Menu

Monthly Archives: October 2019

iBye, bad guy: Apple yanks 18 iOS store apps that sheltered advert-mashing malware
Religious Website Data Exposed for Months

Type: Vulnerability. Golang Go is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. file is prone to a heap-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Direct Mail Extension for TYPO3 is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. F5 BIG-IQ Centralized Management is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Multiple D-Link products are prone to a command-injection vulnerability.

Type: Vulnerability. ISC BIND is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Google Chrome is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. F5 BIG-IQ Centralized Management is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a local memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Python is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Multiple Dell EMC products are prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. libxslt is prone to an arbitrary code-execution vulnerability; fixes are available.

Raccoon Malware Scavenges 100,000+ Devices to Steal Data

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Antivirus hid more than 9,000 ‘cybercrime’ reports from UK cops, says watchdog
Cash App Twitter Giveaway a Haven for Stealing Money
Samsung Rolls Out Fix For Galaxy S10 Fingerprint Sensor Glitch
Facebook lays out plan to protect elections

How is the social network preparing to curtail the spread of misinformation as the election season heats up? The post Facebook lays out plan to protect elections appeared first on WeLiveSecurity

5 tips for better cybersecurity
Vulnerability in content distribution networks found by researchers
Robot Hotel says sorry about the buggy bedside bots

An update that fixes 13 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 16 vulnerabilities is now available.

Google warns devs as it tightens Chrome cookie security: Stuff will break if you’re not clued up
12 year jail sentence for man who hacked Los Angeles Superior Court to send two million phishing emails
ThreatList: Sharp Increase in Fake Mobile Apps Impersonating Legit Ones
Apple Removes 17 Malicious iOS Apps From App Store
IBM tears into Google’s ‘quantum supremacy’ claim

The 5.3.7 update contains a number of important fixes across the tree. The update also includes a fix for the [CVE-2019-17666](https://access.redhat.com/security/cve/CVE-2019-17666) security vulnerability regarding a buffer overflow in a Realtek wireless driver.

The 5.3.7 update contains a number of important fixes across the tree. The update also includes a fix for the [CVE-2019-17666](https://access.redhat.com/security/cve/CVE-2019-17666) security vulnerability regarding a buffer overflow in a Realtek wireless driver.

sudo: Privilege escalation via ‘Runas’ specification with ‘ALL’ keyword (CVE-2019-14287) SL7 x86_64 sudo-1.8.23-4.el7_7.1.x86_64.rpm sudo-debuginfo-1.8.23-4.el7_7.1.x86_64.rpm sudo-debuginfo-1.8.23-4.el7_7.1.i686.rpm sudo-devel-1.8.23-4.el7_7.1.i686.rpm sudo-devel-1.8.23-4.el7_7.1.x86_64.rpm – Scientific Linux Development Team

Smashing Security #151: Frankly, sometimes paying the ransom is a good idea
Tor blimey, Auntie! BBC launches dedicated dark web mirror site

An update is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Stalker app maker Retina-X settles FTC charges

An update for sudo is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for sudo is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Tracking down the developer of Android adware affecting millions of users

ESET researchers discovered a year-long adware campaign on Google Play and tracked down its operator. The apps involved, installed eight million times, use several tricks for stealth and persistence. The post Tracking down the developer of Android adware affecting millions of users appeared first on WeLiveSecurity

An update is now available for Ansible Engine 2.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Would you open an email from one Dr Brian Fisher? GP app staff did – and they got phished
Republican senators shoot down a triple whammy of proposed election security laws

Type: Vulnerability. Ansible is prone to multiple information-disclosure vulnerabilities; fixes are available.

Type: Vulnerability. Google Chrome is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Fortinet FortiOS is prone to an insufficient entropy vulnerability; fixes are available.

Type: Vulnerability. McAfee Endpoint Security is prone to a vulnerability that lets attackers inject and execute arbitrary code; fixes are available.

Type: Vulnerability. URL redirect extension for TYPO3 is prone to an SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Citrix NetScaler ADC and NetScaler Gateway are prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. Libexpat Expat is prone to a heap-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Google Chrome is prone to multiple vulnerabilities; fixes are available.

Type: Vulnerability. Mozilla Firefox and Firefox ESR are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Mozilla Firefox is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a local directory-traversal vulnerability; fixes are available.

Type: Vulnerability. Mozilla Firefox ESR is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. The Booking and Availability Management Tools module for Drupal is prone to an access-bypass vulnerability; fixes are available.

Type: Vulnerability. ISC BIND is prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. Schneider Electric ProClima is prone to multiple remote code-execution vulnerabilities; fixes are available.

Type: Vulnerability. NetApp SnapManager for Oracle is prone to an unspecified local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Fortinet FortiMail is prone to multiple remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Trend Micro Anti-Threat Toolkit is prone to a remote code-execution vulnerability.

Bedside Hotel Robot Hacked to Stream In-Room Video

Reading Time: ~ 3 min. Entrepreneur Jim Rohn once said, “Time is more valuable than money. You can get more money, but you cannot get more time.” I think anyone involved in running a business can relate to this statement, but it carries a particularly deep meaning to those of us who deal with cybersecurity. […]

Fujitsu Wireless Keyboard Plagued By Unpatched Flaws
ThreatList: Google’s Advertising Network Dominates Global Data Collection

An update that solves 16 vulnerabilities and has four fixes is now available.

Firefox, Chrome Bugs Allow Arbitrary Code-Execution
Alexa and Google Home phishing apps demonstrated by researchers
Hacker breached servers used by NordVPN

The package pacman before version 5.2.0-1 is vulnerable to arbitrary command execution.

The package go before version 2:1.13.3-1 is vulnerable to denial of service.

The package go-pie before version 2:1.13.3-1 is vulnerable to denial of service.

The package xpdf before version 4.02-1 is vulnerable to arbitrary code execution.

Facebook pulls fake news networks linked to Russia and Iran
15 Years Later, Metasploit Still Manages to be a Menace
Haxis of evil: Russia, China, Iran and North Korea are ‘continuous threat’ to UK, say spies

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Travel database exposed PII on US government employees

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Smart cities must be cyber‑smart cities

As cities turn to IoT to address long-standing urban problems, what are the risks of leaving cybersecurity behind at the planning phase? The post Smart cities must be cyber‑smart cities appeared first on WeLiveSecurity

Upstream details at : https://access.redhat.com/errata/RHSA-2019:3157

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2964

Upstream details at : https://access.redhat.com/errata/RHSA-2019:3127

Upstream details at : https://access.redhat.com/errata/RHSA-2019:3128

Deepfakes, quantum computing cracking codes, ransomware… Find out what’s really freaking out Uncle Sam
Messed Western: Vuln hunters say hotel giant’s Autoclerk code exposed US soldiers’ info, travel plans, passwords…

security update

security update

FTC Cracks Down on Stalkerware With Retina-X App Bans
Open Redirect Bug in Bridge Theme Plugin Opens Admins to Spearphishing

Type: Vulnerability. Cisco Identity Services Engine is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. IBM Maximo Anywhere is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Cisco Identity Services Engine is prone to an HTML-injection vulnerability; fixes are available.