Menu

Monthly Archives: July 2019

Why are they “smart” locks if more money buys you less security?
Derp! DDoS attacker who brought down EA, Sony, and Steam jailed for 27 months

An update that contains security fixes can now be installed.

An update that solves three vulnerabilities and has two fixes is now available.

St John Ambulance service hit by ransomware attack
Reports of cyber attacks fall, says UK.gov survey: GDPR? Fewer nasties? More targeted attacks? We just don’t know

USN-4038-1 introduced a regression in bzip2.

USN-4038-1 introduced a regression in bzip2.

An update that solves three vulnerabilities and has 26 fixes is now available.

An update that solves three vulnerabilities and has 26 fixes is now available.

An update that fixes three vulnerabilities is now available.

Open Sesame! Zipato’s smart hub hacked to open front doors
Facebook’s down-ranking those ‘miracle cure’ health posts we all hate
Facebook should put a stop to Libra for now, says Congress
TikTok investigated (again) over how it handles children’s data and safety

It was discovered that there was a XML external entity vulnerability in the lemonldap-ng single-sign on system. This may have led to the disclosure of confidential data, denial of service, server side request forgery, port scanning, etc.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

US Cyber Command warns that the Outlook is not so good – Iranians hitting email flaw
Smashing Security #135: Zombie grannies and unintended leaks

This update includes a rebase from 9.0.13 up to 9.0.21 which resolves two CVEs along with various other bugs/features: * rhbz#1673856 tomcat-9.0.21 is available * rhbz#1713279 CVE-2019-0221 tomcat: XSS in SSI printenv * rhbz#1693326 CVE-2019-0199 tomcat: Apache Tomcat HTTP/2 DoS

How do we stop facial recognition from becoming the next Facebook: ubiquitous and useful yet dangerous, impervious and misunderstood?
YouTube mystery ban on hacking videos has content creators puzzled
Facebook and Instagram suffer massive outage
D-Link must suffer indignity of security audits to settle with the Federal Trade Commission
Apple Transparency Report Now Includes App Store Takedown Requests
NHS warned to act now to keep hackers at bay

A trifecta of issues impact the organization’s cyber-resilience and conspire to put it in the firing line of cyberattacks The post NHS warned to act now to keep hackers at bay appeared first on WeLiveSecurity

Serious Security: Beware eBay scrapers promising to help you
Amazon Admits Alexa Voice Recordings Saved Indefinitely

An update that fixes 15 vulnerabilities is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1650

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1652

You lost US Customs Border data? You’re losing your government contracts…
US Cyber Command warns nation-state hackers are exploiting old Microsoft Outlook bug. Make sure you’re patched!
IoT vendor Orvibo gives away treasure trove of user and device data
Georgia’s court system hit by ransomware

Two vulnerabilities have been discovered in pdns, an authoritative DNS server which may result in denial of service via malformed zone records and excessive NOTIFY packets in a master/slave setup.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Russian ‘Silence’ hacking crew turns up the volume – with $3m-plus cyber-raid on bank’s cash machines
Miami police body cam videos up for sale on the darkweb
Patch Android! July 2019 update fixes 9 critical flaws

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Here’s a great idea: Why don’t we hardcode the same private key into all our smart home hubs?
$30/month email upstart Superhuman brought low with a blast of privacy Kryptonite
Cloudflare’s recent 502 Bad Gateway outage blamed on bad software

Update to v5.1.15 —- Update to v5.1.14

Update to v5.1.15 —- Update to v5.1.14

Security Camera Firm Arlo Zaps High-Severity Bugs

security update

security update

IBM Patches Critical, High-Severity Flaws in Spectrum Protect
We are shocked to learn oppressive authoritarian surveillance state China injects spyware into foreigners’ smartphones
Google July Android Security Bulletin Fixes 3 Critical RCE Bugs
Two billion user logs leaked by smart home vendor

The leak, which apparently has yet to be plugged, exposes a range of very specific data about users The post Two billion user logs leaked by smart home vendor appeared first on WeLiveSecurity

Mobile app building is simple and affordable – the Appy Pie way!
Mac Malware Pushed via Google Search Results, Masquerades as Flash Installer

A specially crafted URL in can potentially cause cgit to excessively use CPU and network resources, resulting in a Denial-of-Service. This update resolves that issue

Several security issues were fixed in Thunderbird.

