Menu

Monthly Archives: August 2019

Chrome Incognito mode detection fix busted by researchers

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

US insurers face SEC probe over web-access bungle that exposed ‘up to 885 million’ files

An update that fixes one vulnerability is now available.

An update that fixes 16 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

Header aches in Firefox, Tor, Brave and Chrome as HTTP opens new security holes
Hacking my airplane – BlackHat edition

After welcoming hacking research, automobile technology started to get better at defending against hacks. So why has the airline industry not been as welcoming? The post Hacking my airplane – BlackHat edition appeared first on WeLiveSecurity

Android users menaced by pre-installed malware
Web body mulls halving HTTPS cert lifetimes. That screaming in the distance is HTTPS cert sellers fearing orgs will bail for Let’s Encrypt
Tor pedos torpedoed again, this time Feds torpedo four Tor pedos – and keep how they unmasked dark-web scumbags under wraps
What do Windows 10 and Uber or Lyft have in common? One bad driver can really ruin your day. And 40 can totally ruin your month

security update

security update

AT&T, T-Mobile, Sprint, Verizon Blasted For Data Privacy Policies
White hat hackers infect Canon DSLR camera with ransomware
4 Dating Apps Pinpoint Users’ Precise Locations – and Leak the Data
Printer pwnage, phone poppage, and apparently US Homeland Security needs security help
US still ‘not prepared’ in event of a serious cyber attack and Congress can’t help if it happens
Tips for Successful Zero-Trust Implementation
US military swoops into DEF CON seeking a few good hackers for debut aviation pwning village
Black Hat 2019 News Wrap: The Best and Worst of the Show
Plot twist: Google’s not spying on King’s Cross with facial recognition tech, but its landlord is
Gamers Beware: Zero-Day in Steam Client Affects All Windows Users
Hacking 4G hotspots – when did you last update?

The package postgresql before version 11.5-1 is vulnerable to multiple issues including access restriction bypass and information disclosure.

The package postgresql-libs before version 11.5-1 is vulnerable to multiple issues including access restriction bypass and information disclosure.

The package chromium before version 76.0.3809.100-1 is vulnerable to arbitrary code execution.

Apple will hand out unlocked iPhones to vetted researchers
Facebook facial recognition: class action suit gets court’s go ahead

An update that fixes one vulnerability is now available.

GDPR privacy can be defeated using right of access requests
I could throttle you right about now: US Navy to ditch touchscreens after kit blamed for collision

poppler could be made to crash if it received specially crafted PDF.

An update for cockpit-ovirt is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for rhvm-appliance is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several vulnerabilities were discovered in python-django, a web development framework. They could lead to remote denial-of-service or SQL injection,

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

Security fix for CVE-2018-19800 CVE-2018-19801 CVE-2018-19802

Security fix for CVE-2018-19800 CVE-2018-19801 CVE-2018-19802

DEF CON 2019: Picture Perfect Hack of a Canon EOS 80D DSLR

Benno Fuenfstueck discovered that Pango, a library for layout and rendering of text with an emphasis on internationalization, is prone to a heap-based buffer overflow flaw in the pango_log2vis_get_embedding_levels function. An attacker can take advantage of this flaw for denial of

Driver Disaster: Over 40 Signed Drivers Can’t Pass Security Muster

The 5.2.7 stable kernel update contains a number of important fixes across the tree. —- The 5.2.6 kernel rebase contains new hardware support, features, and a number of important bug fixes across the tree. —- Update to v5.1.12

The 5.2.7 stable kernel update contains a number of important fixes across the tree. —- The 5.2.6 kernel rebase contains new hardware support, features, and a number of important bug fixes across the tree. —- Update to v5.1.12

The 5.2.7 stable kernel update contains a number of important fixes across the tree. —- The 5.2.6 kernel rebase contains new hardware support, features, and a number of important bug fixes across the tree. —- Update to v5.1.12

