Menu

Monthly Archives: May 2019

An update that fixes three vulnerabilities is now available.

Extinguishing the IoT Insecurity Dumpster Fire

jQuery mishandles jQuery.extend(true, {}, …) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. For additional information, please refer to the upstream advisory at

Amid Bug Bounty Hype, Sometimes Security is Left in the Dust
Mozilla bug throws Tor Browser users into chaos

* Mouse cursor doubled on QEMU VNC on ppc64le (bz #1565253) * CVE-2019-3840: NULL deref after running qemuAgentGetInterfaces (bz #1665229)

This update provides an update to the new Virtualbox 6.0 branch, currently 6.0.6. It also fixes the following security issues. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise

An update that solves 13 vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 19 vulnerabilities is now available.

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes 16 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Colin Snover discovered a denial-of-service vulnerability in phpBB3, a full-featured web forum. Previous versions allowed users to run searches that might result in long execution times and load on larger boards when using the fulltext native search engine. To combat this, further

Security fix for CVE-2019-3885, CVE-2018-16877, CVE-2018-16878

Researchers Weigh in on Trump’s Cyber Workforce Executive Order
White House issues Executive Order on cybersecurity, including hacker Hunger Games

Update to April 2019 CPU. See: http://mail.openjdk.java.net/pipermail/jdk- updates-dev/2019-April/000951.html

New upstream release with significantly reworked PKCS#11 support, GSSAPI key exchange and several fixes for CVE-2019-6111 and CVE-2019-6109

New upstream release

News Wrap: Cartoon Network Hack, the Catholic Church and Jason Statham Scams
Mystery Git ransomware appears to blank commits, demands Bitcoin to rescue code
Belgian programmer solves cryptographic puzzle – 15 years too soon!

Reading Time: ~2 min. “FBI Director” Phishing Campaign A new email phishing campaign has been making its way around the web that claims to be from “FBI Director Christopher Wray,” who would love to assist with a massive wire transfer to the victim’s bank account. Unfortunately for anyone hoping for a quick payday, the $10 […]

HMRC to finally erase five million voice records it collected without permission
UK taxman falls foul of GDPR, agrees to wipe 5 million voice recordings used to make biometic IDs
Retefe Banking Trojan Resurfaces, Says Goodbye to Tor
Multiple Sierra Wireless AirLink Routers Open to Remote Code Execution

An update that contains security fixes can now be installed.

Europol takes down Wall Street market: No, the other cesspool of dark international financial skullduggery

An update that contains security fixes can now be installed.

An update that fixes 18 vulnerabilities is now available.

Venture deep into cybersecurity at SANS Amsterdam this month: Full details inside
Criminals are hiding in Telegram – but backdoors are not the answer
Cryptocoin theft, scam and fraud could total more than $1.2b in Q1
Cybersecurity experts battle for right to repair
A day in the life of London seen through spam and weak Wi-Fi
Google rolling out auto-delete for your location and activity history

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Critical Flaws Found in Eight Wireless Presentation Systems
It’s May 2. Know what that means? Yep, it’s the PR orgy that is World Password Day… again
D-Link Cloud Camera Flaw Gives Hackers Access to Video Stream
New Google Chrome mobile phishing scam can steal private data
Ladders, SkyMed Leak Employment, Medical Data for Millions
Dell Security Support Tool Harbors High-Severity Flaws
Google will ‘auto-delete’ your location & web activity data
Japan is developing a computer virus to fight cyberattacks, claim reports
Cisco Warns of Critical Nexus 9000 Data Center Flaw
World Password Day – what (NOT!) to do
World Password Day: A day to review your defenses

So, do you think you’ve been ‘pwned’? That’s the question to ask yourself today The post World Password Day: A day to review your defenses appeared first on WeLiveSecurity

DHS policies allow unlimited, warrantless device search
Is a sticky label the answer to the IoT’s security problems?
Extortionists leak data of huge firms after IT provider refuses to pay

Several security issues were fixed in python-gnupg

US Government halves deadline for applying critical patches to 15 days
‘I do not wish to surrender’ Julian Assange tells court over US extradition bid

An update that fixes two vulnerabilities is now available.

D-Link camera vulnerability allows attackers to tap into the video stream

ESET researchers highlight a series of security holes in a device intended to make homes and offices more secure The post D-Link camera vulnerability allows attackers to tap into the video stream appeared first on WeLiveSecurity

We dunno what’s worse: Hackers ransacked Citrix for FIVE months, or that Equifax was picked to help mop up the mess
Smashing Security #126: Zombie chickens and fast-food victims
Sinister secret backdoor found in networking gear perfect for government espionage: The Chinese are – oh no, wait, it’s Cisco again

**horde 5.2.21** * [mjr] SECURITY: Fix XSS vulnerability in the Cloud Block.

**turba 4.2.24** * [mjr] SECURITY: Fix XSS vulnerability in display of contact tags. * [jan] Clarify objectClass filter examples for LDAP backends (Ralf Lang).

Ad Server Patched to Stop Possible Malware Distribution
Crypto-chaps on scam rap in a flap over Slack chat tap, want court case zapped: ‘Attorney-client priv info’ in messages

**horde 5.2.21** * [mjr] SECURITY: Fix XSS vulnerability in the Cloud Block.

**turba 4.2.24** * [mjr] SECURITY: Fix XSS vulnerability in display of contact tags. * [jan] Clarify objectClass filter examples for LDAP backends (Ralf Lang).

Wipro Attackers Have Operated Under the Radar for Years
DHS Shortens Deadline For Gov Agencies to Fix Critical Flaws
Hey, those warrantless smartphone searches at the US border? Unconstitutional, yeah? Civil-rights warriors ask court to settle this

An update that fixes two vulnerabilities is now available.

An update that solves 5 vulnerabilities and has 5 fixes is now available.

An update that contains security fixes can now be installed.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

May Day! PM sacks UK Defence Secretary Gavin Williamson for Huawei 5G green-light ‘leak’

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Cartoon Network Hacked Worldwide to Show Brazilian Stripper Videos

An unsafe shell call enabling shell injection via a user ID was corrected in gpg-key2ps, a tool to generate a PostScript file with OpenPGP key fingerprint slips.

Muhstik Botnet Variant Targets Just-Patched Oracle WebLogic Flaw
Michael Bublé’s Instagram suffers cock-up

The update of proftpd-dfsg issued as DLA-1753-1 caused a regression when using the sftp module. Login to the sftp server was impossible when the SFTPPAMEngine option was turned on (#926719).

Sky Broadband firmware update bricks routers using third-party DNS settings
Keeping your data safe when traveling
Millions of consumer smart devices exposed by serious security flaw
Julian Assange jailed for 50 weeks over Ecuador embassy bail-jumping
Diabetics are hunting down obsolete insulin pumps with a security flaw
Mystery database exposes data on 80 million US households
NordVPN rapped by ad watchdog over insecure public Wi-Fi claims
Crooks using hacked Microsoft email accounts to steal cryptocurrency

Memcached could be made to crash if it received specially crafted network traffic.

If you’re using Oracle’s WebLogic Server, check for security fixes: Bug exploited in the wild to install ransomware