Menu

Monthly Archives: March 2019

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

Apple iOS 12.2 Patches 51 Serious Flaws

xmltooling could be made to crash if it opened a specially crafted file.

Red Hat Ansible Tower 3.3.5 2. Description: For a list of changes included in this release, please read the Ansible Tower Release Notes:

Red Hat Ansible Tower 3.4.3 2. Description: For a list of changes included in this release, please read the Ansible Tower Release Notes:

FEMA exposes sensitive data of 2.3 million disaster survivors

Reading Time: ~3 min. The last decade has been one of digital revolution, leading to the rapid adoption of new technology standards, often without the consideration of privacy ramifications. This has left many of us with a less-than-secure trail of digital breadcrumbs—something cybercriminals are more than aware of. Identity theft is by no means a […]

Several vulnerabilities have recently been discovered in libssh2, a client-side C library implementing the SSH2 protocol

Tech giants back bill that privacy advocates claim is toothless

An update that fixes one vulnerability is now available.

Hackers poison Asus software updates, may have infected one million PCs
Family tracking app spilled pics, names and real-time location data

openwsman: Disclosure of arbitrary files outside of the registered URIs (CVE-2019-3816) SL7 x86_64 libwsman1-2.6.3-6.git4391e5c.el7_6.i686.rpm libwsman1-2.6.3-6.git4391e5c.el7_6.x86_64.rpm openwsman-client-2.6.3-6.git4391e5c.el7_6.i686.rpm openwsman-client-2.6.3-6.git4391e5c.el7_6.x86_64.rpm openwsman-debuginfo-2.6.3-6.git4391e5c.el7_6.i686.rpm openwsman-debuginfo-2. [More…]

DXC Security exec: Yes, I’d have thought we’d spend more on certs and laptop kit for staff, too

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Huge news from Apple: No, not mags, games or TV – more than 50 security bugs to patch

Risk Level: Very Low. Type: Trojan, Virus.

Risk Level: Very Low. Type: Trojan, Virus.

Risk Level: Very Low. Type: Trojan, Virus.

ThreatList: Remote Workers Threaten 1 in 3 Organizations

security update

Spyware sneaks into ‘million-ish’ Asus PCs via poisoned software updates, says Kaspersky
Malware Payloads Hide in Images: Steganography Gets a Reboot
Medtronic cardiac implants can be hacked, FDA issues alert
Bugs in Grandstream Gear Lay Open SMBs to Range of Attacks

An update that fixes four vulnerabilities is now available.

Some ASUS Updates Drop Backdoors on PCs in ‘Operation ShadowHammer’
Two white hats hack a Tesla, get to keep it

The electric automaker is working to release a fix for the underlying vulnerability in a matter of days The post Two white hats hack a Tesla, get to keep it appeared first on WeLiveSecurity

Get trained to turn the tables on your computer adversaries at SANS Bucharest

Multiple scp client vulnerabilities have been discovered in OpenSSH, the premier connectivity tool for secure remote shell login and secure file transfer.

Firefox, Edge, Safari, Tesla & VMware pwned at Pwn2Own
FEMA leaks sensitive details of 2.3 million disaster survivors

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

FEMA Exposes PII for Millions of Hurricane, Wildfire Survivors

Two issues have been fixed in bash, the GNU Bourne-Again Shell: CVE-2016-9401

Thousands of API and cryptographic keys leaking on GitHub every day
Update now! WordPress hackers target Easy WP SMTP plugin
New ratings point to keyless cars that can stand up to relay attacks

Security fix for [CVE-2018-1000877 CVE-2018-1000878 CVE-2018-1000879 CVE-2018-1000880] —- Applied various flaws from upsteam

CVE-2018-19364: 9pfs: use-after-free (bz #1651359) CVE-2018-19489: 9pfs: use- after-free renaming files (bz #1653157) CVE-2018-16867: usb-mtp: path traversal issue (bz #1656746) CVE-2018-16872: usb-mtp: path traversal issue (bz #1659150) CVE-2018-20191: pvrdma: uar_read leads to NULL deref (bz #1660315) CVE-2019-6778: slirp: heap buffer overflow (bz #1669072) CVE-2019-3812: Out-of-

Geiger counters are so last summer. Lasers can detect radioactive material too, y’know

Update to 3.0. License has changed to ASL 2.0 + exception. See https://github.com/michaelrsweet/mxml/releases/tag/v3.0 for more info.

