Menu

Latest articles

Police bust drug dealers using fingerprint from a WhatsApp photo
US, UK cyber cops warn Russians are rooting around in your routers

LinuxSecurity.com: Marcin Noga discovered multiple vulnerabilities in readxl, a GNU R package to read Excel files (via the integrated libxls library), which could result in the execution of arbitrary code if a malformed spreadsheet is processed.

Google to add extra Gmail security … by building a walled garden
Security? We’ve heard of it, say web-app devs. 31 in 33 codebases have at least one big bad vuln

LinuxSecurity.com: Several security issues were fixed in Ruby.

LinuxSecurity.com: Minor update from upstream with fix for CVE-2018-9234 and other bug fixes.

Police locate suspect from a crowd of 50,000 using Facial Recognition
Google Play Boots Three Malicious Apps From Marketplace Tied to APTs
UK spy agency warns Brit telcos to flee from ZTE gear
Hackers attack Casino’s fish tank thermometer to obtain sensitive data

LinuxSecurity.com: Several security issues were fixed in Patch.

How to protect your Facebook data [UPDATED]
Quarterly cybercrime digest: Sentencing

The long arm of the law caught up with a number of cybercriminals in the first three months of this year. The post Quarterly cybercrime digest: Sentencing appeared first on WeLiveSecurity

LinuxSecurity.com: It was discovered that there was an input validation vulnerability in the patch(1) utility where an ed(1) script embedded in a regular input file could result in arbitrary code execution. This was reported by Rachel Kroll [0] et al.

Nation-State Attacks Take 500% Longer to Find
Allscripts: Ransomware, recovery, and frustrated customers
Tracking protection in Firefox for iOS now on by default – why this matters
Facial recognition cameras on lamp posts to be tested in Singapore
Cisco backs test to help classical crypto outlive quantum computers
Security bods liberate EITest malware slaves

LinuxSecurity.com: A NULL Pointer Dereference was discovered in the TIFFPrintDirectory function (tif_print.c) when using the tiffinfo tool to print crafted TIFF information. This vulnerability could be leveraged by remote attackers to cause a crash of the application.

LinuxSecurity.com: A NULL Pointer Dereference was discovered in the TIFFPrintDirectory function (tif_print.c) when using the tiffinfo tool to print crafted TIFF information. This vulnerability could be leveraged by remote attackers to cause a crash of the application.

Android apps prove a goldmine for dodgy password practices
Australian Feds cuff woman who used BTC to buy drugs on dark web

LinuxSecurity.com: A vulnerability in Go allows remote attackers to execute arbitrary commands.

So you’ve got a zero-day – do you sell to black, grey or white markets?

LinuxSecurity.com: The package lib32-openssl before version 1:1.1.0.h-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package zsh before version 5.5-1 is vulnerable to arbitrary code execution.

security update

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Multiple vulnerabilities were discovered in the implementation of the Perl programming language. The Common Vulnerabilities and Exposures project identifies the following problems:

How Netflix Deploys Open Source AI to Reveal Your Favorites

LinuxSecurity.com: Minor update from upstream with fix for CVE-2018-9234 and other bug fixes.

LinuxSecurity.com: * Rebase to Ruby 2.5.1. * Several CVE fixes. * Conflict requirement needs to generate dependency. * Stop using –with-setjmp-type=setjmp on aarch64.

LinuxSecurity.com: harden the binaries (rhbz#1548670)

LinuxSecurity.com: Security fix for CVE-2018-1086 and CVE-2018-1079 Rebased to latest upstream sources

LinuxSecurity.com: Fix CVE-2017-11550 and CVE-2004-2779

LinuxSecurity.com: Fixes several heap-buffer-overflows, see related Bugzilla tickets!

LinuxSecurity.com: GwanYeong Kim reported that ‘pack()’ could cause a heap buffer write overflow with a large item count. For Debian 7 “Wheezy”, these problems have been fixed in version

security update

UK health service boss in the guts of WannaCry outbreak warns of more nasty code infections
Tried checking under the sofa? Indian BTC exchange Coinsecure finds itself $3.5m lighter

LinuxSecurity.com: python-paramiko: Authentication bypass in transport.py (CVE-2018-7750) SL6 noarch python-paramiko-1.7.5-4.el6_9.noarch.rpm – Scientific Linux Development Team

New malware mine cryptocurrency without open browser session
Critical Vulnerability in Drupal CMS Used for Cryptomining
Router ravaging, crippling code, and why not to p*ss off IT staff
Q1 Cyber-Attacks on UK Firms Jump 27%
USING OPEN SOURCE DESIGNS TO CREATE MORE SPECIALIZED CHIPS
Exposed: Lazy Android mobe makers couldn’t care less about security
Don’t Trust Android OEM Patching, Claims Researcher
Website security firm Sucuri hit by large scale volumetric DDoS attacks
NHS boss at the centre of WannaCry outbreak warns of more attacks

LinuxSecurity.com: USN-3621-1 caused a regression in Ruby.

