Menu

Monthly Archives: November 2019

security update

Google Discloses Android Camera Hijack Hack
McDonalds-Themed Facebook Ads Serve Up Banking Trojans
Shopped online at Macy’s last month? Might want to toss, or at least check, that card
Servers Running Linux May Get Riskier for Enterprises Next Year>

Type: Vulnerability. Ghostscript is prone to a remote privilege-escalation vulnerability; fixes are available.

Brexit bad boy Arron Banks’ Twitter account hacked: Private messages put online
Interpol: Strong encryption helps online predators. Build backdoors

Security fix for CVE-2019-14869

fixed multiple security bugs

Fake ‘Windows Update’ Installs Cyborg Ransomware
Bad boy of Brexit Arron Banks hacked, private Twitter messages leaked
Second time lucky: Sweden drops Julian Assange rape investigation
Man who made $542,925 renting out DDoS services sentenced to prison
Macy’s Suffers Data Breach by Magecart Cybercriminals
‘Wildly Different’ Privacy Regulations Causing Compliancy Chaos
Research: 5G Networks Still Vulnerable to Location Tracking, Downgrading Attacks>
Portland Seeks to Become First City in Maine to Ban Facial Recognition Technology>
Brand new Android smartphones shipped with 146 security flaws

An update that fixes one vulnerability is now available.

Ho Ho OUCH! There are 4x more fake retailer sites than real ones
Ransomware strikes again in the state of Louisiana

An update for machine-os-content-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Booter boss behind millions of DDoS-for-hire attacks jailed
Mispadu: Advertisement for a discounted Unhappy Meal

Another in our occasional series demystifying Latin American banking trojans The post Mispadu: Advertisement for a discounted Unhappy Meal appeared first on WeLiveSecurity

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Americans Concerned, Confused Over Privacy, Survey Reveals
WhatsApp Remote Code Execution Triggered by Videos

Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to a timing attack/information leak, argument injection and code execution via unserialization.

The Unhappiest Subscribers on Earth? Disney+ Accounts Hacked & Hijacked

security update

security update

Type: Vulnerability. Teamviewer is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Intel Ethernet 700 Series Controllers are prone to a buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. McAfee Advanced Threat Defense is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Multiple Siemens Products are prone to an unspecified denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Multiple Siemens Products are prone to a security vulnerability; fixes are available.

Type: Vulnerability. Multiple ABB products are prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. McAfee Data Loss Prevention is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. FriBidi is prone to a stack-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Siemens SIMATIC S7-1200 is prone to a local unauthorized-access vulnerability.

Type: Vulnerability. Fortinet FortiOS is prone to an local information-disclosure vulnerability; fixes are available.

Office 365 Admins Targeted in Ongoing Phishing Scam
Interpol: Strong encryption helps paedos. Build backdoors
Disney+ accounts hijacked – How to protect yourself

As users are losing access to their accounts by the dozens, we offer a few tips to help keep your streaming subscriptions safe The post Disney+ accounts hijacked – How to protect yourself appeared first on WeLiveSecurity

Pack your bags, you’re going to America, Lord Chief Justice tells accused Brit hacker
NextCry Ransomware Targets NextCloud Linux Servers and Remains Undetected>
Pipka Card Skimmer Removes Itself After Infecting eCommerce Sites

Earlier versions of this package package were vulnerable to Cross-site Scripting (XSS) due to no proper sanitization of xlink:href attributes.

An update that solves one vulnerability and has 22 fixes is now available.

Multiple security issues have been found in Thunderbird which could potentially result in the execution of arbitrary code or denial of service. Debian follows the Thunderbird upstream releases. Support for the 60.x series

Tianfu Cup Round-Up: Safari, Chrome, D-Link Routers and Office 365 Successfully Hacked
NSA won’t collect phone location data, promises US government

An update is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

GitHub launches Security Lab to boost open source security

An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security vulnerability was found in libapache2-mod-auth-openidc, the OpenID Connect authentication module for the Apache HTTP server. Insufficient validation of URLs leads to an Open Redirect

Two men busted for hijacking victims’ phones and email accounts
Wikipedia co-founder offers a Facebook/Twitter wannabe

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in python-ecdsa.

Several security issues were fixed in MySQL.

An update for libcomps is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Pemex hit by ransomware, US Postal Service gets a copycat and new WhatsApp bugs

New kernel packages are available for Slackware 14.2 to fix security issues.

A vulnerability was discovered in mosquitto, a MQTT version 3.1/3.1.1 compatible message broker, allowing a malicious MQTT client to cause a denial of service (stack overflow and daemon crash), by sending a specially crafted SUBSCRIBE packet containing a topic with a extremely

VCPUOP_initialise DoS [XSA-296, CVE-2019-18420] missing descriptor table limit checking in x86 PV emulation [XSA-298, CVE-2019-18425] Issues with restartable PV type change operations [XSA-299, CVE-2019-18421] (#1767726) add-to-physmap can be abused to DoS Arm hosts [XSA-301, CVE-2019-18423] passed through PCI devices may corrupt host memory after deassignment [XSA-302, CVE-2019-18424]

8u232 update

Security fix for CVE-2019-15142, CVE-2019-15143, CVE-2019-15144 and CVE-2019-15145.

Update to 1.1.20

Security fix for CVE-2019-16275

Rich Mirch discovered that the pg_ctlcluster script didn’t drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.

An update that fixes 11 vulnerabilities is now available.

Holiday Shoppers Beware: 100K Malicious Sites Found Posing as Well-Known Retailers
GitHub makes CodeQL free for research and open source

security update

security update

Security fix for CVE-2019-14664, CVE-2019-12269 and compatibility with Thunderbird 68

Update to Samba 4.10.10 – Security fixes for CVE-2019-10218, CVE-2019-14833, CVE-2019-14847

Denial of service kingpin hit with 13 months denial of freedom and a massive bill to pay

Type: Vulnerability. Philips IntelliBridge EC40 and EC80 is prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. Multiple Veritas products are prone to an arbitrary command-injection vulnerability; fixes are available.

Type: Vulnerability. Multiple Siemens Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Siemens Desigo PX is prone to denial of service vulnerability; fixes are available.

Type: Vulnerability. Redhat Syndesis is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. McAfee Threat Intelligence Exchange Server is prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. OpenStack Mistral is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. McAfee Total Protection is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Exim is prone to an arbitrary code-execution vulnerability; fixes are available.

Update to latest stable (78.0.3904.97). This build contains a number of bug fixes and security updates. Changes can be viewed here: https://chromium.googles ource.com/chromium/src/+log/78.0.3904.86..78.0.3904.92?n=10000

James Clapper: Lessons Learned in a Post-Snowden World
1Password hopes to cross some items off its todo list with help from $200m in venture capital
Lizard Squad Threatens UK’s Labour Leader with Cyberattacks Against His Family
Stealthy Malware Flies Under AV Radar with Advanced Obfuscation
How ransomware attacks
How the Linux kernel balances the risks of public bug disclosure

An update that solves one vulnerability and has two fixes is now available.

An update that solves two vulnerabilities and has one errata is now available.