Menu

Latest articles

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Olympic Destroyer: A False Flag Confusion Bomb
Lookout: Dark Caracal Points To APT Actors Moving To Mobile Targets
UK data watchdog raids companies suspected of 11 million nuisance texts
Android P promises new security and privacy features
Bitcoin Price Drops 10% Amid Binance Exchange Hacking Rumors
Facebook Onavo VPN app collects user data even when its off
New DDoS attack method breaks record again, adds extortion

DDoS mitigation service Arbor Networks has announced that an undisclosed US company has suffered an attack fueled by internet-facing Memcached servers that clocked in at 1.7 terabits per second (Tbps), beating the previous record of 1.35 Tbps. The post New DDoS attack method breaks record again, adds extortion appeared first on WeLiveSecurity

Your entire ID is worth £820 to crooks on dark web black market
Download Kali Linux from Microsoft Store and use on Windows 10
Smart traffic lights cause jams when fed spoofed data
Spyware maker shuts down surveillance services after hacks
Hope Hicks hacked
Ad-Blocker Ghostery Just Went Open Source-And Has a New Business Model
Memcached DDoS: This ‘kill switch’ can stop attacks dead in their tracks
How women are helping to fight cybercrime
Chrome 65 rolls out: You’re getting a stronger redirect blocker, 45 security fixes
Open-source Exim remote attack bug: 400,000 servers still vulnerable, patch now
MoviePass removes ‘unused’ location feature that tracked cinema-goers’ movements
Sigh. Cisco security kit has Java deserialisation bug and a default password SNAFU
IBM’s homomorphic encryption accelerated to run 75 times faster
Audit finds Department of Homeland Security’s security is insecure
Smashing Security #068: Malware from outer space!

LinuxSecurity.com: Several vulnerabilities have been discovered in the ISC DHCP client, relay and server. The Common Vulnerabilities and Exposures project identifies the following issues:

Memcached DDoS Attack PoC Code & 17,000 IP addresses Posted Online

LinuxSecurity.com: Kernel: KVM: MMU potential stack buffer overrun during page walks (CVE-2017-12188, Important) * Kernel: KVM: debug exception via syscall emulation (CVE-2017-7518, Moderate) SL7 x86_64 kernel-3.10.0-693.21.1.el7.x86_64.rpm kernel-debug-3.10.0-693.21.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-693.21.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-693.21.1.el7.x86_64.rpm ke [More…]

LinuxSecurity.com: libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula (CVE-2018-6871) SL7 x86_64 libreoffice-base-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-calc-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-core-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-debuginfo-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-draw-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-emailmerge-5.0.6. [More…]

LinuxSecurity.com: php: Buffer over-read from unitialized data in gdImageCreateFromGifCtx function (CVE-2017-7890) SL7 x86_64 php-5.4.16-43.el7_4.1.x86_64.rpm php-bcmath-5.4.16-43.el7_4.1.x86_64.rpm php-cli-5.4.16-43.el7_4.1.x86_64.rpm php-common-5.4.16-43.el7_4.1.x86_64.rpm php-dba-5.4.16-43.el7_4.1.x86_64.rpm php-debuginfo-5.4.16-43.el7_4.1.x86_64.rpm php-devel-5.4.16-43.el7_4.1. [More…]

LinuxSecurity.com: 389-ds-base: remote Denial of Service (DoS) via search filters in SetUnicodeStringFromUTF_8 in collate.c (CVE-2018-1054) * 389-ds-base: Authentication bypass due to lack of size check in slapi_ct_memcmp function in ch_malloc.c (CVE-2017-15135) Bug Fix(es): * Previously, if an administrator configured an index for an attribute with a specific matching rule in the “nsMatchingRule” parameter, [More…]

Facebook Onavo Protect doesn’t protect against Facebook

LinuxSecurity.com: A vulnerability in Go might allow remote attackers to execute arbitrary commands during source code build.

