Menu

Monthly Archives: March 2020

Apple iOS 13.4 offers fixes for 30 vulnerabilities

An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

SANS is offering fully certified cybersecurity training – without leaving your bunker

**PHP version 7.3.16** (19 Mar 2020) **Core:** * Fixed bug php#63206 (restore_error_handler does not restore previous errors mask). (Mark Plomer) **DOM:** * Fixed bug php#77569: (Write Access Violation in DomImplementation). (Nikita, cmb) * Fixed bug php#79271 (DOMDocumentType::$childNodes is NULL). (cmb) **Enchant:** * Fixed bug php#79311 (enchant_dict_suggest() fails on big

Security and performance fixes.

If there’s something strange in Symantec’s neighborhood, who you gonna call? Not Broadcom, it seems: Systems go down, cut off customers
Apple Update Fixes WebKit Flaws in iOS, Safari
Public health vs. personal privacy: Choose only one?

As the world turns to technology to track and contain the COVID-19 pandemic, could this spell the end of digital privacy rights? The post Public health vs. personal privacy: Choose only one? appeared first on WeLiveSecurity

Chinese Hackers Exploit Cisco, Citrix Flaws in Massive Espionage Campaign
Tupperware-dot-com has a live credit card skimmer on its payment page, warns Malwarebytes
GE Employees Lit Up with Sensitive Doc Breach
Hackers are actively targeting WHO amid Coronavirus pandemic

An exploitable heap overflow vulnerability exists in the Psych::Emitter startdocument function of Ruby. In Psych::Emitter startdocument function heap buffer “head” allocation is made based on

An update that solves one vulnerability and has 6 fixes is now available.

An update that solves one vulnerability and has 6 fixes is now available.

Multiple vulnerabilities have been found in Samba, the worst of which could lead to remote code execution.

TrickBot App Bypasses Non-SMS Banking 2FA

Multiple vulnerabilities have been found in WeeChat, the worst of which could allow remote attackers to cause a Denial of Service condition.

Windows has a zero-day that won’t be patched for weeks

Multiple vulnerabilities were found in Tor, the worst of which could allow remote attackers to cause a Denial of Service condition.

Apple Safari Blocks Ad-Targeting Cookie Support
Your unused computer could help find a COVID-19 cure
Hackers target WHO in phishing attack
Battling the global COVID-19 scammers and fake news hawkers
Brit housing association blabs 3,500 folks’ sexual orientation, ethnicity in email blunder
Stuck inside with nothing to do? Apple fires out security fixes for iOS, macOS, wrist-puters… and something weird called iTunes for Windows

Reading Time: ~ 3 min. Have you ever watched a movie and seen a character doing something you know how to do, and thought to yourself, “jeez, that’s totally wrong. Couldn’t they have done a little research?” That’s exactly what hackers think when they watch movies, too. For most of us, the image that comes […]

Unknown ‘WildPressure’ Malware Campaign Lets Off Steam in Middle East
Covid-19 Privacy Poll: Phone Tracking, Public Health and Surveillance
Adobe debuts disk-cleaning tool cleverly disguised as an arbitrary file deletion bug in Creative Cloud on Windows
WHO Targeted in Espionage Attempt, COVID-19 Cyberattacks Spike
Hackers are exploiting a critical, unpatched flaw in Windows

IBus could allow local users to capture key strokes of other locally logged in users.

Critical Adobe Flaw Fixed in Out-of-Band Security Update
Watch live online this week: Why you need managed detection and response

Tomcat8 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle

Android malware caught infecting Play Store apps for kids
Free Netflix pass because of Coronavirus? It’s a scam
Microsoft warns of two Windows zero‑day flaws

Updates for the critical-rated vulnerabilities, which are being actively exploited in the wild, are still weeks away The post Microsoft warns of two Windows zero‑day flaws appeared first on WeLiveSecurity

