Menu

Monthly Archives: July 2019

Scots NHS symptom checker pings Facebook, Google and other ad peddlers
Buhtrap group uses zero‑day in latest espionage campaigns

ESET research reveals notorious crime group also conducting espionage campaigns for the past five years The post Buhtrap group uses zero‑day in latest espionage campaigns appeared first on WeLiveSecurity

Dodgy-govt fave FinSpy snoopware is back and badder than ever for Android and iOS kit
Sea Turtle hackers head to the Mediterranean, snag Greece’s TLD registrar as a souvenir
“Mozilla aren’t villains after all” – ISPs back down after public outcry
AMD’s SEV tech that protects cloud VMs from rogue servers may as well stand for… Still Extremely Vulnerable
Bug in Anesthesia Respirators Allows Cyber-Tampering
Remember Stuxnet? You’ll endure its hated-by-critics sequel if you don’t patch your holey Siemens industrial kit

New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure Automation is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server and Team Foundation Server are prone to an remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Visual Studio is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Visual Studio is prone to a local privilege-escalation vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Zoom Pushes Emergency Patch for Webcam Hijack Flaw
Latest FinSpy Modules Lift Data from Secure Messaging Apps
UK watchdog fined firms £3m for data breaches last year – before its GDPR balls dropped

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Agent Smith Malware Infects 25M Android Phones to Push Rogue Ads

dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass (CVE-2019-12749) SL6 x86_64 dbus-1.2.24-11.el6_10.x86_64.rpm dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-debuginfo-1.2.24-11.el6_10.x86_64.rpm dbus-libs-1.2.24-11.el6_10.i686.rpm dbus-libs-1.2.24-11.el6_10.x86_64.rpm dbus-x11-1.2.24-11.el6_10.x86_64.rpm dbus-devel-1.2.24-11.el6_10.i686.rpm dbus-devel-1 [More…]

Marriott faces £99.2 million fine after hack exposed 393 million hotel guest records

An update that solves one vulnerability and has 8 fixes is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that solves 21 vulnerabilities and has two fixes is now available.

An update that solves one vulnerability and has two fixes is now available.

Two zero days and 15 critical flaws fixed in July’s Patch Tuesday
Rogue Android apps ignore your permissions
Did a hacked smart TV upload footage of couple having sofa sex to a porn website?
Instagram asks bullies, ‘Are you sure you want to say that?’

It was discovered that there were two heap buffer overflows in the Hyperloglog functionality provided by the Redis in-memory key-value database.

Windows zero‑day CVE‑2019‑1132 exploited in targeted attacks

ESET research discovers a zero-day exploit that takes advantage of a local privilege escalation vulnerability in Windows The post Windows zero‑day CVE‑2019‑1132 exploited in targeted attacks appeared first on WeLiveSecurity

An update for openstack-ironic-inspector is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for openstack-tripleo-common is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Mozilla boots alleged snoop troupe from its root cert coop: UAE-based DarkMatter thrown onto CA blocklist
It’s 2019 and SQL Server can be pwned by an SQL query, DHCP failover server failed by a packet, Edge, IE by webpages…

Risk Level: Very Low. Type: Trojan.

Intel Patches High-Severity Flaw in Processor Diagnostic Tool
Cyber ​​attacks cost $45 billion in 2018 with Ransomware at top

security update

Microsoft Patches A Pair of Zero-Days Under Active Attack
Huawei website ████ ██████ security flaws ██████ customer info and biz operations at risk: ███████ patched
Marriott’s got 99 million problems and the ICO’s one: Starwood hack mega-fine looms over
Vulnerability in Zoom video conference app lets Mac’s camera hijacking
UK’s data watchdog hands out two mega‑fines for breaches

The times they have a-changed since the ICO could only slap fines worth a fraction of the current amounts The post UK’s data watchdog hands out two mega‑fines for breaches appeared first on WeLiveSecurity

1,300 Popular Android Apps Access Data Without Proper Permissions
‘This repository is private’ – so what’s it doing on the public internet, GE Aviation?
Zoom flaw could force you into a meeting, expose your video feed
Marriott Hit With $123M Fine For Massive 2018 Data Breach
Zoom Zero-Day Bug Opens Mac Users to Webcam Hijacking
Backdoor discovered in Ruby strong_password library
Rapid Incident Response Now Available through Cynet’s Free IR Service Providers Offering
Boffins ready to go live with system that will track creatures great and small from space
Anyone for unintended Chat Roulette? Zoom installs hidden Mac web server to allow auto-join video conferencing

Apport could be made to expose sensitive information in crash reports.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Two pentesters, one glitch: Firefox browser menaced by ancient file-snaffling bug, er, feature
Zoom Mac flaw allows webcams to be hijacked – because they wanted to save you a click
Google suspends Trends emails after revealing murder suspect’s name

An update is now available for Red Hat JBoss Web Server 3.1. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Firefox to include tracker blocking report feature
Apple aims privacy billboard at Google’s controversial smart-city

An update is now available for Red Hat JBoss Web Server 3.1 for RHEL 6 and Red Hat JBoss Web Server 3.1 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in GVfs.

The package python2-django before version 1.11.22-1 is vulnerable to silent downgrade.

The package python-django before version 2.2.3-1 is vulnerable to silent downgrade.

The package irssi before version 1.2.1-1 is vulnerable to arbitrary code execution.

Spring Security support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user

Whoopsie could be made to crash or expose sensitive information if it processed a specially crafted crash report.

Apport could be made to expose sensitive information in crash reports.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.