Menu

Monthly Archives: November 2019

Police arrest alleged Chuckling Squad member who hijacked @Jack Dorsey
Firefox gets tough on tracking tricks that sneakily sap your privacy

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Risk Level: Very Low. Type: Trojan.

security update

Austin Man Indicted for Stealing Unreleased Music from Artists
Magecart Group Switches Up Tactics with MiTM, Phishing

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Google Chrome is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. FasterXML Jackson is prone to multiple XML External Entity injection vulnerabilities.

Type: Vulnerability. Google Chrome is prone to an out-of-bounds memory access vulnerability; fixes are available.

Type: Vulnerability. Google Chrome is prone to a security-bypass vulnerability; fixes are available.

Contract for the Web wants your endorsement

Risk Level: Very Low. Type: Trojan.

Managing the Human Security Factor in the Age of Ransomware
Parents say creep hacked their baby monitor to tell toddler they ‘love’ her

Several security issues were fixed in Ruby.

Facebook and Twitter warn some users’ private data was accessed via third-party app SDK
Court says suspect can’t be forced to reveal 64-character password
National Veterinary Associates catches dose of ransomware
Black Friday Shoppers Targeted By Scams and Fake Domains
Stantinko botnet adds cryptomining to its pool of criminal activities

ESET researchers have discovered that the criminals behind the Stantinko botnet are distributing a cryptomining module to the computers they control The post Stantinko botnet adds cryptomining to its pool of criminal activities appeared first on WeLiveSecurity

Sir Tim Berners-Lee publishes plan to save the web from ‘digital dystopia’

An update that fixes 7 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Stop us if you’ve heard this one: Facebook and Twitter profiles silently slurped by shady code
TrickBot Evolves to Go After SSH Keys

security update

Type: Vulnerability. The Jetpack plugin for WordPress is prone to an unspecified security vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. HP ThinPro Linux is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. McAfee Client Proxy is prone to a local authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. libgd is prone to multiple denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. Infinispan is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. The Linux Kernel is prone to a local race-condition vulnerability; fixes are available.

NYPD Fingerprint Database Taken Offline to Thwart Ransomware
How to decrypt your data from Hakbit & Jigsaw ransomware for free
PoS Malware Exposes Customer Data of Catch Restaurants
Smash-and-grab car thieves use Bluetooth to target cars containing tech gadgets
Hackers attack OnePlus again – this time stealing customer details

An update that fixes one vulnerability is now available.

An update that fixes 42 vulnerabilities is now available.

An update that fixes 18 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

OneCoin crypto-scam lawyer found guilty of worldwide $400m fraud
Ad-blocking companies block ‘unblockable’ tracker
OnePlus website hacked to breach user data AGAIN!
Russia to ban sale of devices that don’t come with “Russian software”
Hacker gets 4 years in jail for NeverQuest banking malware

An out-of-bounds write vulnerability was discovered in php-imagick, a PHP extension to create and modify images using the ImageMagick API, which could result in denial of service, or potentially the execution of arbitrary code.

CyberwarCon – the future of nation‑state nastiness

How the field of play has changed and why endpoint protection still often comes down to doing the basics, even in the face of increasingly complex threats The post CyberwarCon – the future of nation‑state nastiness appeared first on WeLiveSecurity

Several security issues were fixed in libvpx.

Get ahead of the cyber-criminals using training and advice from SANS Manchester in 2020

Type: Vulnerability. Symantec Critical System Protection is prone to an unspecified authentication-bypass vulnerability; fixes are available.

Hackers now use web skimmers to steal credit card data
Hackers access customer data in latest T-Mobile data breach
Cyborg ransomware posing as Windows update hits PCs
How to Write a Resume for a Cybersecurity Position
A reason for the season: Reason antivirus offers 70% off to keep you safe during holiday shopping rush
Flaw authorizes attackers to spy on users through Android camera
About Internet Anonymity, Our Life and Its Relativity
Hacker Releases 2TB of Data from Cayman National Bank
Meet ACbackdoor malware targeting Linux and Windows devices

An update that solves one vulnerability and has one errata is now available.

An update that fixes 18 vulnerabilities is now available.

Security fix for CVE-2019-14869

rebase to upstream version 8.1911.0 ————————————————- new modules available: * ClickHouse output * generic REST API http output * docker API input * misc. external program input (takes output of specified binary as log source)

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Database with 1.2 billion people’s data leaked online without password
T-Mobile US hacked, Monero wallet app infected, public info records on 1.2bn people leak from database…

There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump.

It was discovered that pam-python, a PAM Module that runs the Python interpreter, has an issue in regard to the default environment variable handling of Python. This issue could allow for local root escalation in certain PAM setups.

RDP loves company: Kaspersky finds 37 security holes in VNC remote desktop software
ID Thieves Turn to Snail Mail as Juicy Target for Financial Crimes
Three Areas to Consider, to Focus Your Cyber-Plan

This update fixes CVE-2019-17545.

This update fixes CVE-2019-17545.

This update fixes CVE-2019-17545.

Update to latest stable (78.0.3904.97). This build contains a number of bug fixes and security updates. Changes can be viewed here: https://chromium.googles ource.com/chromium/src/+log/78.0.3904.86..78.0.3904.92?n=10000

Critical Flaws in VNC Threaten Industrial Environments

Type: Vulnerability. Multiple Asterisk Products are prone to an authorization-bypass vulnerability; fixes are available.

Type: Vulnerability. Asterisk Manager Interface is prone to an arbitrary command-execution vulnerability; fixes are available.

Type: Vulnerability. Asterisk Open Source is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Apache Shiro is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to an information-disclosure vulnerability and a denial-of-service vulnerability; fixes are availabl

Type: Vulnerability. Lexmark Services Monitor is prone to a directory-traversal vulnerability.

Type: Vulnerability. Apache Impala is prone to an authorization-bypass vulnerability; fixes are available.

Type: Vulnerability. ISC BIND is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Apache NiFi is prone to multiple information-disclosure vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Email Security Appliance is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. IBM WebSphere Application Server is prone to a directory-traversal vulnerability; fixes are available.

Type: Vulnerability. IBM Cloud Pak System is prone to an information-disclosure vulnerability; fixes are available.

Reading Time: ~ 1 min. Webroot has evolved its secure login offering from a secondary security code to a full two-factor authentication (2FA) solution for both business and home users. Webroot’s 2FA has expanded in two areas. We have: Implemented a time-based, one-time password (TOTP) solution that generates a passcode which is active for only […]

Data-Enriched Profiles on 1.2B People Exposed in Gigantic Leak