Menu

Monthly Archives: February 2020

security update

An update that fixes one vulnerability is now available.

Israeli firm leaks database with addresses of millions of Americans

Updated wireshark packages fix security vulnerabilities: LTE RRC dissector memory leak. WiMax DLMAP dissector crash.

This update is based on upstream 5.5.6 and fixes atleast the following security vulnerability: A flaw was found in the way KVM hypervisor handled instruction emulation for the L2 guest when nested(=1) virtualization is enabled. In the

Updated hiredis packages fix security vulnerability: async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked (CVE-2020-7105).

Updated rsync packages fix security vulnerabilities: It was discovered that rsync incorrectly handled pointer arithmetic in zlib. An attacker could use this issue to cause rsync to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2016-9840,

Updated zsh packages fix security vulnerability: A privilege escalation vulnerability was discovered in zsh, whereby a user could regain a formerly elevated privelege level even when such an action should not be permitted (CVE-2019-20044).

The package chromium before version 80.0.3987.122-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

Bruce Schneier Proposes ‘Hacking Society’ for a Better Tomorrow
Hackers leak up to 4 TB of OnlyFans content for download

It was discovered that libusbmuxd incorrectly handled socket permissions. A remote attacker could use this issue to access services on iOS devices, contrary to expectations.

Beware secret lovers spreading Nemty ransomware
Israeli firm leaks addresses of millions of Americans & Europeans
Southern Water not such a phisherman’s phriend, hauls itself offline to tackle email lure
RSAC 2020: Ransomware a ‘National Crisis,’ CISA Says, Ramps ICS Focus
Patrick Wardle: Apple Devices Hit With Recycled macOS Malware
“Shark Tank” TV star loses almost $400,000 in Business Email Compromise scam
Clearview AI loses entire database of faceprint-buying clients to hackers
Ransomware wipes evidence, lets suspected drug dealers walk free
Firefox rolling out DNS-over-HTTPS privacy by default in the US
Google has right to censor conservative nonprofit on YouTube

An update that fixes 5 vulnerabilities is now available.

An update that solves 9 vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Your phone wakes up. Its assistant starts reading out your text messages. To everyone around. You panic. How? Ultrasonic waves
Police lose evidence to Ryuk ransomware attack; suspects walk free
Google’s War on Android App Permissions, 60 Percent Successful
RSAC 2020: GM’s Transportation Future Hinges on Cybersecurity

security update

security update

kr00k – Billions of Wi-Fi devices affected by encryption vulnerability

An uninitialized pointer vulnerability was discovered in pure-ftpd, a secure and efficient FTP server, which could result in an out-of-bounds memory read and potential information disclosure.

Cyber-wrath of Iran for top general’s assassination hasn’t progressed beyond snooping and nicking logins… yet
Clearview AI firm with photos of billions of unsuspecting users got HACKED
How one man could have flooded your phone with Microsoft spam
Facial recognition company Clearview AI hit by data theft

The startup came under scrutiny after it emerged that it had amassed 3 billion photos from social media for facial recognition software The post Facial recognition company Clearview AI hit by data theft appeared first on WeLiveSecurity

IoT Insecurity: When Your Vacuum Turns on You
Slickwraps data breach earns scorn for all
RSA 2020 – Hacking humans

What the human battle against biological viruses can teach us about fighting computer infections – and vice versa The post RSA 2020 – Hacking humans appeared first on WeLiveSecurity

Sophos was gearing up for a private life – then someone remembered the bike scheme
Brave beats other browsers in privacy study
Chrome 80 encryption change blocks AZORult password stealer
Facebook bans coronavirus ‘miracle cure’ ads
Did someone file your taxes before you?

