Menu

Latest articles

security update

Senator Calls For Use Of DMARC To Curb Phishing

Type: Vulnerability. Cisco WebEx Browser Extension is prone to a remote code-execution vulnerability; fixes are available.

Millions of IoT devices at hacking risk due to flaw in open source software library
News in brief: moving Segway hacked; Google Glass resurrected; 308 Oracle fixes
Ransomware attack on KQED TV, Radio Station wiped out pre-recorded segments
How Verified by Visa and MasterCard SecureCode Can Prevent E-commerce Chargebacks
Windows security hole – the “Orpheus’ Lyre” attack explained
Woman arrested for smuggling 102 iPhones, 15 Watches to China
Myspace bug left old accounts vulnerable to attack
Ships Can Be Hacked By Exploiting VSAT Communication System
Modified Versions of Nukebot in Wild Since Source Code Leak
Texting is no laughing matter

LinuxSecurity.com: LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.

LinuxSecurity.com: OpenLDAP could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: This is an update fixing CVE-2017-10965 and CVE-2017-10966.

Police bodycams get tech that can identify “faces and people”
IBM’s Plan To Encrypt Unthinkable Amounts of Sensitive Data
Linux Users Urged to Update as a New Threat Exploits SambaCry
Want porn? Prove your age (or get a VPN)
Bad Code Library Triggers Devil’s Ivy Vulnerability in Millions of IoT Devices

LinuxSecurity.com: An update that solves one vulnerability and has 8 fixes is An update that solves one vulnerability and has 8 fixes is An update that solves one vulnerability and has 8 fixes is now available. now available.

OneLogin: Businesses vulnerable to data breaches by ex-employees

Businesses leave themselves open to potential data breaches through their ex-employees, according to a new study by OneLogin. The post OneLogin: Businesses vulnerable to data breaches by ex-employees appeared first on WeLiveSecurity

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Watch: Man’s smartphone reboots every time he calls 911
Oracle Releases Biggest Update Ever: 308 Vulnerabilities Patched
Oracle E-Business Suite Flaw Allows Downloads of Documents
CoinDash Hacked During its ICO
Privacy Activists Suffer Legal Setback In National Security Letter Case
Myspace fixes account security hole – but delete your account anyway

Risk Level: Very Low. Type: Trojan.

Hackers Can Breach Burglar Alarm System with $142 Device
News in brief: laptop ban curtailed; robot meets a soggy end; Dow Jones leaks 2.2m customers’ data
Black Hat USA 2017: what’s on the agenda in Las Vegas
Google wants you to bid farewell to SMS authentication
FedEx: It is still suffering the aftermath of Petya attack
Didn’t get your Oreo cookie shipment? Last month’s global cyber attack may be to blame
Hacked drones flying up, up and away over geofencing restrictions
Spyware abuses Telegram messaging app to target Iranian Android users
Security Robot Found “Drowned” in An Indoor Fountain
It’s a trap! Marcher banking trojan masquerades as Adobe Flash Player for Android
Ethereum cryptocurrency heist! Over $7 million reportedly stolen through simple hack
Access all areas – but for how long after you’ve left the company?

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: Several security issues were fixed in ICU.

When good extensions go bad: buyer turns Particle into adware
A major cyberattack could cost the global economy $53 billion

Lloyd’s of London have reported that a serious cyberattack could cost the global economy as much as a devastating natural disaster. The post A major cyberattack could cost the global economy $53 billion appeared first on WeLiveSecurity

Botnet Tweeting, Spamming Porn Shut Down
Cisco Patches Another Critical Ormandy Bug in WebEx Extension
CoinDash’ Token Sale Site Hacked; $7 Million Ethereum Stolen

LinuxSecurity.com: * various flaws: CVE-2017-7515 CVE-2017-9775 CVE-2017-9776 CVE-2017-9865 —- * CVE-2017-9406 CVE-2017-9408 various memory leak flaws

LinuxSecurity.com: Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize function Additionally sqlite has been updated to version 3.19.3, and spatialite-tools rebuilt for the update.

