Menu

Monthly Archives: December 2019

Type: Vulnerability. Philips Veradius Unity, Pulsera, and Endura are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cloud Foundry Cloud Controller API is prone to a security-bypass vulnerability; fixes are available.

Apple Bug bounty: Earn big backs for hacking iPhone & other products

A change introduced in libssh 0.6.3-4+deb8u4 (which got released as DLA 2038-1) has broken x2goclient’s way of scp’ing session setup files from client to server, resulting in an error message shown in a GUI error dialog box during session startup (and session resuming).

An update that fixes two vulnerabilities is now available.

Serious Security: The decade-ending “Y2K bug” that wasn’t
ToTok app caught spying on millions of Android & iPhone users
Patch now: Published Citrix applications leave networks of ‘potentially 80,000’ firms at risk from attackers
Top 10 IoT Disasters of 2019
Podcast: What We’ve Learned from the Year of the Breach
Emirati ‘surveillance app’ ToTok promoted by Huawei as Apple punts it from store
Smartphone location data can be used to identify and track anyone
Congress passes anti-robocall bill
Facebook will stop mining contacts with your 2FA number
Say GDP-aaaR: UK’s Information Commissioner pours £275k fine into London pharmacy’s teaspoon
How to secure your digital Christmas presents

What are some of the key things you should do with your shiny new device as soon as you unbox it? The post How to secure your digital Christmas presents appeared first on WeLiveSecurity

An update for fribidi is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libyang is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An issue has been found in cups, the Common UNIX Printing System(tm). An incorrect bounds check could lead to a possible out-of-bounds read and

An update that fixes 7 vulnerabilities is now available.

security update

Fake streaming sites using Star Wars as bait to spread malware
Tracking President Trump with cellphone location data, Greta-Thunberg-themed malware, SharePoint patch, and more

Several vulnerabilities have recently been discovered in TightVNC 1.x, an X11 based VNC server/viewer application for Windows and Unix.

An update that solves 26 vulnerabilities and has 14 fixes is now available.

How to check for websites hacked to run web skimming, magecart attack

security update

New tigervnc packages are available for Slackware 14.2 and -current to fix security issues.

New openssl packages are available for Slackware 14.2 and -current to fix a security issue.

– Update to 1.2.8 Release notes: https://www.cacti.net/release_notes.php?version=1.2.8

– Update to 1.2.8 Release notes: https://www.cacti.net/release_notes.php?version=1.2.8

Type: Vulnerability. Palo Alto Networks PAN-OS is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Telos AMHS is prone to multiple cross-site scripting vulnerabilities and an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple Apple Products are prone to an arbitrary code execution vulnerability; fixes are available.

Type: Vulnerability. Atlassian Confluence Server and Data Center are prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Django is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. D-Link DIR-615 is prone to a privilege-escalation vulnerability.

Type: Vulnerability. ABB PB610 Panel Builder 600 is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. TYPO3 is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Multiple Dell products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Drupal Core is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Apache Xerces-C is prone to a remote code-execution vulnerability.

Type: Vulnerability. Sysstat is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Apache Tomcat is prone to a session-fixation vulnerability; fixes are available.

Type: Vulnerability. Drupal is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Apache Tomcat is prone to local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Drupal is prone to an access-bypass vulnerability; fixes are available.

It’s cool for Brit snoops to break the law, says secretive spy court. Just hold on while we pull off some legal jujitsu to let MI5 off the hook…
Top Zero Days, Data Breaches and Security Stories of 2019: News Wrap
Greta Thunberg: Emotet’s Person of the Year
It’s Time for Your SOC to Level Up
Wawa Data Breach: Malware Stole Customer Payment Card Info
Apple’s Bug Bounty Opens for Business, $1M Payout Included
What’s that? Encryption’s OK now? UK politicos Brexit from Whatsapp to Signal

Reading Time: ~ 2 min. Honda Customer Database Exposed Officials have been working over the past work to secure a database containing highly sensitive information belonging to more than 26,000 North American customers of the Honda motor company. The database in question was originally created in October and was only discovered on December 11. While […]

Five years for the man who scammed Facebook and Google out of $120m by cunning use of email

An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Twitter trolls attack epileptics with seizure-inducing images
Facebook’s location tracking policy still worries US Senators
What’s behind Putin’s old-school operating system?

