b Ubuntu Security Notice USN-4338-2 By packetstormsecurity.com Published On :: Tue, 28 Apr 2020 15:00:17 GMT Ubuntu Security Notice 4338-2 - USN-4338-1 fixed vulnerabilities in re2c. This update provides the corresponding update for Ubuntu 20.04 LTS. Agostino Sarubbo discovered that re2c incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. Full Article
b Ubuntu Security Notice USN-4341-1 By packetstormsecurity.com Published On :: Tue, 28 Apr 2020 20:42:15 GMT Ubuntu Security Notice 4341-1 - Andrei Popa discovered that Samba incorrectly handled certain LDAP queries. A remote attacker could use this issue to cause Samba to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 19.10 and Ubuntu 20.04 LTS. It was discovered that Samba incorrectly handled certain LDAP queries. A remote attacker could possibly use this issue to cause Samba to consume resources, resulting in a denial of service. Various other issues were also addressed. Full Article
b Ubuntu Security Notice USN-4342-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:46:39 GMT Ubuntu Security Notice 4342-1 - Al Viro discovered that the Linux kernel for s390x systems did not properly perform page table upgrades for kernel sections that use secondary address mode. A local attacker could use this to cause a denial of service or execute arbitrary code. It was discovered that the Intel Wi-Fi driver in the Linux kernel did not properly check for errors in some situations. A local attacker could possibly use this to cause a denial of service. Various other issues were also addressed. Full Article
b Ubuntu Security Notice USN-4343-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:46:53 GMT Ubuntu Security Notice 4343-1 - Al Viro discovered that the Linux kernel for s390x systems did not properly perform page table upgrades for kernel sections that use secondary address mode. A local attacker could use this to cause a denial of service or execute arbitrary code. Full Article
b Ubuntu Security Notice USN-4344-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:55:05 GMT Ubuntu Security Notice 4344-1 - It was discovered that the Intel Wi-Fi driver in the Linux kernel did not properly check for errors in some situations. A local attacker could possibly use this to cause a denial of service. It was discovered that the Intel WiMAX 2400 driver in the Linux kernel did not properly deallocate memory in certain situations. A local attacker could use this to cause a denial of service. Various other issues were also addressed. Full Article
b Ubuntu Security Notice USN-4345-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:56:59 GMT Ubuntu Security Notice 4345-1 - Al Viro discovered that the Linux kernel for s390x systems did not properly perform page table upgrades for kernel sections that use secondary address mode. A local attacker could use this to cause a denial of service or execute arbitrary code. It was discovered that the Intel Wi-Fi driver in the Linux kernel did not properly check for errors in some situations. A local attacker could possibly use this to cause a denial of service. Various other issues were also addressed. Full Article
b Ubuntu Security Notice USN-4346-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:58:35 GMT Ubuntu Security Notice 4346-1 - It was discovered that the QLogic Fibre Channel driver in the Linux kernel did not properly check for error, leading to a NULL pointer dereference. A local attacker could possibly use this to cause a denial of service. It was discovered that the Intel Wi-Fi driver in the Linux kernel did not properly check for errors in some situations. A local attacker could possibly use this to cause a denial of service. Various other issues were also addressed. Full Article
b Ubuntu Security Notice USN-4341-3 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 16:05:01 GMT Ubuntu Security Notice 4341-3 - USN-4341-1 fixed vulnerabilities in Samba. The updated packages for Ubuntu 16.04 LTS introduced a regression when using LDAP. This update fixes the problem. It was discovered that Samba incorrectly handled certain LDAP queries. A remote attacker could possibly use this issue to cause Samba to consume resources, resulting in a denial of service. Various other issues were also addressed. Full Article
