Menu

Monthly Archives: April 2019

Wi-Fi Hotspot Finder Spills 2 Million Passwords
Is Privacy Really iPhone? Researchers Weigh in on Apple’s Targeted Ad Tracking
Evil TeamViewer Attacks Under the Guise of the U.S. State Department
France’s ‘Secure’ Telegram Replacement Hacked in an Hour
WannaCry Hero Pleads Guilty to Kronos Malware Charges
Can you get hit by someone else’s ransomware? [VIDEO]
Millions of Medical Documents for Addiction and Recovery Patients Leaked

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Out-of-bounds read and write conditions have been fixed in clamav. CVE-2019-1787

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

WannaCry hero Hutchins now officially a convicted cybercriminal
The Weather Channel goes offline after ransomware attack

debian-security-support, the Debian security support coverage checker, has been updated in jessie. The jessie relevant changes are: * Mark spice-xpi as end-of-life for Jessie.

An update that solves one vulnerability and has two fixes is now available.

A cross-site scripting vulnerability has been found in Drupal, a fully-featured content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2019-006 .

security update

WannaCry hero MalwareTech pleads guilty to writing banking malware
Wannacry-slayer Marcus Hutchins pleads guilty to two counts of banking malware creation
Microsoft’s Latest Patch Hoses Some Antivirus Software
Defense against the Darknet, or how to accessorize to defeat video surveillance
Not one of the 12 steps: Rehab patients’ details exposed in publicly visible database
Three-Fourths of Consumers Don’t Trust Facebook, Threatpost Poll Finds

An update that solves two vulnerabilities and has two fixes is now available.

ZNC could be made to crash or run programs if it received speciallycrafted network traffic.

Insecure Ride App Database Leaks Data of 300K Iranian Drivers

Reading Time: ~2 min. Major IT Outsourcer Suffers After Phishing Attack Global IT services provider Wipro announced they are in the process of investigating a data possibly affecting some of their clients. These types of companies are popular for hackers because, by breaching a single IT service company, they gain access to a far larger […]

Facebook: we logged 100x more Instagram plaintext passwords than we thought

An update that contains security fixes can now be installed.

Old-school cruel: Dodgy PDF email attachments enjoying a renaissance
Facebook: Storing Instagram passwords in plain text & harvesting your emails
We’ve read the Mueller report. Here’s what you need to know: ██ ██ ███ ███████ █████ ███ ██ █████ ████████ █████
Weather Channel Knocked Off-Air in Dangerous Precedent
Shopify Flaw Exposed Thousands of Merchants’ Revenue, Traffic Numbers
Who’s using Mueller Report Day to bury bad news? If you guessed Facebook, you’re right: Millions more passwords stored in plaintext

Fixes for https://bugzilla.redhat.com/show_bug.cgi?id=1697217

Fixes for https://bugzilla.redhat.com/show_bug.cgi?id=1694523

Poll: Facebook Harvests Email Contacts for 1.5M Users – Is Enough, Enough?

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes 11 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Facebook hoovered up 1.5 million users’ email contacts without permission… “unintentionally”
Facebook’s role in Brexit – and the threat to democracy
Easter Attack Affects Half a Billion Apple iOS Users via Chrome Bug

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Man fried over 50 college computers with weaponized USB stick

OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936) (CVE-2019-2602) * OpenJDK: Incorrect skeleton selection in RMI registry server-side dispatch handling (RMI, 8218453) (CVE-2019-2684) SL7 x86_64 java-11-openjdk-11.0.3.7-0.el7_6.i686.rpm java-11-openjdk-11.0.3.7-0.el7_6.x86_64.rpm java-11-openjdk-debuginfo-11.0.3.7-0.el7_6.i686.rpm java-11-openjdk-debuginfo- [More…]

Cisco Patches Critical Flaw In ASR 9000 Routers
Serious Security: Ransomware you’ll never find – and how to stop it
Facebook: Yeah, we hoovered up 1.5 million email address books without permission. But it was an accident!
Embracing creativity to improve cyber-readiness

How approaching cybersecurity with creativity in mind can lead to better protection from digital threats The post Embracing creativity to improve cyber-readiness appeared first on WeLiveSecurity

OpenJDK: Font layout engine out of bounds access setCurrGlyphID() (2D, 8219022) (CVE-2019-2698) * OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936) (CVE-2019-2602) * OpenJDK: Incorrect skeleton selection in RMI registry server-side dispatch handling (RMI, 8218453) (CVE-2019-2684) Bug Fix(es): * assert failure in coalesce.cpp: attempted to spill a non-spillable item SL6 [More…]

Facebook user data used as bargaining chip, according to leaked docs
Google plays Whack-A-Mole with naughty Android developers

An update that fixes one vulnerability is now available.

Chrome flaw on iOS leads to 500 million unwanted pop-up ads
Smashing Security #124: Poisoned porn ads, the A word, and why why why Wipro?
Oracle issues nearly 300 patches in quarterly update
Never Forget That You Are Being Watched
Google hits brand slam stamping AMP with more crypto glam

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Insane in the domain: Sea Turtle hackers pwn DNS orgs to dash web surfers on the rocks of phishing pages
Ubiquitous Bug Allows HIPAA-Protected Malware to Hide Behind Medical Images

security update

security update

An update that fixes one vulnerability is now available.

Researchers: Facebook’s Data-Leveraging Scandal Puts Users on Notice
Enough about me, why do you hate Kaspersky so much? Revealed: Insp Clouseau-esque bid to smear critics as shills
State-Sponsored DNS Hijacking Infiltrates 40 Firms Globally
Bug in EA’s Origin client left gamers open to attacks

The gaming company has rolled out a fix for the remote code execution vulnerability, so make sure you run the platform’s latest version The post Bug in EA’s Origin client left gamers open to attacks appeared first on WeLiveSecurity

ThreatList: Bad Bots Account for a Fifth of All Web Traffic, FinServ Hit the Worst
Oracle Squashes 53 Critical Bugs in April Security Update
A third-party patch for Microsoft’s Internet Explorer zero-day vulnerability
Extortion emails a go-go
It doesn’t matter if you don’t use Internet Explorer, you could still be at risk from this IE zero-day vulnerability
Mozilla to Apple: Protect user privacy with rotating phone IDs
Ad blocker firms rush to fix security bug
Internet Explorer browser flaw threatens all Windows users
Microsoft confirms Outlook.com and Hotmail accounts were breached
Hackers exploiting unpatched Chrome bug to target 500M iPhone users
Cyber-sec biz Fortinet coughs up $545,000 after ‘flogging’ rebadged Chinese kit to Uncle Sam – but why so low? We may be able to explain
Oracle splats 300 vulns in MySQL, Database, Fusion, etc, pours fresh brew of Java SE terms
The curious case of Spamhaus, a port scanning scandal, and an apparent U-turn
RatVermin Spyware Targets Ukraine Gov Agencies
Wipro Confirms Hack and Supply Chain Attacks on Customers
Crooks are selling “Digital Doppelgangers” to bypass anti-fraud protection