Menu

Monthly Archives: May 2020

Hacking group puts millions of Zoosk dating profiles up for sale
Chatbooks security breach. Users told to change their passwords
Mama mia! Nintendo in need of a plumber after leak sprays N64, GameCube, Wii code

An update that fixes two vulnerabilities is now available.

Mailman could be made to inject arbitrary content in the login page if it received a specially crafted input.

The Internet of Things in 2020: More vital than ever
Clearview AI won’t sell vast faceprint collection to private companies

Open Liberty 20.0.0.5 Runtime is now available from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Microsoft opens IoT bug bounty program

An update that fixes two vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Researchers detected 400 million malware infections in April 2020

The package firefox before version 76.0-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing and insufficient validation.

Chromium-browser 81.0.4044.138 fixes security issues: Multiple flaws were found in the way Chromium 81.0.4044.129 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code,

**MySQL 8.0.20** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-20.html CVEs fixed: CVE-2020-2759 CVE-2020-2761 CVE-2020-2762 CVE-2020-2763 CVE-2020-2765 CVE-2020-2770 CVE-2020-2774 CVE-2020-2779 CVE-2020-2780 CVE-2020-2804 CVE-2020-2812 CVE-2020-2814 CVE-2020-2853 CVE-2020-2892 CVE-2020-2893

**MySQL 8.0.20** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-20.html CVEs fixed: CVE-2020-2759 CVE-2020-2761 CVE-2020-2762 CVE-2020-2763 CVE-2020-2765 CVE-2020-2770 CVE-2020-2774 CVE-2020-2779 CVE-2020-2780 CVE-2020-2804 CVE-2020-2812 CVE-2020-2814 CVE-2020-2853 CVE-2020-2892 CVE-2020-2893

Are you ready, kids? I said, are you ready? Whoooooo has another update for you to see? Google Chromium! For browsing and tweeting (but not FTP) Google Chromium! If improved security be something you wish Google Chromium! Then run dnf while you flop like a fish! Google Chromium! Google Chromium! Google Chromium! Google Chromium! Ahem. […]

**MySQL 8.0.20** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-20.html CVEs fixed: CVE-2020-2759 CVE-2020-2761 CVE-2020-2762 CVE-2020-2763 CVE-2020-2765 CVE-2020-2770 CVE-2020-2774 CVE-2020-2779 CVE-2020-2780 CVE-2020-2804 CVE-2020-2812 CVE-2020-2814 CVE-2020-2853 CVE-2020-2892 CVE-2020-2893

Hackers infect authentic 2FA app to infect Mac devices with malware
Top celebrities data at risk after REvil ransomware hits famous law firm

security update

security update

Multiple security issues have been found in Thunderbird which could result in spoofing the displayed sender email address, denial of service or potentially the execution of arbitrary code.

DigitalOcean suffers data breach after leaving internal document online

– Release 0.24.1

**Version 1.4.4** This is a **service and security update** to the stable version 1.4 of Roundcube Webmail. It contains four fixes for recently reported security vulnerabilities as well a number of general improvements from our issue tracker. – Fix bug where attachments with Content-Id were attached to the message on reply (#7122) – Fix identity […]

**Version 1.4.4** This is a **service and security update** to the stable version 1.4 of Roundcube Webmail. It contains four fixes for recently reported security vulnerabilities as well a number of general improvements from our issue tracker. – Fix bug where attachments with Content-Id were attached to the message on reply (#7122) – Fix identity […]

One malicious MMS is all it takes to pwn a Samsung smartphone: Bug squashed amid Android patch batch

– Release 0.24.1

**Version 1.4.4** This is a **service and security update** to the stable version 1.4 of Roundcube Webmail. It contains four fixes for recently reported security vulnerabilities as well a number of general improvements from our issue tracker. – Fix bug where attachments with Content-Id were attached to the message on reply (#7122) – Fix identity […]

security update

DEF CON is canceled… No, for real. The in-person event is canceled. We’re not joking. It’s canceled. We mean it
Black Hat USA, DEF CON 28 Go Virtual
DDoS-for-hire service SuperiorStresser operator gets suspended sentence
Could this be the world’s most harmless IoT botnet?
Digital transformation could be accelerated by COVID‑19

The pandemic has highlighted the need for businesses to act with alacrity and prepare for the long haul – and to do so with cybersecurity in mind The post Digital transformation could be accelerated by COVID‑19 appeared first on WeLiveSecurity

5 common password mistakes you should avoid

Password recycling or using easy-to-guess passwords are just two common mistakes you may be making when protecting your digital accounts The post 5 common password mistakes you should avoid appeared first on WeLiveSecurity

Hackers Breach 3.5 Million MobiFriends Dating App Credentials
Report: Microsoft’s GitHub Account Gets Hacked
Flaws in 2 famous WordPress plugins put millions of sites at risk
E-commerce firm StorEnvy hacked; 1.5m plain-text accounts leaked
You won’t believe who’s heading up the UK’s Coronavirus tracing app…
Hackers hit Europe’s largest healthcare provider with Snake ransomware
Podcast: Shifting Cloud Security Left With Infrastructure-as-Code
If you miss the happier times of the 2000s, just look up today’s SCADA gear which still have Stuxnet-style holes
More crypto-stealing Chrome extensions swatted by Google

Updated libvncserver packages fix security vulnerability: libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value (CVE-2019-20788).

