Menu

Monthly Archives: December 2019

Type: Vulnerability. The permissions by term for Drupal is prone to an access-bypass vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.

Type: Vulnerability. IBM MQ is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.

Type: Vulnerability. Lenovo Power Management Driver is prone to a local buffer-overflow vulnerability; fixes are available.

Ring Plagued by Security Issues, Flood of Hacks
Microsoft Issues Out-of-Band Update for SharePoint Bug
TP-Link Routers Give Cyberattackers an Open Door to Business Networks

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Jet2 hacker who deleted every account on UK company’s domain cops 5 months in jail
System hijacking flaws found in pre-installed Acer & ASUS software
LifeLabs Pays Hackers Who Accessed 15M Customers’ Lab Test Results
BlackBerry tells UK High Court that security outfit SentinelOne is its direct rival
Doxed credit card data has two hours max before it’s nabbed
Mozilla adds NextDNS to list of DNS-over-HTTPS providers
Log us out: Private equity snaffles Lastpass owner LogMeIn

It was discovered that there was a potential account hijack vulnerabilility in Django, the Python-based web development framework.

Alleged bank vault robber posed with cash on Instagram, Facebook

Kernel: KVM: OOB memory access via mmio ring buffer (CVE-2019-14821) Bug Fix(es): * KEYS: prevent creating a different user’s keyrings SL-6.10 * BUG: unable to handle kernel NULL pointer dereference at (null) * long I/O stalls with bnx2fc from not masking off scope bits of retry delay value SL6 x86_64 kernel-2.6.32-754.25.1.el6.x86_64.rpm kernel-debug-2.6.32-754.25.1.el6.x86_64. [More…]

freetype: a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c leading to information disclosure (CVE-2015-9381) * freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read (CVE-2015-9382) SL6 x86_64 freetype-2.3.11-19.el6_10.i686.rpm freetype-2.3.11-19.el6_10.x86_64.rpm freet [More…]

Google to choke off ‘less secure applications’

An update for rh-maven35-apache-commons-beanutils is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Security fix for CVE-2019-5544

An update that fixes 37 vulnerabilities is now available.

Don’t fall for this porn scam – even if your password’s in the subject!
Half a billion here, half a billion there – pretty soon you’re talking real money: US Congress earmarks $425m for 2020 election security
Rooster Teeth Attack Showcases New Magecart Approach

Type: Vulnerability. Avaya IP Office Application Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability.

Type: Vulnerability. Atlassian Application Links is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Apache Superset is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. IBM API Connect is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. IBM Case Manager is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Apache Superset is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Omron PLC CJ and CS Series are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. ZOHO ManageEngine EventLog Analyzer is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. SQLite is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Mozilla Firefox is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Ansible Tower is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Broadcom CA Automic Sysload is prone to an arbitrary command-execution vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Omron PLC CJ, CS and NJ Series are prone to an authentication-bypass vulnerability; fixes are available.

Epilepsy Foundation Bombarded with Seizure-Triggering Twitter Posts
Massive leak exposes browsing history of millions of users
Alexa, Google Home Eavesdropping Hack Not Yet Fixed

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Ransomware-seized New Orleans declares state of emergency
Researchers discover weakness in IoT digital certificates

It was discovered that python-ecdsa, a cryptographic signature library for Python, incorrectly handled certain signatures. A remote attacker could use this issue to cause python-ecdsa to either not warn about incorrect signatures, or generate exceptions resulting in a

Destroyed: A method of destroying Whatsapp group chats forever, say infosec bods of vuln patch
Mozilla mandates 2FA security for Firefox developers
It’s time to disconnect RDP from the internet

Brute-force attacks and BlueKeep exploits usurp convenience of direct RDP connections; ESET releases a tool to test your Windows machines for vulnerable versions The post It’s time to disconnect RDP from the internet appeared first on WeLiveSecurity

Facebook employees’ payroll data nabbed in car smash-and-grab
London’s Met Police splash the cash on e-learning ‘cyber’ training for 4k staffers

It was found that libssh, a tiny C SSH library, does not sufficiently sanitize path parameters provided to the server, allowing an attacker with only SCP file access to execute arbitrary commands on the server.

An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for freetype is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

security update

It’s 2019 so, of course, this Wells Fargo employee accused of stealing customer cash posed with wads of dosh on Instagram, Facebook

security update

Type: Vulnerability. WordPress is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability.

Type: Vulnerability. Dovecot is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability.

Type: Vulnerability. Siemens SiNVR 3 is prone to multiple security vulnerabilities.

Type: Vulnerability. Apache SpamAssassin is prone to an arbitrary command-injection vulnerability and denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Advantech DiagAnywhere is prone to multiple stack-based buffer-overflow vulnerabilities; fixes are available.

Type: Vulnerability. CESNET libyang is prone to multiple stack-based buffer-overflow vulnerabilities; fixes are available.

Type: Vulnerability. Multiple Cloud Foundry Products are prone to an information-disclosure vulnerability; fixes are available.

Vulnerability expose Barco wireless presentation system to remote attacks
Echobot IoT Botnet Casts a Wide Net with Raft of Exploit Additions
The worst passwords of 2019: Did yours make the list?

These passwords may win the popularity contest but lose flat out in security The post The worst passwords of 2019: Did yours make the list? appeared first on WeLiveSecurity

N.J.’s Largest Hospital System Pays Up in Ransomware Attack
“Dig up his body,” say creditors of deceased cryptocurrency player
Stolen: Unencrypted hard drives with data of 29,000 Facebook employees
Your workmates might still be reading that ‘unshared’ Slack document
Linux: An OS Capable of Effectively Meeting the US Government’s Security Needs Heading into 2020>
Chinese e-commerce site LightInTheBox.com bared 1.3TB of server logs, user data and more

An update that solves 9 vulnerabilities and has one errata is now available.

Plundervolt – stealing secrets by starving your computer of voltage
Police get “unprecedented” data haul from Google with geofence warrants
Npm patches two serious bugs
Google adds Verified SMS and anti-spam feature to Messages app
Emotion-detection in AI should be regulated, AI Now says

Two vulnerabilities were discovered in spamassassin, a Perl-based spam filter using text analysis. CVE-2018-11805

VMware warning, OpenBSD gimme-root hole again, telco hit with GDPR fine, Ring camera hijackings, and more

An update for openshift-enterprise-console-container is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openshift-external-storage is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

How safe is business data stored in third-party supplier websites?

security update

security update

security update

An update that contains security fixes can now be installed.

Multiple security issues have been found in Thunderbird which could potentially result in the execution of arbitrary code. For the oldstable distribution (stretch), these problems have been fixed

Popular forms of cybercrime you should be aware of