Menu

Monthly Archives: December 2019

Two vulnerabilities were discovered in spamassassin, a Perl-based spam filter using text analysis. CVE-2018-11805

70% of the entire US population is now on Facebook

Multiple cross-site scripting and cross-site request forgery issues were discovered in the DAViCal CalDAV Server.

A vulnerability has been found in php-horde, the Horde Application Framework, which may result in information disclosure via cross-site scripting.

GitLab Doles Out Half a Million Bucks to White Hats
Valuable personal info leaks from Facebook – not Zuck selling it, unencrypted hard drives of staff data stolen

This update provides an update to 5.4 series kernels, currently based on upstream 5.4.2, adding support for new hardware and features, and fixing atleast the following security issue: KVM: x86: fix out-of-bounds write in KVM_GET_EMULATED_CPUID

Updated ncurses packages fix security vulnerabilities: Heap-based buffer over-read in the _nc_find_entry function (CVE-2019-17594).

Updated signing-party package fixes security vulnerability: The gpg-key2ps tool in signing-party contained an unsafe shell call enabling shell injection via a User ID (CVE-2019-11627).

Pairing Privacy and Security with Digital Identities in Retail

Reading Time: ~ 4 min. The holiday shopping season is prime time for digital purchases and cybercriminals are cashing in on the merriment. With online shopping officially becoming more popular than traditional in-store visits this year, all signs point to an increase in cyberattacks. It’s more important than ever to be mindful of potential dangers […]

Type: Vulnerability. OpenBSD is prone to a local privilege escalation vulnerability; fixes are available.

Type: Vulnerability. Atlassian FishEye and Crucible are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Redhat 3scale API Management is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. McAfee TechCheck is prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. IBM Cloud Pak System is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to an information disclosure vulnerability.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. IBM Spectrum Scale is prone to a cross-site scripting vulnerability; fixes are available.

Elegant sLoad Carries Out Spying, Payload Delivery in BITS
Critical Bug in WordPress Plugins Open Sites to Hacker Takeovers
Hundreds of counterfeit branded shoe stores hacked with web skimmer

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Risk Level: Very Low. Type: Trojan.

FIN8 Targets Card Data at Fuel Pumps

Reading Time: ~ 2 min. Zeppelin Ransomware Spreading Over the last month, researchers have been monitoring the spread of a new ransomware variant, Zeppelin. This is the latest version of the ransomware-as-a-service that started life as VegaLocker/Buran and has differentiated itself by focusing on healthcare and IT organizations in both the U.S. and Europe. This […]

Facebook will target ads based on your Oculus VR data
YouTube bans malicious insults, veiled threats, harassment
Jack Dorsey wants a decentralised Twitter
Weak account checks earn company $10.5 million privacy fine
RHEL package updates and live kernel patching with Red Hat Satellite
Ever wonder how hackers could possibly pwn power plants? Here are 54 Siemens bugs that could explain things
NPM swats path traversal bug that lets evil packages modify, steal files. That’s bad for JavaScript crypto-wallets
NGINX office in Moscow raided by police

Type: Vulnerability. Atlassian FishEye and Crucible are prone to an unauthorized-access vulnerability; fixes are available.

Critical Remote Code-Execution Bugs Threaten Global Power Plants
How to identify malware on your phone with these 7 signs

– update to upstream version 4.3.0 – fixes CVE-2019-19331 – root.keys is moved to /var/lib/knot-resolver – knot-resolver no longer requires write permission to /etc/knot-resolver/

Device quarantine for alternate pci assignment methods [XSA-306]

– update to upstream version 4.3.0 – fixes CVE-2019-19331 – root.keys is moved to /var/lib/knot-resolver – knot-resolver no longer requires write permission to /etc/knot-resolver/

Type: Vulnerability. Webform Module of Drupal is prone to multiple vulnerabilities; fixes are available.

Type: Vulnerability. OpenStack Keystone is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Siemens SCALANCE W700 and W1700 is prone to an information disclosure vulnerability; fixes are available.

