Menu

Monthly Archives: January 2020

1 in 10 Macs hit by crude malware that poses as Flash Player update, reports Kaspersky

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Libgcrypt could be made to expose sensitive information.

The duke of URL: Zoom meetups’ info leaked out through eavesdrop hole
LoRaWAN Encryption Keys Easy to Crack, Jeopardizing Security of IoT Networks

OpenJPEG had a heap-based buffer overflow in opj_t1_clbl_decode_processor in libopenjp2.so.

Windows 7 definitely won’t ever receive any more bug fixes (errm… apart from this one for its wallpaper)
States sue over rules that allow release of 3D-printed gun blueprints
Zoom Fixes Flaw Opening Meetings to Hackers
Facial recognition firm sued for scraping 3 billion faceprints
Cisco patches bugs in security admin center and Webex
Mozilla bans Firefox extensions for executing remote code
How to take charge of your Google privacy settings

Have you had a Google Privacy Checkup lately? If not, when better than Data Privacy Day to audit the privacy of your Google account? The post How to take charge of your Google privacy settings appeared first on WeLiveSecurity

An update that fixes three vulnerabilities is now available.

16 NFL teams have their social media accounts hijacked by OurMine hacking gang

An update for openjpeg2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

NetWars! Let the SANS Tournaments commence: Compete and learn all about forensics, incident response, red teaming – and much more
Remember the Clipper chip? NSA’s botched backdoor-for-Feds from 1993 still influences today’s encryption debates
Google, Mozilla Ban Hundreds of Browser Extensions in Chrome, Firefox
Google halts paid-for Chrome extension updates amid fraud surge: Web Store in lockdown ‘due to the scale of abuse’
As Necurs Botnet Falls from Grace, Emotet Rises
Maryland: Make malware possession a crime! Yes, yes, researchers get a free pass
N.Y. Could Ban Cities from Paying Ransomware Attackers
Job hunting? Beware hiring scams using spoofed company websites

Cybercriminals are putting a new twist on an old trick The post Job hunting? Beware hiring scams using spoofed company websites appeared first on WeLiveSecurity

Nasty old Android malware with new capabilities gets difficult to remove
A Magecart hacking gang may have been caught by police for the first ever time
Cisco Webex bug allowed anyone to join a password-protected meeting
Cardplanet mastermind pleads guilty to credit card fraud
Mandatory IoT Security in the Offing with U.K. Proposal
Tinder to get panic button, catfish-fighting facial recognition
Microsoft’s Internet Explorer zero-day workaround is breaking printers
Instagram CEO’s homes were targetted by SWATters
Rent out the best properties online in India with these tips

Several security issues were fixed in tcpdump.

Several security issues were fixed in Tomcat.

Several security issues were fixed in MySQL.

New York wants to ban taxpayer-funded ransomware payments

An update for nss is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This update fixes CVE-2019-20093.

This update fixes CVE-2019-20093.

Trend Micro anti-virus zero-day exploited in attack on Mitsubishi Electric
Webex flaw allowed anyone to join private online meetings – no password required
Watch out for Shlayer malware targeting Mac devices

An update that fixes 5 vulnerabilities is now available.

This update fixes CVE-2019-20093.

This update fixes CVE-2019-20093.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Teenagers today. Can’t take them anywhere, eh? 18-year-old kid accused of $50m SIM-swap cryptocurrency heist

– Security fix for CVE-2019-19746, CVE-2019-19797 – New upstream release 3.2.7b – Add patch fixing CVE-2019-19746 (rhbz#1787040) – Add patch fixing CVE-2019-19797 (rhbz#1786726)

– Security fix for CVE-2019-19746, CVE-2019-19797 – New upstream release 3.2.7b – Add patch fixing CVE-2019-19746 (rhbz#1787040) – Add patch fixing CVE-2019-19797 (rhbz#1786726)

** MySQL 8.0.19 ** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-19.html

Security fix for CVE-2020-5395:out-of-bounds write in sfd.c

ThreatList: Ransomware Costs Double in Q4, Sodinokibi Dominates
Netgear vulnerability exposed TLS certificates to public

security update

The importance of protecting your devices from cyber attack
Cisco Webex Flaw Lets Unauthenticated Users Join Private Online Meetings
New Bill Proposes NSA Surveillance Reforms
2015-member database floats off through breach in Royal Yachting Association’s hull
Google finds privacy holes in Safari’s ITP anti-tracking system
We’re dung for! Hackers hit firms with ransomware by exploiting Shitrix flaw
Want your photo removed from our facial recognition database? Just send us your photo and government-issued ID…
Fake Smart Factory Honeypot Highlights New Attack Threats
Sonos backtracks (a little) over its software updates fustercluck

An update that fixes 7 vulnerabilities is now available.

Whoops! LastPass accidentally deleted its browser extension from the Chrome store. But it’s back now

update to enigmail 2.1.5 Includes a security fix for “Unsigned MIME parts displayed as signed”

Update to 12.14.1 Add new subpackage `nodejs-full-i18n` to provide non-English locale and Unicode support.

Update to 12.14.1 Add new subpackage `nodejs-full-i18n` to provide non-English locale and Unicode support.

New upstream release with security fixes for CVE-2019-15945, CVE-2019-15946, CVE-2019-19479, CVE-2019-19480, CVE-2019-19481

Protestors petition equity firm over .org buyout
9th Methbot suspect arrested in massive clickfraud ring

An update that solves three vulnerabilities and has one errata is now available.

Privacy watchdog throws wider net to protect children online
Russian super-crook behind $20m internet fraud den Cardplanet and malware-exchange forum pleads guilty

Reading Time: ~ 2 min. Point-of-Sale Breach Targets U.S. Cannabis Industry Late last month, researchers discovered a database owned by the company THSuite that appeared to contain information belonging to roughly 30,000 cannabis customers in the U.S. With no authentication, the researchers were able to find contact information as well as cannabis purchase receipts, including […]

Study shows prominent apps are selling your data to 3rd parties
Critical, Unpatched ‘MDhex’ Bugs Threaten Hospital Devices
U.S. Gov Agency Targeted With Malware-Laced Emails
Shlayer, No. 1 Threat for Mac, Targets YouTube, Wikipedia
Did Saudi Crown Prince use Israeli spyware to hack Jeff Bezos’s iPhone?
Ransomware: The average ransom payment has doubled in just three months
Cisco Warns of Critical Network Security Tool Flaw
Traffic jams could be worse than normal, because of the Shitrix vulnerability
We need to make it even easier for UK terror cops to rummage about in folks’ phones, says govt lawyer
Looking for silver linings in the CVE-2020-0601 crypto vulnerability
Ooh, watch out Google. You’ve got competition. Verizon has a new ‘privacy-focused’ search engine

USN-4233-1 marked SHA1 as untrusted in GnuTLS with no workaround.

Microsoft exposed 250 million customer support records

Databases containing 14 years’ worth of customer support logs were publicly accessible with no password protection The post Microsoft exposed 250 million customer support records appeared first on WeLiveSecurity

Google: Flaws in Apple’s Private-Browsing Technology Allow for Third-Party Tracking

An update for ansible is now available for Ansible Engine 2 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.9 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.8 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.7 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

A free tool for detecting Shitrix-related compromises on your business network
UN report alleges that Saudi crown prince hacked Jeff Bezos’s phone

Several security issues were fixed in python-apt.

Apple allegedly made nice with FBI by dropping iCloud encryption plan