Menu

Monthly Archives: January 2020

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Smashing Security #160: SNAFUs! MS Word, Amazon Ring, and TikTok

security update

Drake Lyrics Used as Calling Card in Malware Attack
Hash snag: Security shamans shame SHA-1 standard, confirm crucial collisions citing circa $45k chip cost
In a desperate bid to stay relevant in 2020’s geopolitical upheaval, N. Korea upgrades its Apple Jeus macOS malware

security update

Man Sentenced in ATM Skimming Conspiracy
Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy
Why small business corporations fall easy prey to hackers
CES – Taking a smart city for a test drive

No one has a road map for securing a connected city – but there should be a whole atlas of such maps The post CES – Taking a smart city for a test drive appeared first on WeLiveSecurity

Liverpool Voyeur Used IM-RAT to Video Women at Home
Mozilla Updates Firefox Browser: Zero-Day Bug Patched, Fingerprinting Nixed
TikTok on the clock, and the hacking won’t stop: SMS spoofing vuln let baddies twiddle teens’ social media videos
TikTok vulnerability allowed hackers to send SMS with malware
TikTok Riddled With Security Flaws
Get Ready for the Microsoft Windows 7 EOL on January 14th
City of Las Vegas wakes up to a cyber attack

An update that solves 9 vulnerabilities and has two fixes is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes 11 vulnerabilities is now available.

REvil ransomware exploiting VPN flaws made public last April
YouTube to treat all kid-aimed videos like they’re COPPA-liable
US warns of Iranian cyber threat

The package firefox before version 72.0-1 is vulnerable to multiple issues including arbitrary code execution, insufficient validation, access restriction bypass and denial of service.

Facebook bans deepfakes, but not cheapfakes or shallowfakes
What if everyone just said ‘Nah’ to tracking?
“Planned maintenance”? Travelex’s masterclass in how not to respond to a cyberattack

ClamAV could be made to crash if it opened a specially crafted file.

Several security issues were fixed in the kernel.

The Six Million Dollar Scam: London cops probe Travelex cyber-ransacking amid reports of £m ransomware demand, wide-open VPN server holes
If at first you don’t succeed, pry, pry again: Feds once again demand Apple unlock encrypted iPhones in yet another terrorism case

security update

That Pulse Secure VPN you’re using to protect your data? Better get it patched – or it’s going to be ransomware time
Google Fixes Critical Android RCE Flaw
Yeah, says Google Project Zero, when you think about it, going public with exploit deets immediately after a patch is emitted isn’t such a great idea
Encryption: An Essential Yet Highly Controversial Component of Digital Security>
Sodinokibi Ransomware Behind Travelex Fiasco: Report
Accenture pays for CSS injection from Symantec parent Broadcom: Yep, it bought its cybersecurity arm
Hackers steal sensitive data from Japanese search engine for sex hotels
Facebook bans deepfakes but not all altered content

Footage defined as parody or satire will be permitted, as the social network isn’t slamming the door on all types of manipulated media The post Facebook bans deepfakes but not all altered content appeared first on WeLiveSecurity

FBI Taps Apple to Unlock Pensacola Shooter’s iPhone
Facebook Cracks Down on Deepfake Videos
Wheelie bad end to 2019 for Canyon Bicycles as hackers puncture IT systems

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 17 vulnerabilities is now available.

An update that fixes 16 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Google suspends Xiaomi from Home Hub over camera privacy glitch
‘Maze’ ransomware threatens data exposure unless $6m ransom paid
I’m the queen of Gibraltar and will never get a traffic ticket… just two of the things anyone could have written into country’s laws thanks to unsanitised SQL input vuln
IT exec sets up fake biz to scam his employer out of $6m
US military branches ban TikTok following Pentagon’s warning

An update that fixes four vulnerabilities is now available.

Here we go again: Software nasties slip into Google Play, exploit make-me-root Android flaw for maximum pwnage
ToTok Returned to Google Play Despite ‘Spy Tool’ Claims
Magecart Hits Parents and Students via Blue Bear Attack
Cyber-warnings, cyber-speculation over cyber-Iran’s cyber-retaliation cyber-plans post-Soleimani assassination

Risk Level: Very Low. Type: Trojan.

