Menu

Latest articles

Impact Of Chat Service Breach Expands To Best Buy, Kmart
How to Delete Your Facebook Account Permanently – 2018 Guide

LinuxSecurity.com: Minor security update from upstream fixing CVE-2018-0739

LinuxSecurity.com: New version 2.1.26 (#1370156, #1304360)

LinuxSecurity.com: https://nodejs.org/en/blog/release/v8.11.0/

LinuxSecurity.com: Update to latest upstream version.

LinuxSecurity.com: Python Crypto could expose sensitive information.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Ming: CVE-2018-6358

5 Facebook facepalms (just last week)
Cinema voucher-pusher tells customers: Cancel your credit cards, we’ve been ‘attacked’
Hacker mines up to $1 million in Verge after exploiting major bug
Thousands of Google employees call for company to cancel Pentagon work
The Linux Foundation launches a deep learning foundation
There’s security – then there’s barbed wire-laced pains in the arse
Cisco mess from 2017 becomes tool for state-sponsored infrastructure attacks and defacements

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

Linux Beep bug joke backfires as branded fix falls short

LinuxSecurity.com: A vulnerability in SPICE VDAgent could allow local attackers to execute arbitrary commands.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which may allow an attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in libvirt, the worst of which may result in the execution of arbitrary commands.

LinuxSecurity.com: Multiple vulnerabilities were discovered in mailx, the worst of which may allow a remote attacker to execute arbitrary commands.

LinuxSecurity.com: This update fixes assorted CVEs in LibOFX.

LinuxSecurity.com: Fixes for CVE-2018-1002150.

LinuxSecurity.com: Update to the latest upstream release, which fixes CVE-2017-14062.

LinuxSecurity.com: **PHP version 7.1.16** (29 Mar 2018) **Core:** * Fixed bug php#76025 (Segfault while throwing exception in error_handler). (Dmitry, Laruence) * Fixed bug php#76044 (‘date: illegal option — -‘ in ./configure on FreeBSD). (Anatol) **FPM:** * Fixed bug php#75605 (Dumpable FPM child processes allow bypassing opcache access controls). (Jakub Zelenka) **GD:** * Fixed bug php#73957

LinuxSecurity.com: – spec cleanup, silent rpmlint – remove upstreamed patches, fixes rhbz #1507577 – update to 1.2.2

LinuxSecurity.com: rebase and fixed CVE-2018-1000140

LinuxSecurity.com: https://nodejs.org/en/blog/release/v8.11.0/

ATMJackpot Malware Stealing Cash From ATMs
T-Mobile Austria stores passwords as plain text, Outlook gets message crypto, and more
Engineering Group and Open Source Initiative Partner for Enhanced Leadership in Open Source
OPEN SOURCE WON. SO, NOW WHAT?

LinuxSecurity.com: Lilith of Cisco Talos discovered several buffer overflow vulnerabilities in the SDL Image library which can be leveraged by attackers to execute arbitrary code via specially crafted image files.

LinuxSecurity.com: New patch packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Multiple invalid frees and buffer-overflow vulnerabilities were discovered in sam2p, a utility to convert raster images and other image formats, that may lead to a denial-of-service (application crash) or unspecified other impact.

US government seizes classified advertising website Backpage

security update

Mirai Variant Targets Financial Sector With IoT DDoS Attacks
Intel removes remote keyboard app for Android rather than fixing its flaws
Facebook’s secret plan to access hospital patient records
Privacy Advocates Blast Facebook After Data Scraping Scandal
Botched upgrade at Belgian bank Argenta sparks phishing frenzy
Hackers compromise AOL advertising platform to mine cryptocurrency
Is it a bird? Is it a plane? No, it’s a terrible breach of drone buyers’ data
Study: White House email domains at risk of being misused for phishing scams

Most of the White House’s email domains have yet to deploy an email authentication protocol known as DMARC that is designed to reduce the risk of attackers impersonating legitimate email addresses for distributing spam or phishing messages. The post Study: White House email domains at risk of being misused for phishing scams appeared first on […]

Lawmakers press Linux on security of open-source software
Facebook’s new fake news strategy is… decide for yourself!
Facebook knew for years scammers were harvesting users’ details with phone number searches. Did nothing
Intel won’t fix Spectre flaws in older chips
Washington DC “awash” with fake cell towers
Email Fraud is a Top Business Risk for 2018
Iran ‘the New China’ as a Pervasive Nation-State Hacking Threat

LinuxSecurity.com: Fixes for CVE-2018-1002150.

