Menu

Monthly Archives: June 2019

Risk Level: Very Low. Type: Trojan.

SEMrush Plugs Remote Code Execution Bug in Its SaaS Platform

security update

Newly-Discovered Malware Targets Unpatched MacOS Flaw
Serious Security: Rambleed attacks blunted – the OpenSSH way
Cellular networks worldwide hit by hackers in espionage attempt
Malspam Emails Blanket LokiBot, NanoCore Malware With ISO Files

An update that solves one vulnerability and has 24 fixes is now available.

Researchers exploit LTE flaws to send 50,000 fake presidential alerts
McAfee sues ship-jumping sales staff over trade secret theft allegations
9 risky apps that you need to monitor on your kids’ smartphone

Reading Time: ~ 2 min. It’s been more than a decade since Netflix launched its on-demand online streaming service, drastically changing the way we consume media. In 2019, streaming accounts for an astonishing 58 percent of all internet traffic, with Netflix alone claiming a 15 percent share of that use. But as streaming has become […]

Open-heart nerdery: Boffins suggest identifying and logging in people using ECGs
WeTransfer sends user file links to wrong people

An update that contains security fixes can now be installed.

An update that fixes three vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

The update issued as DLA-1835-1 caused a regression in the http.client library in Python 3.4 which was broken by the patch intended to fix CVE-2019-9740 and CVE-2019-9947.

Presidential text alerts are open to spoofing attacks, warn researchers
Government agencies still send sensitive files via hackable .zips
Cop awarded $585K after colleagues snooped on her via license database

A security improvement has been made to policykit-desktop-privileges.

A system hardening measure could be bypassed.

Several security issues were fixed in Ceph.

Several security issues were fixed in ImageMagick.

Several security vulnerabilities were discovered in the rdesktop RDP client, which could result in buffer overflows and execution of arbitrary code.

Stopping stalkerware: What needs to change?

What technology makers and others can – and should – do to counter the kind of surveillance that starts at home The post Stopping stalkerware: What needs to change? appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

Please stop regulating the dumb tubes, says Internet Society boss

Multiple security issues have been found in Thunderbird which may lead to the execution of arbitrary code if malformed email messages are read. For Debian 8 “Jessie”, these problems have been fixed in version

Two brothers arrested for Bitfinex hack and multi-year cryptocurrency phishing campaign
What the cell…? Telcos around the world were so severely pwned, they didn’t notice the hackers setting up VPN points
Biz tells ransomware victims it can decrypt their files… by secretly paying off the crooks and banking a fat margin

security update

Hackers breach NASA, steal Mars mission data

The infiltration was only spotted and stopped after the hackers roamed the network undetected for almost a year The post Hackers breach NASA, steal Mars mission data appeared first on WeLiveSecurity

Iran is doing to our networks what it did to our spy drone, claims Uncle Sam: Now they’re bombing our hard drives
Facebook Faces Lawsuit Over Massive 2018 Data Breach
New cryptomining botnet malware hits Android devices
WeTransfer security failure results in file transfer emails being sent to the wrong people

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Iran Targeting U.S. With Destructive Wipers, Warns DHS

A sandbox escape was discovered in Firefox.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1587

The Modern-Day Heist: IP Theft Techniques That Enable Attackers

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has four fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves two vulnerabilities and has four fixes is now available.

An update that solves 5 vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

Mozilla patched two Firefox zero-day flaws in one week
Mobile apps riddled with high-risk vulnerabilities, warns report
Desjardins’ employee from hell spills 2.9m records
Facebook posts reveal your hidden illnesses, say researchers
Cisco cleans up critical flaws, Florida city forks out $600k to ransomware scumbags, and more from infosec land
Driving Xtreme Cuts: DXC Technology waves bye bye to 45% of Americas Security divison

Risk Level: Very Low. Type: Trojan.

security update

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Two vulnerabilities were discovered in Libvirt, a virtualisation abstraction library, allowing an API client with read-only permissions to execute arbitrary commands via the virConnectGetDomainCapabilities API, or read or execute arbitrary files via the

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Update to 1.1.33 and fix CVE-2019-11068

Hackers using pirated software to spread new cryptomining Mac malware
MobOk Malware Hides in Photo Editors on Google Play, Siphons Cash
Microsoft Outlook for Android Open to XSS Attacks
Podcast: Dating App Privacy and NASA Cyberattack

Reading Time: ~ 2 min. Multiple Tesla Models Vulnerable to GPS Attacks Though it’s not the only manufacturer to offer GPS navigation in their vehicles, Tesla has once again suffered an attack on their GPS autopilot features. These attacks were able to trick the car into thinking it had arrived at an off-ramp more than […]

Hackers exploit Raspberry Pi device to hack NASA’s mission system
Office 365 proves popular with phishers
Mozilla Fixes Second Actively-Exploited Firefox Flaw
Millions of Dell PCs vulnerable to attack, due to a flaw in bundled system-health software
Microsoft uses AI to push Windows 10 upgrade to users

An update that solves three vulnerabilities and has one errata is now available.

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Used Nest cams were letting previous owners spy on you

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Millions of Dell PCs Vulnerable to Flaw in Third-Party Component
Florida city will pay over $600,000 to ransomware attackers
Good old British ‘fair play’ is the answer to vexed Huawei question, claims security minister
Government is exposing identities of child abuse victims

security update

Millions of Windows Dell PCs need patching: Give-me-admin security gremlin found lurking in bundled support tool
Match, Tinder Swipe Right For Privacy Red Flags, Say Experts
Digi-dosh exchange Coinbase: Someone tried to pwn our staff via this week’s Firefox zero-day security hole