Menu

Monthly Archives: October 2019

Type: Vulnerability. CA Network Flow Analysis is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. GE Mark VIe Controller is prone to an authorization-bypass vulnerability.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Update Assistant is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Bootstrap 3 Typeahead is prone to a cross-site scripting vulnerability.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. SMA Solar Technology AG Sunny WebBox is prone to a cross-site request-forgery vulnerability.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Gamers Warned of High-Severity Intel, Nvidia Flaws
Most Americans Fail Cybersecurity Quiz
Privacy Groups: Ring’s Police Partnerships Can Lead to Sinister Ends
How concerned are you about the privacy challenges of your IoT devices?

An ESET survey of thousands of people in North America provides a peek into how they perceive the privacy and security of their smart home connected devices The post How concerned are you about the privacy challenges of your IoT devices? appeared first on WeLiveSecurity

Ransomware victim hacks attacker, turning the tables by stealing decryption keys
October Patch Tuesday: Microsoft fixes critical remote desktop bug

Reading Time: ~ 3 min. First and foremost, endpoint protection must be effective. Short of that, MSPs won’t succeed in protecting their clients and, more than likely, won’t remain in business for very long. But beyond the general ability to stop threats and protect users, which characteristics of an endpoint solution best set its administrators […]

Twitter Uses Phone Numbers, Emails to Sell Ads
Deepfakes have doubled, overwhelmingly targeting women
New and Improved CVE Pages
MasterMana botnet hits users by evading detection with URL shorteners
Copy-and-paste sharing on Stack Overflow spreads insecure code
TOMS hacker tells people to log off and enjoy a screenless day
Internet pioneer Dr. Paul Vixie on global internet security

We sat down with internet pioneer and Farsight Security CEO Dr. Paul Vixie, who co-invented some of the services that are central to the ‘Net’s fabric, to discuss a range of issues affecting security and privacy The post Internet pioneer Dr. Paul Vixie on global internet security appeared first on WeLiveSecurity

Twitter: No, really, we’re very sorry we sold your security info for a boatload of cash
You know the deal: October 2019. Pwned by a spreadsheet. Patch your Microsoft stuff
Tune in today: Learn lessons from Australia and Singapore – find out how to thwart cyber-crooks probing your IT
A trio of boffins scoop the Nobel Prize in physics for the first exoplanet discovery and big bang model
Hackers found tracking web traffic of Chrome and Firefox browsers
Intimate Details on Healthcare Workers Exposed as Cloud Security Lags
Critical Microsoft Remote Desktop Flaw Fixed in Security Update
If you have a security alert, I feel bad for you, son – you got 99 problems but a hack ain’t one
Apple Tackles Over a Dozen Bugs in its Catalina 10.15 Update

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability; fixes are available.

Sextortionists Get Past Defenses with Cryptocurrency Shift

Risk Level: Very Low. Type: Trojan, Worm.

Google October Android Security Update Fixes Critical RCE Flaws

An update that solves two vulnerabilities and has two fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Inside consumer perceptions of security and privacy in the connected home

The ESET survey polled 4,000 people to get a sense of their attitudes towards the privacy and security implications of smart home technology The post Inside consumer perceptions of security and privacy in the connected home appeared first on WeLiveSecurity

APT Groups Exploiting Flaws in Unpatched VPNs, Officials Warn
Yes, MFA isn’t perfect. But that’s not a reason for your company not to use it

A heap buffer overflow vulnerability was discovered in openjpeg2, the open-source JPEG 2000 codec. This vulnerability is caused by insufficient validation of width and height of image components in color_apply_icc_profile (src/bin/common/color.c). Remote attackers might leverage this vulnerability

Nix to the mix: Chrome to block passive HTTP content swirled into HTTPS pages
Signal immediately fixed FaceTime-style eavesdropping bug
GPS tracker from stalked woman’s car led to indictment of 20 mobsters

An update that solves one vulnerability and has one errata is now available.

Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.

Nationwide facial recognition ID program underway in France
Facebook’s Libra cryptocurrency dealt blow by PayPal’s departure
Needles in a haystack: Picking unwanted UEFI components out of millions of samples

ESET experts describe how they trained a machine-learning model to recognize a handful of unwanted UEFI components within a flood of millions of harmless samples The post Needles in a haystack: Picking unwanted UEFI components out of millions of samples appeared first on WeLiveSecurity

Unbound could be made to crash if it received a specially crafted NOTIFY query.

An update for kernel is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for python is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Type: Vulnerability. Microsoft Windows MS XML is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Open Enclave SDK is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Update Client is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft SQL Server Management Studio is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows 10 Mobile is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Remote Desktop Protocol is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Dynamics 365 is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft SQL Server Management Studio is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Kernel is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge and Internet Explorer are prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.