Menu

Monthly Archives: April 2020

Digital wallet app leaks millions of users’ credit cards & Govt IDs

This update is based on upstream 5.5.15 and fixes some security related issues related to use after free and null pointer dereferences and also some other bugfixes. Other fixes in this update:

Updated firefox packages fix security vulnerabilities: Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free (CVE-2020-6819).

Updated python-ntlk package fixes security vulnerability: A vulnerability was found in NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ in an NLTK package (ZIP archive) that is mishandled during extraction

The updated packages fix a security vulnerability: In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number

libmtp is a library for communicating with MTP aware devices. The Media Transfer Protocol (commonly referred to as MTP) is a devised set of custom extensions to support the transfer of music files on USB digital audio players

– New upstream version (74.0.1), fixed 0day vulnerability

Hacker defaces Escrow.com by hacking GoDaddy employee’s account
Bugs allowed hackers to hijack & activate Mac, iPhone cameras
Firefox Zero-Day Flaws Exploited in the Wild Get Patched

Two security issues have been found in the Mozilla Firefox web browser, which could result in the execution of arbitrary code. For the oldstable distribution (stretch), these problems have been fixed

An update that fixes one vulnerability is now available.

A flaw was reported in the DTLS protocol implementation in GnuTLS, a library implementing the TLS and SSL protocols. The DTLS client would not contribute any randomness to the DTLS negotiation, breaking the security guarantees of the DTLS protocol.

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code.

Watch: Rare Second World War footage of Bletchley Park-linked MI6 intelligence heroes emerges, shared online

Security fix for CVE-2020-10188

security update

Not only is Zoom’s strong end-to-end encryption not actually end-to-end, its encryption isn’t even that strong
NSO Group: Facebook tried to license our spyware to snoop on its own addicts – the same spyware it’s suing us over

security update

security update

Reading Time: ~ 2 min. For the past several years, Webroot and its partners have conducted a series of studies aimed at better understanding the attitudes, perspectives, and behaviors related to cyber hygiene in United States. This helps users determine which behaviors put them most at risk and which behavioral changes could help increase their […]

Self-Propagating Malware Targets Thousands of Docker Ports Per Day
Cloud Providers, CDNs Team Up to Battle Internet Routing Attacks
Hacking the iOS/macOS webcam – Apple pays out $75,000 to bug hunter
OGUsers hacking forum hacked; entire database dumped on rival forum
5 things you can do today to make Zooming safer

An update that fixes one vulnerability is now available.

Spearphishing Campaign Exploits COVID-19 To Spread Lokibot Infostealer

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

‘Zombie’ Windows win32k bug reanimated by researcher
Watch out for the new wave of COVID-19 scams, warns IRS

An update that fixes 6 vulnerabilities is now available.

Zoom vows to spend next 90 days thinking hard about its security and privacy after rough week, meeting ID war-dialing tool emerges
If you use Twitter with Firefox in a shared computer account, you may have slightly spilled some private data on that PC
Why is ransomware still a thing? One-in-three polled netizens say they would cave to extortion demands
Google Squashes High-Severity Flaws in Chrome Browser

A regression in GnuTLS breaks the security guarantees of the DTLS protocol.

Work from home: Securing RDP and remote access

As work from home is the new norm in the coronavirus era, you’re probably thinking of enabling remote desktop connections for your off-site staff. Here’s how to do it securely. The post Work from home: Securing RDP and remote access appeared first on WeLiveSecurity

Dark Web child abuse gang busted; 15TB of files seized
Zoom Removes Data-Mining LinkedIn Feature
Don’t get locked out of your own website – update this WordPress plugin now!
Terabytes of OnlyFans data being sold on hacking forum
In COVID-19 Scam Scramble, Cybercrooks Recycle Phishing Kits

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Rethinking VPN: Tailscale startup packages Wireguard with network security
44M Digital Wallet Items Exposed in Key Ring Cloud Misconfig
Zoom promises to improve its security and privacy as usage (and concern) soars
Emerging MakeFrame Skimmer from Magecart Sets Sights on SMBs

An update is now available for Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Phone carriers must authenticate calls to fight robocalls, says FCC
Smashing Security #172: UncleF***Face

An update for haproxy is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

COVID-19 forces browser makers to continue supporting TLS 1.0
“World’s most secure online backup” provider exposes 135M records
Microsoft finds itself in odd position of sparing elderly, insecure protocols: Grants stay of execution to TLS 1.0, 1.1
For the past five years, every FBI secret spy court request to snoop on Americans has sucked, says watchdog
Wiper Malware Called “Coronavirus” Spreads Among Windows Victims

security update

Coronavirus ‘Financial Relief’ Phishing Attacks Spike
Cloudflare family-friendly DNS service flubs first filtering foray: Vital LGBTQ, sex-ed sites blocked ‘by mistake’
Cyberscum target Microsoft SQL Server boxen – and some careless sysadmins were reinfected after cleaning it out
Marriott Hotels hacked AGAIN: Two compromised employee logins abused to siphon off 5.2m guests’ personal info
Critical WordPress Plugin Bug Can Lock Admins Out of Websites
Hackers mining Monero on Microsoft SQL databases for last 2 years

The krb5 PAM module (pam_krb5.so) had a buffer overflow that might have caused remote code execution in situations involving supplemental prompting by a Kerberos library.

Two Zoom Zero-Day Flaws Uncovered
Marriott hacked again, 5.2 million guests affected

Bad actors accessed a range of personally identifiable information, including names, dates of birth and a lot more The post Marriott hacked again, 5.2 million guests affected appeared first on WeLiveSecurity

A vulnerability was discovered in python-bleach, a whitelist-based HTML-sanitizing library. Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to a regular expression denial

Top Email Protections Fail in Latest COVID-19 Phishing Campaign
Bill Gates’s YouTube ‘Bitcoin giveaway’ is a big fat scam
QR code generator scam steals thousands in Bitcoin
At the Supreme Court, Morrisons pops data breach liability win into its trolley – but it’s not a get-out-of-compo free card for businesses
Coronavirus con artists continue to spread infections of their own

The scam machine shows no signs of slowing down, as fraudsters dispense bogus health advice, peddle fake testing kits and issue malware-laced purchase orders The post Coronavirus con artists continue to spread infections of their own appeared first on WeLiveSecurity

Reading Time: ~ 4 min. It’s a nightmare, it’s inconvenient, and it’s inevitable. Losing or having your smart device stolen poses a significant, looming privacy risk— we just don’t like to think about it. However, this is an instance where hiding your head in the sand will only make you more susceptible to attack. The […]

Marriott hacked AGAIN – Millions of guests’ data accessed by hackers

An update that fixes one vulnerability is now available.

Microsoft’s Edge browser to get breached credential alerts
Apple’s latest macOS Catalina update mysteriously borks SSH for some unlucky fans. What could be the cause?

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the idm:DL1 module is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Zoom’s end-to-end encryption isn’t actually end-to-end at all. Good thing the PM isn’t using it for Cabinet calls. Oh, for f…

An update for nss-softokn is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Australian state will install home surveillance hardware to make sure if you’re in virus isolation, you stay there
Singapore government scraps physical 2FA tokens for government services