Menu

Monthly Archives: February 2020

Cosmetic giant Estée Lauder exposed 440 million records online
Gaza Cybergang targeting Palestinian authority figures
Privacy Experts Skeptical of Proposed Data Protection Agency
Puerto Rico government falls for $2.6 million email scam
Almost 2 billion malware installs thwarted by Google Play Protect in 2019

That’s for apps from third-party marketplaces; another 790,000 policy-breaking apps were stopped from reaching Google Play The post Almost 2 billion malware installs thwarted by Google Play Protect in 2019 appeared first on WeLiveSecurity

Puerto Rico Gov Hit By $2.6M Phishing Scam
Secure email service Tutanota complains it is being blocked by AT&T in parts of the United States
Firefox six-weekly security fixes are out – get them now!
Dell fixes privilege elevation bug in support software
IE zero day and heap of RDP flaws fixed in February Patch Tuesday
FBI: Cybercrime tore a $3.5b hole in victims’ pockets last year
Smashing Security #165: Cheapfakes, deepfakes, and Ashley Madison
A dirty dozen of Bluetooth bugs threaten to reboot, freeze, or hack your trendy gizmos from close range
Google: Efforts Against Bad Android Apps on Play Store Are Working
Google to force Nest users to turn on 2FA
Digital addiction: How to get your children off their screens

What are some of the common signs that your child may be a screen addict and what can you do to limit their screen time? The post Digital addiction: How to get your children off their screens appeared first on WeLiveSecurity

An update is now available for Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update of the Red Hat OpenShift Container Platform 3.11 and 4.1 container images is now available for Red Hat AMQ Online. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated flash-player-plugin package fixes a security vulnerability: Type confusion that leads to arbitrary code execution in the context of the current user. (CVE-2020-3757)

The updated packages fix a security vulnerability: In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service

Updated python-waitress packages fix security vulnerabilities: If a front-end server does not parse header fields with an LF the same way as it does those with a CRLF it can lead to the front-end and the back-end server parsing the same HTTP message in two different ways.

Updated vim and neovim package fixes security vulnerability: It was discovered that Vim before 8.1.1365 and Neovim before 0.3.6 did not restrict the `:source!` command when executed in a sandbox. This allows remote attackers to take advantage of the modeline feature to

Jailcore database leaks PII of inmates & correctional officers across US
2FA is being pushed out to all Google Nest users to better protect their accounts
Mozilla Firefox 73 Browser Update Fixes High-Severity RCE Bugs
SoundCloud Tackles DoS, Account Takeover Issues
Mozilla issues final warning to websites using TLS 1.0
Watch as virtual reality helps mom meet her deceased daughter
Katie Moussouris: The Bug Bounty Conflict of Interest
Report to Your Management with the Definitive ‘IR Management and Reporting’ Presentation Template
FBI: $3.5B Lost in 2019 to Known Cyberscams, Ransomware
Netgear’s routerlogin.com HTTPS cert snafu now has a live proof of concept
Patch now! Microsoft releases fixes for 99 security flaws, some being actively exploited by hackers
US charges four Chinese military members with Equifax hack

An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An denial of service via an algorithmic complexity attack on email address parsing have been identified in libemail-address-list-perl.

Data about inmates and jail staff spilled by leaky prison app

An update that fixes 38 vulnerabilities is now available.

An update for ose-baremetal-installer-container and ose-cli-artifacts-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact

An update for ose-installer-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

Microsoft Patch Tuesday fixes IE zero‑day and 98 other flaws

February may be the shortest month of the year, but it brings a bumper crop of patches The post Microsoft Patch Tuesday fixes IE zero‑day and 98 other flaws appeared first on WeLiveSecurity

