Menu

Monthly Archives: August 2019

security update

E3 Website Leaks Private Addresses for Thousands of Journalists
How to avoid getting burned at Black Hat, destroyed at DEF CON or blindsided by Bsides

Reading Time: ~ 3 min. 1949, 1971, 1979, 1981, 1983 and 1991. Yes, these are numbers. You more than likely even recognize them as years. However, without context you wouldn’t immediately recognize them as years in which Sicily’s Mount Etna experienced major eruptions. Data matters, but only if it’s paired with enough context to create […]

Tobias Maedel discovered that the mod_copy module of ProFTPD, a FTP/SFTP/FTPS server, performed incomplete permission validation for the CPFR/CPTO commands.

July CPU update. See: http://openjdk.java.net/groups/vulnerability/advisories/2019-07-16 and https://mail.openjdk.java.net/pipermail/jdk-updates-dev/2019-July/001423.html

This release includes four security fixes: – Prevent an attack where a federated server could send redactions for arbitrary events in v1 and v2 rooms. – Prevent a denial-of-service attack where cycles of redaction events would make Synapse spin infinitely. – Prevent an attack where users could be joined or parted from public rooms without […]

This kernel update is based on the upstream 5.1.20 and fixes atleast the following security issue: With Xen, virtual device backends and device models running in domain 0, or other backend driver domains, need to be able to map guest memory

Puzzling Gwmndy Botnet Focuses on Low-Volume Proxy Connections
The sea is dangerous and no one likes robots, so why not send a drone on rescue missions?
Microsoft Lab Offers $300K For Working Azure Exploits
Google and ARM Tackle Android Bugs with Memory-Tagging
Google and Apple suspend contractor access to voice recordings
Hackers exploit SMS gateways to text millions of US numbers
FileZilla fixes show how far we’ve come since Heartbleed
GermanWiper isn’t ransomware. It’s worse than that
Class-action sueball flung at Capital One and GitHub over theft of 106 million folks’ details
We’ve, um, changed our password policy, says CafePress amid reports of 23m pwned accounts

A system hardening measure could be bypassed.

What we Can Learn from the Recent VLC Security Vulnerability Fiasco: A Conversation with VideoLAN President Jean-Baptiste Kempf
MegaCortex Ransomware Revamps for Mass Distribution
How to write an information security analyst job description
Amazon now lets you opt-out of having humans review your Alexa conversations
Sharpening the Machete

ESET research uncovers a cyberespionage operation targeting the Venezuelan military The post Sharpening the Machete appeared first on WeLiveSecurity

It’s Black Hat and DEF CON in Vegas this week. And yup, you know what that means. Hotel room searches for guns
LAPD loses job applicant details, Project Zero pokes holes in iOS, AWS S3 whack-a-mole continues, and more
New SystemBC malware targets Windows PCs by evading detection

An update that fixes one vulnerability is now available.

The Best Way to Install and Set-Up WinRAR 64-bit
Internet connected cars can be hacked to gridlock major cities

Several minor issues have been fixed in vim, a highly configurable text editor.

Multiple vulnerabilities have been found in libpng, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been found in Binutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

It’s a bird! It’s a plane! No, it’s two-dozen government surveillance balloons over America
Phisherman’s blues: Bogus Dell support rep extradited from Kenya, admits he conned US colleges out of $900,000

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 8 vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has 10 fixes is now available.

An update that fixes three vulnerabilities is now available.

Critical Bug in Android Antivirus Exposes Address Books
Nation-State APTs Target U.S. Utilities With Dangerous Malware
German privacy probe orders Google to stop listening in on voice recordings for 3 months
Another rewrite for 737 Max software as cosmic bit-flipping tests glitch out systems – report

Reading Time: ~ 2 min. Ransomware Targets Louisiana School Districts At least four school districts in Louisiana fell victim to a series of ransomware attacks in recent weeks, forcing the governor to issue a state of emergency to allow federal agencies to assist local governments during these situations. The IT systems for each of these […]

An update that fixes one vulnerability is now available.

90% of Enterprise iPhone Users Open to iMessage Spy Attack
Apple Suspends Siri Program After Privacy Backlash
Convince your users to obey the cybersecurity rules: Tune in live online and find out how
Apple’s Siri contractors will no longer hear you having sex, making drug deals
Google contractors told to stop listening to conversations captured on your Home assistant… for now, in Europe at least
Space agency uses Raspberry Pi to solve satellite encryption puzzle
Club Penguin Rewritten breach caused by rogue admin backdoor
Anime filter glitches, exposing face of one extremely smart vlogger
Facebook is working on mind-reading
Our hero returns home £500 richer thanks to senior dev’s appalling security hygiene

SoX could be made to crash if it received a specially crafted MP3 file.

Warning as small planes found vulnerable to hacking

Several vulnerabilities were discovered in Subversion, a version control system. The Common Vulnerabilities and Exposures project identifies the following problems:

Various minor issues have been addressed in the GLib library. GLib is a useful general-purpose C library used by projects such as GTK+, GIMP, and GNOME.

Org’s network connect to GitHub and Pastebin much? It’s a Rocke road to cryptojacking country
Brand-New SystemBC Proxy Malware Spotted Using SOCKS5 for Stealth
Unpatched Flaws in IoT Smart Deadbolt Open Homes to Danger
From Carnaval to Cinco de Mayo – The journey of Amavaldo

The first in an occasional series demystifying Latin American banking trojans The post From Carnaval to Cinco de Mayo – The journey of Amavaldo appeared first on WeLiveSecurity

New British Army psyops unit fires rebrandogun, smoke clears to reveal… I’m sorry, Dave…
Exposed internal database reveals vulnerable unpatched systems at Honda
For $8.6M, Cisco Settles Suit Over Bug-Riddled Video Surveillance Software
Until airbags are fitted to email apps to stop staff opening bad messages, what else can a small biz do to protect itself?
Researchers hack camera in fake video attack
North Carolina county falls for BEC scam, to the tune of $1,728,083

A XSS vulnerability was discovered in SquirrelMail. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mails can be executed within the application context via

Five Eyes nations demand access to encrypted messaging

Sigil could be made to overwrite files.

Smashing Security #139: Capital One hacked, iMessage flaws, and anonymity my ass!

Several security issues were fixed in Django.

Fed-up graphic design outfit dangles cash to anyone who can free infosec of hoodie pics
Fraudsters are trying to steal $8.7 million every single day through Business Email Compromise

Several security issues were fixed in the Linux kernel.

security update