Menu

Latest articles

LinuxSecurity.com: Two vulnerabilities were discovered in cURL, an URL transfer library. CVE-2017-8816

Google AI lets phone owners know about shoulder surfers
Android spyware found secretly recording WhatsApp, Viber, and Skype chats
Smashing Security podcast #054: A great big fat macOS bug
Keyless convenience or security risk? Car theft in action

Exactly how does the attack work and is it expensive to create? The attack, while seeming to be technology voodoo, is actually rather simple. It requires a transmitting relay near the key and a second relay near the car to receive the relayed signals and mimic the key. The post Keyless convenience or security risk? […]

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

LinuxSecurity.com: An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Accused hacker Lauri Love’s extradition appeal begins

LinuxSecurity.com: An update for tcmu-runner is now available for Red Hat Gluster Storage 3.3.1 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Canadian! fella! admits! hacking! Gmail! inboxes! amid! Yahoo! megahack!
Critical Apple Login Bug Puts macOS High Sierra Systems at Risk
Uber hack coverup: Your next US state lawsuit arrives in four minutes
Huge MacOS bug lets anyone login as root without a password: what you need to know

LinuxSecurity.com: CVE-2017-15369 CVE-2017-15587 CVE-2017-9216 CVE-2017-14685 CVE-2017-14686 CVE-2017-14687

LinuxSecurity.com: Harden the Slurm build and allows it to operate in full relro with GOT sections of the ELF binaries marked read-only.

LinuxSecurity.com: Security fix for CVE-2017-12629

security update

LinuxSecurity.com: rebase to version 1.2.2, solves CVE-2017-16227, solves error produced by install script

Apple Macs have gaping root hole – here’s a superquick way to check and fix it

LinuxSecurity.com: An update for apr is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Leaky AWS Storage Bucket Spills Military Secrets, Again
Gone in Seconds: Hackers Steal Mercedes Car without Key

LinuxSecurity.com: An update for procmail is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

US intelligence blabs classified Linux VM to world via leaky S3 silo

security update

Pro tip: You can log into macOS High Sierra as root with no password
Google Detects and Boots Tizi Spyware Off Google Play
Hackers are digging into Microsoft Word flaw that existed for last 17 year
Researcher: DJI RCE-holes offered me $500 after I found Heartbleed etc on its servers
Most Fancy Bear hacking targets weren’t warned by FBI
Mr. Robot: Now we know where Tyrell was hiding

Since nothing is what is seems, it’s hard to be sure who was really behind the attacks shown in the series. The world still believes fsociety was responsible (and they themselves do too, to an extent), but the truth is that there is a group in the shadows that is pulling all the strings. The […]

Age verification legislation will lead to porn habit database
Ransomware Attack Involving Scarab Malware Sends Over 12M Emails in 6 Hours
Involved in a data breach? Firefox to test alerts in the browser
Boffins craft perfect ‘head generator’ to beat facial recognition

LinuxSecurity.com: New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Surprise: Android apps are riddled with trackers
Open source nameserver used by millions needs patching
Chinese IT security bods accused of siphoning US GPS, biz blueprints
Uber, quit shoveling money into the fire for one second and explain that hack – US senators

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Bulletproof Coffee lacks bulletproof security: Nerd brain juice biz hacked, cards gulped
Deleting anyone’s Facebook photo, a bug that earned researcher $10,000
That $10,000 Facebook bug: Photos shafted, addicts screwed by polls
The end of net neutrality draws near
Barracuda gobbled up by private equity sharks
Imgur Confirms 2014 Breach of 1.7 Million User Accounts

LinuxSecurity.com: Berkeley DB could be made to expose sensitive information.

LinuxSecurity.com: Berkeley DB could be made to expose sensitive information.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash or run programs as an administrator.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash or run programs as an administrator.

LinuxSecurity.com: Samba could be made to expose sensitive information over the network.

LinuxSecurity.com: formail could be made to crash or run programs if it processed specially crafted mail.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

How one man could have deleted any image on Facebook
Hackers can Exploit Load Planning Software to Capsize Balance of Large Vessels
Researchers Convert Human Bacteria into World’s Tiniest Tape Recorder
What keeps IT administrators up at night? Ransomware, for one | Salted Hash Ep 8
Newly Published Exploit Code Used to Spread Mirai Variant
Facebook tool will reveal if you were fooled by Russian propaganda
Imgur breached back in 2014, wasn’t storing your passwords properly
Looking for scrubs? Nah, NHS wants white hats – the infosec techie kind
Don’t shame idiots about their idiotically weak passwords
Facebook flaw allowed unauthorised users to delete any photo
Imgur hackers stole 1.7 million email addresses and passwords

LinuxSecurity.com: An update for samba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for samba is now available for Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6 and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

.GIF garage Imgur plugs 1.7 million-subscriber creds breach
Exim-ergency! Unix mailer has RCE, DoS vulnerabilities
Anonymous Muslim Group Confusing ISIS with Porn and Fake News

LinuxSecurity.com: An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is now available. now available.

Fake Symantec Blog Caught Spreading Proton macOS Malware

LinuxSecurity.com: An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now available. fixes is now available.

Imgur was hacked in 2014; affecting 1.7M users

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

“ProtonMail Contacts” world’s first encrypted contacts manager is here

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: An update that solves 33 vulnerabilities and has 7 fixes is An update that solves 33 vulnerabilities and has 7 fixes is An update that solves 33 vulnerabilities and has 7 fixes is now available. now available.

security update

security update

A gargantuan all-seeing eye is watching you on popular websites

LinuxSecurity.com: An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now available. fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

Alleged HBO hacker is an Iranian the FBI can’t arrest
MS Office’ Default Function Can Be Used to Create Self-Replicating Malware

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan, Worm.

Blockchain Wallet CoinPouch Hacked; Verge Coins Stolen
SAML Post-Intrusion Attack Mirrors ‘Golden Ticket’
3 simple tips to stay off the hook this phishing season
Seek ‘passion’ and tech skills will follow, say recruiting security chiefs
New reality in European banking looming large: the lowdown

At the heart of the regulation is the requirement for banks to allow licensed third-party providers (TPPs) of financial services to access securely their customer-account data, as long as the customer has given their prior consent. The post New reality in European banking looming large: the lowdown appeared first on WeLiveSecurity

UK emergency crews get 4G smartmobes as monkeys attempt to emerge from Reg’s butt
EU’s data protection bods join the party to investigate Uber breach