LinuxSecurity.com: A vulnerability was discovered in util-linux, which could potentially lead to the execution of arbitrary code.

Patch now! Half a million Exim mail servers need an urgent update

First thing’s first—I’d like to introduce myself. I’m senior security analyst Randy Abrams, and I’m delighted to be part of the Webroot team and our online community. Prior to joining the team, I was a research director responsible for analyzing and reporting the test results of antimalware products. I also helped create test methodologies and […]

Hackers can Send Fake Emergency Alerts by Exploiting 4G LTE Protocol Flaws
Buffer overflow in Unix mailer Exim imperils 400,000 email servers
400,000 servers at risk if open-source Exim remote attack bug is left unpatched
Cortana Lets Hackers Infect Windows PC Even when it is Locked
Securing RPM signing keys
Trends 2018: The ransomware revolution

While Denial of Service attacks amplified by the use of networks of bot-compromised PCs were becoming a notable problem by the turn of the century, DDoS extortion threats have accelerated in parallel (if less dramatically) with the rise in ransomware in the past few years. The post Trends 2018: The ransomware revolution appeared first on […]

‘We know all about you’ – MoviePass CEO admits to tracking users
Safer browsing coming soon to MacOS Chrome users
Facebook photos expose “sick” couple as food poisoning fakers
Second company claims it can unlock iPhone X
How to Ensure Data Protection Regulation Compliance in Your Company

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

UK.gov cooks up code of conduct to enforce a smidge of security on Internet of S**t kit

LinuxSecurity.com: Different flaws have been found in leptonlib, an image processing library.

Women of Infosec call bullsh*t on RSA’s claim it could only find one female speaker

LinuxSecurity.com: An update that fixes one vulnerability is now available.

World’s Largest DDoS Attack: US Firm Suffers 1.7 Tbps of DDoS Attack

LinuxSecurity.com: An update for libreoffice is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for php is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: The package python2-django before version 1.11.11-1 is vulnerable to denial of service.

POS Malware Found at 160 Applebee’s Restaurant Locations

LinuxSecurity.com: The package python2-django before version 1.11.11-1 is vulnerable to denial of service.

LinuxSecurity.com: The package python-django before version 1.11.11-1 is vulnerable to denial of service.

LinuxSecurity.com: Updated kernel packages that fix six bugs are now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

ComboJack Malware Steals Cryptocurrency by Modifying Addresses
Google Patches 11 Critical Bugs in March Android Security Bulletin
IoT Security Disconnect: As Attacks Spike, Device Patching Still Lags
CryptoLurker hacker crew skulk about like cyberspies, earn $$$
After Cellebrite, Grayshift Claims to Crack Encrypted iPhone X & 8
World record broken again! DDoS attack exceeds 1.7 terabits per second
“Prince Charming” is a happily married, gay, identity theft victim
Hacker returns $17 million worth of stolen Ethereum
Co-op Bank’s shonky IT in spotlight as delayed probe given go-ahead
“Big Bitcoin Heist” sees 600 Icelandic servers stolen
Hacking operation uses malicious Word documents to target aid organisations
Games site customers offered $5 voucher after credit card breach
Cryptojacking: the result of the “cryptocurrency rush”

Tools for mining cryptocurrencies also fall into this category, as in many cases the websites cannot warn users since they have been compromised themselves, hence even the administrators may not be aware that they are contributing to mining for the benefit of an attacker. The post Cryptojacking: the result of the “cryptocurrency rush” appeared first […]

LinuxSecurity.com: PostgreSQL could be made to execute arbitrary code.

Multicloud’s hidden trade-off: Greater security risk

LinuxSecurity.com: Twisted could be made to run programs if it received specially crafted network traffic.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.

Miner vs miner: Attack script seeks out and destroys competing currency crafters
World’s biggest DDoS attack record broken after just five days
How to Choose the Best Dedicated Server for Your Online Business
Pennsylvania AG sues Uber over 2016 data fail