b Ubuntu Security Notice USN-4348-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 17:22:51 GMT Ubuntu Security Notice 4348-1 - It was discovered that Mailman incorrectly handled certain inputs. An attacker could possibly use this to issue execute arbitrary scripts or HTML. It was discovered that Mailman incorrectly handled certain inputs. An attacker could possibly use this issue to display arbitrary text on a web page. It was discovered that Mailman incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. Various other issues were also addressed. Full Article
b Ubuntu Security Notice USN-4341-2 By packetstormsecurity.com Published On :: Thu, 30 Apr 2020 14:46:29 GMT Ubuntu Security Notice 4341-2 - USN-4341-1 fixed a vulnerability in Samba. This update provides the corresponding update for Ubuntu 14.04 ESM. It was discovered that Samba incorrectly handled certain LDAP queries. A remote attacker could possibly use this issue to cause Samba to consume resources, resulting in a denial of service. Various other issues were also addressed. Full Article
b Ubuntu Security Notice USN-4333-2 By packetstormsecurity.com Published On :: Thu, 30 Apr 2020 14:48:19 GMT Ubuntu Security Notice 4333-2 - USN-4333-1 fixed vulnerabilities in Python. This update provides the corresponding update for Ubuntu 20.04 LTS. It was discovered that Python incorrectly stripped certain characters from requests. A remote attacker could use this issue to perform CRLF injection. Various other issues were also addressed. Full Article
b Ubuntu Security Notice USN-4349-1 By packetstormsecurity.com Published On :: Fri, 01 May 2020 13:52:43 GMT Ubuntu Security Notice 4349-1 - A buffer overflow was discovered in the network stack. An unprivileged user could potentially enable escalation of privilege and/or denial of service. This issue was already fixed in a previous release for 18.04 LTS and 19.10. A buffer overflow was discovered in BlockIo service. An unauthenticated user could potentially enable escalation of privilege, information disclosure and/or denial of service. This issue was already fixed in a previous release for 18.04 LTS and 19.10. Various other issues were also addressed. Full Article
b Ubuntu Security Notice USN-4350-1 By packetstormsecurity.com Published On :: Mon, 04 May 2020 17:29:10 GMT Ubuntu Security Notice 4350-1 - Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.80 in Ubuntu 19.10 and Ubuntu 20.04 LTS. Ubuntu 16.04 LTS and Ubuntu 18.04 LTS have been updated to MySQL 5.7.30. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Various other issues were also addressed. Full Article
b Ubuntu Security Notice USN-4330-2 By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:54:02 GMT Ubuntu Security Notice 4330-2 - USN-4330-1 fixed vulnerabilities in PHP. This update provides the corresponding update for Ubuntu 20.04 LTS. It was discovered that PHP incorrectly handled certain EXIF files. An attacker could possibly use this issue to access sensitive information or cause a crash. Various other issues were also addressed. Full Article
b Ubuntu Security Notice USN-4351-1 By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:27:24 GMT Ubuntu Security Notice 4351-1 - Eli Biham and Lior Neumann discovered that certain Bluetooth devices incorrectly validated key exchange parameters. An attacker could possibly use this issue to obtain sensitive information. Full Article
b Ubuntu Security Notice USN-4352-1 By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:33:27 GMT Ubuntu Security Notice 4352-1 - It was discovered that OpenLDAP incorrectly handled certain queries. A remote attacker could possibly use this issue to cause OpenLDAP to consume resources, resulting in a denial of service. Full Article
b Ubuntu Security Notice USN-4352-2 By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:33:32 GMT Ubuntu Security Notice 4352-2 - USN-4352-1 fixed a vulnerability in OpenLDAP. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. It was discovered that OpenLDAP incorrectly handled certain queries. A remote attacker could possibly use this issue to cause OpenLDAP to consume resources, resulting in a denial of service. Various other issues were also addressed. Full Article
b Best Buy Gift Cards, USB Drive Used To Spread Infostealer By packetstormsecurity.com Published On :: Sat, 28 Mar 2020 15:12:50 GMT Full Article headline malware fraud