There has been an out-of-bounds write in Cyrus SASL leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash was ultimately caused by an off-by-one error

Hello ‘123456,’ my old friend, I’ve come to talk with you again
Ambitious scam wants far more than just PayPal logins

An ongoing phishing scam uncovered by ESET researchers seeks to wreak havoc on your money and digital life in one fell swoop The post Ambitious scam wants far more than just PayPal logins appeared first on WeLiveSecurity

An update that fixes 7 vulnerabilities is now available.

While preparing a fix for CVE-2017-6314 an unknown symbol g_uint_checked_mul() was introduced.

An update that solves 24 vulnerabilities and has 58 fixes is now available.

An update that solves 24 vulnerabilities and has 58 fixes is now available.

Names & Phone numbers of 267 million Facebook users exposed
Want to ‘live long and prosper’? Then avoid pirated, malware-laden Star Wars streams and pay to watch
267M Facebook Users’ Phone Numbers Exposed Online

security update

Google & Mozilla ban Avast security extensions over data snooping
The Scammer Force is Strong with Star Wars: The Rise of Skywalker
Honda Leaks Data of 26K North American Customers
Email blackmail brouhaha tears UKIP apart as High Court refuses computer seizure attempt
38,000 people forced to pick up email passwords in person

Malware and legal requirements force academics and students to join a near-endless line in order to pick up their passwords The post 38,000 people forced to pick up email passwords in person appeared first on WeLiveSecurity

An update for fribidi is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat Quay 3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Chrome 79 patched after Android WebView app chaos
Get in line! 38,000 students and staff forced to queue for new passwords
Proposed standard would make warrant canaries machine-readable
Instagram hides ‘false’ content, unless it’s from a politician

Updated htmldoc packages fix security vulnerability: In HTMLDOC, there was a one-byte underflow in htmldoc/ps-pdf.cxx caused by a floating point math difference between GCC and Clang (CVE-2019-19630).

Updated libssh packages fix security vulnerability: In an environment where a user is only allowed to copy files and not to execute applications, it would be possible to pass a location which contains commands to be executed in addition (CVE-2019-14889).

Updated freerdp packages fix security vulnerabilities: Multiple memory leaks in libfreerdp/codec/region.c (CVE-2019-17177). Memory leak in HuffmanTree_makeFromFrequencies (CVE-2019-17178).

British bloke accused of extorting victims for ‘Dark Overlord’ hacker crew finally gets his free trip* to America
Das Reboot: Uni forces 38,000 students, staff to queue, show their papers for password reset following ‘cyber attack’
FYI: FBI raiding NSA’s global wiretap database to probe US peeps is probably illegal, unconstitutional, court says
Smashing Security #159: Rap, robbery, and IoT holiday hell
Medical biz LifeLabs fesses up: Hackers slurped 15 million customer records – and we paid them to hand it all back

Reading Time: ~ 3 min. As the year draws to a close, the cybersecurity analysts at Webroot and Carbonite pull out their crystal balls to make their predictions for the year ahead.  Our experts predict many of the trends they’ve been tracking throughout the year—well-researched attacks, RDP compromise, and the importance of user education—will continue […]

You leak our secrets? We’ll leak your book sales, speech fees – into our coffers: Uncle Sam wins royalties fight against Edward Snowden

security update

Why Cloud, Collaboration Breed Insider Threats

Type: Vulnerability. TYPO3 is prone to multiple remote code-execution vulnerabilities; fixes are available.

Type: Vulnerability. TYPO3 is prone to an SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Google Chrome is prone to a use-after-free vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.