Menu

Monthly Archives: April 2020

An update that fixes one vulnerability is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that solves 8 vulnerabilities and has two fixes is now available.

An update for ipmitool is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

United Nations reportedly tears up Tencent’s invite to its big 75th birthday bash
Stuck inside with time on your hands? The US govt would like to remind you it’s paying $5m for Nork hacking scalps
Smashing Security #174: Garry Kasparov and Animal Crossing
Malicious Google Web Extensions Harvest Cryptowallet Secrets
Taxpayers Targeted With Improved NetWire RAT Variant

security update

Linksys forces password reset for Smart Wi-Fi accounts after router DNS hack pointed users at COVID-19 malware
49 malware infected Chrome extensions found stealing user data
Tencent Ups Top Bug-Bounty Award to $15K
Zoom passwords for sale on the Dark Web – “ten-a-penny” by all accounts
How to host safer Zoom meetings
Think before filling in that convenient flight refund form with all your delicious details – there’s a scam going about
Intel Fixes High-Severity Flaws in NUC, Discontinues Buggy Compute Module
PPE, COVID-19 Medical Supplies Targeted by BEC Scams
Know Your Enemy: Honeynets>
Decade of the RATs: Is Linux Secure?>
Top 5 Open-Source Serverless Security Tools>
IBM extends z15 mainframe family, intensifies Linux security>
EA Sports down – Gaming giant hit by massive DDoS attacks
Signal: We’ll be eaten alive by EARN IT Act’s anti-encryption wolves
WordPress WooCommerce sites targeted by card swiper attacks
Another day, another Google cull: Chocolate Factory axes 49 malicious Chrome extensions from web store
Apple: We respect your privacy so much we’ve revealed a little about what we can track when you use Maps

An update that fixes 26 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

At least someone’s making out like a bandit: Scammers have pocketed $13m in Coronavirus fraud from the US this year

A directory traversal vulnerability resulting from insufficient input sanitization was discovered in the Horde Application Framework. An authenticated remote attacker could use this flaw to execute code in the

A remote code execution vulnerability was discovered in the Horde Application Framework. An authenticated remote attacker could use this flaw to cause execution of uploaded CSV data.

A vulnerability was discovered in graphicsmagick, a collection of image processing tools, that results in a heap overflow in 32-bit applications because of a signed overflow on range check in the HuffmanDecodeImage

April 2020 and – rest assured – your Windows PC can still be pwned by something so innocuous as an unruly font

security update

An update that fixes one vulnerability is now available.

April Patch Tuesday: Microsoft Battles 4 Bugs Under Active Exploit
Over half a million Zoom accounts being sold on hacker forum
Adobe Fixes ‘Important’ Flaws in ColdFusion, After Effects and Digital Editions
TA505 Crime Gang Deploys SDBbot for Corporate Network Takeover
Cyberattacks Target Healthcare Orgs on Coronavirus Frontlines
Americans report US$13 million in losses from coronavirus scams

The median loss to fraudulent schemes that exploit the global health crisis is almost US$600 The post Americans report US$13 million in losses from coronavirus scams appeared first on WeLiveSecurity

Watch: Flaw exploited to post fake COVID-19 clips from TikTok accounts
Exclusive: Personal data of 1.41m US doctors sold on hacker forum
Safe Remote Access to Critical Infrastructure Networks in a Time of Global Crisis
4 million Quidd user accounts dumped on hacker forum for download
TikTok Flaw Allows Threat Actors to Plant Forged Videos in User Feeds

Reading Time: ~ 3 min. Despite the intent of ensuring safe transit of information to and from a trusted website, encrypted protocols (usually HTTPS) do little to validate that the content of certified websites is safe. With the widespread usage of HTTPS protocols on major websites, network and security devices relying on interception of user […]

An update for podman is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Let’s authenticate: Beyond Identity pitches app-wrapped certificate authority

An update that fixes one vulnerability is now available.

Malware Risks Triple on WFH Networks: Experts Offer Advice

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

TikTok users beware: Hackers could swap your videos with their own

An update is now available for Red Hat Satellite 6.7 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Is “global privacy” an oxymoron?

While in France, a citizen of Brazil who resides in California books a bungee jump in New Zealand. Is it a leap of faith into the unknown, for both the operator and the thrill-seeker? The post Is “global privacy” an oxymoron? appeared first on WeLiveSecurity

Red Hat AMQ Broker 7.4.3 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

ICANN asks registrars to crack down on scam coronavirus websites
Microsoft and Google delay online authentication change
Zoom adds Choose Your Own Routing Adventure to keep chats out of China
So how do the coronavirus smartphone tracking apps actually work and should you download one to help?
Oracle Tackles a Massive 405 Bugs for Its April Quarterly Patch Update
Gaming controllers manufacturer exposed 1.1M customer records
Overlay Malware Leverages Chrome Browser, Targets Banks and Heads to Spain
How to make a stranger’s insecure 3D printer halt-and-catch-fire – plus more alerts from infosec world

New upstream version, fix CVEs

## 1.4.3 (12, Nov 2019) ### Security Improvements: – Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465).

– https://www.drupal.org/project/ckeditor/releases/7.x-1.19 – https://www.drupal.org/sa-contrib-2020-007

New upstream version, fix CVEs

## 1.4.3 (12, Nov 2019) ### Security Improvements: – Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465).

– https://www.drupal.org/project/ckeditor/releases/7.x-1.19 – https://www.drupal.org/sa-contrib-2020-007

Security fix for CVE-2020-11100)

An update that contains security fixes can now be installed.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

2 San Francisco Int. airport websites hacked with info-stealer code
Dutch Police takes down 15 DDoS-for-hire services in one week

An update that solves one vulnerability and has three fixes is now available.

An update that fixes 5 vulnerabilities is now available.

SFO Websites Hacked: Airport Discloses Data Breach
Apple, Google Team on Coronavirus Tracking – Sparking Privacy Fears
Sextortion emails and porn scams are back – don’t let them scare you!
WooCommerce Falls to Fresh Card-Skimmer Malware

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More…]

A vulnerability in libssh could allow a remote attacker to cause a Denial of Service condition.

3D printed fingerprints can unlock your device with 80% success rate
Critical VMware Bug Opens Up Corporate Treasure to Hackers
Apple App Store Riddled With Money-Sucking Fleeceware Apps
The pains – and pleasures? – of network security: Tell us exactly what you think about this corner of business IT
Travelex Pays $2.3M in Bitcoin to Hackers Who Hijacked Network in January

Reading Time: ~ 2 min. Malicious COVID-19 Websites Surge In recent months, more than 136 thousand new domains have been registered that reference the current COVID-19 outbreak, many of which have yet to be flagged. A large portion of these sites are distributing phishing campaigns with fake bank login forms and inaccurate URLs, including any […]

An update that fixes two vulnerabilities is now available.

The package libssh before version 0.9.4-1 is vulnerable to denial of service.

The package wireshark-cli before version 3.2.3-1 is vulnerable to arbitrary code execution.

The package chromium before version 81.0.4044.92-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure, access restriction bypass and insufficient validation.