b A Crypto-Mining Botnet Has Been Hijacking MSSQL Servers For Almost Two Years By packetstormsecurity.com Published On :: Wed, 01 Apr 2020 14:26:20 GMT Full Article headline hacker microsoft database fraud flaw cryptography
b Millions Of Guests Impacted In Marriott Data Breach, Again By packetstormsecurity.com Published On :: Wed, 01 Apr 2020 14:26:34 GMT Full Article headline hacker privacy bank cybercrime data loss fraud
b Microsoft Warns Hospitals About VPN Attacks During Coronavirus By packetstormsecurity.com Published On :: Thu, 02 Apr 2020 13:49:43 GMT Full Article headline hacker microsoft fraud cryptography
b Low-Orbit Internet Banking Fraud Claim Alleged To Be Space Junk By packetstormsecurity.com Published On :: Thu, 09 Apr 2020 14:33:35 GMT Full Article headline bank space fraud
b Coronavirus: Facebook Alerts Users Exposed To Misinformation By packetstormsecurity.com Published On :: Thu, 16 Apr 2020 15:30:39 GMT Full Article headline virus fraud facebook social
b Google Blocked 126 Million COVID-19 Phishing Scams In One Week By packetstormsecurity.com Published On :: Fri, 17 Apr 2020 15:22:41 GMT Full Article headline email virus cybercrime fraud google phish
b Nintendo Accounts Are Getting Hacked To Buy Fortnite Currency By packetstormsecurity.com Published On :: Tue, 21 Apr 2020 13:43:05 GMT Full Article headline hacker cybercrime fraud nintendo password
b Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads By packetstormsecurity.com Published On :: Wed, 22 Apr 2020 15:05:11 GMT Full Article headline hacker malware fraud backdoor
b ESET Takes Down VictoryGate Cryptomining Botnet By packetstormsecurity.com Published On :: Thu, 23 Apr 2020 19:15:16 GMT Full Article headline malware botnet fraud cryptography
b Hackers Turned Virginia Government Sites Into eBook Scam By packetstormsecurity.com Published On :: Fri, 08 May 2020 14:23:04 GMT Full Article headline hacker government usa fraud
b Blue Mockingbird Monero-Mining Campaign Exploits Web Apps By packetstormsecurity.com Published On :: Fri, 08 May 2020 14:23:17 GMT Full Article headline malware fraud cryptography
b Bradford ‘most improved UK city for growth’ By www.fdiintelligence.com Published On :: Thu, 12 Dec 2019 12:38:06 +0000 Bradford has been rated as the most improved city by the Good Growth for Cities 2019 index, while Oxford remained the highest performing UK city. Full Article
b Global FDI flows stable in 2019, reports Unctad By www.fdiintelligence.com Published On :: Wed, 22 Jan 2020 10:52:15 +0000 Global FDI flows recorded a marginal 1% fall in 2019, but the value of announced greenfield investment projects plummets by 22%. Full Article
b Tokyo world’s most talked about city online By www.fdiintelligence.com Published On :: Mon, 27 Jan 2020 09:03:59 +0000 ING Media names Tokyo, New York, London and Paris as global super brands for digital visibility. Full Article
b US tops global soft power ranking By www.fdiintelligence.com Published On :: Thu, 05 Mar 2020 15:49:30 +0000 The US has the world’s strongest soft power, while China and Russia are rising in influence, according to a recent ranking from Brand Finance. Full Article
b Trentino pioneers sustainable approach to cinema investment By www.fdiintelligence.com Published On :: Tue, 25 Feb 2020 13:26:50 +0000 Sustainability is gaining traction in the creative industries, with the Italian region of Trentino designing a film production rating protocol that is being considered by the EU. Full Article
b Finance minister seeks to keep Serbia in FDI spotlight By www.fdiintelligence.com Published On :: Thu, 13 Feb 2020 16:40:58 +0000 Serbia’s minister of finance, Siniša Mali, explains why the country is one of Europe's economic stars, and how its FDI levels have risen on the back of this. Full Article
b Serbia's automotive companies drive inward investment By www.fdiintelligence.com Published On :: Thu, 13 Feb 2020 16:41:16 +0000 Foreign investment into Serbia is growing at a healthy pace thanks to its attractive automotive manufacturing industry and highly regarded free zones. Full Article
b How Serbia has landed on the tech radar By www.fdiintelligence.com Published On :: Thu, 13 Feb 2020 16:40:18 +0000 Serbia’s technology cluster is gaining momentum and attracting FDI, for both its software and hardware expertise. Full Article
