Menu

Monthly Archives: March 2019

Home DNA kit company now lets users opt out of FBI data sharing
Privacy Regulations Needed for Next-Gen Cars

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that solves four vulnerabilities and has one errata is now available.

Two vulnerabilities were discovered in SQLALchemy, a Python SQL Toolkit and Object Relational Mapper.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has four fixes is now available.

LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.

Counter-Strike 1.6 game client 0-day exploited to spread Belonard trojan
Hackers are using 19-year-old WinRAR bug to install nasty malware
SimBad malware on Play Store infected millions of Android devices

Several security issues were fixed in file.

Lone staffer killed our shields, claims etailer Gearbest after infosec bods peep at user deets

An update for openstack-octavia is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for ansible is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

DARPA is working on an open source, secure e-voting system
Intel releases patches for code execution vulnerabilities
G Suite admins can now disallow SMS and voice authentication
53% of Britain’s most frequent porn watchers aren’t aware that they’re about to be blocked
WordPress 5.1.1 patches dangerous XSS vulnerability
MySpace has lost all the music users uploaded between 2003 and 2015
Karpeles walks, Google and Microsoft board up Windows hole, and Android AV still sucks
UK code breakers drop Bombe, Enigma and Typex simulators onto the web for all to try

An update that fixes 18 vulnerabilities is now available.

Security fix CVE-2019-9210

Q&A: Crypto-guru Bruce Schneier on teaching tech to lawmakers, plus privacy failures – and a call to techies to act

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that fixes three vulnerabilities is now available.

What was that P word? Ah. Privacy. Yes, we’ll think about privacy, says FCC mulling cellphone location data overhaul

Reading Time: ~2 min. In late February, the notorious cryptojacking script engine called Coinhive abruptly announced the impending end to its service. The stated reason: it was no longer economically viable to run. Coinhive became infamous quickly following its debut as an innovative javascript-based cryptomining script in 2018. While Coinhive maintained that its service was […]

Welcome. You’re now in a timeline in which US presidential hopeful Beto was a member of a legendary hacker crew
Zillow sued for $60 million after mansion listing hijacked
Lenovo Patches High-Severity Arbitrary Code Execution Flaws

An update that fixes four vulnerabilities is now available.

An update that solves 8 vulnerabilities and has 73 fixes is now available.

Several security issues identified in ikiwiki fixed by updating to version 3.20190228. See references for details References: – https://bugs.mageia.org/show_bug.cgi?id=24453

Sextortion – what’s new, and what to do [VIDEO]

Reading Time: ~2 min. Georgia County Pays Six Figure Ransom to Restore IT Systems Following a ransomware attack earlier this month, officials in Jackson County, Georgia decided to pay a $400,000 ransom in order to obtain a decryption key and return their systems to normal operations. While it’s not normally recommended to pay ransoms, but […]

Unpatched Fujitsu Wireless Keyboard Bug Allows Keystroke Injection
You left WHAT on that USB drive?!
Public spending watchdog snipes at UK.gov’s £1.3bn infosec plan – but broadly nods it through
Facebook outage coincides with (or causes?) 3m new Telegram users
How to make DuckDuckGo your default Chrome search engine
Will the next version of Android get location privacy right?
So you need an IT security center. Fret not: Let an automated solution take the strain
Threatlist: IMAP-Based Attacks Compromising Accounts at ‘Unprecedented Scale’
Zero-Days in Counter-Strike Client Used to Build Major Botnet
Open-source 64-ish-bit serial number gen snafu sparks TLS security cert revoke runaround
Don’t be a WordPress RCE-hole and patch up this XSS vuln, pronto

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Serious Security: What we can all learn from #PiDay
Cisco Patches Critical ‘Default Password’ Bug
GlitchPOS Malware Appears to Steal Credit-Card Numbers
Online training site says it is spamming insecure printers with adverts

An update that fixes two vulnerabilities is now available.

Protip: If you’d rather cyber-scoundrels didn’t know the contents of your comp, don’t apply for a Pakistani passport
Man drives 3,300 miles to talk to YouTube about deleted video
“BreedReady” database of 1.8m Chinese women surfaced online
More than Half of Android apps ask for dangerous permissions. Is yours among?
Hackers cop a FILA thousands of UK card deets after slinking onto clothing brand’s servers

An update is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openstack-octavia is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openstack-ceilometer is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Pakistani Govt’s passport application tracking site hacked with Scanbox framework
US Senators say it shouldn’t be a secret when they’ve been hacked
Insider Threats Get Mean, Nasty and Very Personal
Google needs breaking up, says news chief
Update now! Microsoft’s March 2019 Patch Tuesday is here
Facebook suffer most severe outage ever

Facebook owned Instagram and WhatsApp also affected by unexplained interruption The post Facebook suffer most severe outage ever appeared first on WeLiveSecurity

An update for haproxy is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for haproxy is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

What do sexy selfies, search warrants, tax files have in common? They’ve all been found on resold USB sticks

Multiple vulnerabilities have been found in Oracles JDK and JRE software suites.

Multiple vulnerabilities have been found in BIND, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been found in WebkitGTK+, the worst of which could result in the arbitrary execution of code.

A vulnerability was discovered in XRootD which could lead to the remote execution of code.

Multiple Information Disclosure vulnerabilities in OpenSSL allow attackers to obtain sensitive information.

A vulnerability in the GNU C Library could result in a Denial of Service condition.

Thought you were done patching this week? Not if you’re using an Intel-powered PC or server
Smashing Security #119: Hijacked homes, porn passports, and ransomware regret
New Samsung Galaxy S10 review and features

security update

security update

Purveyor of Cracked Netflix, Hulu, Spotify Accounts Arrested
Just Android things: 150m phones, gadgets installed ‘adware-ridden’ mobe simulator games

Type: Vulnerability. Microsoft NuGet is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Common Control Library is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.