Menu

Monthly Archives: October 2019

Men who were paid $100,000 by Uber to hush-up hack plead guilty to extortion scheme
A stranger’s TV went on spending spree with my Amazon account – and web giant did nothing about it for months

Type: Vulnerability. Apple iOS and macOS are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Apple iTunes and macOS are prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Apple tvOS and macOS are prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Apple iOS, iPadOS, tvOS, watchOS and macOS are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Apple macOS, TV OS, and iOS are prone to multiple memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Philips IntelliSpace Perinatal is prone to a local security-bypass vulnerability.

Type: Vulnerability. Foxit PhantomPDF is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Foxit Studio Photo is prone to a information disclosure vulnerability; fixes are available.

Cyber-security super-brain Rudy Giuliani forgets password, bricks iPhone, begs Apple Store staff for help

Type: Vulnerability. Apple iOS is prone to an address bar spoofing vulnerability; fixes are available.

Type: Vulnerability. Apple macOS, watchOS and iCloud for Windows are prone to a memory corruption vulnerability; fixes are available.

Calypso APT Emerges from the Shadows to Target Governments
From Instagram to insta-banned: Facebook wipes NSO Group workers’ personal profiles amid WhatsApp hack rap
China-Linked Hackers Spy on Texts With MessageTap Malware
ProtonMail shoves its iOS app’s source code on GitHub for world+dog to rummage around in
Radio ham who sipped NHS pager messages then streamed them via webcam may have committed a crime
Untitled Goose Game security hole could have allowed hackers to wreak havoc
ICS Attackers Set To Inflict More Damage With Evolving Tactics
Linux maintainer: Patching side-channel flaws is killing performance
Fake Voicemail/Office 365 Attack Targets Enterprise Execs
Valve Source Engine, Fortnite Servers Crippled By Gafgyt Variant
Judge lambasts porn company for spewing copyright lawsuits
Researchers find hole in EU-wide identity system
WhatsApp sues spyware maker for allegedly hacking phones worldwide

Reading Time: ~ 5 min. “Phishing” may have been a relatively obscure term, but pretty much everyone has heard of it by now. In fact, recent statistics indicate a high likelihood that you—or someone you know—have been the victim of a phishing attack at least once. Now, if you remember the classic Nigerian Prince scams from back in […]

Belgian city slurps mobile data to track visitors – report
Deepfakes: When seeing isn’t believing

Is the world as we know it ready for the real impact of deepfakes? The post Deepfakes: When seeing isn’t believing appeared first on WeLiveSecurity

Smashing Security #152: Cats, hoodies, and rent

Type: Vulnerability. Apple iOS, iPad and macOS are prone to multiple information-disclosure vulnerabilities; fixes are available.

‘Don’t be so concerned with your image’… US prosecutor lets rip on Uber for hack cover-up as pair plead guilty

security update

Insurance Pays Out a Sliver of Norsk Hydro’s Cyberattack Damages

Type: Vulnerability. WebKit is prone to cross-site scripting and multiple memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. WebKit is prone to a cross-site scripting vulnerability and multiple memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Samba is prone to an arbitrary file write vulnerability; fixes are available.

Type: Vulnerability. Samba is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Samba is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. WebKit is prone to multiple memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. D-Link DAP-1320 Wireless Range Extender is prone to an information-disclosure vulnerability.

Type: Vulnerability. IBM Security Guardium Big Data Intelligence is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. IBM Security Guardium Big Data Intelligence is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. McAfee Total Protection Windows client is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. IBM Security Guardium Big Data Intelligence is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple Trend Micro products are prone to an unspecified directory-traversal vulnerability; fixes are available.

Type: Vulnerability. Trend Micro Apex One is prone to a command-injection vulnerability; fixes are available.

Type: Vulnerability. Trend Micro OfficeScan is prone to a directory-traversal vulnerability; fixes are available.

