Menu

Monthly Archives: June 2019

Gang charged with $19 million iPhone scam

Vincent Tondellier reported that the qemu update issued as DSA 4454-1 did not correctly backport the support to define the md-clear bit to allow mitigation of the MDS vulnerabilities. Updated qemu packages are now available to correct this issue.

The Growing Importance of Cyber Security Skills

Several vulnerabilities have been found in the poppler PDF rendering library, which could result in denial of service or possibly other unspecified impact when processing malformed or maliciously crafted files.

Worried ransomware will screw your network? You could consider swallowing your pride, opening your wallet
Smashing Security #131: Zap yourself from the net, and patch now against BlueKeep
It’s that time again: Android kicks off June’s patch parade with fixes for five hijack holes
Buggy Phishing Kits Allow Criminals to Cannibalize Their Own
440 Million Android Users Plagued By Extremely Obnoxious Pop-Ups
Mozilla and Google Browsers Get Security, Anti-Tracking Boosts

Risk Level: Very Low. Type: Trojan.

BlueKeep ‘Mega-Worm’ Looms as Fresh PoC Shows Full System Takeover
Why Election Trust is Dwindling in a Post-Cambridge Analytica World
Crime doesn’t pay? Crime doesn’t do secure coding, either: Akamai bug-hunters find hijack hole in bank phishing kit

The Qualys Research Labs reported a flaw in Exim, a mail transport agent. Improper validation of the recipient address in the deliver_message() function may result in the execution of arbitrary commands.

Patch Android! June 2019 update fixes eight critical flaws
Podcast: Behind-the-Scenes Look at Scattered Canary BEC Cybergang
Newly-Identified BEC Cybergang Targets U.S. Enterprise Victims
Apple bans ads, third-party tracking in apps meant for kids
Smashing Security named the Best Security Podcast

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

ATM skimming crook behind bars after draining bank accounts for 2 years
Apple battles Facebook and Google with rival sign in service

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Wajam: From start-up to massively-spread adware

How a Montreal-made “social search engine” application has managed to become a widely-spread adware, while escaping consequences The post Wajam: From start-up to massively-spread adware appeared first on WeLiveSecurity

Labs are for nerds, it’s simply Kaspersky now – just hold still while we cyber-immunise you

It was discovered that there was a cross-site scripting (XSS) vulnerability in the Django web development framework. For Debian 8 “Jessie”, this issue has been fixed in python-django version

Bloody awful: Hell-thcare hackers break into databases of 20m medical test biz patients
Quest Diagnostics data breach affects 12 million customers
Is ‘Sign in with Apple’ Marketing Spin or Privacy Magic? Experts Weigh In

security update

Zero-Day No More: Windows Bug Gets a Fix
Zebrocy: A Russian APT Specializing in Victim Profiling, Access
Malware spotted doing unspeakable, filthy things to infected Macs – injecting Bing results into Google searches
AI Isn’t Good Enough When Lives Are on the Line, Experts Warn
A New Approach for Combating Insider Threats
Guardian Digital Celebrates 20 Years of Revolutionizing Digital Security, Securing Email with Open Source
Synthetic clicks and the macOS flaw Apple can’t seem to fix
Hackers steal 19 years’ worth of data from Australia’s top university

It is the second major breach that the Australian National University suffered in 2018 The post Hackers steal 19 years’ worth of data from Australia’s top university appeared first on WeLiveSecurity

Strewth: Hackers slurp 19 years of Oz student data in uni’s second breach within a year
GandCrab ransomware crooks to shut up shop
US visa applicants required to hand over social media info

An update for systemd is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Infosecurity Europe: Cryptojacking is Making a Comeback
Apple sunsets iTunes

An update for java-1.8.0-ibm is now available for Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The package python-django before version 2.2.2-1 is vulnerable to cross-site scripting.

The package python2-django before version 1.11.21-1 is vulnerable to cross-site scripting.

An update that contains security fixes can now be installed.

