Menu

Monthly Archives: May 2019

US Air Force probes targeted malware attack, blames… er, the US Navy? What?
Windows Zero-Day Drops on Twitter, Developer Promises 4 More

An update that fixes four vulnerabilities is now available.

Google Stored G Suite Passwords in Plaintext Since 2005
Google stored business customers’ passwords in plaintext on its servers… for 14 years
Data on millions of Instagram accounts spills onto the internet
Cache of 49 million Instagram records found online

An update that fixes one vulnerability is now available.

Some Androids don’t call 911 when you tell them to call an ambulance
Don’t break Windows 10 by deleting SID, Microsoft warns
6 keys to MongoDB database security
Most hackers for hire are scammers, research shows
A journey to Zebrocy land

ESET sheds light on commands used by the favorite backdoor of the Sednit group The post A journey to Zebrocy land appeared first on WeLiveSecurity

An update for python27-python and python27-python-jinja2 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dotnet is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Bug-hunter reveals another ‘make me admin’ Windows 10 zero-day – and vows: ‘There’s more where that came from’
G Suite’n’sour: Google resets passwords after storing some unhashed creds for months, years

An update that fixes 5 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Database with millions of Instagram influencers’ info leaked online

Updates the nss package to upstream NSS 3.44. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.44_release_notes

– New upstream version (67.0) – Release notes are available at https://www.mozilla.org/en-US/firefox/67.0/releasenotes/

Mozilla Tackles Two Critical Flaws with Firefox 67 Release
Intel Fixes Critical, High-Severity Flaws Across Several Products
Data Security in the Cloud: How to Lock Down the Next-Gen Perimeter

An update that fixes 5 vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Hackers hacked: Account hijacking forum OGUsers pwned
What the ban on facial recognition tech will – and will not – do

As San Francisco moves to regulate the use of facial recognition systems, we reflect on some of the many ‘faces’ of the fast-growing technology The post What the ban on facial recognition tech will – and will not – do appeared first on WeLiveSecurity

Cisco Starts Patching Firmware Bug; Millions of Devices Still Vulnerable
Cybersecurity training and awareness: helpful resources for educators

Free resources for cybersecurity awareness and training are out there – links to many of them are provided here The post Cybersecurity training and awareness: helpful resources for educators appeared first on WeLiveSecurity

HCL Exposes Customer, Personnel Info in Wide-Ranging Data Leak
Millions of Golfers Land in Privacy Hazard After Cloud Misconfig
Mining cryptocurrency at work lands Australian civil servant in court
Deep Packet Inspection a threat to net neutrality, say campaigners

Reading Time: ~3 min. Technology has unlocked a new type of worker, unlike any we have seen before—the digital nomad. Digital nomads are people who use technologies like WiFi, smart devices, and cloud-based applications to work from wherever they please. For some digital nomads, this means their favorite coffee shop or co-working space. For others, it means an idyllic […]

Amnesty sues maker of Pegasus, the spyware let in by WhatsApp zero day
Rats leave the sinking ship as hackers’ forum gets hacked
iPhone gyroscopes, of all things, can uniquely ID handsets on anything earlier than iOS 12.2

An update that fixes two vulnerabilities is now available.

WordPress plugin sees second serious security bug in six weeks

An update that fixes four vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Gmail wittingly storing your online purchase data for years

Fixes possible man-in-the-middle security vulnerability – CVE-2019-11065

This update fixes security vulnerability – Checkstyle loads external DTDs by default. Upstream issue: https://github.com/checkstyle/checkstyle/issues/6474 https://github.com/checkstyle/checkstyle/issues/6478 References: https://checkstyle.org/releasenotes.html#Release_8.18

Sharing Threat Intelligence: Time for an Overhaul
Windows 10 Update Bricks PCs, Microsoft Offers Workarounds
Salesforce Woes Linger as Admins Clean Up After Service Outage
Sophos tells users to roll back Microsoft’s Patch Tuesday run if they want PC to boot
Behind the Naming of ZombieLoad and Other Intel Spectre-Like Flaws
Google bans Huawei from accessing Android & its licensed apps
Boeing admits 737 Max sims didn’t accurately reproduce what flying without MCAS was like
Slack Bug Allows Remote File Hijacking, Malware Injection
ZombieLoad: How Intel’s Latest Side Channel Bug Was Discovered and Disclosed
CEO told to hand back 757,000 fraudulently obtained IP addresses
Brave browser concerned that Client Hints could be abused for tracking

Multiple vulnerabilities have been discovered in jruby, Java implementation of the Ruby programming language.

