Menu

Monthly Archives: February 2020

Page Speed Optimization Best Practices
KidsGuard stalkerware leaks data on secretly surveilled victims
Samsung cops to data breach after unsolicited ‘1/1’ Find my Mobile push notification

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 5 vulnerabilities is now available.

It was discovered that the jQuery version embedded in OTRS, a ticket request system, was prone to a cross site scripting vulnerability in jQuery.extend().

Google purges 600 Android apps for “disruptive” pop-up ads
Apple chops Safari’s TLS certificate validity down to one year

libapache2-mod-auth-mellon could be made to redirect users to malicious sites.

libpam-radius-auth could be made to crash if it received specially crafted network traffic.

Do I need a VPN? A simple explanation & some real-life uses
Is your phone listening to you?

Do social media listen in on our conversations in order to target us with ads? Or are we just a bit paranoid? A little test might speak a thousand words. The post Is your phone listening to you? appeared first on WeLiveSecurity

An update that fixes 6 vulnerabilities is now available.

Google rolls out Titan keys to Europe, Japan. Plus: Group Policy bug is a feature, not a flaw, says Microsoft

security update

security update

Resolves: #1795838, #1802904 – Security fix for CVE-2020-8945

* Always use a light theme for rendering form controls. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-3862, CVE-2020-3864, CVE-2020-3865, CVE-2020-3867, CVE-2020-3868

Add patch for CVE-2020-6750 and related issues.

Update to 10.19.0

Update to 10.19.0

Update to Node.js 12.5.0

A vulnerability was found in pam_radius: the password length check was done incorrectly in the add_password() function in pam_radius_auth.c, resulting in a stack based buffer overflow.

Federal Agency that maintains secure communication for Trump got hacked

Ilja Van Sprundel reported a logic flaw in the Extensible Authentication Protocol (EAP) packet parser in the Point-to-Point Protocol Daemon (pppd). An unauthenticated attacker can take advantage of this flaw to trigger a stack-based buffer overflow, leading to denial of service

security update

Lawsuit Claims Google Collects Minors’ Locations, Browsing History
Active Attacks Target Popular Duplicator WordPress Plugin
Duped into running bogus virus scans at Office Depot? Dry your eyes with a small check from $35m settlement

– New upstream release (73.0.1)

This update backports a patch for CVE-2020-8112.

This update backports a patch for CVE-2020-8112.

ISS World “malware attack” leaves employees offline

Backport patches for CVE-2020-5313, CVE-2020-5312, CVE-2020-5311, CVE-2020-5310, CVE-2019-19911

Google kicks out 600 malicious apps from Play Store

An update for python-pillow is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for systemd is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The Amazon Prime phishing attack that wasn’t…
RSAC 2020: Editors’ Preview of Hottest Sessions, Speakers and Themes
Burning Man Tickets for $225? Yep, Too Good to Be True
Private details of 10.7 million MGM Hotel guests sold on Dark Web
ISS World Hit with Malware Attack that Shuts Down Global Computer Network

An update that solves one vulnerability and has 10 fixes is now available.

An update that fixes four vulnerabilities is now available.

Larry Tesler, of copy-and-paste fame, dies at 74
US and UK call out Russian hackers for Georgia attacks
Data of 10.6m MGM hotel guests posted for sale on Dark Web forum
Haken Malware Family Infests Google Play Store
Adobe fixes critical flaws in Media Encoder and After Effects
Washington state Senate passes bill to rein in facial recognition
‘Don’t tell anyone but I have a secret.’ There, that’s my security sorted
ToTok chat app tells users to ignore Google’s spyware warning
Google exiles 600 apps from Play Store for ‘disruptive advertising’ amid push to clean up Android souk’s image
Apple drops a bomb on long-life HTTPS certificates: Safari to snub new security certs valid for more than 13 months
Stuffing nonsense: Persistent cyberpunks are pummelling banks’ public APIs, warns Akamai
Google Bans 600 Android Apps for Obnoxious Ads
RSA Conference loses one more abbreviated tech giant after AT&T disconnects over Wuhan coronavirus fears

New proftpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Researchers recovered 9 billion email & password combos in 2019
We know what you did last summer: MGM’s hotel spinoff lost 10.7m guest records and now they’re on hacker forums
Critical Cisco Bug Opens Software Licencing Manager to Remote Attack
Cybergang Favors G Suite and Physical Checks For BEC Attacks
MGM Resorts data breach exposes details of 10.6 million guests

A number of celebrities, government officials and tech CEOs were also caught up in the incident The post MGM Resorts data breach exposes details of 10.6 million guests appeared first on WeLiveSecurity

GRU won’t believe it: UK and US call out Russia for cyber-attacks on Georgia last year
Ransomware attack forces 2-day shutdown of natural gas pipeline
Keen to check for ‘abnormal’ user behaviours? Microsoft talks insider risk, AWS imports and compliance at infosec shindig RSA
Nearly half of hospital Windows systems still vulnerable to RDP bugs
Popular YouTube gaming channel hacked to run crypto scam
Critical Adobe Flaws Fixed in Out-of-Band Update

An update that fixes 6 vulnerabilities is now available.

Smashing Security #166: What the Dickens! Ad ban thank you scam
MGM Resorts hacked: 10.6 million guests have their personal data exposed on hacking forum
Samsung freaks out smartphone owners with mysterious ‘1’ notification
MGM Grand Breach Leaked Details of 10.6 Million Guests Last Summer
Firefox 73.0.1 fixes crashes, blank web pages and DRM niggles

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0550

Linux and malware: Should you worry?

Malicious code is nothing to worry about on Linux, right? Hold your penguins. How Linux malware has gone from the sidelines to the headlines. The post Linux and malware: Should you worry? appeared first on WeLiveSecurity

Several security issues were fixed in Squid.

ppp could be made to crash or run programs if it received specially crafted network traffic.

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Ring makes 2FA mandatory to keep hackers out of your doorbell account
Samsung will be Putin dreaded Kremlin-approved shovelware on its phones, claims Russia
Oi, Cisco! Who left the ‘high privilege’ login for Smart Software Manager just sitting out in the open?
U.S. Pipeline Disrupted by Ransomware Attack
Assange lawyer: Trump offered WikiLeaker a pardon in exchange for denying Russia hacked Democrats’ email
BlueKeep Flaw Plagues Outdated Connected Medical Devices

security update

When the air gap is the space between the ears: A natural gas plant let ransomware spread from office IT to ops
US Natural Gas-Compression facility cripples after ransomware attack
Don’t use natwest.co.uk for online banking, Natwest bank tells baffled customer
SMS Attack Spreads Emotet, Steals Bank Credentials
Hamas Ensnares Israeli Soldiers with Pretty ‘Ladies’
Hackers clone ProtonVPN website to drop password stealer malware
Cynet Offers Free Threat Assessment for Mid-Sized and Large Organizations

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Latest Tax Scams Target Apps and Tax-Prep Websites
Private photos leaked by PhotoSquared’s unsecured cloud storage