Menu

Latest articles

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Intel Tells Remote Keyboard Users to Delete App After Critical Bug Found
Cyber security developments: Keeping safe and up to date

LinuxSecurity.com: An update that fixes one vulnerability is now available.

White House Lags Far Behind on Email Security Benchmark
No, Panera Bread Doesn’t Take Security Seriously
Intel Halts Spectre Fixes On Older Chips, Citing Limited Ecosystem Support
Mainstream Live Chat widgets leaking personal details of employees
Insecure SCADA Systems Blamed in Rash of Pipeline Data Network Attacks
Why you might want to tell Facebook you now live in Europe
Don’t blame Panera Bread’s security guy just because he used to work at Equifax
Google banishes cryptocurrency mining extensions from Chrome Web Store

The tech giant is taking the measure after a rise in malicious browser extensions that mine digital money by hijacking the processing power of users’ computers. The clampdown follows Google’s recent move to stop serving any and all adverts promoting virtual currencies and initial coin offerings. The post Google banishes cryptocurrency mining extensions from Chrome […]

Free Virgin Atlantic tickets? No, it’s a WhatsApp scam
Magento sites hacked with cryptominers & credential stealing malware
Hand over your social media history before you enter the US
Grindr was sharing HIV status of users, but now it’s not
The 5 IT security actions to take now based on 2018 Trends

Implementing the five actions described in this article can help reduce your organization’s cyber risk and bolster its security defenses The post The 5 IT security actions to take now based on 2018 Trends appeared first on WeLiveSecurity

Facebook Expands Bug Bounty Amid Spiraling Privacy Scandal
Saks, Lord & Taylor Payment Card Breach Affects 5 Million
GoScanSSH Malware Avoids US Military, South Korea Targets
Those Facebook videos you thought were deleted were not deleted

LinuxSecurity.com: Multiple vulnerabilities have been found in glibc, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were discovered in libxslt, the worst of which may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: Michal Kedzior found two vulnerabilities in LDAP Account Manager, a web front-end for LDAP directories. CVE-2018-8763

Intel admits a load of its CPUs have Spectre v2 flaw that can’t be fixed

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Hold the phone: Mystery fake cell towers spotted slurping comms around Washington DC

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, unauthorized access, sandbox bypass or HTTP header injection.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

security update

Furious gunwoman opens fire at YouTube HQ, three people shot

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Gay dating app Grindr shared user HIV & location data with third-parties
Do(ug)h! Half-baked security at Panera Bread spills customer data
Mad March Meltdown! Microsoft’s patch for a patch for a patch may need another patch

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several security issues were fixed in the kernel.

How to delete your Facebook data in bulk with this Chrome extension

Risk Level: Very Low. Type: Trojan.

Panera Bread customer records exposed via leaky database – dough!
Badmins: Magento shops brute-forced to scrape card deets and install cryptominers
Google’s April Android Security Bulletin Warns of 9 Critical Bugs
Panera Bread Slammed After Keeping Massive Data Leak Quiet For Eight Months
New Android Malware Stealing Data from Popular Messenger Apps
5 million credit cards exposed in Saks and Lord & Taylor data breach
Lazarus KillDisks Central American casino

The Lazarus Group gained notoriety especially after cyber-sabotage against Sony Pictures Entertainment in 2014. Fast forward to late 2017 and the group continues to deploy its malicious tools, including disk-wiping malware known as KillDisk, to attack a number of targets. The post Lazarus KillDisks Central American casino appeared first on WeLiveSecurity

Panera Bread’s half-baked security
YouTube prankster sued by In-N-Out Burger
One solution to wreck privacy-hating websites: Flood them with bogus info using browser tools

LinuxSecurity.com: It was discovered that there was a local privilege escalation vulnerability in beep, an “advanced PC speaker beeper”. For Debian 7 “Wheezy”, this issue has been fixed in beep version

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Streaming site 123movies has been shut down; here are its alternatives
Block blocked: Google to banish cryptominers from Chrome Web Store

LinuxSecurity.com: Multiple vulnerabilities were found in the rubygems package management framework, embedded in JRuby, a pure-Java implementation of the Ruby programming language.

LinuxSecurity.com: It was discovered that a race condition in beep (if configured as setuid via debconf) allows local privilege escalation. For the oldstable distribution (jessie), this problem has been fixed

U.S. DoD Hopes To Stamp Out Threats With Bug Bounty Program

security update

security update

Hacks Fifth Avenue: Crooks slurp bank cards from luxury chain Saks

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

LinuxSecurity.com: Several security issues were fixed in OpenJDK 8.

Report Shows Ransomware is the New Normal
Google Shuts Down URL Shortening Service & Acquires GIF Search Platform
Cloudflare Launches Publicly DNS-Over-HTTPS Service
Credit Card Data Swiped From 5M Saks, Lord & Taylor Customers
Phishing scam: Italian football club tricked into sending out €2m to crooks
Lord & Taylor & Saks customers payment cards stolen, sold on Dark Web

LinuxSecurity.com: Several security issues were fixed in Dovecot.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Irssi, a terminal-based IRC client which can result in denial of service. For the stable distribution (stretch), these problems have been fixed in

LinuxSecurity.com: Multiple vulnerabilities were found in rubygems, a package management framework for Ruby. CVE-2018-1000075

LinuxSecurity.com: James Davis discovered two issues in Django, a high-level Python web development framework, that can lead to a denial-of-service attack. An attacker with control on the input of the django.utils.html.urlize() function or django.utils.text.Truncator’s chars() and words() methods

Purism Librem 13: A Security-Focused Powerhouse of a Linux Laptop
How to configure multiple websites with Apache web server

LinuxSecurity.com: Two security vulnerabilities were discovered in the Z shell. CVE-2018-1071 Stack-based buffer overflow in the exec.c:hashcmd() function.

security update

security update

LinuxSecurity.com: CVE-2017-7651 A crafted CONNECT packet from an unauthenticated client could result in extraordinary memory consumption.

LinuxSecurity.com: Several vulnerabilities have been discovered in the Dovecot email server. The Common Vulnerabilities and Exposures project identifies the following issues:

US may screen social media of Immigrant & Non-Immigrant Visa Applicants

LinuxSecurity.com: Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in

LinuxSecurity.com: It was discovered that constructed ASN.1 types with a recursive definition could exceed the stack, potentially leading to a denial of service.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

MailChimp Bans ICO & Blockchain Marketing- Fundraisers Devastated

LinuxSecurity.com: libvncserver version through 0.9.11. does not sanitize msg.cct.length which may result in access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.

security update

security update

Any social media accounts to declare? US wants travelers to tell
Microsoft Fixes Bad Patch That Left Windows 7, Server 2008 Open to Attack

LinuxSecurity.com: An update that solves 19 vulnerabilities and has 16 fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: The system could be made to expose sensitive information.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 41 fixes is now available.