Menu

Monthly Archives: May 2019

Online graphic-design tool Canva hacked; 139 million accounts stolen

Update to version 0.9.5.4. Resolves CVE-2018-20433 and CVE-2019-5427.

Two weeks after Microsoft warned of Windows RDP worms, a million internet-facing boxes still vulnerable

**MySQL 8.0.16** **Release notes:** https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-16.html **Devel Blog:** https://mysqlserverteam.com/the-mysql-8-0-16-maintenance-release- is-generally-available/ **Bugs fixed:** A lot of tests fixed **CVEs fixed:** Unfortunatelly, I don’t have the list of truly CVEs affecting

Update to version 0.9.5.4. Resolves CVE-2018-20433 and CVE-2019-5427.

Germany mulls giving end-to-end chat app encryption das boot: Law requiring decrypted plain-text is in the works
200k Personal Records Exposed by Events Planning Firm
Gatekeeper Bug in MacOS Mojave Allows Malware to Execute
Millions of Canva users’ data stolen as GnosticPlayers strikes again
Equifax stripped of ‘stable’ outlook over 2017 breach

Add that to the US$1.4 billion that the massive incident has cost the company so far The post Equifax stripped of ‘stable’ outlook over 2017 breach appeared first on WeLiveSecurity

One Million Devices Open to Wormable Microsoft BlueKeep Flaw

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The package webkit2gtk before version 2.24.2-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

Google-protected mobile browsers were open to phishing for over a year

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

pacemaker: Insufficient local IPC client-server authentication on the client’s side can lead to local privesc (CVE-2018-16877) * pacemaker: Insufficient verification inflicted preference of uncontrolled processes can lead to DoS (CVE-2018-16878) * pacemaker: Information disclosure through use-after-free (CVE-2019-3885) SL7 x86_64 pacemaker-1.1.19-8.el7_6.5.x86_64.rpm pacemaker-cl [More…]

World’s most dangerous laptop has been sold for $1.3 million
Redditor can stay anonymous, court rules
Hackers breach US license plate scanning company

The package firefox before version 67.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, same-origin policy bypass, content spoofing, information disclosure, cross-site scripting and denial of service.

The package thunderbird before version 60.7.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, same-origin policy bypass, information disclosure and denial of service.

US Senate passes anti-robocalling bill

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has 9 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes four vulnerabilities is now available.

Seize the chance to boost your IT security skills: SANS London has plenty of courses for you
What to do if your email is found on the Dark Web

Risk Level: Very Low. Type: Trojan.

YouTuber hacks fingerprint scanner of OnePlus 7 Pro using hot glue
Baltimore city ransomware attack is powered by stolen NSA hacking tool

Risk Level: Very Low. Type: Trojan.

An update that fixes one vulnerability is now available.

Chinese Spy Group Mixes Up Its Malware Arsenal with Brand-New Loaders

An update that fixes four vulnerabilities is now available.

ThreatList: Top 8 Threat Actors Targeting Canada in 2019

An update for pacemaker is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for pacemaker is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that solves 5 vulnerabilities and has 6 fixes is now available.

Risk Level: Very Low. Type: Trojan.

Why So Many Businesses Can Never Recover After Cyber Attacks
Xbox Two vs PlayStation 5: Which console is winning the race of anticipation?

It was discovered that there was a use after free vulnerability in minissdpd, a network device discovery daemon. A remote attacker could abuse this to crash the process.

Code cleanups and Simplifications: * in stream instance and main connection output handling for a common strategy in h2/h2c versions of the protocol. Stream instances are kept in one place which will make future optimizations in state handling easier. * Discarding idea of re-using bucket beams and let them live for one request only. Removing […]

security update

security update

security update

cURL, an URL transfer library, contains a heap buffer overflow in the function tftp_receive_packet() that receives data from a TFTP server. It calls recvfrom() with the default size for the buffer rather than with the size that was used to allocate it. Thus, the content that

Serious Security: Don’t let your SQL server attack you with ransomware

Reading Time: ~4 min. In a constantly evolving cyber landscape, it’s no simple task to keep up with every new threat that could potentially harm customers. Webroot Senior Threat Research Analyst Kelvin Murray highlighted the volume of threats he and his peers are faced with in our latest conversation. From finding new threats to answering questions from the press, Kelvin has become a trusted voice in the cybersecurity industry. What is your favorite part of working […]

A read past allocated buffer vulnerability and two heap-buffer overflow vulnerabilites were discovered in the PHP5 programming language within the Exif image module.

