Menu

Monthly Archives: May 2019

Sextortion mail from yourself? It doesn’t mean you’ve been hacked…
Ever app users uploaded billions of photos, unaware they were being used to build a facial recognition system
Serious Phar Flaw Allows Arbitrary Code Execution on Drupal
US minister invokes Maggie Thatcher, says she would have halted Huawei 5G rollout
Researchers in the Dark on Powerful LightNeuron Malware, for Years
Metal keys beat smart locks in NYC legal battle
CSS tracking trick can monitor your mouse without JavaScript
DeepDotWeb seized, suspected admins arrested
Chrome plans to save you from sites that mess with your back button
Robbinhood ransomware attack brings down parts of City of Baltimore’s computer network

Reading Time: ~3 min. From recruiting top talent to daily technical leadership, a day-in-a-life of a software engineering is never boring. After chatting with Webroot Senior Manager of Software Development, Michael Balloni, it became even more obvious.   Michael is working hard to build a robust and efficient team, and is undeniably enthusiastic about every stage of the process. The conversation only got […]

The Pitfalls of Keeping Your Ports Wide Open

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update for freeradius is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes 6 vulnerabilities is now available.

Smashing Security #127: I do love the Dutch
Enter the minds of hackers at the SANS Pen Test Hackfest Europe

An update that solves 16 vulnerabilities and has 5 fixes is now available.

Eggheads confirm: Rampant Android bloatware a privacy and security hellscape
Hackers steal US$41 million worth of Bitcoin from cryptocurrency exchange

The thieves bade their time before running off with more than 7,000 Bitcoin ‘in one fell swoop’ The post Hackers steal US$41 million worth of Bitcoin from cryptocurrency exchange appeared first on WeLiveSecurity

DeepDotWeb, Wall St and Valhalla markets seized by authorities

* https://www.drupal.org/project/drupal/releases/7.66 * https://www.drupal.org/SA-CORE-2019-006

Key to success: Tenants finally get physical keys after suing landlords for fitting Bluetooth smart-lock to front door

Fix for CVE-2019-5429

Fix for CVE-2019-5429

security update

Airbnb Superhost Secretly Recorded Guests with Hidden Bedroom Camera
The Different Ways a Data Breach Can Impact Businesses
Google Patches Critical Remote Code-Execution Flaws in Android
Lax Telco Security Allows Mobile Phone Hijacking and Redirects
Binance exchange hacked: Bitcoin worth $40.7M stolen
Orange is at it again, buys SecureLink for an eye-watering €515m including debts
Google Touts Android Q’s New Security Update Process and Better Privacy Controls for Apps
Verizon Data Breach Report: Espionage, C-Suite and Cloud Attacks on the Rise
Top 5 Configuration Mistakes That Create Field Days for Hackers
Cynet Provides Security Responders with Free IR Tool to Validate and Respond to Active Threats
Executive hacked competitor’s website to steal students meal preferences
Latest Android security updates, and Google to fix patch delays for Pixel
$40 million worth of Bitcoin stolen from Binance cryptocurrency exchange

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

US foreign minister Mike Pompeo to give UK a bollocking over Huawei 5G plans
Malvertiser behind 100+ million bad ads indicted in the US
Malware takes Wolters Kluwer CCH cloud accounting service offline
School lunch company exec arrested for skewering rival’s site
Researchers’ Evil Clippy cloaks malicious Office macros
Want rootkit-level access without the hassle? Enter, LightNeuron for Exchange Server

An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rhvm-setup-plugins is now available for Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Airbnb host thrown in the clink after guest finds hidden camera inside Wi-Fi router
And in this week’s weird news, Feds seize dark-web news site, accuse admins of getting rich off drug cyber-souk

Risk Level: Very Low. Type: Virus, Worm.

This update enforces that $LoadCode must be enabled to use the feature of evaluating typeglobs, because with the typeglob feature you would be able to set the variable $YAML::LoadCode from a YAML file, and that would be a security issue.

Critical Flaw in Cisco Elastic Services Controller Allows Full System Takeover
Remember those stolen ‘NSA exploits’ leaked online by the Shadow Brokers? The Chinese had them a year before
Freedom Mobile leaked millions of card data with CVV codes in plain text
Chinese Spies Stole NSA Cyberweapons Long Before Shadow Brokers Leak

Risk Level: Very Low. Type: Trojan.

Reading Time: ~3 min. In a recent report by the firm 451 Research, 62% of SMBs reported having a security awareness training program in place for their employees, with half being “homegrown” training courses. The report also found that most complained their programs were difficult to implement, track, and manage. Like those weights in the […]

Be wary of emails with links to … er, Google Drive? Is that right?
Chinese hackers accessed NSA hacking tools before Shadow Brokers leak
Ukrainian Charged With Launching 100 Million Malicious Ads
MegaCortex ransomware distracts victims with Matrix film references

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for python-jinja2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Restore s390x builds. —- 0.7.3.1

Turla LightNeuron: An email too far

ESET research uncovers Microsoft Exchange malware remotely controlled via steganographic PDF and JPG email attachments The post Turla LightNeuron: An email too far appeared first on WeLiveSecurity

Reading Time: ~5 min. Like many Americans, you might think your online habits are safe enough—or, at least, not so risky as to put you in danger for cybercrime. As it happens, most of us in the U.S. are nowhere near as secure as we think we are. As part of our recent survey to […]

‘Software delivered to Boeing’ now blamed for 737 MAX warning fiasco

An update that solves one vulnerability and has three fixes is now available.

An attempt to phish my Amazon Web Services account
Firefox add-ons with obfuscated code will be banned by Mozilla
Dark web marketplace Wall Street Market busted by international police
Blockchain project settles cross-border payment
Facebook sponsored posts selling access to hacked PayPal accounts
Weekly review – the hot 25 stories of last week
Sensitive data can lurk on second-hand hard drives
NSA foreign spying, biotech snooping, Hamas hackers bombed, airline cams, and much more from infosec land

Risk Level: Very Low. Type: Trojan, Virus, Worm.

WP Live Chat WordPress Plugin Re-Patches File Upload Flaw
Feds nab top exec on allegations he hacked a competitor, stole info… about school lunches?!
Oracle WebLogic Exploit-fest Continues with GandCrab Ransomware, XMRig
Free eBook: A Business Owner’s Guide to Cybersecurity
High-Severity Bug Leaves Cisco TelePresence Gear Open to Attack
Avengers: Endgame Sites Promise Digital Downloads, Deliver Info-Harvesting
Israel claims to bomb Hamas’s cyber Ops HQ amidst uncertainties
High-Severity PrinterLogic Flaws Enable Remote Code Execution
Israel bombs building containing alleged Hamas hackers
Tor Security Add-On Abruptly Killed by Mozilla Bug

An update that fixes 16 vulnerabilities is now available.

An update that fixes one vulnerability is now available.