Menu

Monthly Archives: August 2019

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

It was discovered that the code fixes to address CVE-2018-16858 and CVE-2019-9848 were not complete. For the oldstable distribution (stretch), these problems have been fixed

**MariaDB 10.3.17** Release notes: https://mariadb.com/kb/en/mariadb-10317-release-notes/ **MariaDB Connector/C 3.1.3** Release notes: https://mariadb.com/kb/en/mariadb- connector-c-313-release-notes/ **MariaDB Connector/ODBC 3.1.2** Release notes: https://mariadb.com/kb/en/mariadb-connector-odbc-312-release-notes/ —–

nginx could be made to crash if it received specially crafted network traffic.

fixes for CVE-2019-14232 to 14235

And you thought the cops were bad… Civil rights group warns of facial recog ‘epidemic’ across UK private sites

Reading Time: ~ 2 min. Hookup App Leaks User Locations Geo-locating and other sensitive data has been leaked from the hookup app 3fun, exposing the information for more than 1.5 million users. While some dating apps using trilateration to find nearby users, 3fun showed location data capable of tracing a user to a specific building […]

iPhone holes and Android malware – how to keep your phone safe

Multiple vulnerabilities have been found in imagemagick, an image processing toolkit. CVE-2019-12974

Google removes option to disable Nest cams’ status light
Police site DDoSer/bomb hoaxer caught after jeering on social media
Microsoft won’t shift on AI recordings policy
European Central Bank confirms website hack and data breach
Police costs for Gatwick drone fiasco double to nearly £900k – and still no one’s been charged
Security? We’ve heard of it! But why be a party pooper when there’s printing to be done
Update Windows 10: 800 million devices at risk of critical vulnerability

Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, information disclosure or the execution of arbitrary code.

HTTP Bugs Open Websites to DoS Attacks
Energy Sector Phish Swims Past Microsoft Email Security via Google Drive
Apache Security Advisories Red Flag Wrong Versions in Patching Gaffe

A buffer over-read in the t1-parser of freetype, a font engine, has been found and fixed by checking limits more sensible.

Choice Hotels Breach Showcases Need for Shared Responsibility Model
Clickjacking Evolves to Hook Millions of Top-Site Visitors
Firefox fixes “master password” security bypass bug

Reading Time: ~ 4 min. Cybersecurity has become the hot industry – tips and tricks on how to get the most out of your cybersecurity internship (and land a job after graduation).  Students today are faced with grueling course loads, pressure to get real-world experience and a looming competitive job market. The need for hands-on […]

“NULL” vanity plate hack to dodge parking tickets backfires to the tune of $12,000

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the mysql:8.0 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Microsoft warns of new BlueKeep‑like flaws

Unlike BlueKeep, however, these vulnerabilities affect more recent Windows versions, including Windows 10 The post Microsoft warns of new BlueKeep‑like flaws appeared first on WeLiveSecurity

Serious flaws in six printer brands discovered, fixed
More than a million people have their biometric data exposed in massive security breach
This iPhone charging cable can compromise your device & steal data
Bomb-hoaxing DoSer who targeted police in revenge was caught after Twitter taunts

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More…]

A vulnerability in ZeroMQ might allow an attacker to execute arbitrary code.

A vulnerability in ProFTPD could result in the arbitrary execution of code.

A vulnerability in ZNC allows users to escalate privileges.

Multiple vulnerabilities have been found in polkit, the worst of which could result in privilege escalation.

Multiple vulnerabilities have been found in LibreOffice, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in libarchive, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in Oracles JDK and JRE software suites.

Multiple vulnerabilities have been found in SQLite, the worst of which could result in the arbitrary execution of code.

‘NULL’ license plate gets security researcher $12K in tickets
Hacking forum spills rival’s 321,000 member database
Smashing Security #141: Black Hat and Bridezillas
How dodgy browser plugins, web scripts can silently rewrite that URL you were about to hit – and throw you into an internet wormhole
World recoils in horror as smartphone maker accused of helping government snoops read encrypted texts, track device whereabouts
Intel: Listen up, you NUC-leheads! Mini PCs and compute sticks just got a major security fix
Chin up, CapitalOne: You may not have been the suspected hacker’s only victim. Feds fear 30-plus organizations hit

security update

security update

Fingerprints of 1M Exposed in Public Biometrics Database
Lenovo Warns of ThinkPad Bugs, One Unpatched
20-Year-Old Bug in Legacy Microsoft Code Plagues All Windows Users
Windows Users at Risk From High-Severity Intel Software Flaw
DEF CON and Feds Partner on Anonymous Bug Submission Program

An update that fixes two vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Facebook Records User Audio, Sparking Privacy Questions
Microsoft warns of wormable vulnerabilities in Windows
Patch time! Microsoft warns of new worm-ready RDP bugs

Several security issues have been fixed in otrs2, a well known trouble ticket system.

Norman Cryptominer Employs Sophisticated Obfuscation Tactics
TikTok Scammers Cash In On Adult Dating, Impersonation Tricks
Not very Suprema: Biometric access biz bares 27 million records and plaintext admin creds

An update that fixes 7 vulnerabilities is now available.

Epic Games slapped with lawsuit over hacked Fortnite accounts
Fortnite World Cup champion and family swatted while live streaming

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Coinbase explains background to June zero-day Firefox attack
4 ‘despicables’ jailed for running hidden worldwide child abuse forums

wpa_supplicant and hostapd could be made to expose sensitive information over the network.

In the Balkans, businesses are under fire from a double‑barreled weapon

ESET researchers discovered a campaign that uses two malicious tools with similar capabilities to ensure both resilience and broader potential for the attackers The post In the Balkans, businesses are under fire from a double‑barreled weapon appeared first on WeLiveSecurity

HTTP/2, Brute! Then fall, server. Admin! Ops! The server is dead

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes four vulnerabilities is now available.

This summer’s hottest sequels: BlueKeep II, III, IV and V – the latest wormable RDP holes in Microsoft Windows

security update

We checked and yup, it’s no longer 2001. And yet you can pwn a Windows box via Notepad.exe
Shades of BlueKeep: Wormable Remote Desktop Bugs Top August Patch Tuesday List
Patch your internet-connected printer! Serious vulnerabilities discovered
22 Critical Flaws Patched in Adobe Photoshop
Cerberus Enters the Android Malware Rental Scene
An Army Watchkeeper drone tried to land. Then meatbags took over from the computers

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has three fixes is now available.

British Airways E-Ticketing Flaw Exposes Passenger Flight, Personal Data
Fake news doesn’t (always) fool mice
Hacked devices can be turned into acoustic weapons

An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,