Menu

Monthly Archives: June 2019

It was discovered that there was a code injection issue in PyXDG, a library used to locate “FreeDesktop.org” configuration/cache/etc. directories.

EU accuses Russia of spreading misinformation on social media

security update

An update that fixes 13 vulnerabilities is now available.

An update that fixes 13 vulnerabilities is now available.

An update that fixes 13 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Two vulnerabilities were discovered in the ZNC IRC bouncer which could result in remote code execution (CVE-2019-12816) or denial of service via invalid encoding (CVE-2019-9917).

Black Hat USA axes anti-abortion congressman as keynote speaker after outcry – and more news from infosec land

do not install /usr/libexec/crio – conflicts with crio —- Resolves: #1715668 – CVE-2019-10152

Resolves: #1715758 – CVE-2019-9946

Vulnerable infusion pumps can be remotely accessed to change dosages

https://lists.wikimedia.org/pipermail/mediawiki-announce/2019-June/000230.html

security update

Ransomware: A Persistent Scourge Requiring Corporate Action Now
ThreatList: Ransomware Trojans Picking Up Steam in 2019
No Telegram today, protestors: Chinese boxes DDoS chat app amid Hong Kong protest
News Wrap: Amazon Privacy and Telegram DDoS Attack
TRISIS Group, Known for Physical Destruction, Targets U.S. Electric Companies

Reading Time: ~ 2 min. Radiohead Refuses Ransom, Releases Stolen Tracks The band Radiohead recently fell victim to a hack in which 18 hours of previously unreleased sessions were ransomed for $150,000. Rather than pay the ludicrous fee, the band instead opted to release the tracks through Bandcamp for a donation to charity. The unreleased […]

Amazon Alexa Secretly Records Children, Lawsuits Allege

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

Millions of Linux Servers Under Worm Attack Via Exim Flaw
Student uses Snapchat’s gender filter to bust pervert cop

The package thunderbird before version 60.7.1-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

The package chromium before version 75.0.3770.90-1 is vulnerable to arbitrary code execution.

Hackers Favor Weekdays for Attacks, Share Resources Often
Critical flaw found in Evernote Web Clipper for Chrome
Android phones can now be security keys for iOS devices
Facebook got 187,000 users’ data with snoopy VPN app

Joe Vennix discovered an authentication bypass vulnerability in dbus, an asynchronous inter-process communication system. The implementation of the DBUS_COOKIE_SHA1 authentication mechanism was susceptible to a symbolic link attack. A local attacker could take advantage of this flaw

When virtual mittens sell for thousands, of course gamers are ripe targets for cyber shenanigans
Instagram down: Social networking site suffering service outage

Upstream announcement: Welcome to **phpMyAdmin 4.9.0.1**, a bugfix release that includes important security fixes. This release fixes two security vulnerabilities: * PMASA-2019-3 is an SQL injection flaw in the Designer feature * PMASA-2019-4 is a CSRF attack that’s possible through the ‘cookie’ login form Upgrading is highly recommended for all users. Using the ‘http’

Update to [3.3.8](https://github.com/vakata/jstree/compare/3.3.5…3.3.8).

New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

Yubico YubiKey lets you be me: Security blunder sparks recall of govt-friendly auth tokens

Update to 1.1.33 and fix CVE-2019-11068

Security fix for CVE-2019-11459.

dovecot updated to 2.3.6, includes several security fixes

Upstream announcement: Welcome to **phpMyAdmin 4.9.0.1**, a bugfix release that includes important security fixes. This release fixes two security vulnerabilities: * PMASA-2019-3 is an SQL injection flaw in the Designer feature * PMASA-2019-4 is a CSRF attack that’s possible through the ‘cookie’ login form Upgrading is highly recommended for all users. Using the ‘http’

Evernote Critical Flaw Opened Personal Data of Millions to Attack
Hacking these medical pumps is as easy as copying a booby-trapped file over the network
Max-Severity Bug in Infusion Pump Gateway Puts Lives at Risk
How to Remove Temporary Files In Windows 10?
Telegram CEO Fingers China State Actors for DDoS Attack
Facebook keeps deepfake of Mark Zuckerberg
Train to be a top-notch cybercrime detective at SANS DFIR Europe Summit in Prague
Backpacker claims to find a network of hidden webcams in farm stay

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

Vim devs fix system-pwning text editor bug
High-Severity Cisco Flaw in IOS XE Enables Device Takeover

The package openssl before version 1.1.1.c-1 is vulnerable to information disclosure.

The package vim before version 8.1.1467-1 is vulnerable to arbitrary code execution.

The package gvim before version 8.1.1467-1 is vulnerable to arbitrary code execution.

The package lib32-openssl before version 1:1.1.1.c-1 is vulnerable to information disclosure.

Microsoft’s battle with SandboxEscaper zero days turns into grim Groundhog Day
DDoS attack that knocked Telegram secure messaging service offline linked to Hong Kong protests
UK Home Sec kick-starts US request to extradite ex-WikiLeaker Assange

An update that fixes one vulnerability is now available.

An update that fixes 15 vulnerabilities is now available.

An update for python is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Telegram messaging service hit by massive DDoS attack
Smashing Security #132: CBP cyber attack, an iPhone privacy boost, and Twitter list abuse
Fishwrap Campaign Sways Social Media Users with Old News

1717503 – Security issue: patch 8.1.1365: source command doesn’t check for the sandbox

RAMBleed attack steals sensitive data from computer memory
Spain’s top soccer league fined over its app’s ‘tactics’

La Liga has taken substantial flak for tapping into microphones and geolocation services in fans‘ phones in a bid to root out piracy The post Spain’s top soccer league fined over its app’s ‘tactics’ appeared first on WeLiveSecurity

Data Breach Disclosed by Online Invitation Firm Evite
Unheard recordings of Radiohead from Ok Computer hacked; refuses to pay ransom

Type: Vulnerability. Microsoft Windows is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.