LinuxSecurity.com: Update to the latest upstream release, which fixes CVE-2017-14062.

LinuxSecurity.com: Update to 3.6.5

LinuxSecurity.com: – spec cleanup, silent rpmlint – remove upstreamed patches, fixes rhbz #1507577 – update to 1.2.2

NUC, NUC! Who’s there? Intel, warning you to kill a buggy keyboard app
Buggy Verge crypto-cash gets hacked, devs go fork themselves, hard

LinuxSecurity.com: This update includes the latest upstream release of the Apache HTTP Server, version 2.4.33. A number of security vulnerabilities are fixed in this release: * *Low*: Possible out of bound read in mod_cache_socache (CVE-2018-1303) * *Low*: Possible out of bound access after failure in reading the HTTP request (CVE-2018-1301) * *Low*: Weak Digest auth […]

LinuxSecurity.com: This update includes the latest upstream release of mod_http2, version 1.10.16. This includes a security fix (CVE-2018-1302): When an HTTP/2 stream was destroyed after being handled, mod_http2 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerabilty hard to trigger in usual […]

WhatsApp phishing – how it works, and what to do [VIDEO]
New macOS malware aims at infecting devices with malicious macros
Delta, Sears Breaches Blamed on Malware Attack Against a Third-Party Chat Service
Sears Holdings, Delta and others leak credit cards in “multibreach”

LinuxSecurity.com: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) (CVE-2018-5146) SL6 x86_64 libvorbis-1.2.3-5.el6_9.1.i686.rpm libvorbis-1.2.3-5.el6_9.1.x86_64.rpm libvorbis-debuginfo-1.2.3-5.el6_9.1.i686.rpm libvorbis-debuginfo-1.2.3-5.el6_9.1.x86_64.rpm libvorbis-devel-1.2.3-5.el6_9.1.i686.rpm libvorbis-devel-1.2.3-5.el6_9.1.x86_64.rpm i386 libvorbis-1.2.3 [More…]

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

security update

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libvorbis is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Bot-ched security: Chat system hacked to slurp hundreds of thousands of Delta Air Lines, Sears customers’ bank cards

Reading Time: ~3 min.When WannaCry ransomware spread throughout the world last year by exploiting vulnerabilities for which there were patches, we security “pundits” stepped up the call to patch, as we always do. In a post on LinkedIn Greg Thompson, Vice President of Global Operational Risk & Governance at Scotiabank expressed his frustration with the […]

You are not alone; The Pirate Bay is down once again

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Mark Zuckerberg admits Facebook scans user private messages
Hooray! Facebook ditches searching for people by phone number or email
Rarog Trojan ‘Easy Entry’ For New Cryptomining Crooks, Report Warns
1.5 BEEELLION sensitive files found exposed online dwarf Panama Papers leak
Don’t want to alarm you, but defence bods think North Korea could nuke UK ‘within a few years’
Saks and Lord & Taylor stores suffer data breach exposing five million bank cards

Cybercriminals are believed to have stolen information for more than five million credit and debit cards that shoppers had used at dozens of Saks Fifth Avenue, Saks Off 5th and Lord & Taylor stores mainly in the United States between May 2017 and March 2018. The post Saks and Lord & Taylor stores suffer data […]

Beware ad slingers thinly disguised as security apps

ESET researchers have analyzed a newly discovered set of apps on Google Play, Google’s official Android app store, that pose as security applications. Instead of security, all they provide is unwanted ads and ineffective pseudo-security. The post Beware ad slingers thinly disguised as security apps appeared first on WeLiveSecurity

Find out who is leaking your secrets, with help from invisible zero-width characters
Gosh, these ‘hacker’ nerds are only getting more sophisticated
Facebook and Twitter may be forced to identify bots
Cloudflare’s 1.1.1.1 promises to make DNS more secure
YouTube employee’s Twitter account hijacked during shooting
Smashing Security #072: Why are firms so cr*p with our private data?
US spanks EU businesses in race to detect p0wned servers
Brain monitor had remote code execution and DoS flaw

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

They forked this one up: Microsoft modifies open-source code, blows hole in Windows Defender
Facebook Bolsters Privacy Measures With New Data Access Restrictions

LinuxSecurity.com: The package drupal before version 8.5.1-1 is vulnerable to arbitrary code execution.

security update

security update