Menu

Monthly Archives: April 2019

Microsoft reveals breach affecting webmail users

Some users of Microsoft’s web-based email services such as Outlook.com had their account information exposed in an incident that, as it later emerged, also impacted email contents The post Microsoft reveals breach affecting webmail users appeared first on WeLiveSecurity

Windows Zero-Day Emerges in Active Exploits
Your Android phone can now double as a security key

An extra layer of security never hurt anybody, doubly so now that you can turn your phone into a physical security key The post Your Android phone can now double as a security key appeared first on WeLiveSecurity

Malspam Campaigns Distribute HawkEye Keylogger, Post Ownership Change
Kaspersky updates its cybercrook look book: Smashing Office is hot, browser vulns are not
Hackers bragged that pretty vanilla breach included FBI watchlist? Well, colour us shocked
Watch out! Don’t fall for the Instagram ‘Nasty List’ phishing attack
Google’s location history data shared routinely with police
US feds’ names, home and email addresses hacked and posted online
Indian outsourcing giant Wipro confirms flushing phishers from systems
Security weakness in popular VPN clients

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Top 10 Best Anime Movie Sites 2019
What’s long, hard, and full of seamen? The US Navy’s latest cybersecurity war gaming classes
Just a little FYI: Filtering doodad in Adblock Plus opens door to third-party malware injection
TicTocTrack Smartwatch Flaws Can Be Abused to Track Kids
Fake Instagram Apps on Google Play Harvest User Logins
Authentication Bypass Bug Hits Top Enterprise VPNs
Top VPNs found improperly securing cookies & tokens
Microsoft Outlook Breach Widens in Scope, Impacting MSN And Hotmail – Report
Brit Watchkeeper drone fell in the sea because blocked sensor made algorithms flip out
Hackers could read users’ Outlook, Hotmail, and MSN email via compromised Microsoft support account
Flood of exploits targetting ancient WinRAR flaw continues
Microsoft’s Edge browser reborn after Chromium makeover
Is there a link between videogaming and cybercrime? Police think so
Rogue Waves: Preparing the Internet for the Next Mega DDoS Attack
Dragonblood: Data-leaking flaw in WPA3 Wi-Fi authentication
Top The Pirate Bay Alternatives – Best Torrent Download Sites (2019)
Can you detect hidden cameras in hotel rooms? [VIDEO]
Wikileaks founder Julian Assange arrested in London
Nasty Android & iOS malware found using govt surveillance tech

Several security vulnerabilities were discovered in Graphicsmagick, a collection of image processing tools. Heap-based buffer over-reads and a memory leak may lead to a denial-of-service or information disclosure.

This update backports a fix for CVE-2018-20096, CVE-2018-20097, CVE-2018-20098, CVE-2018-20099.

* Yaws ver. 2.0.6

The update of jasper issued as DLA-1628-1 caused a regression due to the fix for CVE-2018-19542, a NULL pointer dereference in the function jp2_decode, which could lead to a denial-of-service. In some cases not only invalid jp2 files but also valid jp2 files were rejected.

This update fixes security vulnerability – Checkstyle loads external DTDs by default. Upstream issue: https://github.com/checkstyle/checkstyle/issues/6474 https://github.com/checkstyle/checkstyle/issues/6478 References: https://checkstyle.org/releasenotes.html#Release_8.18

An update that solves two vulnerabilities and has four fixes is now available.

rssh could be made to run arbitrary commands if it received specially crafted input.

This update fixes security vulnerability – Checkstyle loads external DTDs by default. Upstream issue: https://github.com/checkstyle/checkstyle/issues/6474 https://github.com/checkstyle/checkstyle/issues/6478 References: https://checkstyle.org/releasenotes.html#Release_8.18

Hackers post private data of thousands of Federal agents online
IE under fire, Triton goes under the microscope, and Norsk still reeling from ransomware attack

Reading Time: ~4 min. The process of bringing a cybersecurity product to market can be long and tedious, but Kiran Kumar, Product Director at Webroot, loves to oversee all the moving parts. It keeps him on his toes and immersed in the ever-changing world of security technology. We sat down to chat with Kumar about […]

security update

US-Cert alert! Thanks to a massive bug, VPN now stands for “Vigorously Pwned Nodes”

security update

security update

Risk Level: Very Low. Type: Trojan, Worm.

