Menu

Monthly Archives: June 2019

It was discovered that Expat, an XML parsing C library, did not properly handle XML input including XML names that contain a large number of colons, potentially resulting in denial of service.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

– Update to 4.1.10 Release notes: https://doc.powerdns.com/authoritative/changelog/4.1.html#change-4.1.10 Security Advisory: https://doc.powerdns.com/authoritative/security- advisories/powerdns-advisory-2019-04.html https://doc.powerdns.com/authoritative/security-advisories/powerdns-

– Update to 4.1.10 Release notes: https://doc.powerdns.com/authoritative/changelog/4.1.html#change-4.1.10 Security Advisory: https://doc.powerdns.com/authoritative/security- advisories/powerdns-advisory-2019-04.html https://doc.powerdns.com/authoritative/security-advisories/powerdns-

New bug and security fix release, see http://www.graphicsmagick.org/NEWS.html#june-15-2019

security update

New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Popular Android Zombie game phish users to steal Gmail credentials

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Scumbags can program vulnerable MedTronic insulin pumps over the air to murder diabetics – insecure kit recalled
New Dridex Variant Slips By Anti-Virus Detection
MongoDB Leak Exposed Millions of Medical Insurance Records
Iran’s blame-it-on-Bitcoin ‘leccy shortage probably isn’t a US hack cover story… yet
Crooks steal $28M in crypto using Google Adwords & spoofed domains

Reading Time: ~ 2 min. Second Florida City Pays Ransom Following the news that Riviera Beach, FL would pay the ransom demanded by cyberattackers, the mayor of Lake City, FL has announced that the city will be paying the demanded ransom of $460,000 to restore access to their email and internal system servers. While law […]

Mozilla’s ‘Track This’ lets you choose fake identity to deceive advertisers
FDA Warns of Potentially Fatal Flaws in Medtronic Insulin Pumps
Fortune 100 passwords, email archives, and corporate secrets left exposed on unsecured Amazon S3 servers

An update that fixes 53 vulnerabilities is now available.

An update that fixes 53 vulnerabilities is now available.

Death of the VPN: Enterprise Security Needs New Foundations

Update to v5.1.15 —- Update to v5.1.14

Update to v5.1.15 —- Update to v5.1.14

$50 DeepNude app undresses women with a single click

Multiple security issues were found in the rdesktop RDP client, which could result in denial of service and the execution of arbitrary code. For the stable distribution (stretch), this problem has been fixed in

An update that fixes 22 vulnerabilities is now available.

Mozilla’s bizarre robo-surfer project demonstrates ad snooping
Google Maps shortcut turns into 100-car mud pie in farmer’s field

Mozilla: Type confusion in Array.pop (CVE-2019-11707) * thunderbird: Stack buffer overflow in icalrecur_add_bydayrules in icalrecur.c (CVE-2019-11705) * Mozilla: Sandbox escape using Prompt:Open (CVE-2019-11708) * thunderbird: Heap buffer over read in icalparser.c parser_get_next_char (CVE-2019-11703) * thunderbird: Heap buffer overflow in icalmemory_strdup_and_dequote function in icalvalu [More…]

Several minor issues have been fixed in mupdf, a lightweight PDF viewer tailored for display of high quality anti-aliased graphics.

It was discovered that Expat, an XML parsing C library, did not properly handled XML input including XML names that contain a large number of colons, potentially resulting in denial of service.

– https://www.drupal.org/project/uuid/releases/7.x-1.3 – https://www.drupal.org/sa-contrib-2019-052

## php-typo3-phar-stream-wrapper2 ### v2.1.2 Handling mime-type & Windows paths #### Resolved Issues – #34: Normalize resolved Windows path to Unix-style – #42: Avoid analysing non-phar files on alias resolving – #40: Add Windows tests using AppVeyor – #33: Add alternative mime-type resolving (without ext- fileinfo) ### v2.1.1 Phar Alias Handling & Performance Releases v3.1.1 and

## php-typo3-phar-stream-wrapper2 ### v2.1.2 Handling mime-type & Windows paths #### Resolved Issues – #34: Normalize resolved Windows path to Unix-style – #42: Avoid analysing non-phar files on alias resolving – #40: Add Windows tests using AppVeyor – #33: Add alternative mime-type resolving (without ext- fileinfo) ### v2.1.1 Phar Alias Handling & Performance Releases v3.1.1 and

security update

Risk Level: Very Low. Type: Trojan.

Cryptocurrency phish dials back the fear, cranks up the politeness
Office 365 Phishing Protection – Is Native Microsoft Protection Safe?
Smart Lock Turns Out to be Not So Smart, or Secure
While we were raging about Putin’s meddling and Kremlin hackers, Five Eyes were pwning Yandex, Russia’s Google
Leaky Amazon S3 Buckets Expose Data of Netflix, TD Bank
Scammers Prey on Instagram Vanity and ‘Verified Account’ Status
2001: Linux is cancer, says Microsoft. 2019: Hey friends, ah, can we join the official linux-distros mailing list, plz?