b Spotlight: Serbian free zones By www.fdiintelligence.com Published On :: Thu, 20 Feb 2020 16:04:00 +0000 Serbia’s 15 free zones are driving forward an ongoing flurry of foreign investment in the country’s buoyant manufacturing scene, especially in automotives. Full Article
b Safari Webkit Proxy Object Type Confusion By packetstormsecurity.com Published On :: Sun, 02 Jun 2019 15:30:59 GMT This Metasploit module exploits a type confusion bug in the Javascript Proxy object in WebKit. The DFG JIT does not take into account that, through the use of a Proxy, it is possible to run arbitrary JS code during the execution of a CreateThis operation. This makes it possible to change the structure of e.g. an argument without causing a bailout, leading to a type confusion (CVE-2018-4233). The type confusion leads to the ability to allocate fake Javascript objects, as well as the ability to find the address in memory of a Javascript object. This allows us to construct a fake JSCell object that can be used to read and write arbitrary memory from Javascript. The module then uses a ROP chain to write the first stage shellcode into executable memory within the Safari process and kick off its execution. The first stage maps the second stage macho (containing CVE-2017-13861) into executable memory, and jumps to its entrypoint. The CVE-2017-13861 async_wake exploit leads to a kernel task port (TFP0) that can read and write arbitrary kernel memory. The processes credential and sandbox structure in the kernel is overwritten and the meterpreter payloads code signature hash is added to the kernels trust cache, allowing Safari to load and execute the (self-signed) meterpreter payload. Full Article
b Ubuntu Security Notice USN-4130-1 By packetstormsecurity.com Published On :: Wed, 11 Sep 2019 20:00:19 GMT Ubuntu Security Notice 4130-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
b WhatWeb Scanner 0.5.0 By packetstormsecurity.com Published On :: Sat, 05 Oct 2019 13:11:29 GMT WhatWeb is a next-generation web scanner. WhatWeb recognises web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 1800 plugins, each to recognise something different. WhatWeb also identifies version numbers, email addresses, account IDs, web framework modules, SQL errors, and more. WhatWeb supports an aggression level to control the trade off between speed and reliability. Full Article
b Ubuntu Security Notice USN-4178-1 By packetstormsecurity.com Published On :: Fri, 08 Nov 2019 15:35:29 GMT Ubuntu Security Notice 4178-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
b Ubuntu Security Notice USN-4181-1 By packetstormsecurity.com Published On :: Tue, 12 Nov 2019 18:56:35 GMT Ubuntu Security Notice 4181-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
b Ubuntu Security Notice USN-4261-1 By packetstormsecurity.com Published On :: Thu, 30 Jan 2020 14:46:06 GMT Ubuntu Security Notice 4261-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
b Ubuntu Security Notice USN-4281-1 By packetstormsecurity.com Published On :: Tue, 18 Feb 2020 15:06:49 GMT Ubuntu Security Notice 4281-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
b WhatWeb Scanner 0.5.1 By packetstormsecurity.com Published On :: Tue, 25 Feb 2020 15:24:44 GMT WhatWeb is a next-generation web scanner. WhatWeb recognizes web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 1800 plugins, each to recognize something different. WhatWeb also identifies version numbers, email addresses, account IDs, web framework modules, SQL errors, and more. WhatWeb supports an aggression level to control the trade off between speed and reliability. Full Article
b Ubuntu Security Notice USN-4310-1 By packetstormsecurity.com Published On :: Mon, 30 Mar 2020 15:43:08 GMT Ubuntu Security Notice 4310-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
b Ubuntu Security Notice USN-4331-1 By packetstormsecurity.com Published On :: Mon, 20 Apr 2020 15:24:18 GMT Ubuntu Security Notice 4331-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
b Ubuntu Security Notice USN-4347-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 16:01:43 GMT Ubuntu Security Notice 4347-1 - A large number of security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
b Baby Monitors Watched By Hackers, Warn Experts By packetstormsecurity.com Published On :: Tue, 03 Mar 2020 14:01:17 GMT Full Article headline hacker privacy flaw spyware