Menu

Monthly Archives: August 2019

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

A vulnerability has been discovered in Python, an interactive high-level object-oriented language, that is relevant for cookie handling. By using a malicious server an attacker might steal cookies that are meant for other

Multiple vulnerabilities have been found in Dovecot, the worst of which could result in the arbitrary execution of code.

A vulnerability in the GNOME desktop library may allow attackers to escape the sandbox.

A vulnerability in Nautilus may allow attackers to escape the sandbox.

Multiple vulnerabilities have been found in libofx, the worst of which could result in the arbitrary execution of code.

The mpg123 package has been updated to version 1.25.12, fixing several issues which could cause it to crash or hang while parsing mp3 files. References: – https://bugs.mageia.org/show_bug.cgi?id=25350

Updated webmin package fixes security vulnerability: Webmin before 1.930 allows remote exploits if the option to change expired passwords is enabled (CVE-2019-15107).

Updated ghostscript packages fix security vulnerability: It was found that the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript

Updated pango package fixes security vulnerability: It was discovered that pango was subject to a heap based buffer overflow vulnerability which could be used to get code execution (CVE-2019-1010238).

Updated ansible package fixes security vulnerability: A flaw was discovered in the way Ansible templating was implemented before version 2.7.12, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable

Updated vlc packages fixes security vulnerabilities: Multiple security issues were discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed file/stream is processed (CVE-2019-13602, CVE-2019-13962,

AUpdated memcached packages fix security vulnerability: In memcached before 1.5.14, a NULL pointer dereference was found in the “lru mode” and “lru temp_ttl” commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in

Updated wavpack packages fixes security vulnerabilities: Rohan Padhye discovered that WavPack incorrectly handled certain WAV files. An attacker could possibly use this issue to cause a denial of service (CVE-2019-1010315, CVE-2019-1010317, CVE-2019-1010318, CVE-2019-1010319).

Updated wavpack packages fixes security vulnerabilities: It was discovered that WavPack incorrectly handled certain DFF files. An attacker could possibly use this issue to cause a denial of service (CVE-2019-11498).

A number of potential side channel attacks were discovered in the SAE implementations used by both hostapd (AP) and wpa_supplicant (infrastructure BSS station/mesh station). SAE (Simultaneous Authentication of Equals) is also known as WPA3-Personal. The discovered side channel attacks may be able to leak information about the used

JACK OF ALL TIRADES: Twitter boss loses account to cunning foul-mouthed pranksters
Twitter CEO Jack Dorsey’s account hacked with racial slurs
Coin-mining malware jumps from Arm IoT gear to Intel servers
@jack’s twitter attacked, phone number hacked
Google security crew sheds light on long-running super-stealthy iOS spyware operation
Google hackers found malicious websites hacking iPhones

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

For Foxit’s sake: PDF editor biz breached, users’ passwords among stolen data
iPhone Zero-Days Anchored Watering-Hole Attacks
Six Hackers Have Now Pocketed $1M From Bug Bounty Programs
Google’s bug bounty bid to make big Android apps more secure
Sophisticated iPhone hacking went unnoticed for over two years
News Wrap: Dentist Offices Hit By Ransomware, Venmo Faces Privacy Firestorm
When you think how infamous NHS-pwning malware’s still hitting the unwary, it’ll make you WannaCry – Kaspersky
Botnet targets set-top boxes using Android OS

Reading Time: ~ 2 min. Cybercriminals use Botnets to Launch Attacks on Social Media According to a new report, more than half of all login attempts on social media sites are fraudulent, and at least 1 in 4 new account creation attempts are also fraudulent. With the sheer number of potential victims these types of […]

Hardening Gluster Installations with TLS
Hear me speak at “Conversations from the Vault” in London
Apple apologizes for humans listening to Siri clips, changes policy

* CVE-2019-11500: IMAP protocol parser does not properly handle NUL byte when scanning data in quoted strings, leading to out of bounds heap memory writes