Updated roundcubemail packages fix security vulnerabilities: – Cross-Site Scripting (XSS) via malicious HTML content (CVE-2020-12625) – CSRF attack can cause an authenticated user to be logged out

Updated samba packages fix security vulnerabilities: A client combining the ‘ASQ’ and ‘Paged Results’ LDAP controls can cause a use-after-free in Samba’s AD DC LDAP server (CVE-2020-10700).

Updated qt4 packages fix security vulnerabilities: A double-free or corruption during parsing of a specially crafted illegal XML document (CVE-2018-15518).

Multiple security issues were discovered in the microdns plugin of the VLC media player, which could result in denial of service or potentially the execution of arbitrary code via malicious mDNS packets (CVE-2020-6071, CVE-2020-6072, CVE-2020-6073, CVE-2020-6077, CVE-2020-6078, CVE-2020-6079, CVE-2020-6080).

Updated matio packages fix a security vulnerability: Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c (CVE-2019-13107).

Bored at home? Cisco has just the thing: A shed-load of security fixes to install, from a Kerberos bypass to crashes
World’s Largest Private Torrent Site Filelist.ro Seized
FYI: Your browser can pick up ultrasonic signals you can’t hear, and that sounds like a privacy nightmare to some
Blue Mockingbird Monero-Mining Campaign Exploits Web Apps

security update

security update

security update

Hackers claim to breach Microsoft’s GitHub account; steal 500GB of data
Cisco Fixes High-Severity Flaws In Firepower Security Software, ASA
More and more organizations are falling to ransomware – will you be next?
Zoom Beefs Up End-to-End Encryption to Thwart ‘Zoombombers’
Vcrypt ransomware brings along a buddy to do the encryption
Over 300 websites taken down in just two weeks as UK public report suspicious emails
For six years Samsung smartphone users have been at risk from critical security bug. Patch now
Hackers Dumpster Dive for Taxpayer Data in COVID-19 Relief Money Scams
Smashing Security #177: Elon Musk, Roblox, and Love Bug author found
How to customize crypto policies in RHEL 8.2
Senior MP tells UK Defence Committee on 5G security: Russia could become China’s cyber-attack dog
Naikon APT Hid Five-Year Espionage Attack Under Radar
Fake news Facebook accounts used coronavirus to attract followers
Police nab InfinityBlack hackers
So you’ve set up MFA and solved the Elvish riddle, but some still think passwords alone are secure enough

Update to 2.53.2 If you have Lightning and/or Chatzilla extensions previously disabled, they are enabled after the update. Disable it again if needed (in about:addons), or remove completely (which can improve startup time).

Update to Samba 4.11.8

Update to Samba 4.11.8

ceph-14.2.9 GA Security fix for CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS Security fix for CVE-2020-1759 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions

Update to Samba 4.10.15

Update to Samba 4.10.15

California’s privacy warriors are back – and this time they want to take their fight all the way to the ballot box
Lazarus Group Hides macOS Spyware in 2FA Application
Fake crypto-wallet extensions appear in Chrome Web Store once again, siphoning off victims’ passwords

security update

security update

InfinityBlack Dismantled After Selling Millions of Credentials
Fake Zoom installers infect PCs with RevCode WebMonitor RAT
Almost a million WordPress websites targeted in massive campaign

An unknown threat actor is exploiting vulnerabilities in plugins for which patches have been available for months, or even years The post Almost a million WordPress websites targeted in massive campaign appeared first on WeLiveSecurity

GitHub blasts code-scanning tool into all open-source projects
Help us understand the shifting sands of network security: What’s working for you – and what’s not?
Professional data leakage: How did that security vendor get my personal data?

…and why are they selling it to other security vendors and product testers? The post Professional data leakage: How did that security vendor get my personal data? appeared first on WeLiveSecurity

Kaiji IoT malware brute-forces Linux devices for DDoS attacks
Microsoft Shells Out $100K for IoT Security
Firefox 76.0 released with critical security patches – update now
Adult streaming site CAM4 leaks 7 TB of data with 11 billion records
Ransomware Attack Takes Down Toll Group Systems, Again
Attackers Claim Identity of Financial NGO to Steal Sharepoint, Office Credentials
Air gap security beaten by turning PC capacitors into speakers

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from