Reading Time: ~ 2 min. We are  excited to announce Webroot® DNS Protection now runs on Google Cloud Platform (GCP). Leveraging GCP in this way will provide Webroot customers with security, performance, and reliability.  Security Preventing denial of service (DoS) attacks is a core benefit of Webroot DNS Protection. Now, the solution benefits from Google Cloud […]

New Microsoft Excel Attack Vector Surfaces
Thousands of IoT Devices Bricked By Silex Malware
Microsoft enhances OneDrive to secure your critical files

The new feature is intended to protect the kind of data that you hold particularly dear The post Microsoft enhances OneDrive to secure your critical files appeared first on WeLiveSecurity

Tesla 3 navigation system fooled with GPS spoofing
ViceLeaker Android malware steals call recordings, photos, videos & texts

An update that solves one vulnerability and has two fixes is now available.

YouTube’s antics with kids’ data prompts call for FTC to force change
FTC crackdown targets operators behind 1 billion robocalls
UK’s MoD is helping itself to cops’ fingerprint database ‘unlawfully’, rules biometrics chief
Are heart electrocardiograms the next big thing in biometrics?

An update for atomic-openshift is now available for OpenShift Container Platform. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

After €24 million stolen by typosquatting a cryptocurrency exchange, six people arrested

An update that fixes 5 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Several security issues were fixed in poppler.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Your server remote login isn’t root:password, right? Cool. You can keep your data. Oh sh… your IoT gear, though?
Smashing Security #134: Sextortion, silicone face masks, and a DDoS doofus
New Windows 10 bug causes PCs to take longer to shut down
Google Announces DNS over HTTPS ‘General Availability’
Hey China, while you’re in all our servers, can you fix these support tickets? IBM, HPE, Tata CS, Fujitsu, NTT and their customers pwned

Reading Time: ~ 2 min. We are excited to announce Webroot® DNS Protection now runs on Google Cloud Platform (GCP). Leveraging GCP in this way will provide Webroot customers with unfailing security, performance, and reliability. Security “The big thing about Google Cloud is that it dynamically manages denial of service (DoS) attacks,” said Webroot Sales […]

Decoding America’s spies: What does the NSA’s cryptic memo really mean? Citizens illegally spied on again
Two US cities opt to pay $1m to ransomware operators

A few days apart, two cities in Florida cave in to extortionists’ demands in hopes of restoring access to municipal computer systems The post Two US cities opt to pay $1m to ransomware operators appeared first on WeLiveSecurity

Epyc crypto flaw? AMD emits firmware fix for server processors after Googler smashes RAM encryption algorithms
Cisco Warns of Critical Flaws in Data Center Network Manager
Iran-linked APT33 Shakes Up Cyberespionage Tactics

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that solves 9 vulnerabilities and has two fixes is now available.

Risk Level: Very Low. Type: Trojan.

It could be Rotterdam or anywhere, Wiltshire or in Bath: Euro cops cuff 6 for cybersquatting, allegedly nicking €24m in Bitcoin
EA Games Patches Account-Hijacking Bug
New attack spreads LokiBot & NanoCore malware in ISO image files
Second Florida City Pays Hackers $500k Post-Ransomware Attack
$1.1 million in two weeks – Florida cities pay out big to ransomware gangs
Wipro wasn’t a one-off: Same hacking crew targeted scores of firms, big and small – researchers
7 Easy-to-Use Java Performance Tuning Tips
Hacker threw Molotov cocktail, dropped USB drive of his DDoS deeds

Mozilla: Type confusion in Array.pop (CVE-2019-11707) * Mozilla: Sandbox escape using Prompt:Open (CVE-2019-11708) SL6 x86_64 firefox-60.7.2-1.el6_10.x86_64.rpm firefox-debuginfo-60.7.2-1.el6_10.x86_64.rpm firefox-60.7.2-1.el6_10.i686.rpm firefox-debuginfo-60.7.2-1.el6_10.i686.rpm i386 firefox-60.7.2-1.el6_10.i686.rpm firefox-debuginfo-60.7.2-1.el6_10.i686.rpm – [More…]

Social engineering forum hacked, user data dumped on rival site
VLC media player gets biggest security update ever
Google creates educational tools to help kids spot fake news
How Phishing Has Evolved in 2019

Several security issues were fixed in bzip2.

Several security issues were fixed in bzip2.

Bought a second-hand Nest Cam? It might have been spying on you
Stop us if you’ve heard this one: US government staff wildly oblivious to basic computer, info security safeguards