Menu

Monthly Archives: June 2019

Post-Ransomware Attack, Florida City Pays $600K
LoudMiner Cryptominer Uses Linux Image and Virtual Machines

Risk Level: Very Low. Type: Trojan.

DanaBot Adds Ransomware to its Arsenal
Samsung asks users to scan their Smart TVs for malware – Here’s how to
Tor Browser Issues Update for Critical System Takeover Flaw
Smashing Security #133: Cookie cock-ups, Hong Kong protests, and smart TV virus scans
Cisco DNA Center Critical Flaw Opens Access to Internal Services
Update Firefox now! Zero-day found in the wild
Google launches new Chrome protection from bad URLs

An update that fixes one vulnerability is now available.

Facebook’s Libra cryptocurrency is big news but will it be secure?
Shut the barn door: UK data watchdog tells MPs mass slurping by firms is a huge risk to privacy
“Deeply personal medical” records exposed online
LoudMiner: Cross-platform mining in cracked VST software

The story of a Linux miner bundled with pirated copies of VST (Virtual Studio Technology) software for Windows and macOS The post LoudMiner: Cross-platform mining in cracked VST software appeared first on WeLiveSecurity

If Uncle Sam could quit using insecure .zip files to swap info across the ‘net, that would be great, says Silicon Ron Wyden
Google takes the PIS out of advertising: New algo securely analyzes shared encrypted data sets without leaking contents
Feds: Cyberattack on NASA’s JPL Threatened Mission-Control Data

security update

security update

Google Releases Open Source Tool For Computational Privacy
Using Oracle WebLogic? Put down your coffee, drop out of Discord, grab this patch right now: Vuln under attack

Risk Level: Very Low. Type: Trojan.

Death linked to prank – France seeks extradition of hacker from Israel
Oracle Warns of New Actively-Exploited WebLogic Flaw

An update that solves one vulnerability and has three fixes is now available.

645,000 people warned their personal health data at risk after phishing attack
EatStreet Hackers Chow Down on Diner Data
Mozilla Patches Firefox Critical Flaw Under Active Attack
Netflix researcher spots TCP SACK flaws in Linux and FreeBSD
Pass the salt! Popular CMSs aren’t securing passwords properly
NASA’s JPL may be able to reprogram a probe at the arse end of the solar system, but its security practices are a bit crap
NHS service accidentally reveals identities of HIV patients in email blunder
Hospitals are being suffocated by robocalls
Millions of Venmo transactions scraped (again)

The package python before version 3.7.3-1 is vulnerable to information disclosure.

The package firefox before version 67.0.3-1 is vulnerable to arbitrary code execution.

The package dbus before version 1.12.16-1 is vulnerable to access restriction bypass.

You’d better change your birthday – hackers may know your PIN

Are you in the 26% of people who use one of these PIN codes to unlock their phones? The post You’d better change your birthday – hackers may know your PIN appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

Spin the wheel and find today’s leaky cloud DB… *clack clack… clack* A huge trove of medical malpractice complaints
Awoogah! Awoogah! Firefox fans urged to update and patch zero-day hole exploited in the wild by miscreants

An update that solves 6 vulnerabilities and has 7 fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

security update

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1481

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1488

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1492

Instagram tests new ways to recover hacked accounts

Locked out and out of luck? The photo-sharing platform is trialing new methods to reunite you with your lost account The post Instagram tests new ways to recover hacked accounts appeared first on WeLiveSecurity

Consumers Urged to Junk Insecure IoT Devices
New Android malware bypass 2FA & steal one-time passwords
Linux Kernel Bug Knocks PCs, IoT Gadgets and More Offline
Delicious irony: Hacked medical debt collector AMCA files for bankruptcy protection from debt collectors
Cellebrite claims its new tool unlocks almost any iOS or Android device
Microsoft Management Console Bugs Allow Windows Takeover

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that solves 9 vulnerabilities and has 9 fixes is now available.

An update that solves 16 vulnerabilities and has two fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves 16 vulnerabilities and has two fixes is now available.

Working BlueKeep Exploit Developed by DHS

The package linux before version 5.1.11.arch1-1 is vulnerable to denial of service.

The package linux-lts before version 4.19.52-1 is vulnerable to denial of service.

The package linux-zen before version 5.1.11.zen1-1 is vulnerable to denial of service.

An update for gvfs is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Parliament IT bods’ fail sees server’s naked OS exposed to world+dog
Bella Thorne releases her own topless photos after hacker threats
90% off Ray-Bans? It’s a 100% Instagram SCAM!
Freaking out about fiendish IoT exploits? Maybe disable telnet, FTP and change that default password first?
Bella Thorne steals hacker’s thunder, publishes nude photos herself
The US is reportedly seeding Russia’s power grid with malware
Phishing attack lures victims with encrypted message alert
Smash GandCrab: Free tools released to decrypt files scrambled by notorious ransomware
Samsung reminds rabble to scan smart TVs for viruses – then tries to make them forget
How I Discovered My First Vulnerability
Irked Researcher Discloses Facebook WordPress Plugin Flaws
5,000 Twitter Accounts Linked to Disinformation Campaigns
Sad SACK: Linux PCs, servers, gadgets may be crashed by ‘Ping of Death’ network packets
A Spate of University Breaches Highlight Email Threats in Higher Ed
Actress Bella Thorne posts her nudes to tackle threats from hackers
Microsoft Pushes Azure Users to Patch Linux Systems
Alex Jones claims malware planted child porn on InfoWars servers

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Yubico recalls FIPS Yubikey tokens after flaw found
Privacy foul for soccer league app that eavesdropped on users

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

I’d like to add you to my professional network of people to spy on
Widely used medical infusion pump can be remotely hijacked
Why are fervid Googlers making ad-blocker-breaking changes to Chrome? Because they created a monster – and are fighting to secure it
Malware sidesteps Google permissions policy with new 2FA bypass technique

ESET analysis uncovers a novel technique bypassing SMS-based two-factor authentication while circumventing Google’s recent SMS permissions restrictions The post Malware sidesteps Google permissions policy with new 2FA bypass technique appeared first on WeLiveSecurity

security update

Multiple security issues have been found in Thunderbird which may lead to the execution of arbitrary code if malformed email messages are read. For the stable distribution (stretch), these problems have been fixed in