Menu

Latest articles

Pre-installed malware on Android devices made $115k revenue in 10 days
Scarlett Johansson’s face lands starring role in database hack
Intel Details CPU ‘Virtual Fences’ Fix As Safeguard Against Spectre, Meltdown Flaws
Poisoned BitTorrent client kickstarted malware outbreak that tried to infect 400,000 PCs
The Chrome extension that knows its you by the way you type

LinuxSecurity.com: Some vulnerabilities have been found in ClamAV, an open source antivirus engine:

LinuxSecurity.com: An update that fixes 27 vulnerabilities is now available.

YouTuber jailed after shooting boyfriend dead in failed prank
yescrypt – modern KDF and password hashing scheme
Why a hard drive RAID array can save your bacon
Linus Torvalds slams CTS Labs over AMD vulnerability report
Facebook: we won’t share data with WhatsApp (yet)
Tricks that cybercriminals use to hide in your phone

Malware in the official Google store never stops appearing. For cybercriminals, sneaking their malicious applications into the marketplace of genuine apps is a huge victory. The post Tricks that cybercriminals use to hide in your phone appeared first on WeLiveSecurity

The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Global Gas Station Software Found Unsecured Researchers have recently discovered a vulnerability that would allow anyone to […]

Ugh, of course Germany trounces Blighty for cyber security salaries
FYI: There’s a cop tool called GrayKey that force unlocks iPhones. Let’s hope it doesn’t fall into the wrong hands!

Risk Level: Very Low. Type: Worm.

Risk Level: Very Low. Type: Trojan.

We’re Putin our foot down! DHS, FBI blame Russia for ongoing infrastructure hacks

LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code, denial of service or information disclosure.

GandCrab Ransomware Crooks Take Agile Development Approach
Walmart Jewelry Partner Exposes Personal Data Of 1.3M Customers

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: This update upgrades Firefox to version 52.7.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 59 and Firefox ESR 52.7 (MFSA 2018-07) (CVE-2018-5125) * Mozilla: Buffer overflow manipulating SVG animatedPathSegList (MFSA 2018-07) (CVE-2018-5127) * Mozilla: Out-of-bounds write with malformed IPC messages (MFSA 2018-07) (CVE-2018-5129) * Mozilla: Mismatched RTP payload type can trigger memo […]

LinuxSecurity.com: This update upgrades Firefox to version 52.7.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 59 and Firefox ESR 52.7 (MFSA 2018-07) (CVE-2018-5125) * Mozilla: Buffer overflow manipulating SVG animatedPathSegList (MFSA 2018-07) (CVE-2018-5127) * Mozilla: Out-of-bounds write with malformed IPC messages (MFSA 2018-07) (CVE-2018-5129) * Mozilla: Mismatched RTP payload type can trigger memo […]

security update

security update

Smart home devices can be hacked within minutes through Google search
Hyperbole Swirls Around AMD Processor Security Threat

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0527

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0526

LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code or denial of service.

LinuxSecurity.com: An update for ceph is now available for Red Hat Ceph Storage 3.0 for Ubuntu 16.04. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for ceph is now available for Red Hat Ceph Storage 3.0 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Intel: Our next chips won’t have data leak flaws we told you totally not to worry about
Hackers continue to exploit hijacked MailChimp accounts in cybercrime campaigns

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Updates for rh-dotnet20-dotnet, rh-dotnetcore10-dotnetcore, and rh-dotnetcore11-dotnetcore are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact

Iran-Linked Group ‘TEMP.Zagros’ Updates Tactics, Techniques In Latest Campaign
Walmart Jewelry Partner Exposes Data of Millions of Customers
Researchers slap SAP CRM with vuln combo for massive damage
Fortnite accounts are being hacked to make fraudulent purchases
YouTube conspiracy videos to get links to Wikipedia and other sources
Firefox makes it easy to banish push notifications
Employers’ best bet for appealing to security pros? Value their opinions

The report also sheds light on how not to go about attracting new hires. Vague and inaccurate job descriptions along with job postings that include insufficient qualifications were found to top the list of turnoffs for many jobseekers The post Employers’ best bet for appealing to security pros? Value their opinions appeared first on WeLiveSecurity

Anti-anti-virus service provider tied to huge hacks cops plea
Former Equifax exec charged with stock dumping before breach disclosure

LinuxSecurity.com: An update for erlang is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Microsoft patches RDP vulnerability. Update now!

LinuxSecurity.com: An update that fixes 14 vulnerabilities is now available.

MailChimp ‘working’ to stop hackers flinging malware-laced spam from accounts

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Several vulnerabilities were discovered in mbed TLS, a lightweight crypto and SSL/TLS library, that allowed a remote attacker to either cause a denial-of-service by application crash, or execute arbitrary code.

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update that fixes 7 vulnerabilities is now available.

VPN tests reveal privacy-leaking bugs

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Microsoft starts buying speculative execution exploits

LinuxSecurity.com: An update that fixes 15 vulnerabilities is now available.

Smashing Security #069: Cryptomining, China, and Bob Ross
Facebook bans anti-Islamic group Britain First

security update

Risk Level: Very Low.

Risk Level: Very Low.

HotSpot Shield, PureVPN & ZenMate found leaking users real IP addresses
New Web-Based Malware Distribution Channel ‘BlackTDS’ Surfaces
Transport for NSW scrambles to patch servers missing fixes released in 2007

Type: Vulnerability. Microsoft Excel is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Access is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Kernel is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.