Menu

Monthly Archives: July 2020

Garmin staggers back to its feet: Aviation systems seem to be lagging, though. Here’s why

An update that solves two vulnerabilities and has three fixes is now available.

Over 1000 Twitter staff and contractors had access to internal tools that helped hackers hijack accounts
ProLock ransomware – new report reveals the evolution of a threat

Several vulnerabilities were fixed in MilkyTracker, a music tracker for composing music in the MOD and XM module file formats. CVE-2019-14464

Several security issues were fixed in ClamAV.

SQLite could be made to crash or run programs if it processed a specially crafted query.

libslirp could be made to crash if it received specially crafted network traffic.

librsvg could be made to crash if it opened a specially crafted file.

Monday review – our recent stories revisited
UKIP blackmail, data breach sueball allegations were groundless, rules High Court
iOS14 shows Instagram opens camera even when users scroll photo feed

An update that fixes 8 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has 55 fixes is now available.

An update that solves four vulnerabilities and has 7 fixes is now available.

The following CVE(s) were reported against src:qemu: CVE-2017-9503

Apple co-founder Steve Wozniak sues YouTube over Bitcoin scams on his name

security update

Hackers leak 7m Dave.com accounts; 17m Couchsurfing accounts for sale
Psst.. You may want to patch this under-attack data-leaking Cisco bug – and these Ripple20 hijack flaws
It’s a Meow-nixed system, I know this: Purr-fect storm of 3,000+ insecure databases – and a data-wiping bot

0.9.24 release

Forex Trading and Online Security: Things to Look Out For
DJI drone app can transfer sensitive data and install malicious apps
DJI Drone App Riddled With Privacy Issues, Researchers Allege

Reading Time: ~ 2 min. ATM Jackpotting Attacks on the Rise ATM manufacturer Diebold Nixdorf has identified a malicious campaign that uses proprietary software to “jackpot” the machines. The attack requires malicious actors to breach the ATM manually and then use the software to force the machine to dispense cash at a rapid rate, known […]

Google adds security enhancements to Gmail, Meet and Chat

The tech giant introduces its own version of verified accounts in Gmail, rolls out increased moderation controls in Meet, and enhances phishing protection in Chat The post Google adds security enhancements to Gmail, Meet and Chat appeared first on WeLiveSecurity

NSA Urgently Warns on Industrial Cyberattacks, Triconex Critical Bug
News Wrap: Twitter Hack, Apple Under Fire and Global Privacy Finger Wags
Ransomware attack on fitness devices maker Garmin cripples operation
Cabinet Office takes over control of UK government data: Mundane machinery or Machiavellian manoeuvrings?
ASUS routers could be reflashed with malware – patch now!

An update that fixes two vulnerabilities is now available.

An update that fixes 10 vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has four fixes is now available.

Brit unis hit in Blackbaud hack inform students that their data was nicked, which has gone as well as you might expect
Malicious ‘Blur’ Photo App Campaign Discovered on Google Play
UK’s NCSC reveals Premier League footie clubs to be ripe pickings for cybercrooks: One almost lost £1m to BEC attack
Garmin knocked out by ransomware attack
Raytheon techie who took home radar secrets gets 18 months in the clink in surprise time fraud probe twist
Congrats, First American Title Insurance, you’ve made technology history. For all the wrong reasons
Cryptojacking botnet Prometei uses NSA exploit to steal data, mine Monero
Cisco Network Security Flaw Leaks Sensitive Data
UPDATED: Garmin Suffers Reported Ransomware Attack
Bridgecrew: Our mission is to set cloud security free
Privacy watchdogs urge videoconferencing services to boost privacy protections

The open letter highlights five security and privacy principles that require heightened attention from videoconferencing services The post Privacy watchdogs urge videoconferencing services to boost privacy protections appeared first on WeLiveSecurity

Sharp Spike in Ransomware in U.S. as Pandemic Inspires Attackers
A free iPhone from Apple? It’s possible, but there are some catches
Sports team nearly paid a $1.25m transfer fee… to cybercrooks
ASUS Home Router Bugs Open Consumers to Snooping Attacks
Cisco, Zoom and Others Must Bolster Security, Say Privacy Chiefs
New privacy tool ‘Fawkes’ blocks your images from facial recognition

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 19 vulnerabilities and has 162 fixes is now available.

