Menu

Monthly Archives: June 2020

This is a security update for JBoss EAP Continuous Delivery 16.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

RIP ROP, COP, JOP? Intel to bring anti-exploit tech to market in this year’s Tiger Lake chip family
Retail giant Claire’s online store hacked after closing 3000 stores

This is a security update for JBoss EAP Continuous Delivery 14.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An error in Cyrus IMAP Server allows mailboxes to be created with administrative privileges.

Fake govt-issued COVID-19 contact tracing apps spread spyware

Update to upstream 3.6.14 release, and security fix for CVE-2020-13777.

Fixes CVE-2020-10995, CVE-2020-12244 and CVE-2020-10030

Update to upstream 3.6.14 release, and security fix for CVE-2020-13777. —- – Fix certificate chain validation involving the expired “AddTrust External Root”. – Disable RSA blinding during FIPS self-tests to avoid hanging if there is not enough entropy for `getrandom()` – Add `–waitresumption` option to `gnutls-cli` to force the client to wait for resumption data […]

Fixes CVE-2019-20479

– Update to 1.20.12 release – ifcfg-rh: handle “802-1x.{,phase2-}ca-path” (rh #1841395, CVE-2020-10754)

Update to upstream 3.6.14 release, and security fix for CVE-2020-13777.

Facebook paying for exploit to catch a predator, voting software security under the microscope…

Reading Time: ~ 2 min. Nintendo Accounts Breached Stemming from a cyber-attack back in April, Nintendo has just announced that roughly 300,000 user accounts have been compromised, though most belong to systems that are now inoperable. From the excessive unauthorized purchases, the attackers likely used credential-stuffing methods to access accounts and make digital purchases through […]

security update

security update

security update

An update that fixes three vulnerabilities is now available.

An update that fixes 10 vulnerabilities is now available.

An update that solves 25 vulnerabilities and has 132 fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Whatsapp blamed own users for failure to keep phone number repo off Google searches
Knoxville Ransomware Attack Leads to IT Network Shutdown
Wailing Wednesday follows Patch Tuesday as versions of Windows 10 stop playing nicely with plugged-in printers
How Big Tech Leveraged Agile Principles to Build Empires
Microsoft Joins Ban on Sale of Facial Recognition Tech to Police
Gamaredon group grows its game

Active APT group adds cunning remote template injectors for Word and Excel documents; unique Outlook mass-mailing macro The post Gamaredon group grows its game appeared first on WeLiveSecurity

Posh Spice’s perfume people pop up in Maze ransomware gang extortion effort
Android ‘ActionSpy’ Malware Targets Turkic Minority Group
Intel patches chip flaw that could leak your cryptographic secrets

An update that fixes four vulnerabilities is now available.

Babylon Health app leaked patients’ video consultations
Smashing Security podcast #182: Space Force, credit card fraud, and beep-ti-beep
Despite resolution not to give in to hackers’ ransom demands, some cities are still paying up after attacks
Suspicious wife fails to get good password advice from The Guardian

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

Facebook paid for a 0-day to help FBI unmask child predator
Twitter wants to know if you meant to share that article

An update for net-snmp is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Multiple security issues have been found in Thunderbird which could result in the setup of a non-encrypted IMAP connection, denial of service or potentially the execution of arbitrary code.

ConnectWise issues a slightly scary but unusually significant security advisory
Trend Micro pulls another app over security fears: This time, the Privacy Browser in the Dr Safety Android suite
As Uncle Sam flies spy drones over protest-packed cities, Homeland Security asks the public if that’s a good idea
Black Lives Matter Emails Deliver TrickBot Malware
Forget biz insider threats for a moment – let’s talk about partners turning rogue and installing spyware on phones
Microsoft Outlook Users Targeted By Gamaredon’s New VBA Macro
Black Lives Matter movement exploited to spread Trickbot malware
Kubernetes Falls to Cryptomining via Machine-Learning Framework
Now you’ve done it: Cyber attack targeted Australian brewery ‘n’ dairy biz Lion
Microsoft ships hefty patch load this month

The latest Patch Tuesday knocks out a record-high number of vulnerabilities, including new bugs in the SMB protocol The post Microsoft ships hefty patch load this month appeared first on WeLiveSecurity

Crooks hijack “Black Lives Matter” to spread zombie malware
How Facebook Helped FBI Capture a Notorious Child Abuser
Russia-linked Gamaredon hacker crew using Microsoft’s Visual Basic for Applications to pwn Microsoft’s Outlook
Podcast: Would You Use A Contact-Tracing Coronavirus App?

