Menu

Monthly Archives: February 2020

Update to Node.js 12.15.0

libasr-1.0.4, opensmtpd-6.6.2p1 update

libasr-1.0.4, opensmtpd-6.6.2p1 update

Facebook’s Twitter account is hijacked by notorious OurMine hacking group
Dark web hackers selling payment card data of half a million Indians
Wacom Tablet Data Exfiltration Raises Security Concerns

Resolve buffer overflow in TexOpen() function, CVE-2019-19601

Resolves: #1796107, #1796109 – Security fix for CVE-2019-19921

Update to upstream 2.0.1 release for CVE-2019-10747

Update to upstream 1.3.2 release for CVE-2019-10746

MinGW cross compiled SDL 2.0.10, fixing a number of CVE issues.

Update to 2.40.0. —- MinGW cross compiled gdk-pixbuf 2.36.12 release, fixing various CVE’s.

Google Chrome to block file downloads – from .exe to .txt – over HTTP by default this year. And we’re OK with this
Critical Android Bluetooth Bug Enables RCE, No User Interaction Needed

security update

security update

The Oscar nominated movie you just downloaded could be a malware

Reading Time: ~ 2 min. Tax Season Brings Emotet to the Front As Americans prepare for tax season, Emotet authors have started a new campaign that imitates a W-9 tax form requested by the target. As with most malicious phishing, an attached document asks users to enable macros when viewing the files. This campaign can […]

Google Chrome To Bar HTTP File Downloads
RobbinHood – the ransomware that brings its own bug
Uncle Sam tells F-35B allies they’ll have to fly the things a lot more if they want to help out around South China Sea
Dutch university paid $220,000 ransom to hackers after Christmas attack
Critical Citrix RCE Flaw Still Threatens 1,000s of Corporate LANs
Day 4 of outage: UK’s Manchester police deploy exciting new carbon-based method to record crime
Phishing Campaign Targets 250 Android Apps with Anubis Malware
Apple fined €25 million for deliberately slowing down old iPhones
The RSAC 2020 Trend Report

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that fixes four vulnerabilities is now available.

Researchers transmit data covertly by altering screen brightness
Android users at risk from Bluetooth hijack attack, and are warned of “short distance worm” threat
Facebook, Google, YouTube order Clearview to stop scraping faceprints
Wacom driver caught monitoring third-party software use
Cybercrooks busted for multimillion-dollar identity fraud
Magecart Gang Attacks Olympic Ticket Reseller and Survival Food Sites

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

Android owners – you’ll want to get these latest security patches, especially for this nasty Bluetooth hijack flaw
How Technology Has Altered the Education Landscape
Good: IT admins scrambled to patch 80 per cent of public-facing Citrix boxes to close nightmare hijack hole
Hackers can steal data from air-gapped PC using screen brightness
Metamorfo Returns with Keylogger Trick to Target Financial Firms
U.S. Finance Sector Hit with Targeted Backdoor Campaign
Shoe with GPS embedded insole tracks ‘lost’ alzheimer’s & dementia patients
Update now – WhatsApp flaw gave attackers access to local files
How your network could be hacked through a Philips Hue smart bulb
Wacom drawing tablets are spying on every app you open, and sending the data back to Wacom
Twitter bans deepfakes, but only those ‘likely to cause harm’
Researchers reckon 500k PCs infested with malware after dodgy downloads install even more nasties from Bitbucket

This package allowed ../ directory traversal to access private resources because resource matching did not ensure that pathnames were in a canonical format.

How your screen’s brightness could be leaking data from your air-gapped computer

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in Pillow.

Google’s Chrome 80 clamps down on cookies and notification spam
Charming Kitten Uses Fake Interview Requests to Target Public Figures
Dropbox Passes $1M Milestone for Bug-Bounty Payouts
Android pulls 24 ‘dangerous’ malware-filled apps from Play Store
Smashing Security #164: A bitter pill to swallow
LCD pwn System: How to modulate screen brightness to covertly transmit data from an air-gapped computer… slowly
Yahoo! hack! payout! nearly! approved! and! the! question! is! how! to! spend! 60! cents!?
WhatsApp flaw gave hackers access to files from Windows and Macs
Terrifying bug in WhatsApp allows hackers to steal files. So get patching all nine of you using it on the desktop
Sketchy behavior? Wacom tablet drivers phone home with names, times of every app opened on your computer
CamuBot Banking Trojan Returns In Targeted Attacks
Time to patch your lightbulb? Researchers demonstrate Philips Hue exploit
Hackers can use flaw in Philips smart light bulbs to spread malware
New Lemon Duck Malware Campaign Targets IoT, Large Manufacturers
RIP FTP? File Transfer Protocol switched off by default in Chrome 80
Oh ****… Sudo has a ‘make anyone root’ bug that needs to be patched – if you’re unlucky enough to enable pwfeedback
Man pleads guilty to hacking Nintendo & possession of child pornography
Coronavirus “safety measures” email is a phishing scam
PayPal SMS scams – don’t fall for them!
WhatsApp Bug Allows Malicious Code-Injection, One-Click RCE
They can’t collect your bins or fix your roads. They let Google stalk visitors to their websites. Yes, it’s UK local government
Critical Cisco ‘CDPwn’ Protocol Flaws Explained: Podcast
Critical Cisco ‘CDPwn’ Flaws Break Network Segmentation

An update that solves two vulnerabilities and has one errata is now available.

Several security issues were fixed in systemd.

Someone else may have your videos, Google tells users
Critical Android flaws patched in February bulletin
Twitter admits to raid on users’ phone numbers
Gamaredon APT Improves Toolset to Target Ukraine Government, Military
How to catch a cybercriminal: Tales from the digital forensics lab

What is it like to defeat cybercrime? A peek into how computer forensics professionals help bring cybercriminals to justice. The post How to catch a cybercriminal: Tales from the digital forensics lab appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

OpenSMTPD could be made to run programs as root if it received specially crafted input over the network.

ipa: Denial of service in IPA server due to wrong use of ber_scanf() (CVE-2019-14867) * ipa: Batch API logging user passwords to /var/log/httpd/error_log (CVE-2019-10195) SL7 x86_64 ipa-client-4.6.5-11.el7_7.4.x86_64.rpm ipa-debuginfo-4.6.5-11.el7_7.4.x86_64.rpm ipa-server-4.6.5-11.el7_7.4.x86_64.rpm ipa-server-trust-ad-4.6.5-11.el7_7.4.x86_64.rpm noarch ipa-client-co [More…]

hw: TSX Transaction Asynchronous Abort (TAA) (CVE-2019-11135) * QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378) SL7 x86_64 qemu-img-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-common-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-debuginfo-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-tools-1.5.3-167.el7_7.4.x86_64.rpm – Scien [More…]

Google Takeout a bit too true to its name after potentially 1000s of private videos shared with complete strangers
Is Chrome really secretly stalking you across Google sites using per-install ID numbers? We reveal the truth
Welp – Google sent your photos & videos to strangers
Community Housing Nonprofit Hit with $1.2M Loss in BEC Scam
This is not Huawei to reassure people about Beijing’s spying eyes: Trivial backdoor found in HiSilicon’s firmware for net-connected cams, recorders
Ransomware Attack Hinders Toll Group Operations
Malware infection attempts appear to be shrinking… possibly because miscreants are less spammy and more focused on specific targets

security update