$3.5 beeeellion Bitcoin falls out of Indian BTC exchange’s wallet

LinuxSecurity.com: The package apache before version 2.4.33-1 is vulnerable to multiple issues including session hijacking, access restriction bypass, content spoofing and denial of service.

Someone stole $3 million from Coinsecure Bitcoin exchange
The ransomware that says, “I don’t want money” – play a violent game instead!
This ransomware wants you to play, not pay

Unlike its much more malicious counterparts, this ransomware has a rather benign demand. It also provides two curious ways of recovering one’s files. The post This ransomware wants you to play, not pay appeared first on WeLiveSecurity

Instagram bends to GDPR – a “download everything” tool is coming
Interview: Sarah Jamie Lewis, Executive Director of the Open Privacy Research Society
Anti-Malware testing needs standards, and testers need to adopt them

A closer look at Anti-Malware tests and the somewhat unreliable nature of the process. The post Anti-Malware testing needs standards, and testers need to adopt them appeared first on WeLiveSecurity

Fake Hillary porn just the tip of Russia’s Reddit penetration
Story of a ransomware victim
Facebook shines a little light on ‘shadow profiles’
From Bangkok to Phuket, they cry out: Oh, Bucket! Thai mobile operator spills 46k people’s data
What Facebook and the CLOUD Act mean for cloud privacy
Quarterly cybercrime digest: Part 1

In Part 1, our roundup of some of the most notable law enforcement actions against computer crime in the first quarter of 2018 will focus on arrests and charges involving suspected cyber-crooks. The post Quarterly cybercrime digest: Part 1 appeared first on WeLiveSecurity

Thousands of compromised websites spreading malware via fake updates

Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Music-Oriented YouTube Channels Hacked Within the last week, hackers have defaced multiple YouTube music […]

Cloudflare promises to tend not two, but 65,535 ports in a storm

LinuxSecurity.com: An update that solves three vulnerabilities and has 7 fixes is now available.

When SecureRandom()… isn’t: JavaScript fingered for poking cash-spilling holes in Bitcoin wallets

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, and Red Hat Enterprise

‘Well intentioned lawmakers could stifle IoT innovation’, warns bug bounty pioneer

Type: Vulnerability. Microsoft Jet Database Engine is prone to a buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Outlook Bug Allowed Hackers to Use .RTF Files To Steal Windows Passwords
Calls For Regulation Build After Facebook Privacy Fallout
Microsoft Outlook bug expose Windows credentials to hackers

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton), Red Hat OpenStack Platform 11.0 (Ocata), Red Hat OpenStack Platform 12.0 (Pike), Red Hat OpenStack Platform 8.0 (Liberty), and Red Hat OpenStack Platform 9.0 (Mitaka).

LinuxSecurity.com: An update for sensu is now available for Red Hat OpenStack Platform 11.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: This updates LibOFX to fix assorted CVEs.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Worm.

Risk Level: Very Low. Type: Worm.

Avoiding the Ransomware Mistakes that Crippled Atlanta
GCHQ boss calls out Russia for ‘industrial scale disinformation’
Hackers can takeover & control emergency alarm system with a $35 radio
New ‘Early Bird’ Code Injection Technique Helps APT33 Evade Detection

LinuxSecurity.com: It was discovered that the poppler upload for the oldstable distribution (jessie), released as DSA-4079-1, did not correctly address CVE-2017-9776 and additionally caused regressions when rendering PDFs embedding JBIG2 streams. Updated packages are now available to correct

Using Outlook? You should probably do some patching
Fake Chrome & Firefox browser update lead users to malware infection
Update now! Microsoft’s April 2018 Patch Tuesday – 65 vulns, 24 critical
Where’s my free monitoring service, One Plus? – hacked-off customers
How many Linux users are there anyway?
Top Ten Ways to Detect Phishing
Congress chews up Zuckerberg, day two: A far more thorough mastication
Death SWAT suspect tweets threats from jail using buggy inmate kiosk