DeathRansom Campaign Linked to Malware Cornucopia
Don’t fall for the “Start your 2020 with a gift from us” scam…
GCHQ: A cyber-what-now? Rumours of our probe into London Stock Exchange ‘cyberattack’ have been greatly exaggerated
Hackers Deface U.S. Gov Website With Pro-Iran Messages

It was discovered that there were three vulnerabilities in Pillow, an imaging library for the Python programming language: * CVE-2019-19911: Prevent a denial-of-service vulnerability caused

Download AV-Comparatives real-world test into how well different security products defend against APTs
Monday review – the hot stories of the holidays
Company held hostage by ransomware shuts down, tells 300 employees to find new jobs
Travelex still offline after discovering malware on New Year’s Eve, and other banks’ currency services are also affected
Tune in this month: What every small-to-medium biz can do to fend off cyber-crooks

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Rowhammer rides again as FPGA attack, RSA again reportedly up for sale, anti-theft kit to nuke laptops, etc
Iranian hackers deface US government & African bank website

Updated compat-openssl10 and openssl packages fix security vulnerability: There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536,

Updated dia package fixes security vulnerability: An endless loop on filenames with invalid encoding (CVE-2019-19451). References:

Updated mediawiki packages fix security vulnerability: MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1

The updated packages fix a security vulnerability: xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. (CVE-2019-19956)

The updated packages fix security vulnerabilities: When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy occurs in which the destination address and the size of the copied data are not considered,

Updated jss packages fix security vulnerability: A flaw was found in the “Leaf and Chain” OCSP policy implementation in JSS CryptoManager, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly

Authorities lost track of suspect after WhatsApp hacking warning

Update to NetHack 3.6.4 – fixes security issue with privilege escalation: http://nethack.org/security/index.html

**PHP version 7.3.13** (18 Dec 2019) **Bcmath:** * Fixed bug php#78878 (Buffer underflow in bc_shift_addsub). (**CVE-2019-11046**). (cmb) **Core:** * Fixed bug php#78862 (link() silently truncates after a null byte on Windows). (**CVE-2019-11044**). (cmb) * Fixed bug php#78863 (DirectoryIterator class silently truncates after a null byte). (**CVE-2019-11045**). (cmb) * Fixed bug

denial of service in find_next_bit() [XSA-307, CVE-2019-19581, CVE-2019-19582] (#1782211) denial of service in HVM/PVH guest userspace code [XSA-308, CVE-2019-19583] (#1782206) privilege escalation due to malicious PV guest [XSA-309, CVE-2019-19578] (#1782210) Further issues with restartable PV type change operations [XSA-310, CVE-2019-19580] (#1782207) vulnerability in dynamic

Update to version 0.9.3 to address CVE-2019-14889

Update to Samba 4.10.11, Security fixes for CVE-2019-14861 and CVE-2019-14870

IT exec sets up fake biz, uses it to bill his bosses $6m for phantom gear, gets caught by Microsoft Word metadata
New year, new critical Cisco patches to install – this time for a dirty dozen of bugs that can be exploited to sidestep auth, inject commands, etc
BusKill USB cable switches off your laptop in the event of theft
Ransomware Attack Topples Telemarketing Firm, Leaving Hundreds Jobless

Reading Time: ~ 2 min. US Coast Guard Facility Hit with Ransomware During the last week of December a US Coast Guard facility was the target of a Ryuk ransomware attack that shut down operations for over 30 hours. Though the Coast Guard has implemented multiple cybersecurity regulations in just the last six months or […]

3 Critical Bugs Allow Remote Attacks on Cisco NX-OS and Switches
TikTok boom: US Army bans squaddies from using trendy app on govt-issued phones
Cybercriminals Fill Up on Gas Pump Transaction Scams Ahead of Oct. Deadline
Cryptocurrency exchange Poloniex issues password reset warning
Travelex Knocked Offline by System-Wide Malware Attack
Brit banking sector hasn’t gone a single day of 2020 without something breaking
Google Boots Security Camera Maker From Nest Hub After Private Images Go Public