WhatsApp Spyware Attack: Uncovering NSO Group Activity
U.S. Universities Get Failing Grades for DMARC Adoption

Risk Level: Very Low. Type: Trojan.

Facebook builds tool to confound facial recognition

However, the social network harbors no plans to deploy the technology in any of its services any time soon The post Facebook builds tool to confound facial recognition appeared first on WeLiveSecurity

While Apple fanbois rage at Catalina, iGiant quietly drops iOS and macOS security patches
Murky Details Surround Bed, Bath and Beyond Breach
Medical data is being leaked by NHS pagers, and then broadcast for the world to see…
MSPs Can Now Provide Managed Detection and Response with Cynet 360
Android Malware Plaguing 45K Devices Remains a Mystery
City of Johannesburg, on Second Hit, Refuses to Pay Ransom
Got an early iPhone or iPad? Update now or turn it into a paperweight
Sextortion scammers are hijacking blogs – and victims are paying up
Facebook launches $2m suit against alleged phishing, hacking sites
Uber sues LA in bid to protect scooter riders’ geolocation data
Europe’s digital identity system needs patching after can_we_trust_this function call ignored
Is HONK nothing sacred HONK? It’s 2019 and an evil save file can pwn much-loved HONK Untitled Goose Game
WhatsApp slaps app hacker chaps on the rack for booby-trapped chat: NSO Group accused of illegal hacking by Facebook
Q. Who’s triumphantly slamming barn door shut after horse bolted at warp 9? A. NordVPN
Australia Proposes Facial Recognition for Adult Sites

security update

security update

security update

Facebook Sues NSO Group Over Alleged WhatsApp Hack

Type: Vulnerability. Multiple IBM products are prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple IBM Products are prone to a local security vulnerability; fixes are available.

Type: Vulnerability. Atlassian JIRA is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Atlassian JIRA is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. NetApp Clustered Data ONTAP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. IBM Security Access Manager is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Atlassian JIRA is prone to an information-disclosure vulnerability; fixes are available.

Chrome devs tell world that DNS over HTTPS won’t open the floodgates of hell
Joker’s Stash Drops Largest-Ever Credit Card Cache on Dark Web
New Adwind Variant Targets Windows, Chromium Credentials
Running on Intel? If you want security, disable hyper-threading, says Linux kernel maintainer
Fancy Bear Targets Sporting, Anti-Doping Orgs As 2020 Olympics Loom

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update for apb, containernetworking-plugins, and golang-github-prometheus-promu is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact

Huawei with you! FCC’s American Pai proposes rip-and-replace of scary Chinese comms kit

A micro version update (from 7.4 to 7.4.1) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

Country of Georgia Suffers Widespread Cyberattack
ThreatList: Most Retail Hardware Bug Bounty Flaws Are Critical

Several security issues were fixed in Samba.

An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for mediawiki is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score,

Reading Time: ~ 4 min. In my previous blog post, Why Healthcare Organizations are Easy Targets for Cybercrime, I discussed various reasons that hospitals and healthcare organizations make desirable and lucrative targets for hackers. In this second installment, I’ll go over how criminals are attacking these organizations, the methods they use, and also what needs to be done […]

Updated file packages fix security vulnerability: A buffer overflow was found in file which may result in denial of service or potentially the execution of arbitrary code if a malformed CDF (Composite Document File) file is processed (CVE-2019-18218).

Updated php and pcre2 packages fix security vulnerabilities: – FPM (#78599) env_path_info underflow in fpm_main.c can lead to RCE. (CVE-2019-11043) – MBString (#78633) Heap buffer overflow (read) in mb_eregi.

This kernel update is based on the upstream 5.3.7 and fixes several issues: * various security issues in the usb subsystem * rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow (CVE-2019-17666)

The updated packages fix a security vulnerability: The agroot() function in cgraphobj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv. (CVE-2019-11023)

Gradient “celebrity matching” photo app sparks privacy fears