Trail of Bits used the automated vulnerability discovery tools developed for the DARPA Cyber Grand Challenge to audit zlib. As rsync, a fast, versatile, remote (and local) file-copying tool, uses an embedded copy of

security update

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

It was discovered that Wireshark, a network traffic analyzer, contained several vulnerabilities in the dissectors for 6LoWPAN, P_MUL, RTSE, ISAKMP, TCAP, ASN.1 BER and RPCAP, which could result in denial of service.

An arbitrary file read vulnerability was discovered in passenger, a web application server. A local user allowed to deploy an application to passenger, can take advantage of this flaw by creating a symlink from the REVISION file to an arbitrary file on the system and have its

Slack slings crypto-keys at big biz, union gets worked over, VPN owners probed, trolls trouble vets, and more

The package firefox before version 66.0.1-1 is vulnerable to arbitrary code execution.

security update

Several issues have been discovered in Apache module auth_mellon, which provides SAML 2.0 authentication. CVE-2019-3877

Facebook stored 600m user passwords in plain text exposed to 20k employees
Panic after hackers take control of emergency tornado alarms in Texas
Flaw in NSA’s GHIDRA leads to remote code execution attacks

**Version 2.7.2** (2019-03-12) * added TemplateWrapper::getTemplateName() —- **Version 2.7.1** (2019-03-12) * fixed class aliases —- **Version 2.7.0** (2019-03-12) * fixed sandbox security issue (under some circumstances, calling the __toString() method on an object was possible even if not allowed by the security policy) * fixed batch filter clobbers array keys when fill

**Version 1.38.2** (2019-03-12) * added TemplateWrapper::getTemplateName() —- **Version 1.38.1** (2019-03-12) * fixed class aliases —- **Version 1.38.0** (2019-03-12) * fixed sandbox security issue (under some circumstances, calling the __toString() method on an object was possible even if not allowed by the security policy) * fixed batch filter clobbers array

Backport a security fix from PuTTY 0.71 affecting SFTP connections: Fix an integer overflow in the RSA key exchange preceeding host key verification

This update addresses various overflow conditions that could result in possible memory read/write out of bounds errors or zero byte allocations when connected to a malicious server.

Facebook password crisis – what to do? [VIDEO]
Uncle Sam’s disaster agency FEMA creates disaster of its own: 2.3 million survivors’ personal records spilled
Security storm brewing for Oracle Java-powered smart cards: More than a dirty dozen flaws found, fixes… er, any fixes?
PewDiePie ransomware forcing users to subscribe him on YouTube
Spycams Secretly Live-Streamed 1,600 Motel Guests
Firefox and Edge Fall to Hackers on Day Two of Pwn2Own

security update

Google Play Touts Certs in Quest For Enterprise Security
Critical DoS Bug Bubbles Up in Facebook Fizz TLS 1.3 Project
Analysis: Drone Tech Creates New Type of Blended Threat

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Medtronic defibrillators vulnerable to life threatening cyber attacks

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

A heap-based buffer overflow was discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of this flaw for local root privilege escalation.

Reading Time: ~2 min. Gnosticplayers Adds 26 Million More Records for Sale After the first 3 major data dumps, which totaled over 600 million records, the hacker known as Gnosticplayers has released his latest cache of data, which contains at least 26 million personal user records. These data caches hold customer information for 32 companies […]

Medtronic Defibrillators Have Critical Flaws, Warns DHS

Libzip could be made to crash if it received specially crafted input.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0622

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0623

BitLocker hacked? Disk encryption – and why you still need it [VIDEO]
Microsoft Windows 7 patch warns of coming patchocalypse
Sacked IT guy annihilates 23 of his ex-employer’s AWS servers
Spycam sex videos of 1,600 motel guests sold to paying subscribers
Scammer pleads guilty to fleecing Facebook and Google of $121m
Hey, what’s Mandarin for ‘WTF is going on?’ Nokia phones caught spewing device IDs to China, software blunder blamed
Don’t have a heart attack but your implanted defibrillator can be hacked over the air (by someone who really wants you dead)

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes three vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

‘Sharing of user data is routine, yet far from transparent’ is not what you want to hear about medical apps. But 2019 is gonna 2019

Update tcpflow to 1.5.2 tag at github, fixing a security issue.

WordPress Plugin Patched After Zero Day Discovered

security update

security update

security update

Press Release: Guardian Digital Leverages the Power of Open Source to Combat Evolving Email Security Threats