Menu

Latest articles

LinuxSecurity.com: An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes is now available. is now available.

News in brief: Oz law ‘trumps maths’; CBP can’t search phones for cloud data; police launch drone unit
BUPA breach – why names and addresses matter
Vault 7: new WikiLeaks dump details Android SMS snooping malware
NemucodAES Ransomware, Kovter Click-Fraud Malware Spreading in Same Campaigns
Siemens Patches Authentication Bypass Flaw in SiPass Server
Beware bogus ‘WhatsApp subscription ending’ emails and texts

You ultimately decide what links you click on, and whether you hand over your passwords and payment card details. Always think twice, because the wrong decision could prove costly. The post Beware bogus ‘WhatsApp subscription ending’ emails and texts appeared first on WeLiveSecurity

Whose job is it to keep us safe from online harassment?
AlphaBay Marketplace busted; admin commits suicide in prison
Cisco Patches Publicly Disclosed SNMP Vulnerabilities in IOS, IOS XE
Dark Web Child Pornographer Avoids Jail Due To Asperger Syndrome 
U.S Bans Kaspersky Software For Links To Russia
Threatpost News Wrap, July 14, 2017
SQL injection attacks controlled using Telegram messaging app
Experts Warn Too Often AWS S3 Buckets Are Misconfigured, Leak Data

LinuxSecurity.com: updated to 2.6.1 (security bugfix release)

LinuxSecurity.com: – Update to 1.1.12 – Fix Cross-site Scripting (XSS) issue with link.php (CVE-2017-10970) Release notes: https://www.cacti.net/release_notes.php?version=1.1.11 Release notes: https://www.cacti.net/release_notes.php?version=1.1.12

LinuxSecurity.com: New upstream release fixing moderate security issue CVE-2017-7526.

Patching: Your questions answered

How do patches work? Could the Microsoft patch have stopped WannaCryptor? All your questions answered. The post Patching: Your questions answered appeared first on WeLiveSecurity

How Active Intrusion Detection Can Seek and Block Attacks
Insider who scammed $14.3m lottery ‘win’ pleads guilty

LinuxSecurity.com: – CVE-2017-1000083: Evince command injection vulnerability in CBT handler (#1468488)

LinuxSecurity.com: https://github.com/libexpat/libexpat/blob/R_2_2_1/expat/Changes

LinuxSecurity.com: – Update to 1.1.12 – Fix Cross-site Scripting (XSS) issue with link.php (CVE-2017-10970) Release notes: https://www.cacti.net/release_notes.php?version=1.1.11 Release notes: https://www.cacti.net/release_notes.php?version=1.1.12

LinuxSecurity.com: updated to 2.6.1 (security bugfix release)

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Verizon Call Logs Found Exposed Online Over the past month, researchers have been learning more about […]

CIA Highrise Android Malware Spies On SMS Messages: WikiLeaks

security update

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

News in brief: Health insurer breached; Vertu calls it quits; Audi tops autonomy
Beware – “Fake Tor Browser Rodeo” Scamming Unsuspecting Users
Scanner Shows EternalBlue Vulnerability Unpatched on Thousands of Machines
Attackers Using Automated Scans to Takeover WordPress Installs

LinuxSecurity.com: An integer overflow has been found in the HTTP range module of Nginx, a high-performance web and reverse proxy server, which may result in information disclosure.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

How did the data of 14m Verizon customers end up online?
Google Changes How it Analyzes Misbehaving Mobile Apps
Who gets gold stars for looking after your privacy?
Microsoft’ Calibri font hinges Pakistan’s entire government
Bupa warns health insurance information exposed by rogue employee

LinuxSecurity.com: Evince could be made run programs as your login if it opened a specially crafted file.

How app developers are gaming Google Play to boost their rankings
Are you looking at me? Welcome to the world of facial recognition
So long, Windows Phone – it was nice knowing you
What is new in OpenSSH 7.4 (in RHEL 7.4)?
Hackers able to turbo-charge DJI drones way beyond what’s legal

LinuxSecurity.com: Updated to the latest version; Security fix for CVE-2017-10788

The Magala trojan makes its money dishonestly by clicking on ads in your browser

LinuxSecurity.com: An update that solves 15 vulnerabilities and has 162 fixes An update that solves 15 vulnerabilities and has 162 fixes An update that solves 15 vulnerabilities and has 162 fixes is now available. is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

14 Million Verizon Customer Records Exposed

security update

security update

Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.

Third Party Exposes 14 Million Verizon Customer Records
New Point-of-Sale Malware LockPoS Hitches Ride with FlokiBot
News in brief: probe in Jupiter fly-by; footage of politician ‘not illegal’; Trump sued over Twitter block
LeakerLocker Android Ransomware: Pay or Your Data Will Be Leaked
Uber Patches Authentication Bypass Vulnerability on Custom SSO Solution
SAP Patches High-Risk Flaws in SAP POS, Host Agent
Social engineering – explored and explained by our experts [VIDEO]
Researchers find chinks in the armour of satellite phone calls
Trump Hotels’ Booking System Hacked, Credit Card Data Stolen
Industrial control security practitioners worry about threats … for a reason

Recent research from the SANS Institute confirms that security of industrial control systems is increasingly seen and understood to be a serious issue. The post Industrial control security practitioners worry about threats … for a reason appeared first on WeLiveSecurity

LinuxSecurity.com: This update updates QtWebEngine to the 5.9.1 release, a security and bugfix release from the 5.9 branch. QtWebEngine 5.9.1 is part of the Qt 5.9.1 release, but only the QtWebEngine component is included in this update. The update fixes the following security issues in QtWebEngine 5.9.0: CVE-2017-5070, CVE-2017-5071, CVE-2017-5075, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078,

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Vulnerabilities Expose Oracle OAM 10g to Remote Session Hijacking
Firms that didn’t patch and enabled local admin rights continue to suffer post cyber-attack
Russians told to log in to Pornhub using verified social media accounts
Linux Foundation launches Open Security Controller Project
Mingis on Tech: How linguistics can help catch cyberattackers
Trump Hotels customers hit by credit-card stealing hackers. Again.

LinuxSecurity.com: https://github.com/libexpat/libexpat/blob/R_2_2_1/expat/Changes

LinuxSecurity.com: New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017

Microsoft issues critical security patches. Have you updated yet?
LDAP & RDP Relay Flaws Found in Windows Security Protocols
Telegram-Controlled Hacking Tool Targets SQL Injection at Scale
Microsoft Patch Tuesday Update Fixes 19 Critical Vulnerabilities
News in brief: dark web sites attacked; radio station pwnd; Russian hacker jailed for nine years
Microsoft Addresses NTLM Bugs That Facilitate Credential Relay Attacks

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Mark your calendar for the net neutrality Day of Action
Adobe Fixes Six Vulnerabilities in Flash, Connect with July Update
Adobe Flash Player users should update their software NOW

Critical security holes keep being found in Adobe Flash Player. Have you updated yours yet? The post Adobe Flash Player users should update their software NOW appeared first on WeLiveSecurity

Creators of dark web chat room arrested for facilitating child abuse
Two-factor via your mobile phone – should you stop using it?