Menu

Monthly Archives: January 2020

Fleeceware is back in Google Play – massive fees for not much at all
Adobe Patches Five Critical Illustrator CC Flaws
Boing Boing bounces back after hack attempted to infect users with fake Adobe Flash update
5 cyber tools your business needs in 2020 to keep safe

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Apple Denies FBI Request to Unlock Shooter’s iPhone—Again

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0086

27% of Windows users are still running Windows 7. They need to stop now
‘Cable Haunt’ vulnerability exposes 200 million cable modem users
Google tests biometric authentication for Android autofill
Lottery hacker gets 9 months for his £5 cut of the loot

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

Microsoft now reviewing Skype audio in ‘secure’ places (not China)
Windows 7 end of life: Time to move on

Today, Microsoft is officially pulling the plug on its support for Windows 7. What’s your plan? The post Windows 7 end of life: Time to move on appeared first on WeLiveSecurity

Several security issues were fixed in SDL_image.

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in gThumb and Pix

Relying on AT&T, Verizon and T-Mob US to protect you from SIM swapping? You better get used to disappointment
Scammers Dupe Texas School District Out of $2.3M
Joker Android Malware Snowballs on Google Play
Someone needs to go back to school: Texas district fleeced for $2.3m after staff fall for devious phishing email
CES Surveillance Hype Worries Privacy Advocates
Privacy activists beg Google to ban un-removable bloatware from Android
New Android malware on Play Store disables Play Protect to evade detection
5 major US wireless carriers vulnerable to SIM swapping attacks

When it comes to protection against this insidious type of scam, the telcos’ authentication procedures leave a lot be desired, a study finds The post 5 major US wireless carriers vulnerable to SIM swapping attacks appeared first on WeLiveSecurity

‘Cable Haunt’ Bug Plagues Millions of Home Modems
Unpatched Citrix Flaw Now Has PoC Exploits
Travelex wants you to know that everything’s going really really well
Man who hacked National Lottery for just £5 is jailed for nine months
Cable Haunt: Hundreds of millions of cable modems may be vulnerable to hijacking attack
Whirlybird-driving infosec boss fined after ranty Blackpool Airport air traffic control antics
Snake alert! This ransomware is not a game…
Powerful GPG collision attack spells the end for SHA-1

An update that solves one vulnerability and has 10 fixes is now available.

An update that fixes one vulnerability is now available.

Updated makepasswd fix insecure default length of password By default, makepasswd generates password with a length between 6 to 8 characters (48 to 64bits). This update raise the default to 16 characters (128 bits).

GraphicsMagick has been updated to fix security issues. References: – https://bugs.mageia.org/show_bug.cgi?id=26056 – http://www.graphicsmagick.org/NEWS.html#december-24-2019

This update is based on upstream 5.4.10 and fixes atleast the following security issues: ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE)

Updated unbound package to version 1.9.6 to fix various potential security vulnerabilities. References: – https://bugs.mageia.org/show_bug.cgi?id=25974

Shitrix: Hackers target unpatched Citrix systems over weekend
Personal data of millions of Americans exposed from PC in China
Reddit bans ‘impersonation,’ but satire and parody are still OK
Google urged to tame privacy-killing Android bloatware
Lawmakers look to spread COPPA out to cover kids up to 16
UK data watchdog kicks £280m British Airways and Marriott GDPR fines into legal long grass
If you haven’t shored up that Citrix hole, you were probably hacked over the weekend: Exploit code now available

An update that fixes four vulnerabilities is now available.

Fixes bugzilla 1126076

Update to v1.15.7 (CVE-2018-1002102 kubernetes: improper validation of URL redirection in the Kubernetes API server allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints)

New bugfix and security upstream release, see http://www.graphicsmagick.org/NEWS.html#december-24-2019

1.5.7, fix for CVE-2019-13107

Release of 19.05.5. Closes security issues CVE-2019-19727, CVE-2019-19728.

Google hackers successfully use remote exploit to hack iPhone

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

Hundreds of millions of Broadcom-based cable modems at risk of remote hijacking, eggheads fear

security update

Getting a VPN in Japan

New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

Cisco Webex Bug Allows Remote Code Execution
Lifeline Assistance Phone Users Targeted with ‘Uninstallable’ Adware
Graham Cluley on the Totally Unprepared Politics podcast
Is the Y2K bug alive after all?
Amazon Ring fired staff for snooping on customers’ security videos
Hackers using Drake’s kiki do you love me to drop Lokibot malware
National Lottery Sentry MBA hacker given nine months in jail after swiping just £5

An update that fixes 7 vulnerabilities is now available.

An update that solves one vulnerability and has three fixes is now available.

Reading Time: ~ 2 min. Snake Ransomware Slithers Through Networks A new ransomware variant, dubbed “Snake,” has been found using more sophisticated obfuscation while targeting entire networks, rather than only one machine. In addition, Snake will append any encrypted file extensions with five random characters following the filetype itself. Finally, the infection also modifies a […]

Oil-and-Gas APT Pivots to U.S. Power Plants
Just one month later, the Currys PC World/Dixons Travel hack would have cost them a heck of a lot more
Hackers use system weakness to rattle doors on Citrix systems
Ransomware pounces on California schools, Las Vegas trounces attack

An update that solves one vulnerability and has 5 fixes is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Fake-review purge: Facebook boots 188 groups, eBay bans 140 shills
Ding-dong: Cisco delivers your Patch Tuesday warm-up with WebEx, IOS fixes for a few irritating security holes
Cryptojacked routers reduce by 78% in SE Asia following Operation Goldfish Alpha
Google scolded for depriving the poor of privacy after Chinese malware bundled on phones for hard-up Americans
SideWinder hackers hit Android users with malware apps on Play Store
Why is a 22GB database containing 56 million US folks’ personal details sitting on the open internet using a Chinese IP address? Seriously, why?
Exploit Fully Breaks SHA-1, Lowers the Attack Bar
Dixons fined £500,000 by ICO for crap security that exposed 5.6 million customers’ payment cards
4 Ring Employees Fired For Spying on Customers
Stop everything. Update Firefox now
California’s Tough New Privacy Law and Its Biggest Challenges
Man jailed for using webcam RAT to spy on women in their bedrooms
Browser zero day: Update your Firefox right now!

An update that solves 9 vulnerabilities and has one errata is now available.

It was found that sa-exim, the SpamAssassin filter for Exim, allows attackers to execute arbitrary code if users are allowed to run custom rules. A similar issue was fixed in spamassassin, CVE-2018-11805, which caused a functional regression in sa-exim. This update restores the

Mozilla rushes out patch for Firefox zero‑day

The US cybersecurity agency warns that the critical vulnerability could allow attackers to take control of people’s computers The post Mozilla rushes out patch for Firefox zero‑day appeared first on WeLiveSecurity

Apple’s scanning iCloud photos for child abuse images
Google voice Assistant gets new privacy ‘undo’ commands
FBI asks Apple to help it unlock iPhones of naval base shooter
Google’s Project Zero highlights patch quality with policy tweak
TrickBot Adds Custom, Stealthy Backdoor to its Arsenal

An update that fixes one vulnerability is now available.

An update that fixes 11 vulnerabilities is now available.