Menu

Monthly Archives: July 2019

An update that fixes 12 vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Programmer from hell plants logic bombs to guarantee future work
Lancaster Uni data breach hits at least 12,500 wannabe students
Big password hole in iOS 13 beta spotted by testers
Your Android’s accelerometer could be used to eavesdrop on your calls
FSB hackers drop files online
It’s 2019 and you can still pwn an iPhone with a website: Apple patches up iOS, Mac bugs in July security hole dump

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Cloud hosting provider iNSYNQ hit by MegaCortex ransomware
Equifax to world+dog: If we give you this $700m, can you pleeeeease stop suing us about that mega-hack thing?
Critical RCE Flaw in Palo Alto Gateways Hits Uber
700 million reasons for Equifax to remember to patch its vulnerable IT systems in future
Tackling the Collaboration Conundrum

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Large-Scale Government Hacks Hit Russia, Bulgaria
VLC player has a critical flaw – and there’s no patch yet

On the flip side, there are currently no known cases of the vulnerability being exploited in the wild The post VLC player has a critical flaw – and there’s no patch yet appeared first on WeLiveSecurity

Amazon Alexa, Google Home On Collision Course With Regulation
Equifax to Pay $700 Million in 2017 Data Breach Settlement
iCloud account hacker jailed for three years after preying on rappers and sports celebrities
Chrome 76 blocks websites from detecting incognito mode

Several security issues were fixed in Squid.

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

No, the Met Police wasn’t hacked. But its Twitter account and website were hijacked

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

Hacked Bulgarian database reaches online forums
Cisco ‘in talks’ to borg with web app protector Signal Sciences for its web app firewall tech

Several vulnerabilities were found in libxslt the XSLT 1.0 processing library. CVE-2016-4610

What makes a secure & successful website: A Guide

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

ClamAV could be made to expose sensitive information if it received a specially crafted CHM file.

Stop facial recognition trials now, warns UK committee

An update for rh-nodejs8-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-redis5-redis is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Marketing biz bares folks’ data in the act of asking for their GDPR comms preferences

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

security update

Hackers steal 7.5TB of data from Russian Intel Agency FSB’s contractor

An update that fixes 10 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that solves 21 vulnerabilities and has two fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Palo Alto gateway security alert, FSB hack, scourge of data-stealing web plugins, and more

Vulnerabilities have been discovered in nss, the Mozilla Network Security Service library.

Jann Horn discovered that the ptrace subsystem in the Linux kernel mishandles the management of the credentials of a process that wants to create a ptrace relationship, allowing a local user to obtain root privileges under certain scenarios.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has four fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes four vulnerabilities is now available.

In the cooler for the next three years: Hacker of iCloud accounts used by athletes and rappers

Update to Samba 4.9.11 —- Update to Samba 4.9.9 Security fixes for CVE-2019-12435

Update to Samba 4.9.11 —- Update to Samba 4.9.9 Security fixes for CVE-2019-12435

Iran-Linked APT34 Invites Victims to LinkedIn for Fresh Malware Infections
When Harry met celly: NSA hoarder thrown in the clink for 9 years – after taking classified work home for decades
Adult Sites Lack Privacy, Open the Door for Harassment and Tracking
All very MoD-ern: RAF test pilot headed into space with Virgin, £30m small sat demo project
Bug in NVIDIA’s Tegra Chipset Opens Door to Malicious Code Execution
Israel’s NSO Group: Our malware? Slurp your cloud backups plus phone data? They’ve misunderstood

Reading Time: ~ 2 min. Over 100 Million Accounts Exposed in Evite Breach More than 100 million users of Evite were exposed after the company’s servers were compromised earlier this year. While the company doesn’t store financial information, plenty of other personally identifiable information was found in the leaked database dump. The initial figures for […]

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Your biz won’t be hacked by a super-leet exploit. It’ll be Bob in sales opening a dodgy email
Slack response. Passwords reset four years after data breach
Excluding Huawei from UK’s 5G will harm security, MPs warn
Firefox to pile on more native privacy features
Shapeshifting Morpheus chip aims to baffle hackers
FaceApp privacy panic sets internet alight

It was discovered that there was an integer overflow vulnerability in exiv2, a tool to manipulate images containing (eg.) EXIF metadata. This could have resulted in a denial of service via a specially-

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

2015 database hack is the terrible gift that keeps giving for Slack: Tens of thousands of passwords now reset

Update to v5.1.18 —- Update to v5.1.17

Update to v5.1.18 —- Update to v5.1.17

– fixes security issues CVE-2019-10190 and CVE-2019-10191 – https://lists.nic.cz/pipermail/knot-resolver-announce/2019/000009.html