Several security vulnerabilities have been discovered in drupal7, a PHP web site platform. The vulnerabilities affect the embedded versions of the jQuery JavaScript library and the Typo3 Phar Stream Wrapper library.

Facebook bans accounts of fake news firm
TeamViewer was Targeted by Chinese Hackers in 2016

An update that fixes one vulnerability is now available.

An update that solves 14 vulnerabilities and has 90 fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes four vulnerabilities is now available.

Bots rigged Russian finale of ‘The Voice Kids’ talent show

An update is now available for Red Hat Quay 3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Firms, stop sending out automated emails that look suspicious as hell!
Let adware be treated as malware, Canuck boffins declare after breaking open Wajam ad injector

gnome-desktop 3.30.2.3 release, fixing thumbnailer sandbox escape, CVE-2019-11460

Multiple vulnerabilities have been discovered in graphicsmagick, the image processing toolkit: CVE-2019-11473

A vulnerability was discovered in libspring-security-2.0-java, a modular Java/J2EE application security framework, when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance,

The update for ghostscript released as DLA-1792-1 uncovered an issue in cups-filters which was using the undocumented Ghostscript internal “pdfdict” now hidden in the ghostscript update. Updated cups-filters

* Fix rendering of emojis copy-pasted from GTK emoji chooser. * Fix space characters not being rendered with some CJK fonts. * Fix adaptive streaming playback with older GStreamer versions. * Set a maximum zoom level for pinch zooming gesture. * Fix navigation gesture to not interfere with scrolling. * Fix SSE2 detection at compile […]

CIA traitor spy thrown in the clink for selling secrets to China. Stack Overflow, TeamViewer admit: We were hacked…
Giga-hurts radio: Terrorists build Wi-Fi bombs to dodge cops’ cellphone jammers
WordPress WP Live Chat Support Plugin Fixes XSS Flaw
It’s not chicken feed: Million-dollar meal deal for livestock sabotaged by hackers… and, er, exchange rates
Ransomware ‘Remediation’ Firm Exposed: Researchers Weigh in on Paying
How Decoding Network Traffic Can Save Your Data Bacon

Reading Time: ~2 min. WhatsApp Exploited to Install Spyware through Calls A serious flaw has been discovered in the messaging app WhatsApp that would allow an attacker to install spyware on a victim’s device by manipulating the packets being sent during the call. Further disguising the attack, the malicious software could be installed without the […]

Get out of Huawei, it’s an avalanche of news from everyone’s favourite Chinese bogeyman

An update that fixes 6 vulnerabilities is now available.

The minified jquery library was broken in version 1.7.2+dfsg-3.2+deb8u6 due to an error during the build. This problem has now been fixed in version 1.7.2+dfsg-3.2+deb8u7

News Wrap: WhatsApp, Microsoft, Intel and Cisco Flaws
Google recalls Titan Bluetooth keys after finding security flaw
Hacking gang stole millions in cryptocurrency via SIM swaps
Europol arrests end GozNym banking malware gang
Trump seeks tales of social media bias – and your phone number

An update that fixes 8 vulnerabilities is now available.

Good heavens, is it time to patch Cisco kit again? Prime Infrastructure root privileges hole plugged
Freed whistleblower Chelsea Manning back in jail for refusing to testify before secret grand jury
Bank-account-raiding Goznym malware bust: Five suspects collared, five still on the run. $100m feared stolen

– [3.1.1](https://github.com/TYPO3/phar-stream-wrapper/releases/tag/v3.1.1) – [TYPO3-PSA-2019-007](https://typo3.org/security/advisory/typo3-psa-2019-007/) / [CVE-2019-11831](https://nvd.nist.gov/vuln/detail/CVE-2019-11831) – [TYPO3-PSA-2019-008](https://typo3.org/security/advisory/typo3-psa-2019-008/) / [CVE-2019-11830](https://nvd.nist.gov/vuln/detail/CVE-2019-11830) –