An update is now available for CloudForms Management Engine 5.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

All in the (Ransomware) Family: 10 Ways to Take Action
Iran says it staved off cyber attack but doesn’t blame US

This update upgrades Thunderbird to version 68.3.0. * Mozilla: Use-after-free in worker destruction (CVE-2019-17008) * Mozilla: Memory safety bugs fixed in Firefox 71 and Firefox ESR 68.3 (CVE-2019-17012) * Mozilla: Buffer overflow in plain text serializer (CVE-2019-17005) * Mozilla: Use-after-free when performing device orientation checks (CVE-2019-17010) * Mozilla: Use-after-free when ret [More…]

Red Hat OpenShift Service Mesh 1.0.3. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that fixes 118 vulnerabilities is now available.

RabbitMQ could be made to execute arbitrary code if it received a specially crafted input.

Facebook refuses to break end-to-end encryption
Chrome 79 includes anti-phishing and hacked password protection
Maze Ransomware Behind Pensacola Attack, Data Breach Looms
“The Smartest Lock Ever” KeyWe is Vulnerable to Hacking
Brexit – even cybercriminals want to have their say…
S2 Ep20: Why don’t they send ransomware on floppies anymore?
Waco water bill attack just the latest in a wave of Click2Gov breaches
Your Smart Christmas Lights Are Safer Than They Were Last Year
Disgrace of Base: Scammy hordes force Keybase to end cryptocoin giveaway
Chrome now warns you if your password has been stolen

The browser’s latest version also aims to up the ante in phishing protection The post Chrome now warns you if your password has been stolen appeared first on WeLiveSecurity

It’s time you were T0RTT a lesson: Here’s how you could build a better Tor, say boffins
Retail Cyberattacks Set to Soar 20% in 2019 Holiday Season
December Patch Tuesday blunts WizardOpium attack chain
Apple iOS 13.3 is here, bringing support for keyfobby authentication
Microsoft movie tried to Azure Ignite attendees about CPU side-channel flaws, but biz wouldn’t be drawn on details
LightAnchors array: LEDs in routers, power strips, and more, can sneakily ship data to this smartphone app
You had one job, Cupertino: Apple’s Intelligent Tracking Protection actually gets tracking protection
Smashing Security #158: The man behind The Missing Cryptoqueen
Plundervolt: A new attack on Intel processors threatening SGX data
Smart Krampus-3PC Malware Targets iPhone Users

Update to Samba 4.11.3 – Security fixes for CVE-2019-14861, CVE-2019-14870 —- Restart winbindd on samba-winbind package upgrade

Serious Security Flaws Found in Children’s Connected Toys

security update

Apple Fixes ‘AirDoS’ Bug That Cripples Nearby iPhones, iPads

Type: Vulnerability. WebKit is prone to an arbitrary-code execution vulnerability; fixes are available.

Type: Vulnerability. Broadcom CA Nolio is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Apple iOS and iPadOS are prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Apple iOS and iPadOS are prone to an arbitrary code execution vulnerability; fixes are available.

Type: Vulnerability. Apple Xcode is prone to an arbitrary code-execution vulnerability; fixes are available.

Signal Tests Upgraded Cryptography for Groups Function

Risk Level: Very Low. Type: Virus.

Risk Level: Very Low. Type: Trojan.

Bad news: KeyWe Smart Lock is easily bypassed and can’t be fixed
Modern Intel CPUs Plagued By Plundervolt Attack
2.7 billion email addresses & plain-text passwords exposed online
Web-hosting firm 1&1 hit by almost €10 million GDPR fine over poor security at call centre
Google Chrome will check for breached credentials every time you sign in anywhere
Lazarus APT Collaborates with Trickbot’s Anchor Project

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4152

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4108

Several security issues were fixed in Samba.

Windows 10 Mobile receives its last security patches
DoItForState domain name thief gets 14 years for pistol-whipping plot
49% of workers, when forced to update their password, reuse the same one with just a minor change
FTC warns Christmas buyers that smart toys are a security risk
Beware of bad Santas this Xmas: Piles of insecure smart toys fill retailers’ shelves