Updated firefox packages fix a security vulnerability thats being exploited in the wild: sandbox escape using Prompt:Open. (CVE-2019-11708)

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Scary Granny zombie game slurps credentials, spawns phishing attack

libssh2: Integer overflow in transport read resulting in out of bounds write (CVE-2019-3855) * libssh2: Integer overflow in keyboard interactive handling resulting in out of bounds write (CVE-2019-3856) * libssh2: Integer overflow in SSH packet processing channel resulting in out of bounds write (CVE-2019-3857) * libssh2: Integer overflow in user authenticate keyboard interactive allows out […]

An update that fixes one vulnerability is now available.

QEMU: Slirp: information leakage in tcp_emu() due to uninitialized stack variables (CVE-2019-9824) SL6 x86_64 qemu-guest-agent-0.12.1.2-2.506.el6_10.4.x86_64.rpm qemu-img-0.12.1.2-2.506.el6_10.4.x86_64.rpm qemu-kvm-0.12.1.2-2.506.el6_10.4.x86_64.rpm qemu-kvm-debuginfo-0.12.1.2-2.506.el6_10.4.x86_64.rpm qemu-kvm-tools-0.12.1.2-2.506.el6_10.4.x86_64.rpm i386 qemu-gue [More…]

An update that solves one vulnerability and has one errata is now available.

Updated thunderbird packages fix security vulnerabilities: Type confusion in Array.pop. (CVE-2019-11707) Sandbox escape using Prompt:Open. (CVE-2019-11708)

Dating app Jack’d fined $240K for leaving private photos up for a year
Medtronic rushes to replace insulin pumps after flaws found

An update for spacewalk-backend is now available for Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Relatives’ DNA in geneology database leads to murder conviction
July is here – and so are the latest Android security fixes. Plenty of critical updates for all
Cop a load of this: 1TB of police body camera videos found lounging around public databases
Is Your VPN Provider in a 14 Eyes Country? (What is 14 Eyes?)
Facebook staff sarin for a bad day: Suspected chemical weapon parcel sent to Silicon Valley HQ
Finding Beauty in the IT Architecture
Facebook Removes Accounts Used to Infect Thousands With Malware
Hacker deletes entire student newspaper website of University of Ottawa
Ex-Equifax CIO, who knew about huge data breach, jailed for insider trading
Ex-Equifax executive sent to jail for insider trading after breach

“Sounds bad”, the former Equifax CIO wrote in a text after learning of the breach that ended up affecting almost half the US population The post Ex-Equifax executive sent to jail for insider trading after breach appeared first on WeLiveSecurity

Dating App Jack’d Fined After Leaking Users’ Nude Pics
Don’t tell Alice and Bob: Security maven Bruce Schneier is leaving IBM
RDP BlueKeep exploit shows why you really, really need to patch

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 9 vulnerabilities and has two fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes four vulnerabilities is now available.

ETERNALBLUE sextortion scam puts your password where your name should be

openSUSE: openSUSE Leap 42.3 has reached end of SUSE support

Malware makes an exhibition of itself

vim/neovim: ‘:source!’ command allows arbitrary command execution via modelines (CVE-2019-12735) SL7 x86_64 vim-X11-7.4.160-6.el7_6.x86_64.rpm vim-common-7.4.160-6.el7_6.x86_64.rpm vim-debuginfo-7.4.160-6.el7_6.x86_64.rpm vim-enhanced-7.4.160-6.el7_6.x86_64.rpm vim-filesystem-7.4.160-6.el7_6.x86_64.rpm vim-minimal-7.4.160-6.el7_6.x86_64.rpm – Scientific Linux Develo [More…]

Mozilla: Type confusion in Array.pop (CVE-2019-11707) * thunderbird: Stack buffer overflow in icalrecur_add_bydayrules in icalrecur.c (CVE-2019-11705) * Mozilla: Sandbox escape using Prompt:Open (CVE-2019-11708) * thunderbird: Heap buffer over read in icalparser.c parser_get_next_char (CVE-2019-11703) * thunderbird: Heap buffer overflow in icalmemory_strdup_and_dequote function in icalvalu [More…]