An update that fixes one vulnerability is now available.

Smashing Security podcast #188: Dinner with Elon Musk and Kris Jenner
Twitter hack latest: Up to 36 compromised accounts had their private messages read – including a Dutch politician’s
Twitter: Hackers Accessed Private Messages for Elite Accounts
Politician amongst those who had their direct messages accessed during Twitter hack
Ubiquiti, go write on the board 100 times, ‘I must validate input data before using it’… Update silently breaks IDS/IPS
UK surveillance laws tightened up as most spying demands to be subject to warrants
Shocked I am. Shocked to find that underground bank-card-trading forums are full of liars, cheats, small-time grifters
New ‘BadPower’ attack on fast chargers can burn your smartphone
OilRig APT Drills into Malware Innovation with Unique Backdoor
Apple Security Research Device Program Draws Mixed Reactions

Reading Time: ~ 3 min. Most people are familiar with phishing attacks. After all, they’re one of the most common forms of data breach around. At their most basic, phishing attacks are attempts to steal confidential information by pretending to be an authorized person or organization. Standard phishing is not targeted. It relies on achieving […]

security update

Stick that in your named pipe and smoke it: Flaw in Citrix Workspace app could let remote attacker pwn host
UFO VPN leaks database again; gets taken over & destroyed by hackers
Argentine telecom company hit by major ransomware attack

Telecom Argentina says it has contained the attack and regained access to its systems without paying up The post Argentine telecom company hit by major ransomware attack appeared first on WeLiveSecurity

Lazarus Group Surfaces with Advanced Malware Framework
Going Down the Spyware Rabbit Hole with SilkBean Mobile Malware

Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine. CVE-2020-13934

Several security issues were fixed in FFmpeg.

Leak Exposes Private Data of Genealogy Service Users
Fake cryptocurrency trading app hits Mac users with malware

Several security issues were fixed in Python.

Capita’s bespoke British Army recruiting IT cost military 25k applicants after switch-on

Pillow could be made to crash if it opened a specially crafted file.

Evolution Data Server could be made to expose sensitive information over the network.

Several vulnerabilities have been found in librsvg, an SVG rendering library. This update corrects some denial of service issues via exponential element processing, stack exhaustion or application crash when processing specially crafted files, as well as some memory safety

Pakistan bans one Chinese app and gives TikTok a final warning to clean up its act
Twilio: Someone broke into our unsecured AWS S3 silo, added ‘non-malicious’ code to our JavaScript SDK
Emotet Returns in Malspam Attacks Dropping TrickBot, QakBot
It’s July 2020, and your PC or Mac can be pwned by a dodgy Photoshop file – Adobe emits critical patch batch
Coinbase stopped scammers from stealing an extra $280,000 during Twitter hack
Camera privacy bug found in Firefox Android in 2019 hasn’t been fixed yet
Bad: US govt says Chinese duo hacked, stole blueprints from just about everyone. Also bad: They extorted cash
Chris Vickery: AI Will Drive Tomorrow’s Data Breaches
Software firm leaks 25GB worth of subscription & Ancestry.com user data
7 VPN services leaked data of over 20 million users, says report

A report calls into question the providers’ security practices and dismisses their claims of being no-log VPN services The post 7 VPN services leaked data of over 20 million users, says report appeared first on WeLiveSecurity

Data breach reports down by one‑third in first half of 2020

The Identity Theft Resource Center doesn’t expect the trend to last, however The post Data breach reports down by one‑third in first half of 2020 appeared first on WeLiveSecurity