Menu

Monthly Archives: August 2019

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Reading Time: ~ 2 min. Android Apps Riddled with Adware Another 85 photo and gaming apps have been removed from the Google Play store after they were discovered to have been distributing adware to the roughly 8 million users who had downloaded the fake apps. The adware itself is rather tricky: by sitting dormant on […]

News Wrap: Linux Utility Backdoor, Steam Zero Day Disclosure Drama
Lenovo High-Severity Bug Found in Pre-Installed Software
Cybercrook hands cops £923k in Bitcoin made from selling phished deets on the dark web
Instagram phishing uses 2FA as a lure
‘Privacy policy change’ hoax infects Instagram; it confirms it’s crud

An update that fixes one vulnerability is now available.

YouTube joins Facebook and Twitter, disabling accounts targeting Hong Kong protests
Bumper Cisco patches fix four new ‘critical’ vulnerabilities
GitHub upgrades two-factor authentication with WebAuthn support
Steam cleaned of zero-day security holes after Valve turned off by bug bounty snub outrage

This update includes the latest release of the Apache HTTP Server, version `2.4.41`, fixing various security issues. Several major enhancements are also included in this update: * `mod_md` is now packaged from upstream *github* releases, adding support for ACMEv2. * `mod_cgid` stderr handling has been improved See http://www.apache.org/dist/httpd/CHANGES_2.4.41 for a full list of

This update includes the latest release of the Apache HTTP Server, version `2.4.41`, fixing various security issues. Several major enhancements are also included in this update: * `mod_md` is now packaged from upstream *github* releases, adding support for ACMEv2. * `mod_cgid` stderr handling has been improved See http://www.apache.org/dist/httpd/CHANGES_2.4.41 for a full list of

– update to the latest upstream release (fixes CVE-2019-9511 and CVE-2019-9513)

– Security fix for CVE-2019-13636 – Security fix for CVE-2019-13638

As browser rivals block third-party tracking, Google pitches ‘Privacy Sandbox’ peace plan
Quick thinking by Portland Public Schools stops $2.9m BEC scam

The latest security update of openjdk-7 caused a regression when applications relied on elliptic curve algorithms to establish SSL connections. Several duplicate classes were removed from rt.jar by the upstream developers of OpenJDK because they were also present in

Google Launches Open-Source Browser Extension for Ad Transparency
Humans may have been listening to you via your Xbox

Two issues have been found in cups, the Common UNIX Printing System(tm). Basically both CVEs (CVE-2019-8675 and CVE-2019-8696) are about

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has 7 fixes is now available.

An update that contains security fixes can now be installed.

Microsoft, PayPal & Facebook most targeted brands in phishing scams: Report
Contacts-slurping Android malware sneaked onto Google Play store – twice

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Building a Mobile Defense: 5 Key Questions to Ask
Spyware App on Google Play Gets Boot, Returns Days Later
Meet Utopia; a privacy focused decentralized P2P ecosystem
Block newly-registered domains to reduce security threats in your organisation
Shhh! Microsoft, Intel, Google and more sign up to the Confidential Computing Consortium
Security flaws caused by compiler optimizations
Facebook delivers ‘clear history’ tool that doesn’t ‘clear’ anything
Update now! Microsoft patches its Android RDP app to fix flaw
Massive MoviePass database found exposed on public server
The Silence hacking crew grows louder
Smashing Security #142: Mercedes secret sensors, smart cities, and ransomware runs riot
First‑of‑its‑kind spyware sneaks into Google Play

ESET analysis breaks down the first known spyware that is built on the AhMyth open-source espionage tool and has appeared on Google Play – twice The post First‑of‑its‑kind spyware sneaks into Google Play appeared first on WeLiveSecurity

An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 and Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Disgruntled bug-hunter drops Steam zero-day to get back at Valve for refusing him a bounty
The Joy of Six… critical security patches: Cisco small biz switches open to hijacking via web UI
Finally. Thanks so much, nerds. Google, Apple, Mozilla end government* internet spying for good

An update for atomic-openshift-web-console is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Fixes CVE-2019-9511, CVE-2019-9513, CVE-2019-9516

Researcher Discloses Second Steam Zero-Day After Valve Bug Bounty Ban

security update

Here’s a top tip: Don’t trust the new guy – block web domains less than a month old. They are bound to be dodgy
The Texas Ransomware Attacks: A Gamechanger for Cybercriminals

Multiple security issues were discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed file/stream is processed.

Cisco Patches Six Critical Bugs in UCS Gear and Switches
New ‘Off-Facebook Activity Tool’ lets users control data collected by websites
Microsoft: Reckon our code is crap? Prove it and $30k could be yours
Backdoor Found in Utility for Linux, Unix Servers
Webcam woes – world’s oldest online camera struggles with security

An update that solves one vulnerability and has one errata is now available.

Sorry script kiddies, hacktivism isn’t cool anymore: No one cares about stuff that’s easy-peasy to defend against

Several security issues were fixed in OpenJPEG.

Adult Content Site Exposed Personal Data of 1M Users
HOAX ALERT! Facebook ‘deadline’ on making your content public is fake
Ransomware disrupts 22 Texas government departments

An update is now available for Red Hat Ceph Storage 3.3 on Ubuntu 16.04. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Zstandard could be made to execute arbitrary code if it received specially crafted input.

An update that fixes 30 vulnerabilities is now available.

An update is now available for Red Hat Ceph Storage 3.3 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Google’s Nest webcam needs patching after flaws found
Education and privacy legislation at ChannelCon

As education is becoming an increasingly vital tool in companies’ security toolboxes, the question arises: How can they effectively implement security awareness training? The post Education and privacy legislation at ChannelCon appeared first on WeLiveSecurity

Stuff like sophisticated government spyware is scary and all – but don’t forget, a single .wmv file can pwn you via VLC