Menu

Latest articles

LinuxSecurity.com: OpenJDK: incorrect handling of Reference clones can lead to sandbox bypass (Hotspot, 8192025) (CVE-2018-2814) * OpenJDK: unrestricted deserialization of data from JCEKS key stores (Security, 8189997) (CVE-2018-2794) * OpenJDK: insufficient consistency checks in deserialization of multiple classes (Security, 8189977) (CVE-2018-2795) * OpenJDK: unbounded memory allocation during deserializati [More…]

LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.60, which includes additional changes. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for

Is it time to kill the pen test? | Salted Hash Ep 22
Yahoo! Hacker! Faces! Nearly! Eight! Years! In! Prison!

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

A Facebook malware has compromised thousands of accounts
IoT Security Concerns Peaking – With No End In Sight
Eight months after Equifax megahack, some Brits are only just being notified
Cloud Credentials: New Attack Surface for Old Problem
48 million personal profiles left exposed by data firm LocalBlox
Google in hot water over privacy of Android apps for kids
NSA reveals how it beats 0-days
Chris Vickery Discusses Data Leak of 48 Million Users by Private Intelligence Firm
Excel pivot table data leak leads to £120,000 fine for London council
Use of ‘StegWare’ Increases in Stealth Malware Attacks
Employee from hell busted by VPN logs
RSA 2018: Hacking the grid

The challenges facing critical infrastructure systems The post RSA 2018: Hacking the grid appeared first on WeLiveSecurity

Silence! Chrome hushes noisy autoplaying videos
Rough patch, or how to shut the window of (unpatched) opportunity

Simply throwing more staff at the patching problem won’t cut it, a study suggests. The post Rough patch, or how to shut the window of (unpatched) opportunity appeared first on WeLiveSecurity

Cutting custody snaps too costly for cash-strapped cops – UK.gov
PCI Council releases vastly expanded cards-in-clouds guidance
Facebook’s login-to-other-sites service lets scum slurp your stuff

LinuxSecurity.com: New gd packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New upstream release with security fix for CVE-2018-1084

Flash! Ah-ahhh! WebEx pwned for all of us!

LinuxSecurity.com: Security fix for CVE-2018-1086 and CVE-2018-1079

LinuxSecurity.com: It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities that could result in infinite loops in different dissectors. Other issues are related to crash in dissectors that are

LinuxSecurity.com: Two vulnerabilities were found in OpenCV, the “Open Computer Vision Library”. CVE-2018-5268

How’s your Wednesday? Things going well? OK, your iPhone, iPad can be pwned via Wi-Fi sync
Surprise! Wireless brain implants are not secure, and can be hijacked to kill you or steal thoughts
iOS Sync Glitch Lets Attackers Control Devices
Millions of apps are exposing sensitive & unencrypted user data
Gold Galleon Hacking Group Plunders Shipping Industry
Vlogger loses $2M in cryptocurrency during YouTube live stream
German Government Chooses Open Source For Its Federal Cloud Solution
50,000 Minecraft users infected with hard drive wiping malware
Microsoft built its own custom Linux kernel for its new IoT service
Researcher Billy Rios, Talks Medical Device Security at RSA Conference 2018
Facebook pushes ahead with controversial facial recognition feature in Europe
ID theft in UK hits record high as crooks shift to more vulnerable targets
RSA 2018: Untangling the enterprise security mess

Securely keeping track of data and security applications The post RSA 2018: Untangling the enterprise security mess appeared first on WeLiveSecurity

Nate Cardozo, Attorney with EFF Talks Encryption at RSA Conference 2018
Why ‘remote detonator’ is a bad name for your Wi-Fi network
Russia’s Grizzly Steppe gunning for vulnerable routers

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

Facebook: 3 reasons we’re tracking non-users
Hackers are using botnets to take the hard work out of breaking into networks
Detailing The Idle Loop Ordering Problem & The Power Improvement In Linux 4.17
Casino Gets Hacked Through Its Internet-Connected Fish Tank Thermometer
My letter urging Georgia governor to veto anti-hacking bill
Trends 2018: Democracy hack

Can the electoral processes be protected? The post Trends 2018: Democracy hack appeared first on WeLiveSecurity

NHS given a lashing for lack of action plan one year since WannaCry
Cisco, Microsoft and 32 big vendor pals join ‘Accord’ to improve security by doing … security stuff
Hop to it, bunnies: TaskRabbit breach means new passwords

LinuxSecurity.com: Wojciech Regula discovered an XML External Entity vulnerability in the XML Parser of the mindmap loader in freeplane, a Java program for working with mind maps, resulting in potential information disclosure if a malicious mind map file is opened.