Patches for CVE-2019-14295, CVE-2019-14296

fixed CVEs 2019-10181, 2019-10182, 2019-10185 —- Updated to fres upstream release: https://mail.openjdk.java.net/pipermail/distro-pkg- dev/2019-March/041320.html New in release 1.8 (2019-03-12): * added support for javafx-desc and so allwong run of pure-javafx only applications * –nosecurity enhanced for possibility to skip invalid signatures * enhanced to allow

July CPU update. See: http://openjdk.java.net/groups/vulnerability/advisories/2019-07-16 and http://mail.openjdk.java.net/pipermail/jdk8u-dev/2019-July/009840.html

The 5.2.7 stable update contains a number of important fixes across the tree.

The 5.2.7 stable update contains a number of important fixes across the tree.

The 5.2.7 stable update contains a number of important fixes across the tree.

Security fix for CVE-2019-14378

Patches for CVE-2019-14295, CVE-2019-14296

SELECT code_execution FROM * USING SQLite: Eggheads lift the lid on DB security hi-jinks
DEF CON 2019: New Class of SQLite Exploits Open Door to iPhone Hack

security update

Multiple vulnerabilities have been found in LibVNCServer, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in Redis, the worst of which may allow execution of arbitrary code.

Multiple vulnerabilities have been found in JasPer, the worst of which could result in a Denial of Service condition.

DEF CON 2019: MacOS Gets a Malware Beatdown in Attack Demo
Anatomy of an attack: How Coinbase was targeted with emails booby-trapped with Firefox zero-days

Updated cyrus-imapd package fixes security vulnerability: It was discovered that cyrus-imapd had a buffer overflow in CalDAV request handling triggered by a long iCalendar property name (CVE-2019-11356).

Updated php packages fixes atleast the following security issues: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with

So you can’t find enough cyber-security experts to join the team. Time to dial a managed security service provider?

security update

security update

Hack of High-End Hotel Smart Locks Shows IoT Security Fail
DEF CON 2019: Delta ICS Flaw Allows Total Industrial Takeover

An update that fixes 7 vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

The Risks of a Smart City
DEF CON 2019: Researchers Demo Hacking Google Home for RCE

Reading Time: ~ 2 min. Children’s Tablets Leave Users Vulnerable At least one LeapPad tablet designed specifically for children has been found to harbor critical vulnerabilities in the app Pet Chat that could allow unauthorized access to online traffic. The vulnerabilities could be used locate the tablet’s owner by creating a temporary WiFi network to […]

Blackmailed for Bitcoin – exchange rebuffs $3.5m ransom demand

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Instagram boots ad partner for location tracking and scraping stories
Election Security Threats: From Misinformation to Voting Machine Flaws
Your Skype Translator calls may be heard by humans

Dominik Penner discovered that KConfig, the KDE configuration settings framework, supported a feature to define shell command execution in .desktop files. If a user is provided with a malformed .desktop file (e.g. if it’s embedded into a downloaded archive and it gets opened in

Transport Layer Security version 1.3 in Red Hat Enterprise Linux 8

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Who will save us from deepfakes? Other AIs? Humans? What about vastly hyperintelligent pandimensional beings?
Talk about unintended consequences: GDPR is an identity thief’s dream ticket to Europeans’ data

* CVE-2019-10208: `TYPE` in `pg_temp` executes arbitrary SQL during `SECURITY DEFINER` execution Versions Affected: 9.4 – 11

You can easily secure America’s e-voting systems tomorrow. Use paper – Bruce Schneier
Pwn an iPhone to bank $1m and Check Point gripes about WhatsApp privacy again
Apple Upgrades Bug Bounty Program: Adds Macs, $1M Reward

New upstream bugfix and security release.

State Farm Falls Victim to Credential-Stuffing Attack
What You Need to Know About Creating A Website

An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton), Red Hat OpenStack Platform 13.0 (Queens), and Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact