for CVE-2016-4434 and CVE-2016-6809.

LinuxSecurity.com: New upstream release – This release fixes CVE-2018-1106 which is a moderate security issue.

LinuxSecurity.com: Security fix for [CVE-2018-10194](https://access.redhat.com/security/cve/cve-2018-10194).

LinuxSecurity.com: Rebase to qpdf-7.1.1 because of CVEs

LinuxSecurity.com: Rebase to qpdf-7.1.1 because of CVEs

LinuxSecurity.com: This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. — https://www.genivia.com/advisory.html

Ozzie Ozzie Ozzie, oi oi oi! Tech zillionaire Ray’s backdoor crypto for the Feds is Clipper chip v2
SamSam Ransomware Evolves Its Tactics Towards Targeting Whole Companies
What is tar and why does OpenShift Container Application Platform use it?

LinuxSecurity.com: A remote code execution vulnerability has been found within multiple subsystems of Drupal. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised.

Uber Tightens Bug Bounty Extortion Policies
Man bought mail bomb from dark web (Alpha Bay market) to kill ex-wife
Ex-NSA staffer creates app to notify users of evil maid attack on MacBook
ThaiCERT Seizes Hidden Cobra Server Linked to GhostSecret, Sony Attacks
Flawed routers with hardcoded passwords were manufactured by firm that posed ‘national security risk’ to UK
High Court gives UK.gov six months to make the Snooper’s Charter lawful
“SamSam” ransomware – a mean old dog with a nasty new trick

Reading Time: ~2 min.Two big trends stood out at RSAC 2018. Many organizations that once thought all threat intelligence was created equal have gained appreciation for quality data feeds that deliver real-time information vs. crowdsourced or static lists. Endless alerts and flashy numbers are no longer enough. Companies want to know the “why?” and “what […]