Rebuilt with newer nghttp2 —- This update includes the latest upstream release of `mod_http2`, version **1.15.3**. Upstream changes include: * fixes Timeout vs. KeepAliveTimeout behaviour, see PR 63534. * Fixes stream cleanup when connection throttling is in place. * Counts stream resets by client on streams initiated by client as cause for connection throttling. * […]

Despite billions in spending, your ‘military grade’ network will still be leaking data
Google warns of system-controlling Chrome bug
The top reason businesses make a cyber insurance claim – Business Email Compromise

An update that fixes one vulnerability is now available.

I just love your accent – please, have a new password
Google takes a little more responsibility for its Android world, will cough up bounties for mega-popular app bugs
TGI Fridays Delivers Customer Indigestion Over Data Exposure

New version 3.0.3, Security fix for CVE-2019-13619

Update to 2.6.7

FIN6 Switches Up PoS Tactics to Target E-Commerce

security update

An update that solves four vulnerabilities and has three fixes is now available.

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Capital One ‘hacker’ hit with fresh charges: She burgled 30 other AWS-hosted orgs, Feds claim

Several security issues were fixed in Apache.

Hongxu Chen found several issues in djvulibre, a library and set of tools to handle images in the DjVu format.

New version 3.0.3, Security fix for CVE-2019-13619

Update to 2.6.7

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Google Targets Data-Abusing Apps with Bug Bounty Launch
Which Linux Distros Are Most Focused On Privacy?
Venmo’s Public Transactions Policy Stirs Privacy Concerns
Ex-Amazon worker – suspected of hacking Capital One – faces charges of breaching 30 other companies to mine cryptocurrency
Web clickjacking fraud makes a comeback thanks to JavaScript tricks

The package libnghttp2 before version 1.39.2-1 is vulnerable to denial of service.

The package go-pie before version 2:1.12.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.

The package go before version 2:1.12.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.

The package gettext before version 0.20.1-1 is vulnerable to arbitrary code execution.

Critical Cisco VM Bug Allows Remote Takeover of Routers
Innovation on the Dark Web: How Bad Actors Are Keeping Pace
Video captures glitching Mississippi voting machines flipping votes
Microsoft may still be violating privacy rules, says Dutch regulator
Smashing Security #143: Hacking from outer space, Ukrainian cryptomining, and deepfaked Canadians

An update for pango is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes two vulnerabilities is now available.

Ceph could be made to crash if it received specially crafted network traffic.

Today’s Resident Evil: Ransomware crooks think local, not global, prey on schools, towns, libraries, courts, cities…
Ways to Help Keep Your Business Systems Secure
Elderly China Chopper Tool Still Going Strong in Multiple Campaigns
Are US border cops secretly secreting GPS trackers on vehicles without a warrant? EFF lawyers want to know

Ghostscript could be made to access arbitrary files if it opened a specially crafted file.

Two security vulnerabilities were found in the Apache HTTP server. CVE-2019-10092

Come on, hackers, do your worst ‒ Facebook opens Portal gizmo to Pwn2Own exploit fest
TrickBot Targets Verizon, T-Mobile, Sprint Users to Siphon PINs

USN-4110-1 introduced a regression in Dovecot.

Popular CamScanner app for Android infected with nasty malware
Apple Updates Privacy Policies After Siri Audio Recording Backlash
Google Squashes High-Severity Blink Browser Engine Flaw
Emergency iOS patch fixes jailbreaking flaw for second time
Defense Takeaways from Three Adversary Playbooks
Dangerous Cryptomining Worm Racks Up 850K Infections, Self-Destructs
Magecart Hits 80 Major eCommerce Sites in Card-Skimming Bonanza

An update for jenkins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for pango is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat Ceph Storage 3.3 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that contains security fixes can now be installed.

An update that fixes 9 vulnerabilities is now available.