If you’re running Windows, I feel bad for you, son. Microsoft’s got 99 problems, better fix each one
Emotet Trojan now exploits WiFi networks to infect nearby devices
Microsoft Addresses Active Attacks, Air-Gap Danger with 99 Patches
Intel Patches High-Severity Flaw in Security Engine
Estée Lauder Exposes 440M Records, with Email Addresses, Network Info
B-but it doesn’t get viruses! Not so, Apple fanbois: Mac malware is growing faster than nasties going for Windows
U.S. FDA: No link between smartphone radiation & cancer
Crypto AG backdooring rumours were true, say German and Swiss news orgs after explosive docs leaked
Adobe Addresses Critical Flash, Framemaker Flaws
China denies it was behind the Equifax hack, as four men charged for data breach
Tens of millions of biz Dell PCs smacked by privilege-escalation bug in bundled troubleshooting tool
5 tips for you and your family on Safer Internet Day
5 tips for businesses on Safer Internet Day
Prison inmates’ sensitive data left exposed on leaky cloud bucket
Graham Cluley on Tripwire’s Talking Cybersecurity Podcast
Dell Patches SupportAssist Flaw That Allows Arbitrary Code Execution
Freedom Hosting owner pleads guilty to distributing child abuse images
Officials raise alarm about Chinese hacking
Facebook’s Twitter and Instagram accounts hijacked
Dashlane password manager’s Chrome extension has disappeared

Yubico PIV Tool could be made to crash or run programs as an administrator if it received specially crafted input.

Competing in esports: 3 things to watch out for

If you’re looking to become a pro gamer, there are risks you shouldn’t play down The post Competing in esports: 3 things to watch out for appeared first on WeLiveSecurity

spice-client: Insufficient encoding checks for LZ can cause different integer/buffer overflows (CVE-2018-10893) SL6 x86_64 spice-glib-0.26-8.el6_10.2.i686.rpm spice-glib-0.26-8.el6_10.2.x86_64.rpm spice-gtk-0.26-8.el6_10.2.i686.rpm spice-gtk-0.26-8.el6_10.2.x86_64.rpm spice-gtk-debuginfo-0.26-8.el6_10.2.i686.rpm spice-gtk-debuginfo-0.26-8.el6_10.2.x86_64.rpm spic [More…]

An update for spice-gtk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for nss-softokn is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Forgotten motherboard driver turns out to be perfect for slipping Windows ransomware past antivirus checks
US charges 4 Chinese military hackers over 2017 Equifax breach
Five Open-Source Projects AI Enthusiasts Might Want to Know About>
Game over, LAN, game over! Windows software nasty Emotet spotted spreading via brute-forced Wi-Fi networks
BYO-Bug Tactic Attacks Windows Kernel with Outdated Driver
Active PayPal Phishing Scam Targets SSNs, Passport Photos
These truly are the end times for TLS 1.0, 1.1: Firefox hopes to ‘eradicate’ weak HTTPS standard by blocking it
Hackers caught using CNET website to spread nasty malware
US govt accuses four Chinese army soldiers of hacking Equifax and siphoning 145m Americans’ personal info

The updated packages fix a security vulnerability: In Sudo before 1.8.31, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however,

Equifax Breach: Four Members of Chinese Military Charged with Hacking
Docker Registries Expose Hundreds of Orgs to Malware, Data Theft
Emotet Now Hacks Nearby Wi-Fi Networks to Spread Like a Worm
Owner of dark web Freedom hosting pleads guilty to host child abuse content
Coronavirus phishing attack disguises as a message from the Center for Disease Control
Google Chrome to start blocking downloads served via HTTP

Security researchers from Snyk discovered that the fix for CVE-2019-9658 was incomplete. Checkstyle, a development tool to help programmers write Java code that adheres to a coding standard, was still vulnerable to XML External Entity (XXE) injection.

Facebook encrypted messaging will ‘create hiding places for child abuse’
FBI director warns of sustained Russian disinformation threat
Frustrated author cybersquats novelist’s website
How to bring security into agile development and CI/CD
Home anti-virus products put to the test by AV-Comparatives – which received the highest score?

an out-of-bounds write vulnerability due to an integer overflow was reported in libexif, a library to parse exif files. This flaw might be leveraged by remote attackers to cause denial of service, or potentially execute arbitrary code via crafted image files.

Several security issues were fixed in libxml2.

Several security issues were fixed in Qt.

Facebook loses control of its own Twitter account in hacker attack – and more news

Add patch for CVE-2020-6750 and related issues.

Emergency call service in Australia to use AI to detect signs of heart attack

An update that fixes 38 vulnerabilities is now available.

Update to Node.js 12.15.0

Update to Node.js 12.15.0