Menu

Monthly Archives: April 2019

The package evolution before version 3.32.0-1 is vulnerable to content spoofing.

Lazarus Group rises again from the digital grave with Hoplight malware for all
Smashing Security #123: Backups – a necessary evil?
The Samsung Galaxy S10’s ultrasonic fingerprint scanner is hacked

Backport more patches: – shared/install: Preserve escape characters for escaped unit names (https://github.com/coreos/bugs/issues/2569) – timedate: fix emitted value when ntp client is enabled/disabled (#1696586) – udev: run programs in the specified order (#1696784) – core: add Manager::honor_device_enumeration flag (https://pagure.io/fedora-

The scourge of stalkerware

Multiple vulnerabilities have been found in Git, the worst of which could result in the arbitrary execution of code.

SAS 2019: Joe FitzPatrick Warns of the ‘$5 Supply Chain Attack’
Taj Mahal and SneakyPastes: Kaspersky reveals pair of attacks menacing Asia, Middle East
You Can Now Get This Award-Winning VPN For Just $1/month

Type: Vulnerability. Microsoft Azure DevOps Server and Team Foundation Server are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server and Team Foundation Server are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server is prone to a spoofing vulnerability; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Open Enclave SDK is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge and Internet Explorer are prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows VBScript Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

An update that fixes 11 vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Yahoo Offers $117.5M Settlement in Data Breach Lawsuit
Ep. 027 – Honeypots, GPS rollover and the MySpace data vortex
Hackers claims to steal 6 million Israeli voters data
Samsung Galaxy S10’ biometric sensor hackable with copy of owner’s fingerprint
Cynet is Launching a Free Threat Assessment for Businesses
How to identify & protect yourself from online dating scams
Mar-a-Lago intruder had instant-malware-inflicting thumb drive

Several security issues were fixed in wpa_supplicant and hostapd.

Credential-stuffing attacks behind 30 billion login attempts in 2018

Streaming media feature among services that take the spotlight in a report on credential-stuffing attacks in 2018 The post Credential-stuffing attacks behind 30 billion login attempts in 2018 appeared first on WeLiveSecurity

Update now! Here’s the April Patch Tuesday roundup

Reading Time: ~5 min. Not that long ago, before data breaches dominated daily headlines, we felt secure with our social media apps. Conveniently, every website seemed to allow logging in with Facebook or Twitter instead of creating a whole new password, and families of apps quickly became their own industry. Third-party apps and games on social media platforms (remember […]

An update that solves three vulnerabilities and has 9 fixes is now available.

An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Check your Verizon FiOS Quantum Gateway G1100 router now
Two robocallers fined $3m for Google listings scam
King’s College London internal memo cops to account ‘compromise’ as uni resets passwords
Two teens charged with jamming school Wi-Fi to get out of exams

Several security issues were fixed in Apache.

It was discovered that SPIP, a website engine for publishing, did not properly sanitize its user input. This would allow an authenticated user to perform arbitrary command execution.

SAS 2019: Triton ICS Malware Hits A Second Victim

An update that solves one vulnerability and has 5 fixes is now available.

SAS 2019: Gaza Cybergang Blends Sophistication Levels in Highly Effective Spy Effort
SAS 2019: Meet ‘TajMahal,’ A New and Highly Advanced APT Framework
Shock revelation as massive American presidential election hack confirmed

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

update to the bugfix release 3.9.0

update to the bugfix release 3.9.0

New upstream release 0.14.2 which also fixes CVE-2019-3878 and CVE-2019-3877

It’s raining patches, Hallelujah! Microsoft and Adobe put out their latest major fixes

security update

Intel Patches High-Severity Flaws in Media SDK, Mini PC

An update that fixes one vulnerability is now available.

Best password managers for 2019
Yahoo! tries! again! with! 3 billion! email! account! theft! payout!

Various vulnerabilities were discovered in Samba, SMB/CIFS file, print, and login server/client for Unix

Adobe Fixes 24 Critical Flaws in Acrobat Reader, Flash, Shockwave Player

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Brit hacker jailed for strapping ransomware to smut site ad networks
Samsung Galaxy S10 Fingerprint Sensor Duped With 3D Print
Sharpen your security skills at SANS Dublin 2019
Shadow App Development: Insider Threat or Opportunity?
2 students arrested for disrupting school WiFi to skip exam

An update that fixes three vulnerabilities is now available.

An update for katello-installer-base which configures qpid-dispatch-router is now available for Red Hat Satellite 6.2 for RHEL 6 and Red Hat Satellite 6.2 for RHEL 7. Red Hat Product Security has rated this update as having a security impact

An update for katello-installer-base which configures qpid-dispatch-router is now available for Red Hat Satellite 6.4 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for katello-installer-base which configures qpid-dispatch-router is now available for Red Hat Satellite 6.3 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Knock and don’t run: the tale of the relentless hackerbots
Verizon Router Command Injection Flaw Impacts Millions
SAS 2019: 4 Stuxnet-Related APTs Form Gossip Girl, an ‘Apex Threat Actor’

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Chrome, Safari and Opera criticised for removing privacy setting
Airbnb says sorry after man detects hidden camera with network scan
Hacker unlocks Samsung S10 with 3D-printed fingerprint
Fired sysadmin pleads guilty to doxxing five senators on Wikipedia

An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

OceanLotus: macOS malware update

Latest ESET research describes the inner workings of a recently found addition to OceanLotus’s toolset for targeting Mac users The post OceanLotus: macOS malware update appeared first on WeLiveSecurity

Several security issues were fixed in Wget.

Several security issues were fixed in Wget.

SAS 2019: Genesis Marketplace Peddles 60K Stolen Digital Identities

An update for openssh is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Type: Vulnerability. Microsoft Windows VBScript is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.