Menu

Monthly Archives: November 2019

VIDEO: “Not All Cybercriminals Are Evil Geniuses”
Twitter finally upgrades its 2FA security feature. Mobile number no longer required!
Download: 2019 Security Team Assessment Template
Google plans to take Android back to ‘mainline’ Linux kernel
Iran’s APT33 sharpens focus on industrial control systems
Raccoon Stealer Malware Scurries Past Microsoft Messaging Gateways
News Wrap: Amazon Ring Risks, Stalkerware, and D-Link Router Flaws

Reading Time: ~ 2 min. Shade Ransomware Takes Crown as Most Distributed Variant Over the course of 2019, one ransomware variant, known as Shade, has taken over 50 percent of market share for ransomware delivered via email. Otherwise known as Troldesh, this variant receives regular updates to further improve it’s encrypting and methods of generating […]

Google Will Award $1M-Plus to People Who Can Hack Titan M Security Chip
Why cryptocoin scams work, and how to avoid them
Convicted Nigerian fraudster keeps a-fraudin’ from behind bars

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Bad news: ‘Unblockable’ web trackers emerge. Good news: Firefox with uBlock Origin can stop it. Chrome, not so much

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Senators Demand Amazon Disclose Ring Privacy Policies

Type: Vulnerability. Cisco IOS XR Software is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Cisco Unity Express is prone to a local command-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco Webex Centers are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Cisco Email Security Appliance is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Cisco SD-WAN Solution is prone to a cross-site request-forgery vulnerability; fixes are available.

Type: Vulnerability. Cisco Stealthwatch Enterprise is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Cisco DNA Spaces Connector is prone to a local command-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco Small Business RV Series Routers are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Cisco Unified Communications Manager is prone to an SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco Webex Teams for Windows is prone to a local arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Cisco DNA Spaces Connector is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to multiple information-disclosure vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Unified Communications Domain Manager is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco DNA Spaces: Connector is prone to an SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Lenovo LenovoPaper software is prone to an unspecified local privilege-escalation vulnerability.

Type: Vulnerability. Lenovo System Interface Foundation is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Unbound IPSEC Module is prone to a command-injection vulnerability; fixes are available.

Type: Vulnerability. Lenovo CCSDK is prone to an unspecified local privilege-escalation vulnerability.

Type: Vulnerability. Fortinet FortiOS is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Multiple Fortinet products are prone to hard-coded cryptographic key vulnerability; fixes are available.

Type: Vulnerability. Fortinet FortiOS is prone to a hardcoded cryptographic key vulnerability; fixes are available.

Type: Vulnerability. Multiple Cloud Foundry Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Lenovo ThinkPad USB-C Dock is prone to a unspecified denial-of-service vulnerability; fixes are available.

Microsoft Outlook for Android Bug Opens Door to XSS

Risk Level: Very Low. Type: Trojan.

Bon sang! French hospital contracts 6,000 PC-locking ransomware infection
Linux Webmin Servers Under Attack by Roboto P2P Botnet
Gnip Banking Trojan Shows Ongoing, Aggressive Development
DNS-over-HTTPS is coming to Windows 10
Android camera bug could have turned phones against their users
Official Monero site delivers malicious cash-grabbing wallet
Popular Apps on Google Play Store Remain Unpatched
Registers as “Default Print Monitor”, but is a malicious downloader. Meet DePriMon

ESET researchers have discovered a new downloader with a novel, not previously seen in the wild installation technique The post Registers as “Default Print Monitor”, but is a malicious downloader. Meet DePriMon appeared first on WeLiveSecurity

UK tax collectors warn contractors about being ripped-off – and not by HMRC for a change
Orange is the new green: Nigeria scammer bags $1m while operating behind bars
Smashing Security #155: Juicejacking, YouTube hacking, password slacking
Amnesty slams Facebook, Google over ‘pervasive surveillance’ business model
Tories change Twitter name to ‘factcheckUK’ during live TV debate
Security Firms, Nonprofits Team to Fight Stalkerware
Mozilla Bug Bounty Program Doubles Payouts, Adds Firefox Monitor

security update

Apache Solr Bug Gets Bumped Up to High Severity

Type: Vulnerability. Multiple IBM Products are prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Broadcom Brocade SANnav is prone to a security weakness; fixes are available.

Type: Vulnerability. Google Android is prone to multiple security-bypass vulnerabilities; fixes are available.

Type: Vulnerability. Schneider Electric Floating License Manager is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Dell EMC iDRAC is prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. Broadcom Brocade SANnav is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook for Android is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Atlassian Jira Service Desk Server and Jira Service Desk Data Center are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Broadcom Brocade SANnav is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Broadcom Brocade SANnav is prone to a hard-coded credentials vulnerability; fixes are available.

Type: Vulnerability. Apache Solr for Linux is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Oracle MySQL Connectors is prone to a remote vulnerability; fixes are available.

High-Severity Windows UAC Flaw Enables Privilege Escalation

Reading Time: ~ 4 min. With major advancements in communication technology, many employees and entrepreneurs are opting to work from home at least some of the time. In fact, according to CNBC, 70 percent of people globally worked remotely at least once a week in 2018. And why shouldn’t they? They save gas and time by not […]

ThreatList: Admin Rights for Third Parties is the Norm
What does it take to attract top cybersecurity talent?

From professional backgrounds to competitive salaries – a study delves into what it takes to build strong cybersecurity teams The post What does it take to attract top cybersecurity talent? appeared first on WeLiveSecurity

Millions of Android phones may be vulnerable to camera spying vulnerability
Hackers Dump 2.2M Gaming, Cryptocurrency Passwords Online
UK public sector IT chiefs shrug off breach threats: The data we hold isn’t that important

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Update WhatsApp now: MP4 video bug exposes your messages
Instagram stalker app Ghosty yanked from Play store
XSS security hole in Gmail’s dynamic email
Adobe Acrobat and Reader 2015 reach end of support

Updated packages that provide Red Hat JBoss Core Services Pack Apache Server 2.4.37 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

An update is now available for JBoss Core Services on RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Updated Red Hat JBoss Web Server 5.2.0 packages are now available for Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

Red Hat JBoss Core Services Pack Apache Server 2.4.37 zip release for RHEL 6, RHEL 7 and Microsoft Windows is available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Video-editing upstart bares users’ raunchy flicks to world+dog via leaky AWS bucket
Twitter warns verified users against attempts to mislead public after Conservative factcheckUK stunt
Half of Oracle E-Business customers open to months-old bank fraud flaw
ICO scammer Maksim Zaslavskiy to miss 2020 Tokyo Olympics over digital currency fraud
Linux Kernel Security in a Nutshell: How to Secure Your Linux System>
Mozilla expands bug bounty program and triples payouts for flaw finders for hire
400 Vet Locations Nipped by Ryuk Ransomware
D-Link Adds More Buggy Router Models to ‘Won’t Fix’ List

security update