With tax season – and tax scams – in full swing, here’s how fraudsters can steal your tax refund, and how you can avoid becoming a victim The post Did someone file your taxes before you? appeared first on WeLiveSecurity

If you’re serious about browser privacy, you should probably pass on Edge or Yandex, claims Dublin professor
Billions of Devices Open to Wi-Fi Eavesdropping Attacks
RSAC 2020: Smart Baby Monitor Vulnerable to Remote Hackers
HackerOne rewards bughunter who found critical security hole in… HackerOne
Smashing Security #167: Coronavirus scams and an exaggerated lion
Wi-Fi of more than a billion PCs, phones, gadgets can be snooped on. But you’re using HTTPS, SSH, VPNs… right?
Top 10 worst countries for Internet freedom & censorship
After blowing $100m to snoop on Americans’ phone call logs for four years, what did the NSA get? Just one lead
RSAC 2020: Lack of Machine Learning Laws Open Doors To Attacks
Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now
Is bug hunting a viable career choice?

With earnings of top ethical hackers surpassing hundreds of thousands of dollars, some would say yes The post Is bug hunting a viable career choice? appeared first on WeLiveSecurity

Exaggerated Lion and Business Email Compromise – Don’t send that check!
Hackers Cashing In On Healthcare Industry Security Weaknesses
Departing MI5 chief: Break chat app crypto for us, kthxbai
Apple’s iOS pasteboard leaks location data to spy apps
LTE vulnerability allows impersonation of other mobile devices
KrØØk: Serious vulnerability affected encryption of billion+ Wi‑Fi devices

ESET researchers uncover a previously unknown security flaw allowing an adversary to decrypt some wireless network packets transmitted by vulnerable devices The post KrØØk: Serious vulnerability affected encryption of billion+ Wi‑Fi devices appeared first on WeLiveSecurity

Iranian APT Targets Govs With New Malware
Unpatched Security Flaws Open Connected Vacuum to Takeover
Stalkerware Attacks Increased 50 Percent Last Year, Report
Rotherwood Healthcare AWS bucket security fail left elderly patients’ DNR choices freely readable online
Switch to Signal for encrypted messaging, EC tells staff
Taking a GPS tracker off your car isn’t ‘theft,’ court rules

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

It was discovered that pysaml2, a Python implementation of SAML to be used in a WSGI environment, was susceptible to XML signature wrapping attacks, which could result in a bypass of signature verification.

Updated squid packages fix security vulnerabilities: Jeriko One discovered that Squid incorrectly handled memory when connected to an FTP server. A remote attacker could possibly use this issue to obtain sensitive information from Squid memory (CVE-2019-12528).

Mind the gap: Google patches holes in Chrome – exploit already out there for one of them after duo spot code fix
Mystery zero-day in Chrome – update now!
RSAC 2020: Blockchain is ‘Garbage In’, Voting Needs Paper Ballots

security update

Google Patches Chrome Browser Zero-Day Bug, Under Attack
RSAC 2020 Keynote: Changing the World’s False Perception of Cybersecurity
Android 11 to clamp down on background location access
Apple tries to have VirnetX VPN patent ruling overturned again, US Supremes say no… again
Sen. Schumer Pushes for TSA Employee Ban on TikTok App at Work
Free Download: The Ultimate Security Pros’ Checklist
Password killer FIDO2 comes bounding into Azure Active Directory hybrid environments
The “Cloud Snooper” malware that sneaks into your Linux servers

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Microsoft uses its expertise in malware to help with fileless attack detection on Linux

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) Mozilla: Out-of-bounds read when processing certain email messages (CVE-2020-6793) Mozilla: Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords (CVE-2020-6794) Mozilla: Crash processing S/MIME messages with multiple signatures (CVE-2020-6795) Mozilla: Incorrect p [More…]

python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c (CVE-2020-5312) python-pillow: reading specially crafted image files leads to allocation of large amounts of memory and denial of service (CVE-2019-16865) SL7 x86_64 python-pillow-2.0.0-20.gitd1c6db8.el7_7.x86_64.rpm python-pillow-debuginfo-2.0.0-20.gitd1c6db8.el7_7.x86_64.rpm python-pillow- [More…]

Smart speakers mistakenly eavesdrop up to 19 times a day
Google denies illegally slurping data off free student Chromebooks
Apple Takes Heat Over ‘Vulnerable’ iOS Cut-and-Paste Data
Open-Source AI Projects For Linux>
PayPal rejects report that exposed critical account takeover vulnerabilities
Data Breach Occurs at Agency in Charge of Secure White House Communications