Menu

Monthly Archives: September 2019

TalkTalk still struggles to shut down legacy email addresses on request

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

A command injection vulnerability in Nokogiri allows commands to be executed in a subprocess by Ruby’s `Kernel.open` method. For Debian 8 “Jessie”, this problem has been fixed in version

US senators green-light recruitment of crack infosec teams, both public and private
Smashing Security #147: Don’t Snapchat and drive
Magecart Group Targets Routers Behind Public Wi-Fi Networks
How to Secure a Website by Monitoring DNS Records
Confused why Trump fingered CrowdStrike in that Ukraine call? You’re not the only one…

Update to current release. Python3 compatible Installable with f31+ —- Update to 2.5.0 (pre-release)

Two security vulnerabilities were found in OpenSSL, the Secure Sockets Layer toolkit. CVE-2019-1547

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Firefox could be made to hijack the mouse pointer it if opened a malicious website.

‘Narrator’ Windows Utility Trojanized to Gain Full System Control

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Unpatched Bug Under Active Attack Threatens WordPress Sites with XSS
Hacker House shoved under UK Parliament’s spotlight following Boris Johnson funding allegs
Cybercrooks Target U.S. Veterans with Fake Hiring Website

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

Microsoft rushes out patch for Internet Explorer zero‑day

There is no word on which threat actor is abusing the severe vulnerability for attacks The post Microsoft rushes out patch for Internet Explorer zero‑day appeared first on WeLiveSecurity

What You Need to Know About Next Gen EDR
Microsoft rushes out fix for Internet Explorer zero-day
Teenage TalkTalk hacker accused of $800,000 cryptocurrency theft in the United States
Apple to Patch Bug Granting Full Access to 3rd-Party Keyboards

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

Google wins landmark case: Right to be forgotten only applies in EU
Patch released for Windows-pwning VPN bug
Twitter’s new policy bans financial scams

File Roller could be made to overwrite sensitive files if it received a specially crafted TAR file.

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that solves 7 vulnerabilities and has one errata is now available.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Hot patches for ColdFusion: Adobe drops trio of fixes for three serious flaws
Google takes sole stand on privacy, rejects new rules for fear of ‘authoritarian’ review

It was discovered that SPIP, a website engine for publishing, would allow unauthenticated users to modify published content and write to the database, perform cross-site request forgeries, and enumerate registered users.

We finally got one! Russian ‘fesses up to cracking bank servers, netting big bucks

security update

security update

This vBulletin vBug is vBad: Zero-day exploit lets miscreants hijack vulnerable web forums
GandCrab Operators Resurface with REvile Malware
An illegal prostitution ring took Kazakhstan offline
Adobe Unscheduled Update Fixes Critical ColdFusion Flaws
DoH! Mozilla assures UK minister that DNS-over-HTTPS won’t be default in Firefox for Britons
CafePress finally warns customers that it was hacked
Can you code a way to foil online terrorist vids? The Home Office might just have £600K for you
Dtrack RAT is Behind Virulent ATM-Espionage Campaign
Zebrocy Retools for New Political Attacks
Instagram phish poses as copyright infringement warning – don’t click!
YouTube ‘influencers’ get 2FA tokens phished
Do companies take cybersecurity seriously enough?

Many companies are ranking cybersecurity as a top 5 priority but their actions do not measure up to the claim, a survey finds The post Do companies take cybersecurity seriously enough? appeared first on WeLiveSecurity

Malicious Ad Blockers for Chrome Caught in Ad Fraud Scheme
Why do cloud leaks keep happening? Because no one has a clue how their instances are configured
Facebook has booted tens of thousands of data-grabbing apps
Apple restricts old adblocking tech
Jira development and ticketing software hit by critical flaws
No summer vacations for Zebrocy

ESET researchers describe the latest components used in a recent Sednit campaign The post No summer vacations for Zebrocy appeared first on WeLiveSecurity

World of Warcraft’s suspected DDoS attacker has been arrested
How to Protect Your Online Store from Cyber Threats
Nine words to ruin your Monday: Emergency Internet Explorer patch amid in-the-wild attacks
4 Helpful Tips to Make Your WiFi Fast and Efficient
How to Increase Your Business’s Online Brand Awareness
Microsoft Internet Explorer Zero-Day Flaw Addressed in Out-of-Band Security Update

Type: Vulnerability. Microsoft .NET Core is prone to a remote denial-of-service vulnerability; fixes are available.

The Benefits of Using a VPN at Home
More U.S. Utility Firms Targeted in Evolving LookBack Spearphishing Campaign
Several months after the fact, CafePress finally acknowledges huge data theft to its customers
I’m keynoting about cybercrime at the CRN MSP conference in London next week
Google Assistant Audio Privacy Controls Updated After Outcry

An update that solves 8 vulnerabilities and has one errata is now available.

USN 4134-1 introduced a regression in IBus.

HMRC’s HTTPS howler: Childcare payments site cert expired at 1am on Sunday, down for hours
200K Sign Petition Against Equifax Data Breach Settlement
Google pulls more fake adblockers from Chrome Web Store

Reading Time: ~ 3 min. When you’re running a business, it’s important to stay connected, whether you’re in the office or not. Modern technology has made this easier than ever, ensuring you can answer emails and stay on top of tasks in hotels, coffee shops, wherever. Social media influencer and serial entrepreneur Gary Vaynerchuk has even […]

Investors accuse FedEx of lying, stock dumping after NotPetya attack

An update that fixes 24 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Could EarEcho change the way we authenticate our phones?

A buffer overflow flaw was found in the way Linux kernel’s vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host. (CVE-2019-14835) […]

Two charged with tech-support scamming the elderly for $10m
Pizza prankster’s prisoner plea plot perturbs police, Norks invading and Uber woes
WannaCry – and why it never went away

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dbus is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dbus is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kpatch-patch is now available for RHEL-7.6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

It was discovered that Expat, an XML parsing C library, did not properly handled internal entities closing the doctype, potentially resulting in denial of service or information disclosure if a malformed XML file is processed.

security update

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.