Menu

Monthly Archives: February 2020

Facebook asks to be regulated kinda like a newspaper, kinda like telco
WordPress plugin hole could have allowed attackers to wipe websites

An update for rabbitmq-server is now available for Red Hat OpenStack Platform 15 (Stein). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

OpenSSH eases admin hassles with FIDO U2F token support
What DNS encryption means for enterprise threat hunters

The dawn of the DNS over HTTPS era is putting business security and SOC teams to the challenge The post What DNS encryption means for enterprise threat hunters appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

What do a Lenovo touch pad, an HP camera and Dell Wi-Fi have in common? They’ll swallow any old firmware, legit or saddled with malware

security update

Russia Blocks Encrypted Email Service Tutanota
FC Barcelona Suffers Likely Credential-Stuffing Attack on Twitter

security update

security update

Ring Mandates 2FA After Rash of Hacks
Plastic surgery tech firm leaks images of 100,000s of customers
Iran-Backed APTs Collaborate on 3-Year ‘Fox Kitten’ Global Spy Campaign
Sensitive plastic surgery photos exposed online

Other leaked records include videos, facial and body scans, as well as a range of patients’ personal data The post Sensitive plastic surgery photos exposed online appeared first on WeLiveSecurity

$2.07bn? That’s one Dell of a deal to offload infosec biz RSA
Active Exploits Hit Vulnerable WordPress ThemeGrill Plugin
Shipping is so insecure we could have driven off in an oil rig, says Pen Test Partners
Latest LokiBot malware variant distributed as Epic Games installer
Plugin flaw leaves up to 200,000 WordPress sites at risk of attack

A fix is available, so you may want to make sure that you run the plugin’s latest version The post Plugin flaw leaves up to 200,000 WordPress sites at risk of attack appeared first on WeLiveSecurity

Malware and HTTPS – a growing love affair
Hacker Scheme Threatens AdSense Customers with Account Suspension

An update that solves two vulnerabilities and has 5 fixes is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in QEMU.

Council returns to using pen and paper after cyberattack
AI filter launched to block Twitter cyberflashing

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0515

IOTA shuts down network temporarily to fight wallet hacker
Sensitive plastic surgery images exposed online
Lenovo, HP, Dell Peripherals Face Unpatched Firmware Bugs
Hamas hackers posed as women to con IDF into downloading malware
Tutanota cries ‘censorship!’ after secure email biz blocked – for real this time – in Russia
Iranian APT group hacking VPN servers for “Fox Kitten Campaign”
Severe vuln in WordPress plugin Profile Builder would happily hand anyone the keys to your kingdom
FC Barcelona Twitter account hacked – again

The same hackers have also got their mitts on social media accounts of other high-profile sporting targets The post FC Barcelona Twitter account hacked – again appeared first on WeLiveSecurity

Twitter accounts of The Olympics and FC Barcelona hijacked by OurMine hacking group

An update that fixes 6 vulnerabilities is now available.

An update that fixes 25 vulnerabilities is now available.

The package thunderbird before version 68.5.0-1 is vulnerable to multiple issues including arbitrary code execution, cross-site scripting, denial of service and information disclosure.

The package systemd before version 244.2-1 is vulnerable to privilege escalation.

Google pulls 500 malicious Chrome extensions after researcher tip-off
Google forced to reveal anonymous reviewer’s details
Senator calls for dedicated US data protection agency
Police bust alleged operator of Bitcoin mixing service Helix

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Tom Lane discovered that “ALTER … DEPENDS ON EXTENSION” sub commands in the PostgreSQL database did not perform authorisation checks. For Debian 8 “Jessie”, this problem has been fixed in version

It is with a heavy heart we must inform you, once again, folks are accidentally spilling thousands of sensitive pics, records onto the internet

security update

Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (stretch), these problems have been fixed

PhotoSquared app leaks photos & home addresses of 100,000s of users

Do not evaluate arithmetic expressions from environment variables at startup

security update

Do not evaluate arithmetic expressions from environment variables at startup

An update that fixes 7 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Several vulnerabilities were discovered in evince, a simple multi-page document viewer. CVE-2017-1000159

Roses are red, IBM is Big Blue. It’s out of RSA Conference after coronavirus review: IBMers will not attend infosec event over ‘health concerns’

Reading Time: ~ 2 min. Estée Lauder Leaves Massive Database Unprotected Earlier this week researchers discovered an unsecured database containing over 440 million records belonging to Estee Lauder, a major make-up manufacturer. Though the company has confirmed that no customer data was stored in that database, they are still unsure on how long it was […]

Google burns down more than 500 private-data-stealing, ad-defrauding Chrome extensions installed by 1.7m netizens

Fix CVE-2019-20388 and CVE-2020-7595

500 Google Chrome extensions found to be spreading malware
Huawei Controversy Highlights 5G Security Implications
500 Malicious Chrome Extensions Impact Millions of Users

security update

security update

Apple iPhone Users Targeted with Bogus Dating App for Valentine’s Day
Bluetooth bugs – researchers find 10 “Sweyntooth” security holes
SMS Phishing Campaign Targets Mobile Bank App Users in North America

Risk Level: Very Low. Type: Trojan.

News Wrap: Valentine’s Day Scams and Emotet’s Wi-Fi Hack
Institute of International Education leaks data of thousands of students
Austrian foreign ministry: ‘State actor’ hack on government IT systems is over
Hackers Can Seize Control of Ballots Cast Using the Voatz Voting App, Researchers Say
Call us immediately if your child uses Kali Linux, squawks West Mids Police
Cookie-nabbing app could have served users side helping of XSS
Suspect who refused to decrypt hard drives released after four years
Facebook ices in-app dating in EU after questions from regulator
Self-driving car dataset missing labels for pedestrians, cyclists
Corp.com is up for sale – check your Active Directory settings!
How romance scammers break your heart – and your bank account

What are some of the most common warning signs that your online crush could be a dating scammer? The post How romance scammers break your heart – and your bank account appeared first on WeLiveSecurity

AT&T insists it’s not blocking Tutanota after secure email biz cries foul, cites loss of net neutrality as cause
Voatz of no confidence: MIT boffins eviscerate US election app, claim fiends could exploit flaws to derail democracy
Fix Microsoft Outlook When Stuck on Loading Profile

– Update to 73.0

Rebase to radare2-4.2.1 and cutter-re 1.10.1. It fixes CVE-2019-19590 and CVE-2019-19547. It also fix a problem in cutter-re that did not display the window icon on Wayland.

Rebase to radare2-4.2.1 and cutter-re 1.10.1. It fixes CVE-2019-19590 and CVE-2019-19547. It also fix a problem in cutter-re that did not display the window icon on Wayland.

**Horde_Data 2.1.5** * [jan] Fix Remote Code Execution vulnerability (CVE-2020-8518, Reported by: Andrea Cardaci/SSD).

security update

security update

Critical WordPress Plugin Bug Afflicts 700K Sites
FBI: Cybercrime losses tripled over the last 5 years

On the upside, the Bureau recovered more than US$300 million in funds lost to online scams last year The post FBI: Cybercrime losses tripled over the last 5 years appeared first on WeLiveSecurity

Resolve buffer overflow in TexOpen() function, CVE-2019-19601

Rebase to radare2-4.2.1 and cutter-re 1.10.1. It fixes CVE-2019-19590 and CVE-2019-19547. It also fix a problem in cutter-re that did not display the window icon on Wayland.