Domain Name Security: Important Measures You Need to Know
Tekya Malware Threatens Millions of Android Users via Google Play
Got your number? Maybe. 118 118 Money shutters website after spotting an intruder
Facebook Messenger may ban mass-forwarding of messages
Russia’s FSB wanted its own IoT botnet
Memcached has a crash-me bug, but hey, only about 83,000 public-facing servers appear to be running it

An update for openshift-enterprise-template-service-broker-operator-container is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact

An update for openshift-enterprise-builder-container, openshift-enterprise-cli-container, and ose-cli-artifacts-container is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact

Feds shut down bogus COVID-19 vaccine site

An update for openshift-clients is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Have you patched your IoT devices against the KrØØk Wi-Fi chip flaw?
The Shield: the open source Israeli Government app which warns of Coronavirus exposure
Apache Tomcat Exploit Poised to Pounce, Stealing Files
Hackers Actively Exploit 0-Day in CCTV Camera Hardware

security update

It’s 2020 and hackers are still hijacking Windows PCs by exploiting font parser security holes. No patch, either
Microsoft Warns of Critical Windows Zero-Day Flaws
WhatsApp “Martinelli” hoax is back, warning about “Dance of the Pope”
Fake Coronavirus ‘Vaccine’ Website Busted in DoJ Takedown
Coronavirus extortion scam threatens to infect victim’s family
The good, the bad and the plain ugly

A prolific ransomware gang vows to dial back its campaigns and spare healthcare organizations altogether during the COVID-19 crisis. It’s no cause for celebration. The post The good, the bad and the plain ugly appeared first on WeLiveSecurity

Cisco issues urgent fixes for SD-WAN router flaws
Tour guide/Chinese spy gets four years for SD card dead drops
Stolen data of company that refused REvil ransom payment now on sale
Firefox is dropping FTP support

Several security issues were fixed in Vim.

An update for samba is now available for Red Hat Gluster Storage 3.5 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for runc is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Red Hat AMQ Streams 1.4.0 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

It’s time to track people’s smartphones to ensure they self-isolate during this global pandemic, says WHO boffin
No, the head of the World Health Organization has not emailed you – it’s a message laced with malware

An update for devtoolset-8-gcc is now available for Red Hat Developer Toolset 8 for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The following packages CVE(s) were reported against phpmyadmin. CVE-2020-10802

The Dance of the Pope virus hoax

An update that fixes 7 vulnerabilities is now available.

The following CVE(s) were reported against jackson-databind. CVE-2020-10672

5 Best Internet Service Locators

An update that fixes 9 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

Russian Intel Agency FSB’s contractor hacked; sensitive data leaked online

security update

security update

A vulnerability was discovered in graphicsmagick, a collection of image processing tools, that allows allows an attacker to read arbitrary files via a crafted image because of TranslateTextEx for SVG.

It was discovered that systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local

A denial of service vulnerability (by triggering high CPU consumption) was found in Tor, a connection-based low-latency anonymous communication system.

Multiple vulnerabilities have been found in Node.js, worst of which could allow remote attackers to write arbitrary files.

It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when strip=False and ‘math’ or ‘svg’ tags and one or more of the RCDATA tags were whitelisted.

A vulnerability in Exim could allow a remote attacker to execute arbitrary code.

German army’s sensitive data found on laptop bought from eBay
Bored during lockdown? Why not try out these data-spilling KrØØk Wi-Fi bug exploits against your nearby devices

security update

Revamped HawkEye Keylogger Swoops in on Coronavirus Fears
Defying Covid-19’s Pall: Pwn2Own Goes Virtual
Online face mask sales scams, 400% uptick of coronavirus phishing reports: Brit cops’ workload shifts online along with the nation’s
News Wrap, Coronavirus Edition: WFH Security Woes, Pwn2Own
Security firm leaves more than five billion records exposed on unsecured database
Trolls ZoomBomb work-from-home videocall with filth
Cyber Security firm exposes 5 billion+ login credentials
Keep calm and carry on working (remotely)

How can employees stay motivated and productive while teleworking during the COVID-19 crisis? The post Keep calm and carry on working (remotely) appeared first on WeLiveSecurity