Menu

Monthly Archives: April 2020

The package firefox before version 75.0-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and access restriction bypass.

The package haproxy before version 2.1.4-1 is vulnerable to arbitrary code execution.

Compromised Zoom Credentials Swapped in Underground Forums
Ransomware scumbags leak Boeing, Lockheed Martin, SpaceX documents after contractor refuses to pay
Cloudflare Axes Google reCAPTCHA Due to Privacy, Price
Unique P2P Architecture Gives DDG Botnet ‘Unstoppable’ Status

security update

security update

Signal sends smoke, er, signal: If Congress cripples anonymous speech with EARN IT Act, we’ll shut US ops
Copycat Site Serves Up Raccoon Stealer
A billion-dollar US firm caught exposing highly sensitive database online
Report: Travelex paid hackers $2.3 million worth of Bitcoin after ransomware attack
Zoom takes action after meeting IDs leak in careless screenshots
Fleeceware on your iPhone? Don’t get caught out while penned up at home

An update that fixes 5 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Consumer reviewer Which? finds CAN bus ports on Ford and VW, starts yelling ‘Security! We have a problem…’

An update that fixes 5 vulnerabilities is now available.

Zoom Taps Ex-Facebook CISO Amid Security Snafus, Lawsuit

Security fix for CVE-2020-5247, CVE-2020-5249

This update incorporates fixes from the upstream glibc 2.29 stable release branch, including 3 fixes for medium severity security vulnerabilities. (CVE-2020-10029, CVE-2020-1752, CVE-2020-1751)

Cisco ‘Critical Update’ Phishing Attack Steals Webex Credentials
‘Unbreakable’ Smart Lock Draws FTC Ire for Deceptive Security Claims
Smashing Security #173: 5G fiascos, Zoom gloom, and butt biometrics
52k Iranian ID cards with selfies sold on dark web & hacking forum
Google removes Android VPN with ‘critical vulnerability’ from Play Store
Low-orbit internet banking fraud claim alleged to be a load of space junk
Cloudflare dumps Google’s reCAPTCHA, moves to hCaptcha as free ride ends (and something about privacy)
PowerPoint ‘Weakness’ Opens Door to Malicious Mouse-Over Attack
Dark_Nexus Botnet Compromises Thousands of ASUS, D-Link Routers
Fake Coronavirus vaccine, patients’ blood & saliva sold on dark web
ThreatList: Skype-Themed Apps Hide a Raft of Malware
Slack in the security spotlight – lessons for collaboration servers

Updated firefox packages fix security vulnerabilities: When reading from areas partially or fully outside the source resource with WebGL’s copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized,

Bisq Bitcoin exchange halts trade due to critical vulnerability
Top tips for videoconferencing security

ESET Chief Security Evangelist Tony Anscombe shares advice on how to keep your virtual meet-ups private and safe while you’re holed up at home during the pandemic The post Top tips for videoconferencing security appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

WhatsApp Axes COVID-19 Mass Message Forwarding

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For the oldstable distribution (stretch), these problems have been fixed

‘Fake Fingerprints’ Bypass Scanners with 3D Printing
COVID-19 CISO Checklist for Securing a Remote Workforce
Be careful when pulling images by short name
Linux Malware: The Truth About This Growing Threat>
Update Firefox again – more RCEs and an Android “takeover” bug too
Microsoft prevents Domain of Danger from falling into miscreants’ paws by forking out cash for corp.com
Microsoft project proposed to aid Linux IoT code integrity
As if the world couldn’t get any weirder, this AI toilet scans your anus to identify you
Please, just stop downloading apps from unofficial stores: Android users hit with ‘unkillable malware’
China and Taiwan aren’t great friends. Zoom sends chats through China. So Taiwan has banned Zoom
Serious Exchange Flaw Still Plagues 350K Servers
Login details of verified Zoom accounts posted on Dark Web
Visual Studio Code extension flags NPM vulnerabilities
New year, old threats: Malware peddlers went into overdrive in Q1, says Trend Micro
Flaw hunter bags $75,000 off Apple after duping Safari into spying through iPhone, Mac cameras without permission
xHelper: The Russian Nesting Doll of Android Malware
FIN6 and TrickBot Combine Forces in ‘Anchor’ Attacks
Italian email provider Email.it hacked with data on sale
600,000 people affected in email provider breach

The users’ personal data are now up for grabs on the dark web for anywhere between US$3,500 and US$22,000 worth of Bitcoin The post 600,000 people affected in email provider breach appeared first on WeLiveSecurity

Official Government COVID-19 Mobile Apps Hide a Raft of Threats

The package firefox before version 74.0.1-1 is vulnerable to arbitrary code execution.