Millions of personal files exposed by insurance biz, serial web hacker strikes again, and more from infosec land

Several vulnerabilities have been found in wireshark, a network traffic analyzer. CVE-2019-10894

Security fix for CVE-2019-12083

Snapchat Privacy Blunder Piques Concerns About Insider Threats
Joomla and WordPress Found Harboring Malicious Redirect Code
Crypto tumbler BestMixer.io seized for large-scale money laundering
Microsoft Beefs Up Wi-Fi Protection

Reading Time: ~2 min. Banking Trojan Shuts Down Ohio School District After the discovery of the banking Trojan known as Trickbot, an Ohio school district was forced to cancel school since they were unable to fully disinfect the networks before classes resumed the following Monday. Preliminary reports have concluded that no students were responsible for […]

London Underground passengers told to turn off their Wi-Fi if they don’t want to be tracked

An update that fixes 5 vulnerabilities is now available.

News Wrap: Which Companies Are Doing Privacy Right and Which Aren’t?
Snapchat workers snooped on users with internal tool

A vulnerability was found in the WPA protocol implementation found in wpa_supplication (station) and hostapd (access point). The EAP-pwd implementation in hostapd (EAP server) and wpa_supplicant (EAP

Any advance on $1.2m for this virus-infested netbook?

An update that fixes 5 vulnerabilities is now available.

Safari test points to a future with tracker-free ads

An update that fixes one vulnerability is now available.

Batterygate news: Apple to warn users if iOS updates throttle iPhones
Google Ad Exchange in data privacy probe
Maker of US border’s license-plate scanning tech ransacked by hacker, blueprints and files dumped online
WikiLeaks boss Assange acted as a foreign spy, Uncle Sam exclaims in fresh rap sheet
Goodbye Passwords: Hello Identity Management

security update

security update

Why telcos ‘handed over’ people’s GPS coords to a bounty hunter: He just had to ask nicely
Shade Ransomware Expands to U.S. Targets
Calibration Attack Drills Down on iPhone, Pixel Users
World’s most dangerous laptop ‘Persistence of Chaos’ is up for auction
Smashing Security #129: Too Long; Didn’t Listen
British Army cyber ‘n’ psyops unit 77 Brigade can’t even brainwash civvies into helping it meet recruitment targets
SandboxEscaper Drops Three More Windows Exploits, IE Zero-Day
Download official version of Tor browser on Android devices

An update that fixes three vulnerabilities is now available.

Soaring Cryptocurrency Prices Draw Malicious New Onslaught of Apps, Malware

Security fix for CVE-2019-11328

Google stored some passwords in plaintext for 14 years
We’ll hack back at Russians, declare UK ministers in cyber-Blitz blitz
Tor Browser for Android 8.5 offers mobile users privacy boost
Mozilla fixes bugs, improves privacy in latest Firefox release
The city of Baltimore is being held hostage by ransomware
Phisher folk reel in Computacenter security vetting mailbox packed with sensitive staff data
Fake cryptocurrency apps crop up on Google Play as bitcoin price rises

ESET researchers have analyzed fake cryptocurrency wallets emerging on Google Play at the time of bitcoin’s renewed growth The post Fake cryptocurrency apps crop up on Google Play as bitcoin price rises appeared first on WeLiveSecurity

WannaCry-Infested Laptop Starts at $1.13M in Art Auction
Fingerprinting iPhones with the built-in gyroscope
Critical Flaws in Khan Academy Opened Door to Account Takeovers
Patch now! Why the BlueKeep vulnerability is a big deal

What you need to know about the critical security hole that could enable the next WannaCryptor The post Patch now! Why the BlueKeep vulnerability is a big deal appeared first on WeLiveSecurity

Google says it stored some G Suite passwords in plain text for 14 years