LinuxSecurity.com: Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize function Additionally sqlite has been updated to version 3.19.3, and spatialite-tools rebuilt for the update.

FreeRADIUS Update Patches Bugs Static Analysis Tools Missed
News in brief: Beijing bans Pooh; Ashley Madison offers settlement; patient data shared on Facebook
Fake WhatsApp Subscription Email Stealing Banking Data
What does Imogen Heap have in common with mail? The blockchain
GhostCtrl Android Malware Records Audio, Video and Spies on Users
Free Certs Come With a Cost
Wait, you didn’t want to clean the toilets? Should have read the terms!
Want to a hack a Myspace account? They’ve made it shockingly easy

LinuxSecurity.com: The 4.11.10 update contains a number of important fixes across the tree

Siri implicated in yet another iPhone lockscreen hole
Unix: How random is random?
White House released voter-fraud commenters’ sensitive personal information
Want to kill your IT security team? Put the top hacker in charge
Alexa is listening to what you say – and might share that with developers

LinuxSecurity.com: Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize function

LinuxSecurity.com: CVE-2017-1000381: c-ares NAPTR parser out of bounds access

Malware installs Signal as part of scheme to steal Mac users’ banking credentials

LinuxSecurity.com: – CVE-2017-1000083: Evince command injection vulnerability in CBT handler (#1468488)

LinuxSecurity.com: File /etc/sysconfig/httpd is ghosted now —- Version update —- Security fix for CVE-2017-3167 CVE-2017-3169 CVE-2017-7659 CVE-2017-7668 CVE-2017-7679

LinuxSecurity.com: This update updates QtWebEngine to the 5.9.1 release, a security and bugfix release from the 5.9 branch. QtWebEngine 5.9.1 is part of the Qt 5.9.1 release, but only the QtWebEngine component is included in this update. The update fixes the following security issues in QtWebEngine 5.9.0: CVE-2017-5070, CVE-2017-5071, CVE-2017-5075, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078,

LinuxSecurity.com: New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017

Giveaway: Download Millions of Free Microsoft E-books

LinuxSecurity.com: Jeffrey Altman, Viktor Dukhovni, and Nicolas Williams reported that Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos, trusts metadata taken from the unauthenticated plaintext (Ticket), rather than the authenticated and encrypted KDC response. A

security update

security update

security update

security update

You can buy password stealing malware ‘Ovidiy Stealer’ for $7

LinuxSecurity.com: Samba could allow unintended access to network services.

LinuxSecurity.com: Heimdal could allow unintended access to network services.

LinuxSecurity.com: Clément Berthaux from Synaktiv discovered a signature forgery vulnerability in knot, an authoritative-only DNS server. This vulnerability allows an attacker to bypass TSIG authentication by sending crafted DNS packets to a server.

LinuxSecurity.com: Felix Wilhelm discovered that the Evince document viewer made insecure use of tar when opening tar comic book archives (CBT). Opening a malicious CBT archive could result in the execution of arbitrary code. This update disables the CBT format entirely

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize function

LinuxSecurity.com: – Update to 1.1.12 – Fix Cross-site Scripting (XSS) issue with link.php (CVE-2017-10970) Release notes: https://www.cacti.net/release_notes.php?version=1.1.11 Release notes: https://www.cacti.net/release_notes.php?version=1.1.12

Risk Level: Very Low. Type: Trojan.

Gandi hosting’ logins breached; 751 domains diverted to malware site
OSX/Dok malware hits Macs; bypasses Apple’ Gatekeeper
Crooks Stealing Data From ATMs Using Infrared
Black Hat to Host Discussion on Diversity
Kerberos bypass, login theft bug slain by Microsoft, Linux slingers

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: New mariadb packages are available for Slackware 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.