Menu

Monthly Archives: January 2020

Sonos’s tone-deaf legacy product policy angers customers
FBI issues warning about lucrative fake job scams
Smashing Security #162: Robocalls, health hacks, and facial recognition fears
Still losing sleep over that awful Citrix bug? This scanner is here to help… you realize you’ve already been pwned
Pwn2Own Miami Contestants Haul in $180K for Hacking ICS Equipment
Who honestly has a crown prince in their threat model? UN report officially fingers Saudi royal as Bezos hacker
Vivin Nets Thousands of Dollars Using Cryptomining Malware
Safari’s Intelligent Tracking Protection is misspelled, says Google: It should be Dumb Browser Stalking Enabler
Owner of DDoS mitigation firm launched DDoS attacks on others

security update

Big Microsoft data breach – 250 million records exposed
Academics call for UK’s Computer Misuse Act 1990 to be reformed
sLoad Malware Revamped as Powerful ‘StarsLord’ Loader
Dating apps share personal data with advertisers, study says

Some of the most popular dating services may be violating GDPR or other privacy laws The post Dating apps share personal data with advertisers, study says appeared first on WeLiveSecurity

Plastic surgery patients at risk after ransomware attack
Microsoft Leaves 250M Customer Service Records Open to the Web
WindiLeaks: Microsoft exposes 250 million customer support records dating back to 2005 (Not on purpose though)
Teenager charged over $50 million SIM-swap cryptocurrency theft
Microsoft data breach exposes 250 million customer service and support records
250 million Microsoft customer support records leaked in plain text

An update that fixes three vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

New Muhstik Botnet Attacks Target Tomato Routers
Ubisoft sues DDoS-for-hire operators for ruining game play
PoC Exploits Do More Good Than Harm: Threatpost Poll
NIST’s new privacy rules – what you need to know
Regus spills data of 900 staff on Trello board set to ‘public’

apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086) SL7 noarch apache-commons-beanutils-1.8.3-15.el7_7.noarch.rpm apache-commons-beanutils-javadoc-1.8.3-15.el7_7.noarch.rpm – Scientific Linux Development Team

Jeff Bezos, WhatsApp, and Mohammed bin Salman – what you need to know
Nobody boogies quite like you
Capita Education Services accidentally spaffs email addresses in Helpdesk snafu

An update that solves 5 vulnerabilities and has one errata is now available.

python-reportlab: code injection in colors.py allows attacker to execute code (CVE-2019-17626) SL6 x86_64 python-reportlab-2.3-3.el6_10.1.x86_64.rpm python-reportlab-debuginfo-2.3-3.el6_10.1.x86_64.rpm i386 python-reportlab-2.3-3.el6_10.1.i686.rpm python-reportlab-debuginfo-2.3-3.el6_10.1.i686.rpm noarch python-reportlab-docs-2.3-3.el6_10.1.noarch.rpm – Scientific L [More…]

Crown Prince of Saudi Arabia accused of hacking Jeff Bezos’ phone with malware-laden WhatsApp message
16Shop Phishing Gang Goes After PayPal Users

security update

security update

No backdoors needed: Apple ditched plans to fully encrypt iCloud backups after heavy pressure from FBI – claim
Citrix Accelerates Patch Rollout For Critical RCE Flaw
Clearview app lets police find your information with just a photo
FTCODE Ransomware Now Steals Chrome, Firefox Credentials
Microsoft Zero-Day Actively Exploited, Patch Forthcoming
WTF, EFS? Experts warn Windows encryption could spawn nasty new ransomware
Citrix ships patches as vulnerable servers come under attack

A security update is now available for Open Liberty 20.0.0.1 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Hacker Leaks More Than 500K Telnet Credentials for IoT Devices
China and US top user data requests in Apple transparency report
Exams cancelled? University closing due to Brexit? A mischievous email from Southampton’s Vice-Chancellor

An update for openvswitch2.12 is now available for Fast Datapath for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

What do online file sharers want with 70,000 Tinder images?

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

3 ways to browse the web anonymously

Are you looking to hide in plain sight? Here’s a rundown of three options for becoming invisible online The post 3 ways to browse the web anonymously appeared first on WeLiveSecurity

Internet-enabled dash cams that allow anyone to track your GPS location in real-time

An update that fixes one vulnerability is now available.

Leave your admin interface’s TLS cert and private key in your router firmware in 2020? Just Netgear things

security update

security update

New sextortion scam claims to record you with hacked Google Nest cam
Citrix emits patches to stop RCE-holes fiddling with Gateway and ADC
Ubisoft sues handful of gamers for DDoSing Rainbow Six: Siege
New Internet Explorer zero‑day remains unpatched

You may want to implement a workaround or stop using the browser altogether, at least until Microsoft issues a a fix The post New Internet Explorer zero‑day remains unpatched appeared first on WeLiveSecurity

Sextortion scam leverages Nest video footage to fool victims into believing they are being spied upon everywhere
LastPass stores passwords so securely, not even its users can access them

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

FBI seizes credentials-for-sale site WeLeakInfo.com
Good news. Citrix delivers first patches to mop up Shitrix flaw that is being actively exploited
FBI to inform election officials about hacking attempts
Teen entered ‘dark rabbit hole of suicidal content’ online
Ubisoft takes DDoS-for-hire website to court over attacks on video game servers
Hospital hacker spared prison after plod find almost 9,000 cardiac images at his home
Facebook and Instagram ban alleged ‘brainwashing’ service
Google Algorithm Updates vs SEO Strategies
These smart contact lenses equip your eyes with augmented reality

Update to Rack 2.0.8.

UFC champ Kamaru Usman says his Twitter account was hacked, after series of explicit tweets against Conor McGregor

In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests

Hackers are closing the Shitrix security hole to keep everyone out of Citrix servers apart from themselves
Microsoft issues Internet Explorer zero-day warning, but there’s no patch yet

Updated wireshark packages fix security vulnerability: BT ATT dissector crash (CVE-2020-7045). References:

Updated suricata packages fix security vulnerabilities: The suricata package has been updated to version 4.1.6, which fixes security issues and other bugs. See the upstream announcements for details.

Updated tigervnc packages fix security vulnerabilities: The tigervnc package has been updated to version 1.10.1 to fix multiple unspecified security issues. These issues affect both the client and server and could theoretically allow an malicious peer to take control over the

security update

Update to 79.0.3945.117. Fixes CVE-2020-6377. —- Security fix for CVE-2019-13767. —- Update to Chromium 79. Fixes the usual giant pile of bugs and security issues. This time, the list is: CVE-2019-13725 CVE-2019-13726 CVE-2019-13727 CVE-2019-13728 CVE-2019-13729 CVE-2019-13730 CVE-2019-13732 CVE-2019-13734 CVE-2019-13735 CVE-2019-13764 CVE-2019-13736 CVE-2019-13737

How Modern Technology is Making Business Life Easier
FBI unlocks iPhone 11 Pro Max using Graykey raising privacy concerns
Protect your identity from fraudster with AI-powered Identity Guard
To catch a thief, go to Google with a geofence warrant – and it will give you all the details

An update that fixes one vulnerability is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0124

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0122

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0122

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0124