Menu

Latest articles

Chrome bug that lets sites secretly record you ‘not a flaw’, insists Google
How to remove all your cookies, cached data, and browsing history from Opera

LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.

LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Samsung’s Latest Iris Scanners are Easily Fooled Recently, ethical hackers have been able to bypass Samsung’s […]

Risk Level: Very Low. Type: Trojan, Virus, Worm.

security update

iPhone – the likely cause of the EgyptAir Flight 804 crash
FreeRADIUS Update Resolves Authentication Bypass

LinuxSecurity.com: It was discovered that pattern-based ACLs in the Mosquitto MQTT broker could be bypassed. For the stable distribution (jessie), this problem has been fixed in

LinuxSecurity.com: A security fix for a systemd-resolved crash on a crafted DNS packet. Relevant only to systemd-resolved users (not enabled by default). No need to reboot or logout.

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-2496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2496), [CVE-2017-2539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2539), [CVE-2017-2510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus

LinuxSecurity.com: Fix for CVE-2016-8728 CVE-2016-8729 —- Rebuild with new jbig2dec

LinuxSecurity.com: An issue in `git-shell` could allow remote users to run an interactive pager. From the [update announcement](https://public- inbox.org/git/xmqq8tm5ziat.fsf@gitster.mtv.corp.google.com/): … fix a recently disclosed problem with “git shell”, which may allow a user who comes over SSH to run an interactive pager by causing it to spawn “git

News in brief: no laptop ban from EU for now; China warns on new laws; bug bounty scheme for DHS

Risk Level: Very Low. Type: Trojan.

Bug Lets Chrome Stealthily Record Audio and Video
Shadow Brokers double down on zero-day subscription service
Surprise! Extortionists have no qualms about claiming they ‘hacked’ your business
ShadowBrokers Put Price on Monthly Zero Day Leaks
Security of medical devices ‘is a life or death issue’, warns researcher
Judy malware campaign victimized as many as 36.5 million Android users
Why you should avoid Star Hop and Candy Link in Google Play
Get hacked, and watch your company’s share price plummet
How to get away with hacking the Department of Homeland Security

LinuxSecurity.com: USN-3212-1 caused a regression in LibTIFF.

LinuxSecurity.com: Several security issues were fixed in ImageMagick.

LinuxSecurity.com: Several security issues were fixed in WebKitGTK+.

LinuxSecurity.com: strongSwan could be made to crash or hang if it received specially crafted network traffic.

Tuesday review – the hot 24 stories of the week

LinuxSecurity.com: Two denial of service vulnerabilities were identified in strongSwan, an IKE/IPsec suite, using Google’s OSS-Fuzz fuzzing project. CVE-2017-9022

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Chinese Scam Website Caught Selling Hacked Xbox Accounts
US May Expand Laptop Ban to All International Flights
How Companies can stay Secure while using Omni-Channel

security update

Google Scraps Judy Malware Infected Apps Downloaded By 36M Android Users
Android ‘design shortcomings’ allow for Cloak and Dagger series of attacks
The good old NTFS bug in Windows strikes back but with a different name
Microsoft Quietly Patches Another Critical Malware Protection Engine Flaw
IT outage chaos: All British Airways Flights Canceled
Thousands of Critical Security Flaws Leave Pacemaker Vulnerable to Hackers
Democracy-minded DEF CON hackers promise punishing probe on US election computers
New Android Exploit ‘Cloak and Dagger’ Lets Attackers Steal User Data

security update

security update

Hackers alter stolen emails for clandestine attacks against Putin’s critics
News in brief: tech firms ‘must do more’ on terror’; romance scammers jailed; Disney film heist ‘a hoax’
Crysis ransomware master keys posted to Pastebin

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Mark Dowd on Exploit Mitigation Development
Pacemaker Ecosystem Fails its Cybersecurity Checkup
Threatpost News Wrap, May 26, 2017
Rash Of Phishing Attacks Use HTTPS To Con Victims
3 types of employees that can cause a data breach

When it comes to cybersecurity, what type of employee is most likely to cause a data breach? And how can companies protect themselves? The post 3 types of employees that can cause a data breach appeared first on WeLiveSecurity

Samba exploit – not quite WannaCry for Linux, but patch anyway!
A wormable code-execution bug has lurked in Samba for 7 years. Patch now!
Campaigners demand halt to Vermont’s use of facial recognition
5 Proven Cyber Security Certifications That Will Skyrocket Your Salary

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: A vulnerability in Smb4K could allow local attackers to execute commands as root.

LinuxSecurity.com: Teeworlds client vulnerability in snap handling could result in execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which could allow for privilege escalation.

WannaCry: the rush to blame XP masked bigger problems
Samba users urged to patch 7-year-old remote code execution flaw ASAP
Student hacks university computer; changes grade from F to B
Keybase Extension Brings End-to-End Encrypted Chat To Twitter, Reddit, GitHub
Revised Active Defense Bill Allows Victims to Recover or Destroy Stolen Data

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: MiniUPnP could be made to crash or run programs if it received specially crafted network traffic.

News in brief: Twitter pays $7,500 bounty; China gets ‘tweaked’ Windows; how to hide passwords
WannaCry Ransom Note Written by Chinese, English Speaking Authors
Put down the popcorn and patch your media player
Samba Patches Wormable Bug Exploitable With One Line Of Code
Google debuts a new way to follow your footsteps around the web
Russian Postal Service Hit by WannaCry Ransomware Attack
ICO urges businesses to focus on becoming GDPR compliant

The ICO says businesses should stop focussing on the consequences of non-compliance and instead be motivated by the advantages of getting GDPR right. The post ICO urges businesses to focus on becoming GDPR compliant appeared first on WeLiveSecurity

4 Reasons the Vulnerability Disclosure Process Stalls
YouTube, Twitter and Facebook face curbs on hate speech videos

LinuxSecurity.com: Firefox was updated to a new version.

Yup, the Android app store is full of useless, unwanted anti-WannaCry apps
Smashing Security #022: Walk this way… to defeat biometrics
Password Breaches Fueling Booming Credential Stuffing Business
Samsung Galaxy S8’ iris scanner hacked using contact lens and photo

LinuxSecurity.com: New samba packages are available for Slackware 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Samba could be made to run programs as an administrator.

Hackers have found a way to hijack your system through subtitles
Android Overlay and Accessibility Features Leave Millions at Risk
Europol busts 27 burglars for Black box-based ATM logic attacks
EU security body calls for a security trust mark for IoT devices
News in brief: drones could be hobbled; cost of ransomware counted; Target agrees $18.5m deal
Twitter Flaw Could Have Allowed Attacker to Tweet From Any Account
Police swoop on gang that planted banking Trojan on 1m phones