Menu

Monthly Archives: September 2019

WordPress XSS Bug Allows Drive-By Code Execution

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

iPhone iOS 13 Lockscreen Bypass Flaw Exposes Contacts
Whoa, bot wars: As cybercrooks add more AI to their arsenal, the goodies will have to too
The Joker is haunting Google Play Store with malware
Consumer ransomware insurance? You could be painting a target on us all for avaricious crims

Mozilla: Sandbox escape through Firefox Sync (CVE-2019-9812) * Mozilla: Memory safety bugs fixed in Firefox 69, Firefox ESR 68.1, and Firefox ESR 60.9 (CVE-2019-11740) * Mozilla: Same-origin policy violation with SVG filters and canvas to steal cross-origin images (CVE-2019-11742) * Mozilla: XSS by breaking out of title and textarea elements using innerHTML (CVE-2019-11744) * Mozilla: […]

An update that fixes two vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

Updated flash-player-plugin package fixes security vulnerabilities: Same origin method execution that leads to arbitrary code execution?in the context of the current user. (CVE-2019-8069)

Astaroth Spy Trojan Uses Facebook, YouTube Profiles to Cover Tracks
Just how private are your browsing habits?
North Korean Spear-Phishing Attack Targets U.S. Firms
Intel: SSH-stealing NetCAT bug not really a problem
Charmin’. Garmin admits customers’ full credit card data nicked from South African web store
News Wrap: IoT Radio Telnet Backdoor And ‘SimJacker’ Active Exploit
Leaky database full of fake Groupon emails turns out to belong to crooks

This package ignored the value of the Hash header, which allows an attacker to spoof it. An attacker can not only embed arbitrary Armor Headers, but also prepend arbitrary text to cleartext messages without invalidating the signatures.

Reading Time: ~ 3 min. AI and machine learning offer tremendous promise for humanity in terms of helping us make sense of Big Data. But, while the processing power of these tools is integral for understanding trends and predicting threats, it’s not sufficient on its own. Thoughtful design of threat intelligence—design that accounts for the […]

Reading Time: ~ 2 min. Ransomware Closes Arizona School District As many students began returning for the fall semester, classes were cancelled in the Flagstaff Unified School District in Arizona after a ransomware attack disabled some of the district’s computer systems. Officials haven’t yet released any additional information on the ransom demanded or if any […]

Cybercriminals Adding Sophistication to BEC Threats
A Critical Exim Vulnerability, Lilocked Ransomware on the Rise, but Linux Not to Blame
Mozilla Private Network VPN gives Firefox another privacy boost

Samuel R Lovejoy discovered a security vulnerability in dnsmasq. Carefully crafted packets by DNS servers might result in out of bounds read operations, potentially leading to a crash and denial

Fin7 sysadmin pleads guilty to running IT for billion-dollar crime syndicate
From PowerShell to auditing: Expand your cybersecurity know-how at SANS London 2019
From pen-test to penitentiary: Infosec duo cuffed after physically breaking into courthouse during IT security assessment
Snoops can bypass iOS 13 lock screen to eyeball your address book. Apple hasn’t fix it yet. Valid flaw? You decide

An update that fixes one vulnerability is now available.

Those fake spying cell towers in Washington DC? Ex-intel staffers claim they’re Israeli
Eco-activists arrested by Brit cops after threatening to close Heathrow with drones

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Simjacker vulnerability lets attackers track your location with an SMS
Library-Themed University Phishing Attack Expands to Massive Scale
California Passes Bill to Ban Police Use of Facial Recognition
1B Mobile Users Vulnerable to Ongoing ‘SimJacker’ Surveillance Attack
UNICEF Leaks Personal Data of 8,000 Users via Email Blunder

Reading Time: ~ 3 min. According to a report from hired.com, the demand for security engineers is up 132%. Additionally, the need for engineers who specialize in data analytics and machine learning has increased by 38% and 27%, respectively. Given recent trends in cybersecurity, it’s no wonder, and demand at Webroot is no exception. To […]

September 2019’s Patch Tuesday: 2 zero-days, 17 critical bugs
Massive email fraud bust snares 281 suspects
Google experiments with DNS-over-HTTPS in Chrome
Error-laden phone location data suspended from use in Danish courts
How to download online video & audio files with new tool from SaveFrom.net
Mystery database left open turns out to be massive Groupon fraud ticket fraud ring
Watch live today: How to make your voice heard – and keep your staff safe from hackers

Risk Level: Very Low. Type: Trojan.

Smashing Security #145: Apple and Google willy wave while home assistants spy – DoH!
ThreatList: Apple Adware, Phishing, APT Attacks Threaten macOS Users
Major Groupon, Ticketmaster Fraud Scheme Exposed By Insecure Database
100s of Flashlight apps on Play Store ask for dangerous permissions

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Several security issues were fixed in curl.

Infosec prophet Bruce Schneier (peace be upon him) is only as famous as half of Salt-N-Pepa
198 Million Car-Buyer Records Exposed Online for All to See
Intel CPUs Vulnerable to Sensitive Data Leakage in NetCAT Attack
Toyota parts supplier loses $37 million in email scam
Lemonade is changing the way we insure our homes
Operation reWired: 281 suspected email scammers arrested around the world
CISO/CIO: Get an iPad and Apple Watch with an App Monitoring your Security 24/7
Strangest Phishing Lures of 2019: From Divorce Papers to Real Estate Decoys
Feds Indict 281 People for Involvement in Massive E-Mail Fraud Scheme
Wikipedia fights off huge DDoS attack
LinkedIn can’t block public profile data scraping, court rules
Telegram fixes ‘unsend message’ bug that held on to your pictures
Facebook says location data in iOS 13, Android 10 may be confusing
How Can SEO Help Increase Website Security?
Selfies for kids – A guide for parents

Are you – and especially your children – aware of the risks that may come with sharing selfies? The post Selfies for kids – A guide for parents appeared first on WeLiveSecurity

D-Link, Comba network gear leave passwords open for potentially whole world to see

An update for rh-dotnet21-dotnet and rh-dotnet22-dotnet is now available for .NET Core on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for dotnet is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that solves three vulnerabilities and has 9 fixes is now available.

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the pki-deps:10.6 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for poppler is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for libwmf is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

USN 4115-1 introduced a regression in the Linux kernel.

An update for the openshift and atomic-enterprise-service-catalog packages is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Required: Massive email fraud bust. Tired: Cops who did the paperwork. Expired: 281 suspected con men’s freedom
It’s 2019, and Windows PCs can be pwned via a shortcut file, a webpage, an evil RDP server…

security update

security update

security update

security update

Insider Threats Are Rising – But They Shouldn’t Be
Rolling in DoH: Chrome 78 to experiment with DNS-over-HTTPS – hot on the heels of Firefox
Microsoft Addresses Two Zero-Days Under Active Attack
ThreatList: Amidst Data Breaches, Account Creation Fraud Soars in 2019
Adobe Fixes Critical Flash Player Code Execution Flaws
The NetCAT is out of the bag: Intel chipset exploited to sniff SSH passwords as they’re typed over the network
600,000 GPS child trackers found vulnerable to location tracking

An update that fixes 24 vulnerabilities is now available.

An update that fixes one vulnerability is now available.