Menu

Monthly Archives: December 2019

Microsoft pwns domains used by hackers for large-scale cyber attacks
4 uses for programmable logic controllers in industrial settings
7 Tips for Maximizing Your SOC

The updated packages fix a security vulnerability: Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor. (CVE-2019-17064)

Updated hunspell packages fix security vulnerability: Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx (CVE-2019-16707).

The updated package fixes a security vulnerability: Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks. (CVE-2019-15237)

Updated pdfresurrect package fixes security vulnerabilities: A vulnerability was found in PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled (CVE-2019-14267).

The updated packages fix an issue: Wrong permissions on /etc/freshclam.conf prevent freshclam usage with authenticated proxy. (rhbz#1733112)

Updated filezilla packages fix bugs and a security vulnerability: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

2020 Cybersecurity Trends to Watch
20 tips for 2020: Be smarter with your smartphone

In the second blogpost of the two-part series we’ll suggest handy tips to help enhance the security of your mobile devices The post 20 tips for 2020: Be smarter with your smartphone appeared first on WeLiveSecurity

Most popular tech stories of 2019
Most second-hand phones contain previous owner’s data
Smart TVs make screenshots every second & send them to the server
Celebrity addresses posted online in New Year’s Honours List leak
IoT Company Wyze Leaks Emails, Device Data of 2.4M
Mean Time to Hardening: The Next-Gen Security Metric
Top Mobile Security Stories of 2019

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes three vulnerabilities is now available.

Monday review – the hot 12 stories of the week
20 tips for 2020: Mistakes to avoid

In this first instalment of the two-article series we will be looking at cybersecurity habits to avoid when using your computing devices The post 20 tips for 2020: Mistakes to avoid appeared first on WeLiveSecurity

Several security bugs have been identified and fixed in php5, a server-side, HTML-embedded scripting language. The affected components include the exif module and handling of filenames

It was discovered that there was a potential denial of service vulnerability in libxml2, the GNOME XML parsing library. For Debian 8 “Jessie”, this issue has been fixed in libxml2 version

Multiple vulnerabilities have been found in imagemagick, an image processing toolkit. CVE-2019-19948

7 types of virus – a short glossary of contemporary cyberbadness

security update

security update

security update

security update

security update

Several issues were discovered in the Tomcat servlet and JSP engine, which could result in session fixation attacks, information disclosure, cross- site scripting, denial of service via resource exhaustion and insecure redirects.

It was discovered that debian-lan-config, a FAI config space for the Debian-LAN system, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other user principals.

Guido Vranken discovered an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. For the oldstable distribution (stretch), this problem has been fixed

It was found that freeimage, a graphics library, was affected by the following two security issues: CVE-2019-12211

What Brings The Essence Of Secured Web Hosting
Christmas malware uses “Support Greta Thunberg” as a lure
Google Chrome Affected By Magellan 2.0 Flaws
Prison surveillance footage posted on YouTube

It’s not a stretch to surmise that the incident was enabled by poor security settings The post Prison surveillance footage posted on YouTube appeared first on WeLiveSecurity

Facebook Security Debacles: 2019 Year in Review
Podcast: The Roadblocks and Opportunities For Women in Cybersecurity

An update that fixes one vulnerability is now available.

An update that solves 24 vulnerabilities and has 75 fixes is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that solves 24 vulnerabilities and has 75 fixes is now available.

An update that fixes one vulnerability is now available.

How to get rid of your old devices safely

Disposing of old tech isn’t a one-click solution; there are multiple things you have to consider before moving on to greener pastures The post How to get rid of your old devices safely appeared first on WeLiveSecurity

Beware the three-finger-salute, or ‘How I Got The Keys To The Kingdom’
Critical Citrix Bug Puts 80,000 Corporate LANs at Risk

Updated php packages fix security vulnerabilities: DirectoryIterator class silently truncates after a null byte (CVE-2019-11045).

he updated packages fix security vulnerabilities and a packaging problem: An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make

The updated package fixes a security vulnerability: A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon. (CVE-2019-14857)

Updated libofx packages fix security vulnerability: There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump (CVE-2019-9656).

Apple iCloud “data dump” extortionist avoids prison
Combining AI and Playbooks to Predict Cyberattacks
Top 10 Breaches and Leaky Server Screw Ups of 2019
Top 7 PDF Tools to Edit, Merge/Split and Protect PDF

An issue was discovered in libopensc/card-setcos.c in OpenSC, which has an incorrect read operation during parsing of a SETCOS file attribute.

Type: Vulnerability. ImageMagick is prone to multiple heap-based buffer-overflow vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. IBM Cognos Analytics is prone to a cross-site scripting vulnerability and a cross-site request-forgery vulnerability; fixes are available.

Type: Vulnerability. FasterXML Jackson-databind is prone to a remote code-execution vulnerability; fixes are available.

This update is based on upstream 5.4.6 and fixes various potential security issues related to buffer overflows, double frees, NUll pointer dereferences, improper / missing input validations and so on. It also adds other bugfixes all over the kernel.

Happy Holidays – and big thanks to everyone who’s working today!
Man accused of hiring hitman on dark web to kill ex-girlfriend

Type: Vulnerability. Trend Micro Apex Central is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. TYPO3 is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. IBM Spectrum Scale is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Samba is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.

Type: Vulnerability. Redis is prone to a buffer overflow vulnerability; fixes are available.

Type: Vulnerability. Multiple Trend Micro Products are prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Apple iOS/iPadOS/watchOS/macOS are prone to a security vulnerability; fixes are available.

Type: Vulnerability. Wecon PLC Editor is prone to multiple stack-based buffer-overflow vulnerabilities.

Type: Vulnerability. Multiple Moxa Products are prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Broadcom CA Client Automation is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Sudo is prone to multiple security-bypass vulnerabilities; fixes are available.

Biggest Malware Threats of 2019
Sextortionists return for Christmas – price goes down, threats go up
Londoner who tried to blackmail Apple with 300m+ iCloud account resets was reusing stale old creds
The Case for Cyber-Risk Prospectuses
What a decade! Our baddest stories and biggest lessons, year by year…
Here is a list of top 25 worst passwords of 2019

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4107

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4148

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4240

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4326

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4190

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4190

To protect data and code in the age of hybrid cloud, you can always turn to Intel SGX
Twitter Fixes Bug that Enabled Takeover of Android App Accounts

Type: Vulnerability. RedHat Ceph is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Redis is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Kubernetes API Server is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Apache Log4j is prone to remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Multiple VMware products are prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Kubernetes is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Equinox Control Expert is prone to an SQL-injection vulnerability.