You’re a govt official. You accidentally slap personal info on the web. Quick, blame a kid!

LinuxSecurity.com: Version 2.1.3 (March 5th, 2018) ——————————- **Security fixes** * Attributes that have URI values weren’t properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized. This security issue was introduced in Bleach 2.1. […]

Hey, govt hacker bod. Made some really nasty malware? Don’t be upset if it returns to bite you

security update

Millions of Apps Leak Private User Data Via Leaky Ad SDKs
Woman who hacked airline network busted through VPN logs

security update

Signal app guru Moxie: Facebook is like Exxon. Everyone needs it, everyone despises it
RSAC 2018: Tech Giants Form Cybersecurity Tech Accord
Android malware on Play Store targeting Palestinians on Facebook

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Worm.

US, UK, and Australian governments accuse Russia of targeting networking infrastructure
We ‘could’ send troubled Watchkeeper drones to war, insists UK minister
Over 20 million Chrome users have installed fake malicious Ad Blockers
Traditional firewalls fall short in protecting organizations, says survey
Cryptominer Malware Threats Overtake Ransomware, Report Warns
Automated Bots Growing Tool For Hackers
5 simple tips for better computer security
WhatsApp image showing drug dealer’s fingerprints leads to arrest
Fake or not fake – that is the question

An interview with ESET’s Lukáš Štefanko on the thin line between what deserves the name “security app” and what can be called fake. The post Fake or not fake – that is the question appeared first on WeLiveSecurity

Gmail’s new ‘Confidential Mode’ won’t be completely private
“Privacy is not for sale,” says Telegram founder
Could an Intel chip flaw put your whole computer at risk?
Build up your security credentials at SANS London June 2018
Security Trends to Watch Out for in 2018
Quarterly cybercrime digest: Extraditions and more

As Internet crime knows no borders, mutual legal assistance involving various nations and, by extension, requests for extraditing suspected cyber-offenders are sometimes part and parcel of prosecution efforts. The post Quarterly cybercrime digest: Extraditions and more appeared first on WeLiveSecurity

LinuxSecurity.com: The Citrix Security Response Team discovered that corosync, a cluster engine implementation, allowed an unauthenticated user to cause a denial-of-service by application crash.

Facebook admits it does track non-users, for their own good
Intel’s security light bulb moment: Chips to recruit GPUs to scan memory for software nasties
Microsoft has designed an Arm Linux IoT cloud chip. Repeat, an Arm Linux IoT cloud chip

LinuxSecurity.com: – update to the latest upstream release (fixes CVE-2018-1000168)

LinuxSecurity.com: Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use python send2trash module from system * use correct shebang for python2 * upstream changelog: https://apps.ankiweb.net/docs/changes.html

LinuxSecurity.com: New upstream release with security fix for CVE-2018-1084

LinuxSecurity.com: Update to latest upstream version.

LinuxSecurity.com: update to latest upstream release, which fixes the following vulnerabilities: – CVE-2018-1100 – stack-based buffer overflow in utils.c:checkmailpath() – CVE-2018-1083 – stack-based buffer overflow in compctl.c:gen_matches_files() – CVE-2018-1071 – stack-based buffer overflow in exec.c:hashcmd()

LinuxSecurity.com: Removing dependency on wireshark metapackage from wireshark-cli —- Added wireshark-qt to wireshark metapackage —- – New version 2.4.5 – Contains fixes for CVE-2018-7419, CVE-2018-7418, CVE-2018-7417, CVE-2018-7420, CVE-2018-7320, CVE-2018-7336, CVE-2018-7337, CVE-2018-7334, CVE-2018-7335, CVE-2018-6836, CVE-2018-5335, CVE-2018-5334, CVE-2017-6014, CVE-2017-9616,

security update

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

LinuxSecurity.com: This update doesn’t fix a vulnerability in linux-tools, but provides support for building Linux kernel modules with the “retpoline” mitigation for CVE-2017-5715 (Spectre variant 2).

Threatpost RSA Conference 2018 Preview