Menu

Monthly Archives: August 2019

Several security issues were fixed in PostgreSQL.

Black Hat 2019: Addressing Supply-Chain Risk Starts with People, Microsoft Says
Critical RCE Bug Found Lurking in Avaya VoIP Phones
Meet AttackSurfaceMapper; new automated penetration testing tool
Facebook hits two app developers with lawsuit

The legal action, brought over alleged click injection fraud, is said to be among the first of its kind The post Facebook hits two app developers with lawsuit appeared first on WeLiveSecurity

Researchers Bypass Apple FaceID Using Biometrics ‘Achilles Heel’

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Update your iPhone – remote control holes revealed by researchers
Ransomware Sees Triple-Digit Spike in Corporate Detections
The Threat in the Cloud: Phishing Abuses Amazon AWS S3 Buckets
Cryptocurrency exchange Binance offers $290,000 bounty to unmask blackmailer
How powerful are Russian hackers? One new law could transform global crime operations
Twitter may have shared your data with its ad partners without your permission
Cisco 220 Series Smart Switch owners told to apply urgent patch
More than 2m AT&T phones illegally unlocked by bribed insiders
Black Hat 2019: WhatsApp Users Still Open to Message Manipulation
Transport for London Oyster system pulled offline after credential-stuffing crooks board customers’ accounts

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

DEF CON 2019: 35 Bugs in Office Printers Offer Hackers an Open Door
Microsoft puts another nail in VBScript coffin
Varenyky: Spambot à la Française

ESET researchers document malware-distributing spam campaigns targeting people in France The post Varenyky: Spambot à la Française appeared first on WeLiveSecurity

Smashing Security #140: Love, PINs, and 8chan
WTF is Boeing on? Not just customer databases lying around on the web. 787 jetliner code, too, security bugs and all

A minor version update (from 7.3 to 7.4) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

FBI, NSA to hackers: Let us be blunt. Weed need your help. We’ll hire you even if you’ve smoked a little pot in the past

New kdelibs packages are available for Slackware 14.2 and -current to fix a security issue.

Black Hat 2019: Microsoft Protocol Flaw Leaves Azure Users Open to Attack
Black Hat 2019: 5G Security Flaw Allows MiTM, Targeted Attacks

**PHP version 7.2.21** (01 Aug 2019) **Date:** * Fixed bug php#69044 (discrepency between time and microtime). (krakjoe) **EXIF:** * Fixed bug php#78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042) (Stas) * Fixed bug php#78222 (heap-buffer-overflow on exif_scan_thumbnail). (CVE-2019-11041) (Stas) **Fileinfo:** * Fixed bug php#78183 (finfo_file shows

Fixed out of bounds heap read in function rtreenode() Enhance the rtreenode() function of rtree (used for testing) so that it uses the newer sqlite3_str object for better performance and improved error reporting.

**PHP version 7.2.21** (01 Aug 2019) **Date:** * Fixed bug php#69044 (discrepency between time and microtime). (krakjoe) **EXIF:** * Fixed bug php#78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042) (Stas) * Fixed bug php#78222 (heap-buffer-overflow on exif_scan_thumbnail). (CVE-2019-11041) (Stas) **Fileinfo:** * Fixed bug php#78183 (finfo_file shows

Black Hat 2019: Ethical Hackers Must Protect Digital Human Rights

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Hack computers to steal someone’s identity in China? Why? You can just buy one from a bumpkin for, like, $3k
There’s fraud, and then there’s backdoor routers, fenced logins, malware, and bribing AT&T staff seven figures to unlock 2m phones
Hack-age delivery! Wardialing, wardriving… Now warshipping: Wi-Fi-spying gizmos may lurk in future parcels
Black Hat 2019: Security’s Powerful Cultural Transformation
AT&T workers bribed to install malware on company network and unlock iPhones
Top Dangers That Online Gamers Face
Smominru Cryptominer Scrapes Credentials for Half-Million Machines
Don’t let the crooks ‘borrow’ your home router as a hacking server
8chan down after Cloudflare & hosting firms boots it off
10 Typical Mistakes in Scientific Research Paper Writing

An update that solves one vulnerability and has one errata is now available.

New SWAPGS Side-Channel Attack Bypasses Spectre and Meltdown Defenses

Rack could allow cross-site scripting (XSS) attacks.

Scammers recruiting money mules on dating sites is on the rise, says FBI
Security Vulnerabilities Are Increasingly Putting Kids at Risk
Don’t fall for fake Equifax settlement sites, warns FTC
Black Hat: LeapFrog Tablet Flaws Let Attackers Track, Message Kids

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

PHP could be made to denial of service, expose sensitive information or execute arbitrary code if it received a specially crafted regular expression.

Banking PINs exposed in Monzo secure storage slip-up
Latest Android patches fix critical ‘QualPwn’ Wi-Fi flaws
FBI warns of romance scams using online daters as money mules

Up to 30 percent of romance fraud victims in 2018 are estimated to have been used as money mules The post FBI warns of romance scams using online daters as money mules appeared first on WeLiveSecurity

SWAPGS attack: The Spectre-like flaw affecting Intel CPUs

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libssh2 is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for augeas is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for systemd is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for perl is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

Your mid-week infosec news bonanza: Cisco bugs, VMware-Nvidia guest escapes, KDE hijacking, and more
Deja-wooo-oooh! Intel chips running Windows potentially vulnerable to scary Spectre variant
They say piracy killed the Amiga. Know what else it’s killing? Malware sales. Awww, diddums
Democrats and Doctors Behind Latest Wave of Leaked Data
Cryptolocking WordPress Plugin Locks Up Blog Posts
Add passwords to list of stuff CafePress made hash of storing, says infoseccer. 11m+ who used Facebook ‘n’ pals to sign in were lucky
Mass Spoofing Campaign Takes Aim at Walmart
Millions of Android Smartphones Vulnerable to Trio of Qualcomm Bugs

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

You really should listen to the award-winning “Smashing Security” podcast
Baldr malware unpicked with a little help from crooks’ bad opsec

Mercurial could be made to overwrite files.

NVIDIA patches high-severity bugs in Windows GPUs and SHIELD
Fake Dell support rep admits to talking US colleges out of $874,000
500,000 Monzo banking customers told to change their PINs
GitHub ‘encourages’ hacking, says lawsuit following Capital One breach
Attackers ransom bookseller’s exposed MongoDB database

An update that solves two vulnerabilities and has one errata is now available.

An update for perl-Archive-Tar is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for dhcp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for linux-firmware is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libtiff is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for python-requests is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Need to automatically and securely verify a download is legit? You bet rget this new tool
It’s 2019 – and you can completely pwn a Qualcomm-powered Android over the air
PIN the blame on us, says Monzo in mondo security blunder: Bank card codes stored in log files as plain text
F-B-Yikes! FBI bod allegedly hid spy camera under desk to snap coworker’s upskirt pics
Googlers hate it! This one weird trick lets websites dodge Chrome 76’s defenses, detect you’re in Incognito mode