Menu

Monthly Archives: December 2019

Ad industry groups ask that the CCPA keep its mitts off their cookies

An update that fixes three vulnerabilities is now available.

nss: Out-of-bounds write when passing an output buffer smaller than the block size to NSC_EncryptUpdate (CVE-2019-11745) SL6 x86_64 nss-softokn-3.44.0-6.el6_10.i686.rpm nss-softokn-3.44.0-6.el6_10.x86_64.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.i686.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.x86_64.rpm nss-softokn-freebl-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-3 [More…]

nss: Out-of-bounds write when passing an output buffer smaller than the block size to NSC_EncryptUpdate (CVE-2019-11745) * nss: Empty or malformed p256-ECDH public keys may trigger a segmentation fault (CVE-2019-11729) SL7 x86_64 nss-3.44.0-7.el7_7.i686.rpm nss-3.44.0-7.el7_7.x86_64.rpm nss-debuginfo-3.44.0-7.el7_7.i686.rpm nss-debuginfo-3.44.0-7.el7_7.x86_64.rpm nss-so [More…]

Alleged Nigerian social engineer wins free flight to the US for business email fraud and love scams
Cyber attack cripples networks in city of Pensacola days after shooting
It’s the end of the 20-teens, and your Windows PC can still be pwned by nothing more than a simple bad font
Microsoft Zaps Actively Exploited Zero-Day Bug
Americans should have strong privacy-protecting encryption …that the Feds and cops can break, say senators

security update

Type: Vulnerability. Openssl is prone to an integer-overflow vulnerability; fixes are available.

Type: Vulnerability. Zoho Applications Manager Plugin is prone to an SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Zoho Applications Manager Plugin is prone to a remote command-execution vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.

Type: Vulnerability. Symantec Industrial Control System Protection is prone to an unauthorized access vulnerability; fixes are available.

Cyberattack Downs Pensacola’s City Systems
Intel might want to reconsider the G part of SGX – because it’s been plunderstruck
Snatch Team Steals Data and Hammers Orgs with Ransomware
Adobe Fixes 17 Critical Acrobat, Photoshop and Brackets Flaws
Don’t pay off Ryuk ransomware, warn infoseccers: Its creators borked the decryptor
Amazon’s Blink Smart Security Cameras Open to Hijack
Download: The 2020 Cybersecurity Salary Survey Results
Data leak exposes 750,000 birth certificate applications

A variety of sensitive information has been there for the taking due to an unsecured cloud storage container The post Data leak exposes 750,000 birth certificate applications appeared first on WeLiveSecurity

20 years prison for Romanian hackers who infected 400,000 computers
Snatch ransomware reboots Windows in Safe Mode to bypass anti-virus protection
DHS Rolls Back Facial-Recognition Expansion Plan

It was found that freeimage, a graphics library, was affected by the following two security issues: CVE-2019-12211

Snatch ransomware pwns security using sneaky ‘safe mode’ reboot
EU releases its 5G conclusions

An update for nss, nss-softokn, and nss-util is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

It was found that Squid, a high-performance proxy caching server for web clients, has been affected by the following security vulnerabilities.

SIEMs like a stretch: Elastic searches for cash from IT pros with security budgets
Facebook users were duped by Cambridge Analytica, FTC rules
TikTok settles class action over child privacy one day after it’s filed

An update for sudo is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Cybersecurity Trends 2020: Technology is getting smarter – are we?

With 2019 ending, ESET experts offer their insights into how new innovations will impact our privacy, security and lives in the not so distant future The post Cybersecurity Trends 2020: Technology is getting smarter – are we? appeared first on WeLiveSecurity

An update that solves three vulnerabilities and has one errata is now available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Remote Desktop Protocol is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple information-disclosure vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple arbitrary code-execution vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple arbitrary code-execution vulnerabilities; fixes are available.

Type: Vulnerability. Adobe ColdFusion is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to a heap-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Adobe Photoshop CC is prone to multiple unspecified memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Samba is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. SAP Adaptive Server Enterprise is prone to an unspecified information-disclosure vulnerability; fixes are available.

Type: Vulnerability. SAP BusinessObjects Business Intelligence Platform is prone to an cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. SAP Portfolio and Project Management is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. SAP Enable Now is prone to multiple unspecified security vulnerabilities; fixes are available.

Type: Vulnerability. SAP BusinessObjects Business Intelligence Platform is prone to an unspecified cross-site request-forgery vulnerability; fixes are available.

Advertisers want exemption from web privacy rules that, you know, enforce privacy
Birth Certificate Data Laid Bare on the Web in Multiple States
Serious Security: Understanding how computers count
Romanian Duo Receives Jailtime For Infecting 400,000 With Malware

Type: Vulnerability. Palo Alto Networks PAN-OS is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Dell Command Configure is prone to an arbitrary file-overwrite vulnerability; fixes are available.

Type: Vulnerability. Adobe Stock is prone to remote code-execution vulnerability.

Type: Vulnerability. Multiple QNAP products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Multiple QNAP products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. OpenSLP is prone to a heap-memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Docker is prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Facebook Mcrouter is prone to multiple denial of service vulnerabilities; fixes are available.

Type: Vulnerability. Atlassian Companion is prone to a security-bypass vulnerability.

FBI uses PlayStation to bust large scale drug deal
Elder Scrolls Online Targeted by Cybercrooks Hunting In-Game Loot
Will the new iPhone 11 track you even if you tell it not to?
Fake VPN website delivering password-stealing malware
Ad network ransomware crook to flog £5k Rolex after court confiscates £270k in ill-gotten gains
Hackers steal credit card details from Sweaty Betty customers
GE, Dunkin’, Forever 21 Caught Up in Broad Internal Document Leak
Reddit Says Influence Campaign is Behind Leaked U.S.-U.K. Trade Documents
Metasploit for drones? Best of luck with that, muses veteran tinkerer

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

Networking attack gives hijackers VPN access
HackerOne pays $20,000 bounty after breach of own systems
Facebook suing ILikeAd for hijacking users’ ad accounts
$5m bounty set on the alleged head of Evil Corp banking Trojan group
5 scam prevention tips for seniors

How can people who didn’t grow up with technology protect themselves against some of the most common types of online fraud? The post 5 scam prevention tips for seniors appeared first on WeLiveSecurity

A security update is now available for Open Liberty 19.0.0.12 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

NSS could be made to crash if it received a specially crafted certificate.

An update for nss is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

security update

Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, information disclosure or the execution of arbitrary code.