Menu

Monthly Archives: July 2019

Security fix for CVE-2019-13228, CVE-2019-13229, CVE-2019-13227, CVE-2019-13226.

Security fix for CVE-2019-13228, CVE-2019-13229, CVE-2019-13227, CVE-2019-13226.

Security fix for CVE-2019-13228, CVE-2019-13229, CVE-2019-13227, CVE-2019-13226.

OpenSSL versions 1.1.0 through 1.1.0j and 1.1.1 through 1.1.1b are susceptible to a vulnerability that could lead to disclosure of sensitive information or the addition or modification of data (CVE-2019-1543). Oracle VM VirtualBox prior to 6.0.10 has an easily exploitable vulnerability

Imre Rad discovered several vulnerabilities in GNU patch, leading to shell command injection or escape from the working directory and access and overwrite files, if specially crafted patch files are processed.

WannaCry hero Marcus Hutchin aka MalwareTech won’t serve prison time

Fixed out of bounds heap read in function rtreenode() Enhance the rtreenode() function of rtree (used for testing) so that it uses the newer sqlite3_str object for better performance and improved error reporting.

Louisiana Gov Declares Emergency After Cyberattacks Plague Schools
He’s coming home, he’s coming home … Hutchins’ coming home: British Wannacry killer held in US on malware dev rap set free by judge
Rare Steganography Hack Can Compromise Fully Patched Websites
Gamers Are Easy Prey for Credential Thieves

Several security issues were fixed in the Linux kernel.

VLC 3.0.7 has been released on June 6 including security fixes References: – https://bugs.mageia.org/show_bug.cgi?id=24940 – http://www.jbkempf.com/blog/post/2019/VLC-3.0.7-and-security

USN-4054-1 caused some minor regressions in Firefox.

An update that solves two vulnerabilities and has 10 fixes is now available.

Various security problems have been additionally fixed in libssh2, an SSH client implementation written in C++.

Louisiana declares state of emergency after ransomware attacks
‘Google’ Sites Are the Latest Ploy by Card-Skimming Thieves
Sysadmins need to know – how DO you pronounce “sudo”?

Reading Time: ~ 2 min. Vulnerability Exposes Dozens of U.S. Colleges At least 62 U.S. colleges have been compromised after an authentication vulnerability was discovered by hackers, allowing them to easily access user accounts. At several of the compromised colleges, officials were tipped off after hundreds of fraudulent user accounts were created within a 24-hour […]

An update that solves two vulnerabilities and has two fixes is now available.

Happy SysAdminDay 2019!
BlueKeep guides make imminent public exploit more likely
Browser plug-ins peddled personal data from over 4m browsers
Cyberlaw wonks squint at NotPetya insurance smackdown: Should ‘war exclusion’ clauses apply to network hacks?

This is the one-month notification for the end of the maintenance phase for Red Hat OpenShift Enterprise 3.6 and 3.7. This notification applies only to customers with subscriptions for Red Hat OpenShift Enterprise 3.6 and 3.7. 2. Description:

Risk Level: Very Low. Type: Trojan.

Streamlining Patch Management: Expert Advice

Update to v5.1.19

Update to v5.1.19

South Africans shivering in the dark after file-scrambling nasty hits Johannesburg power biz
Backdoors won’t weaken your encryption, wails FBI boss. And he’s right. They won’t – they’ll fscking torpedo it
New Loader Variant Behind Widespread Malware Attacks

An issue with quoting has been found in patch, a tool to apply a diff file to an original, when invoking ed. In order to avoid this, ed is now directly started instead of calling a shell which starts ed.

An update for atomic-openshift and jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Streaming service endures 13‑day DDoS raid

The attack, unleashed by a 400,000-strong Mirai-style botnet, may be the largest of its kind on record The post Streaming service endures 13‑day DDoS raid appeared first on WeLiveSecurity

Facebook gets its wrist slapped $5b for fumbling our data, confirms FTC
EvilGnome – Linux malware aimed at your laptop, not your servers
Protecting Against Ransomware Attacks: A Checklist

An update that solves three vulnerabilities and has 9 fixes is now available.

An update that fixes one vulnerability is now available.

Exim could be made to run programs as an administrator if it received specially crafted network traffic.

New York City moves to protect citizens’ location data

An update for rh-redis32-redis is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

You can probably be identified from your anonymized data
Red Hat Certificate System achieves Common Criteria certification
Interview with Security Expert and Author Ira Winkler: Advanced Persistent Security, Threat Intelligence, Social Engineering and more

An update that solves two vulnerabilities and has one errata is now available.

Several security issues were fixed in VLC.

libEBML could be made to crash if it opened a specially crafted file.

Jeremy Harris discovered that Exim, a mail transport agent, does not properly handle the ${sort } expansion. This flaw can be exploited by a remote attacker to execute programs with root privileges in non-default (and unusual) configurations where ${sort } expansion is used for items

Smashing Security #138: Logic bombs, brain data exploitation, and Digga D tweets

security update

Popular File-Sharing Service WeTransfer Used in Malicious Spam Campaigns

Update including July CPU fixes.

Update including July CPU fixes.

ThreatList: Human Error is Behind One Quarter of Data Breaches

security update

security update

security update

Several security issues were fixed in Ansible.

Sanctions-hit Russian developers fingered for crafting ‘Monokle’ Android snoopware
New malware attack turns Elasticsearch databases into DDoS botnet
Unique Monokle Android Spyware Self-Signs Certificates

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes 10 vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

Man arrested over UK’s Lancaster University data breach hack allegations

Several security issues were fixed in Patch.

Data breaches can haunt firms for years

The compromised company may bear the financial brunt of the breach within the first year after the incident occurs, but the price tag is still far from final The post Data breaches can haunt firms for years appeared first on WeLiveSecurity

Police arrest man after Lancaster University hacking attack

An update that fixes 5 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Several security issues were fixed in Patch.

Sky worries users with phishy-looking password reset email
Apple’s July patchfest fixes bugs in multiple products
Facebook admits to Messenger Kids security hole

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

An update is now available for CloudForms Management Engine 5.10. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

With more hints dropped online on how to exploit BlueKeep, you’ve patched that Windows RDP flaw, right?
Low Barr: Don’t give me that crap about security, just put the backdoors in the encryption, roars US Attorney General
Citrix Confirms Password-Spraying Heist of Reams of Internal IP
Dodgy vids can hijack PCs via VLC security flaw, US, Germany warn. Software’s makers not app-y with that claim
WordPress Plugin Flaws Exploited in Ongoing Malvertising Campaign
Malware-Loader ‘Brushaloader’ Grows More Menacing
SharePoint Online scam – sadly, phishing’s not dead
Popular Samsung, LG Android Phones Open to ‘Spearphone’ Eavesdropping

Reading Time: ~ 4 min. You’ve likely heard of the dark web. This ominous sounding shadow internet rose in prominence alongside cryptocurrencies in the early 2010s, eventually becoming such an ingrained part of our cultural zeitgeist that it even received its own feature on an episode of Law & Order: SVU. But as prominent as […]

Jann Horn discovered that the ptrace subsystem in the Linux kernel mishandles the management of the credentials of a process that wants to create a ptrace relationship, allowing a local user to obtain root privileges under certain scenarios.

VLC Media Player Plagued By Unpatched Critical RCE Flaw

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.