An update that fixes one vulnerability is now available.

Three vulnerabilities have been found in the MySQL Connector/J JDBC driver. For the oldstable distribution (stretch), these problems have been fixed

Multiple security issues have been found in Thunderbird which could result in the setup of a non-encrypted IMAP connection, denial of service or potentially the execution of arbitrary code.

Network traffic control for containers in Red Hat OpenShift

It was discovered that there was an escaping issue in libphp-phpmailer, an email generation utility class for the PHP programming language.

Bitcoin scammers take YouTube channels for a SpaceX ride

This update ships updated CPU microcode for some types of Intel CPUs and provides mitigations for the Special Register Buffer Data Sampling (CVE-2020-0543), Vector Register Sampling (CVE-2020-0548) and L1D Eviction Sampling (CVE-2020-0549) hardware vulnerabilities.

An update that solves four vulnerabilities and has one errata is now available.

Microsoft squishes 129 bugs with Patch Tuesday updates
How to scale endpoint management, improve employee productivity and reduce costs
Tencent floats bug bounties for its cloudy Linux and IoT OSes

security update

Another month, another way to smash Intel’s SGX security. Let’s take a closer look at these latest holes…
Gaming Security – Valve and Riot Games

security update

security update

Helping Remote Workers Overcome Remote Attacks
Snake Ransomware Delivers Double-Strike on Honda, Energy Co.
Vast hack‑for‑hire scheme targeted thousands of people, organizations

An obscure Indian company operated a scheme targeting banks, non-profits, politicians and journalists all over the world, a report says The post Vast hack‑for‑hire scheme targeted thousands of people, organizations appeared first on WeLiveSecurity

Critical Intel Flaws Fixed in Active Management Technology
Keepnet kerfuffle: Firing legal threats at bloggers did infosec biz more damage than its exposed database
YouTube scammers impersonated Elon Musk, SpaceX; stole $150k in BTC
14 IT certifications that will survive and thrive in the pandemic
Readers of a certain age will remember GPRS: Old insecure tech from turn of millennium still haunts 5G networks

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Encryption Utility Firm Accused of Bundling Malware Functions in Product

An update for expat is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Thanos Ransomware First to Weaponize RIPlace Tactic

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2432

hw: Special Register Buffer Data Sampling (SRBDS) (CVE-2020-0543) * hw: L1D Cache Eviction Sampling (CVE-2020-0549) * hw: Vector Register Data Sampling (CVE-2020-0548) SL6 x86_64 microcode_ctl-1.17-33.26.el6_10.x86_64.rpm microcode_ctl-debuginfo-1.17-33.26.el6_10.x86_64.rpm i386 microcode_ctl-1.17-33.26.el6_10.i686.rpm microcode_ctl-debuginfo-1.17-33.26.el6_10.i686.rpm [More…]

kernel: NULL pointer dereference due to KEYCTL_READ on negative key (CVE-2017-12192) SL6 x86_64 kernel-2.6.32-754.30.2.el6.x86_64.rpm kernel-debug-2.6.32-754.30.2.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-754.30.2.el6.i686.rpm kernel-debug-debuginfo-2.6.32-754.30.2.el6.x86_64.rpm kernel-debug-devel-2.6.32-754.30.2.el6.i686.rpm kernel-debug-devel-2.6.32-754.30.2.el [More…]

Lettuce Encrypt, Encrypt We Must: Hobby projects change name after Let’s Encrypt fires off trademark complaints
Babylon mobile health app mixes up patient consultation videos
Billions of devices affected by UPnP vulnerability
Google tracks browsing activity in Chrome’s Incognito mode – Lawsuit
An Internet of Trouble lies ahead as root certificates begin to expire en masse, warns security researcher
Nintendo warns 300,000 accounts have been hacked since early April
GnuTLS patches huge security hole that hung around for two years – worse than Heartbleed, says Google cryptoboffin
June’s Patch Tuesday reveals 23 ways to remotely pwn Windows – and over 100 more bugs that could ruin your day
Barcode Reader Apps on Play Store Infected with Adware
Thought you’d addressed those data-leaking Spectre holes on Linux? Guess again. The patches aren’t perfect