Menu

Monthly Archives: April 2019

Don’t be Russian to judgement but… Bloke accused of $1.5m+ tax filing biz hack, fraud

Fix CVE-2019-11372

Fake Jason Statham Bilks a Fan Out of Serious Money

Fix CVE-2019-11372

**horde 5.2.21** * [mjr] SECURITY: Fix XSS vulnerability in the Cloud Block.

**turba 4.2.24** * [mjr] SECURITY: Fix XSS vulnerability in display of contact tags. * [jan] Clarify objectClass filter examples for LDAP backends (Ralf Lang).

security update

New Electrum DDoS botnet steals $4.6M after infecting 152,000 hosts

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability.

New ‘Sodinokibi’ Ransomware Exploits Critical Oracle WebLogic Flaw
Extortionist hacks IT provider used by the stars of tech and big biz, leaks customer info after ransom goes unpaid
Researchers Compromise Netflix Content in Widevine DRM Hack
BEC Hack Cons Catholic Church Out of $1.75 Million
Sensitive data of 80 million US households exposed online

libvirt-domain.c in libvirt supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required. This could lead to could lead to potentially disclosing unintended

Android users: watch out for this fake address bar trick
Oh dear. Sneaky Huawei enterprise router ‘backdoor’ was Telnet service, sighs Vodafone

An update that fixes two vulnerabilities is now available.

An update for openstack-neutron is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Dovecot could be made to crash if it received specially crafted network traffic.

An update for openstack-neutron is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for openstack-ceilometer is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openstack-neutron, openstack-neutron-lbaas, and python-networking-bigswitch is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact

An update for openstack-cinder is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Securing edge devices – how to keep the crooks out of your network

An update is now available for Red Hat Ceph Storage 3.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

A minor version update (from 7.2 to 7.3) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

An update that solves three vulnerabilities and has four fixes is now available.

Docker breach of 190,000 users exposes lack of two-factor authentication

WavPack could be made to crash if it received a speciallycrafted file.

Facebook under investigation for harvesting 1.5m users’ contact lists
Man posing as Hollywood superstar scams woman out of a ‘fortune’
Buhtrap backdoor and ransomware distributed via major advertising platform

Criminal activities against accountants on the rise – Buhtrap and RTM still active The post Buhtrap backdoor and ransomware distributed via major advertising platform appeared first on WeLiveSecurity

Chinese dev jailed and fined for posting DJI’s private keys on Github
From Docker Hub hack to Facebook’s burglar-friendly API to phone fingerprint bypasses…
Change your password: Docker suffers breach; 190k users affected
America’s anti-hacking laws are so loose, even Donald Trump Jr broke them. So, what do we do about it?
Malware Infests Popular Pirate Streaming Hardware

security update

MuddyWater APT Hones an Arsenal of Custom Tools
Apple Defends Parental Control App Removal Amid Backlash
Hackers targeting embassies with trojanized version of TeamViewer
5 Cybersecurity Best Practices You Should Be Following Right Now
Docker Hub Hack Affects 190K Accounts

An update that fixes two vulnerabilities is now available.

2 Million IoT Devices Vulnerable to Complete Takeover
Scammer posed as actor Jason Statham to steal from fan
Brit events and info biz Incisive Media admits open server port may have left readers deets exposed
NIST tool boosts chances of finding dangerous software flaws
Cryptocurrency giants in $850m fraud allegations

An update that solves one vulnerability and has four fixes is now available.

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that solves 11 vulnerabilities and has one errata is now available.

Cops need warrant for both location history and phone pinging, says judge

An update for rh-python35-python is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Piracy streaming apps are stuffed with malware

Evince could be made to expose sensitive information if it receiveda specially crafted file.

Several security issues were fixed in MySQL.

GStreamer Base Plugins could be made to crash or run programs if it received specially crafted network traffic.

Train up to navigate the diverse, chaotic cyber security landscape at SANS Munich

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Powershell, the Gandcrab infection and the long-forgotten server
Watch: Hackers send explicit messages to riders on hacked e-scooters

An update that fixes 16 vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that solves 8 vulnerabilities and has one errata is now available.

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that solves 5 vulnerabilities and has three fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has three fixes is now available.

7 Times Apple Watch Saved Lives

An update that solves one vulnerability and has two fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

So, how’s Facebook going to screw us next?
Docker Hub security breach exposes credentials of 190,000 users

A use-after-free vulnerability was discovered in the png_image_free() function in the libpng PNG library, which could lead to denial of service or potentially the execution of arbitrary code if a malformed image is processed.

security update

An update that solves 13 vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Reading Time: ~4 min. Today we chat with Web Analyst Manager Serena Peruzzi. Serena constantly filters through the web to analyze content. Sometimes her position requires looking through difficult material, but other times you can find her traveling, organizing company events, and even gardening!   See how Serena helps build Webroot’s company culture in this Employee […]

Users Urged to Disable WordPress Plugin After Unpatched Flaw Disclosed

Zack Flack found several issues in monit, a utility for monitoring and managing daemons or similar programs.

Hanno Bck discovered that GNOME Evolution is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted HTML email. This issue was mitigated by moving the security

News Wrap: Amazon Echo Privacy, Facebook FTC Fines and Biometrics Regulation
GoDaddy Shutters 14,000 Subdomains Tied to ‘Snake Oil’ Scams
Thousands of firms hit by Beapy malware using NSA hacking tools
Critical Flaws in Sierra Wireless 5G Gateway Allow RCE, Command Injection