Bucharest’s Bayrob boys blasted based on bogus buys, Bitcoin banditry, bound to be behind bars
Romanian Duo Convicted of Malware Scheme Infecting 400,000 Computers

Reading Time: ~2 min. Tax Extortion Emails Bring Major Threats A new email campaign has been spotted threatening ransomware and DDoS attacks over fake tax documents allegedly held by the attackers if a Bitcoin ransom isn’t paid. The campaign authors also threaten to send fake tax documents to the IRS through a poorly-worded ransom email […]

North Korea’s Hidden Cobra Strikes U.S. Targets with HOPLIGHT

An update that fixes one vulnerability is now available.

WordPress Yellow Pencil Plugin Flaws Actively Exploited

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 13 fixes is now available.

ThreatList: Tax Scammers Launch a Raft of Fake Mobile Apps
Bayrob malware gang convicted of infecting over 400,000 computers worldwide, stealing millions through online auction fraud
Hackers crack university defenses in just two hours

More than 50 universities in the United Kingdom had their cyber-defenses tested by ethical hackers, and the ‘grades’ aren’t pretty The post Hackers crack university defenses in just two hours appeared first on WeLiveSecurity

Assange arrested, faces extradition for hacking
Hear me speak about how to make a billion dollars through cybercrime
Feds say Russian 2016 election meddling spanned all US states
Flickr tackling online image theft with new AI service

An update that fixes one vulnerability is now available.

US: We’ll pull security co-operation if you lot buy from Huawei
Android phones transformed into anti-phishing security tokens

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0710

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0697

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0717

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0711

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has 15 fixes is now available.

Risk Level: Very Low. Type: Trojan, Worm.

Bug-hunters punch huge holes in WPA3 standard for Wi-Fi security
Client-attorney privilege? Not when you’re accused of leaking Vault 7 CIA code
Juniper slips out update after hardcoded credentials left in switches
As Alexa’s secret human army is revealed, we ask: Who else has been listening in on you?
WordPress Urges Users to Uninstall Yuzo Plugin After Flaw Exploited
SAS 2019: Fake News Peddlers Adopt Clever New Trick to Fool Facebook, Twitter
WPA3 flaws may let attackers steal Wi-Fi passwords

The new wireless security protocol contains multiple design flaws that hackers could exploit for attacks on Wi-Fi passwords The post WPA3 flaws may let attackers steal Wi-Fi passwords appeared first on WeLiveSecurity

Serious Security: How web forms can steal your bandwidth and harm your brand
Uncle Sam charges Julian Assange with conspiracy to commit computer intrusion
High-rolling hacker jailed after launching malware attacks via porn websites
Patch blues-day: Microsoft yanks code after some PCs are rendered super secure (and unbootable) following update
Amazon Auditors Listen to Echo Recordings, Report Says

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Ban the use of ‘dark patterns’ by tech companies, say US lawmakers
App could have let attackers locate and take control of users’ cars
Toddler locks father out of iPad for 25.5 MILLION minutes, or until 2067

Several security issues were fixed in Ruby.

An update for ceph and grafana is now available for Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

As you wrap up this month’s patch installs, don’t forget these four Intel fixes

An update for httpd24-httpd and httpd24-mod_auth_mellon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Mathy Vanhoef (NYUAD) and Eyal Ronen (Tel Aviv University & KU Leuven) found multiple vulnerabilities in the WPA implementation found in wpa_supplication (station) and hostapd (access point). These vulnerability are also collectively known as “Dragonblood”.

The package apache before version 2.4.39-1 is vulnerable to multiple issues including privilege escalation, access restriction bypass and denial of service.

The package thunderbird before version 60.6.1-1 is vulnerable to arbitrary code execution.

The package gnutls before version 3.6.7-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.