Menu

Monthly Archives: September 2018

LinuxSecurity.com: Zsh could be made to execute arbitrary code if it received a specially crafted script.

security update

LinuxSecurity.com: Henning Westerholt discovered a flaw related to the Via header processing in kamailio, a very fast, dynamic and configurable SIP server. An unauthenticated attacker can take advantage of this flaw to mount a denial of service attack via a specially crafted SIP message

Bad Actors Sizing Up Systems Via Lightweight Recon Malware
Millions of Records Exposed in Veeam Misconfigured Server
When is a patch not a patch? When it’s for this McAfee password bug

LinuxSecurity.com: A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Drive away a Tesla today (even if it isn’t yours)
Law firm seeking leak victims to launch £500m suit at British Airways
Live broadcast: Threat hunting in the modern attack landscape
Adobe Patches Six Critical Flaws in ColdFusion
The rise of targeted ransomware
Airbnb launches investigation after man finds hidden camera in clock
Abandoning a domain name can come back to bite you, research shows

A domain name once left behind can catch up with you – by giving fraudsters access to a treasure trove of sensitive information The post Abandoning a domain name can come back to bite you, research shows appeared first on WeLiveSecurity

Fetish app put users’ identities at risk with plain-text passwords
Magecart Group Pinned in Recent British Airways Breach
Yikes: 1 in 5 employees share their email passwords with coworkers

LinuxSecurity.com: Several security issues were fixed in the kernel.

Trend Micro apologises after Mac apps found scooping up users’ browser history
British Airways hack: Infosec experts finger third-party scripts on payment pages
Keybase browser extension weakness discovered
Microsoft extends security patch support for some Windows 7 users
Email security crisis… What email security crisis?

LinuxSecurity.com: An update is now available for Red Hat Fuse. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Safari, Edge fans: Is that really the website you think you’re visiting? URL spoof bug blabbed

LinuxSecurity.com: The system could be made to crash if it received specially craftednetwork traffic.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Subsystem for Linux is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure IoT SDK is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows kernel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft System.IO.Pipelines is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Lync for Mac is prone to a security-bypass vulnerability.

Type: Vulnerability. Microsoft Word PDF is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft OData is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows kernel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Jet Database Engine is prone to a buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Microsoft Jet Database Engine is prone to a buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Register-Orbi-damned: Netgear account order irks infosec bods
Tor(ched): Zerodium drops exploit for version 7 of anonymous browser

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several vulnerabilities were discovered in libextractor, a library to extract arbitrary meta-data from files, which may lead to denial of service or the execution of arbitrary code if a specially crafted file is opened.

Law firm launches £500 million group action over British Airways hack
Arms race: SiFive, Hex Five build code safe houses for RISC-V chips
ProtonVPN, NordVPN Flaws Open Door to Privilege Escalation
Trend Micro tools tossed from Apple’s Mac App Store after spewing fans’ browser histories
Tor Brings Onion Browser to Android Devices
Apple Finally Boots Sneaky Adware Doctor App from Mac App Store
Apple yanks top grossing app from Mac App Store for grabbing private user data

The several thousand glowing reviews that Adware Doctor had garnered prior to its removal were “likely fake”, researchers say The post Apple yanks top grossing app from Mac App Store for grabbing private user data appeared first on WeLiveSecurity

Mirai, Gafgyt Botnets Return to Target Infamous Apache Struts, SonicWall Flaws
Apps that steal users’ browser histories kicked out of the Mac App store
Apple’s new tool will make it easier for law enforcement to request data
Supermicro servers fixed after insecure firmware updating discovered
North Korean programmer charged for Sony, WannaCry attacks and more
Sextortion scum armed with leaked credentials are persistent pests
100 days of GDPR

What impact has the new data protection directive had on businesses so far? The post 100 days of GDPR appeared first on WeLiveSecurity