Menu

Monthly Archives: September 2019

It’s been a couple of days, so Apple releases yet another iOS update
Stop us if you’ve heard this one before: Yet another critical flaw threatens Exim servers
Holy smokes! Ex-IT admin gets two years prison for trashing Army chaplains’ servers

security update

Type: Vulnerability. Google Android is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Dell EMC Integrated Data Protection Appliance is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Google Android is prone to multiple local privilege-escalation vulnerabilities; fixes are available.

Type: Vulnerability. Exim is prone to a heap-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Cloud Foundry UAA is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Google Android is prone to multiple local privilege-escalation vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Flash Player is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Apple iOS is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Apple Safari is prone to is prone to multiple security vulnerabilities; fixes are available.

Thousands of Windows PCs infected by Nodersok/Divergent fileless malware
New Bug Found in NSA’s Ghidra Tool
Dark web data center in former NATO bunker seized for hosting child porn
Senate Passes Bill Aimed At Combating Ransomware Attacks
Checkm8 jailbreak and AltStore put cracks in Apple’s walled garden
600 armed German cops storm Cyberbunker hosting biz on illegal darknet market claims
Critical Exim Flaw Opens Servers to Remote Code Execution
Thanks-thanks to TalkTalk teen hacker: UK cops’ first auction of ill-gotten Bitcoin nets £240k
Hack strikes Words with Friends and Draw Something, amid claims 218 million players’ details breached
Social media manipulation as a political tool is spreading
Outlook on the web bans a further 38 file types
Is the era of social media Likes over?
Microsoft changes encryption, another D-Link bug, phishing dangers, and more

An update that fixes 24 vulnerabilities is now available.

An update that fixes 24 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Two vulnerabilities were found in the WPA protocol implementation found in wpa_supplication (station) and hostapd (access point). CVE-2019-13377

Security fix for CVE-2019-14822

– double free due to subsequent call of realloc() (CVE-2019-5481) – fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)

New upstream version 1.12.8. Fixes second Denial of Service attack: https://www.redhat.com/archives/libguestfs/2019-September/msg00272.html

security update

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

New upstream version 1.14.2. Fixes second Denial of Service attack: https://www.redhat.com/archives/libguestfs/2019-September/msg00272.html

Update to latest upstream version.

An open redirect, that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control,

Hackers used fake job website to scam jobless US veterans

security update

security update

Got a pre-A12 iPhone? Love jailbreaks? Happy Friday! ‘Unpatchable tethered Boot ROM exploit’ released
Hacker publishes ‘unpatchable’ permanent jailbreak for iPhone 4s to iPhone X
What’s that smell? Perfume merchant senses the scent of a digital burglary
iOS Exploit ‘Checkm8’ Could Allow Permanent iPhone Jailbreaks
Masad Spyware Uses Telegram Bots for Command-and-Control

Risk Level: Very Low. Type: Trojan.

Dunkin’ Donuts Gets Hit with Lawsuit Over 2015 Attack
Arcane Stealer V Takes Aim at the Low End of the Dark Web
Microsoft Blacklists Dozens of New File Extensions in Outlook

An update that solves one vulnerability and has one errata is now available.

‘Fleeceware’ Play store apps quietly charging up to $250
Apple users, patch now! The ‘bug that got away’ has been fixed
Chrome cripples movie studio Mac Pros
Google made thousands of deepfakes to aid detection efforts
News Wrap: GandCrab Operators Resurface, Utilities Firms Hit By LookBack Malware

Reading Time: ~ 2 min. Copyright Phishing Campaign Hits Instagram Many Instagram accounts were recently compromised after receiving a notice that their accounts would be suspended for copyright infringement if they didn’t complete an objection form within 24 hours. By setting a timeframe, the attackers are hoping that flustered victims would quickly begin entering account […]

Thousands of PCs Affected by Nodersok/Divergent Malware

An update that solves two vulnerabilities and has two fixes is now available.

Match knowingly puts people at risk from scammers, FTC charges
Pupil mental health monitor promises app rewrite after hardcoded login creds discovered

An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS. Red Hat Product Security has rated this update as having a security impact

DoorDash doesn’t just pick up your food orders, it delivers your data to hackers, too
Accept certain inalienable truths: Prices will rise, politicians will philander… And US voting machines will be physically insecure
Tune in next month: Learn all about the hackers staring down Singapore, Australia

Security fix for CVE-2019-1010228

An update for kibana is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

DoorDash Data Breach Impacts Personal Data of Almost 5M Users

Security fix for CVE-2019-1010228

Dunkin do-nots: Deep-fried cake maker did not warn its sugar addicts that crooks raided web accounts, says NY AG

security update

An update for golang-github-openshift-oauth-proxy-container is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for logging-elasticsearch5-container is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Reading Time: ~ 3 min. You have probably seen or heard news reports about STEM education (Science, Technology, Engineering, and Math), and how important STEM jobs are for the economy; or maybe you’ve heard reports on schools that are making strides to improve their STEM programs for kids. It’s important for parents with school-aged children to fully understand what a STEM education is and why access to […]

Rash of Exploits Targets Critical vBulletin RCE Bug

Risk Level: Very Low. Type: Trojan.

5G and IoT: How to Approach the Security Implications
Cisco Patches 13 High-Severity Router and Switch Bugs
Hearing aid manufacturer hit by cyber attack slashes profits by $95 million
Phish Uses Google’s URL Decoding to Swim Past Defenses
Vimeo Slapped With Lawsuit Over Biometrics Privacy Policy

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Who is reading your CEO’s email? And how to stop it
WordPress sites hacked through defunct Rich Reviews plugin

An update for gRPC, included in sriov-network-device-plugin-container, is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

CISOs: Support Vendor Security Ops for Best Cloud Results
Four words from Cisco to strike fear into the most hardened techies: Guest account as root
Now Uncle Sam would like a word with Brit teen TalkTalk hacker about a huge crypto-coin heist
Cyber-Risk Business Cases: Using Economic Impact to Justify TIG Investment
Chrome Bug, Not Avid Software, Causes Damage to MacOS File Systems
Hackers are infecting WordPress sites via a defunct plug-in
Russian pleads guilty in massive JPMorgan hacking scheme
Update ColdFusion now! Emergency patch for critical flaws
AI Leaps into Banking: When to know You Can Trust It
Vimeo sued for storing faceprints of people without their say-so

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2836