Menu

Monthly Archives: July 2019

Slack data breach: Company resets thousands of passwords
Security Watch: Elon Musk’s NeuraLink Links Brains to iPhones via Bluetooth

– fixes security issues CVE-2019-10190 and CVE-2019-10191 – https://lists.nic.cz/pipermail/knot-resolver-announce/2019/000009.html

It’s never good when ‘Magecart’ and ‘bulletproof’ appear in the same sentence, but here we are
Mirai Botnet Sees Big 2019 Growth, Shifts Focus to Enterprises
Slack Initiates Mass Password Reset

Several security issues were fixed in LibreOffice.

Google Triples Some Bug Bounty Payouts
Ke3chang APT Linked to Previously Undocumented Backdoor
Bulgaria hack: 20-year-old infosec whizz cuffed after ‘adult population’s’ finance deets nicked
EvilGnomes Linux malware record activities & spy on users

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Those facial recognition trials in the UK? They should be banned, warns Parliamentary committee
Thousands of NHS computers are still running Windows XP from beyond the grave
Hacked Bluetooth hair straighteners are too hot to handle
Google Chrome is ditching its XSS detection tool
Microsoft demos end-to-end voting verification system ElectionGuard, code will be on GitHub
Still not using HTTPS? Firefox is about to shame you

An update that solves two vulnerabilities and has three fixes is now available.

‘Member Ke3chang? They’re still at it, you know. Euro diplomats targeted by ‘China-based’ hacker crew
Okrum: Ke3chang group targets diplomatic missions

Tracking the malicious activities of the elusive Ke3chang APT group, ESET researchers have discovered new versions of malware families linked to the group, and a previously unreported backdoor The post Okrum: Ke3chang group targets diplomatic missions appeared first on WeLiveSecurity

Security researcher arrested after data on every adult in Bulgaria hacked from government site
Dutch cops collar fella accused of crafting and flogging Office macro nasties to cyber-crooks
Fresh stalkerware crop pops up on Google’s Android Play Store, swiftly yanked offline
Don’t give it away, give it away, give it away now, bot busting biz tells reCAPTCHA data serfs
Smashing Security #137: Porn trolling lawyers, Insta hacking, and Ctrl-Alt-LED
Wormable BlueKeep Bug Still Threatens Legions of Windows Systems

security update

Several security issues were fixed in Thunderbird.

BlueKeep patching isn’t progressing fast enough

Keeping up with BlueKeep; or how many internet-facing systems, and in which countries and industries, remain ripe for exploitation? The post BlueKeep patching isn’t progressing fast enough appeared first on WeLiveSecurity

For pity’s sake, groans Mimecast, teach your workforce not to open obviously dodgy emails
Firmware Bugs Plague Server Supply Chain, 7 Vendors Impacted
Bluetooth Flaws Could Allow Global Tracking of Apple, Windows 10 Devices

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Massive Malvertising Campaign Reaches 100M Ads, Manipulates Supply Chain

An update that fixes three vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Email scammers extract over $300m a month from American suits’ pockets

An update that fixes 10 vulnerabilities is now available.

An update that solves 7 vulnerabilities and has three fixes is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1775

The package chromium before version 75.0.3770.142-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

The package squid before version 4.8-1 is vulnerable to arbitrary code execution.

The package firefox before version 68.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, cross-site request forgery, sandbox escape, arbitrary filesystem access, content spoofing, cross-site scripting, denial of service, information disclosure, insufficient validation and silent downgrade.

StrongPity APT Returns with Retooled Spyware
RDP exposed: the wolves already at your door

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1774

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1777

A use-after-free in onig_new_deluxe() in regext.c allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker

Microsoft, Google and Apple clouds banned in Germany’s schools
Facebook rolls out anti-scam reporting tool in UK
Apple pushes out another silent update to address flaws in RingCentral and other video conferencing apps
Researchers hide data in music – and human ears can’t detect it
Meet IRpair & Phantom; powerful anti-facial recognition glasses

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

It was totally Samsung’s fault that crims stole your personal info from a Samsung site, says Samsung-blaming Sprint
Let’s open the Mystery Data Security Blunder box, and see what’s inside today… Ah! Hotel reservations and more
LenovoEMC Storage Gear Leaks Sensitive Financial Data
Hackers used Samsung website to access Sprint’s customer data
Maybe double-check that HMRC email? UK taxman remains a fave among the phisherfolk
The Future is Female: A Key to the Cybersecurity Workforce Challenge
WhatsApp, Telegram Coding Blunders Can Expose Personal Media Files
How your Instagram account could have been hijacked

A researcher found that it was possible to subvert the platform’s password recovery mechanism and take control of user accounts The post How your Instagram account could have been hijacked appeared first on WeLiveSecurity

GandCrab ransomware revisited – is it back under a (R)evil new guise?
JetBlue Bomb Scare Set Off with Apple AirDrop

An update that solves one vulnerability and has two fixes is now available.

Several security issues were fixed in NSS.

Patch now before you get your NAS kicked: Iomega storage boxes leave millions of files open to the internet

An update is now available for Red Hat JBoss BPM Suite. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Bluetooth LE’s anti-tracking technology beaten
$5b privacy fine against Facebook seen as ‘chump change’
Ransomware attackers demand $1.8m from US college

Several security issues were fixed in Redis.

Asian consortium plans blockchain-based mobile ID system
Amadeus! Amadeus! Pwn me Amadeus! Airline check-in bug may have exposed all y’all boarding passes to spies

An update for vim is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for keepalived is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libssh2 is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for perl is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for 389-ds-base is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in NSS.

Alan Turing chosen for the UK’s new £50 note – a cracking result!

Risk Level: Very Low. Type: Trojan.

This update includes a fix for a security vulnerability, CVE-2018-20843: > Fix extraction of namespace prefixes from XML names; XML names with multiple colons could end up in the wrong namespace, and take a high amount of RAM and CPU resources while processing, opening the door to use for denial-of-service attacks For more information on […]

Rebase to radare2 3.6.0 and fixes CVE-2019-12790 and CVE-2019-12802

Privacy Experts: Facebook’s $5B Fine Unlikely to Do Much
Turla APT Returns with New Malware, Anti-Censorship Angle

security update

Symantec share price nose dives after rumored Broadcom biz gobble taken off the menu
Hacker gets $30,000 for reporting hack Instagram account flaw
Instagram bug could have allowed anyone to take over your account
Alan Turing – the face of the new £50 note
How to secure your website – InfoSec tips for newbie website owners
Researcher Bypasses Instagram 2FA to Hack Any Account

An update that fixes 5 vulnerabilities is now available.