Twitter warns users – Firefox might hold on to private messages

telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code (CVE-2020-10188) SL6 x86_64 krb5-appl-clients-1.0.1-10.el6_10.x86_64.rpm krb5-appl-debuginfo-1.0.1-10.el6_10.x86_64.rpm krb5-appl-servers-1.0.1-10.el6_10.x86_64.rpm i386 krb5-appl-clients-1.0.1-10.el6_10.i686.rpm krb5-appl-debuginfo-1.0.1-10.el6_10.i686.rpm krb5-appl-se [More…]

Mozilla: Use-after-free while running the nsDocShell destructor (CVE-2020-6819) * Mozilla: Use-after-free when handling a ReadableStream (CVE-2020-6820) SL6 x86_64 firefox-68.6.1-1.el6_10.x86_64.rpm firefox-debuginfo-68.6.1-1.el6_10.x86_64.rpm firefox-68.6.1-1.el6_10.i686.rpm firefox-debuginfo-68.6.1-1.el6_10.i686.rpm i386 firefox-68.6.1-1.el6_10.i686.rpm firefox- [More…]

Two schoolkids sue Google for collecting biometrics

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

GnuTLS could expose sensitive information over the network.

Thousands of Android apps contain undocumented backdoors, study finds
Crazy cryptomining Cooking Mama rumours spread as game pulled from Nintendo Switch online store
Atlassian issues advice on how to keep your IT service desk secure… after hundreds of portals found facing the internet amid virus lockdown

Reading Time: ~ 2 min. Zoom Video Software Targeted by Hackers With much of the professional world now telecommuting, hackers have taken notice and are finding vulnerabilities within Zoom’s software to hijack online meetings. Over 400 new domains have been registered through Zoom in just the last month, of which many have been found to […]

A Brisk Private Trade in Zero-Days Widens Their Use
FBI Threatens ‘Zoom Bombing’ Trolls With Jail Time
Mozilla plugs two Firefox browser holes exploited in the wild by hackers to hijack victims’ computers
Maze ransomware group hacks oil giant; leaks data online
Apple Safari Flaws Enable One-Click Webcam Access
Roaring trade in zero-days means more vulns are falling into the hands of state spies, warn security researchers
Learn Morse Code in 30 minutes on your smartphone with Google
Government VPN Servers Targeted in Zero-Day Attack
Will Apple’s “microphone switch” stop your iPad getting bugged?
Staying home? Here are 5 best Java learning platforms

An update for ksh is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c (CVE-2020-5208) SL6 x86_64 ipmitool-1.8.15-3.el6_10.x86_64.rpm ipmitool-debuginfo-1.8.15-3.el6_10.x86_64.rpm i386 ipmitool-1.8.15-3.el6_10.i686.rpm ipmitool-debuginfo-1.8.15-3.el6_10.i686.rpm – Scientific Linux Development Team

An update for ipmitool is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for ksh is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code (CVE-2020-10188) SL6 x86_64 telnet-0.17-49.el6_10.x86_64.rpm telnet-debuginfo-0.17-49.el6_10.x86_64.rpm telnet-server-0.17-49.el6_10.x86_64.rpm i386 telnet-0.17-49.el6_10.i686.rpm telnet-debuginfo-0.17-49.el6_10.i686.rpm telnet-server-0.17-49.el6_10.i686.rpm – Scientif [More…]

Rights groups appeal to governments over COVID-19 surveillance

An update for telnet is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Kaspersky cleans up poisoned watering hole, Google presses pause on cookie crackdown
Hackers’ forum hacked, OGUsers database dumped (again)
Beyond Zoom: How Safe Are Slack and Other Collaboration Apps?
What to do you if your phone is lost or stolen

Losing your smartphone can be expensive, but the cost of the device may not be the final price you’ll be paying The post What to do you if your phone is lost or stolen appeared first on WeLiveSecurity

British Airways and Marriott UK data protection fines deferred again as coronavirus shutdown hits business
Pan-European group plans cross-border contact-tracing app – and promises GDPR compliance

security update

Firefox zero day in the wild: patch now!