Supra smart TVs aren’t so super smart: Hole lets hackers go all Max Headroom on e-tellies
Devs slam Microsoft for injecting tech-support scam ads into their Windows Store apps

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Tap ‘n Ghost Attack Creatively Targets Android Devices
WWDC 2019: Apple Takes Aim at Facebook on Privacy
Smart-TV Bug Allows Rogue Broadcasts
Google may limit ad blockers for Chrome users
GandCrab Ransomware Shutters Its Operations

An update that solves 5 vulnerabilities and has 6 fixes is now available.

IEEE says it may have gone about things the wrong Huawei, lifts ban after US govt clearance
MacOS Zero-Day Allows Trusted Apps to Run Malicious Code
Legacy app whitelist can be abused to bypass latest macOS security features, expert warns
Your phone’s sensors could be used as a cookie you can’t delete
New controversy erupts over Chrome ad blocking plans
Facebook lawyer argues you should have ‘no expectation of privacy’

An update that fixes four vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Pharma-testing biz Eurofins Scientific says it fell victim to ‘new version’ of malware

An update that fixes 8 vulnerabilities is now available.

An update that solves 5 vulnerabilities and has 6 fixes is now available.

An update that fixes three vulnerabilities is now available.

Going to Infosec Europe this week? Want a free T-shirt?
Fake news writer: If people are stupid enough to believe this stuff…
Data protection authority reports itself to itself after data breach
5G Security Challenges: A Vendor’s POV

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Nginx nJS will need patches, hotels exposed via security systems, Docker containers dinged, and more
5 Best VPN Apps for Android 2019

An update that fixes 16 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

– https://www.drupal.org/project/module_filter/releases/7.x-2.2 – [Moderately critical – Cross site scripting – SA- CONTRIB-2019-042](https://www.drupal.org/sa-contrib-2019-042)

– https://www.drupal.org/project/views/releases/7.x-3.23 – https://www.drupal.org/project/views/releases/7.x-3.22 – https://www.drupal.org/project/views/releases/7.x-3.21 – [Less critical – Cross site scripting – SA-CONTRIB-2019-036](https://www.drupal.org/sa- contrib-2019-036) – [Moderately critical – Information disclosure – SA-

Update to 4.6.6 Various bugfixes on the 4.6 branch

– https://www.drupal.org/project/ds/releases/7.x-2.16 – https://www.drupal.org/project/ds/releases/7.x-2.15 – [Critical – Cross site scripting (XSS) – SA-CONTRIB-2018-019](https://www.drupal.org/sa- contrib-2018-019)

– https://www.drupal.org/project/uuid/releases/7.x-1.2 – https://www.drupal.org/project/uuid/releases/7.x-1.1 – [Moderately critical – Arbitrary file upload – SA-CONTRIB-2018-045](https://www.drupal.org/sa- contrib-2018-045)

– https://www.drupal.org/project/xmlsitemap/releases/7.x-2.6 – https://www.drupal.org/project/xmlsitemap/releases/7.x-2.5 – https://www.drupal.org/project/xmlsitemap/releases/7.x-2.4 – [Moderately critical – Information Disclosure – SA- CONTRIB-2018-053](https://www.drupal.org/sa-contrib-2018-053) –

– https://www.drupal.org/project/context/releases/7.x-3.10 – [Moderately critical – Cross site scripting – SA- CONTRIB-2019-028](https://www.drupal.org/sa-contrib-2019-028) – https://www.drupal.org/project/context/releases/7.x-3.9 – https://www.drupal.org/project/context/releases/7.x-3.8

– https://www.drupal.org/project/path_breadcrumbs/releases/7.x-3.4 – [Less critical – Cross site scripting – SA- CONTRIB-2019-027](https://www.drupal.org/sa-contrib-2019-027)

– https://www.drupal.org/project/ds/releases/7.x-2.16 – https://www.drupal.org/project/ds/releases/7.x-2.15 – [Critical – Cross site scripting (XSS) – SA-CONTRIB-2018-019](https://www.drupal.org/sa- contrib-2018-019)

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.