Menu

Monthly Archives: July 2020

5 dating apps caught leaking millions of user-sensitive data

An update that fixes one vulnerability is now available.

Updated docker packages fix security vulnerability: A flaw was found in Docker when it creates network bridges that accept IPv6 router advertisements by default. This flaw allows an attacker who can execute code in a container to possibly spoof rogue IPv6 router

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in information disclosure, denial of service or potentially the execution of arbitrary code.

Updated tcpreplay package fixes security vulnerability: tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c (CVE-2020-12740).

Updated tomcat packages fix security vulnerability: When using Apache Tomcat versions 9.0.0.M1 to 9.0.34, if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a

Updated mailman package fixes security vulnerability: Up to mailman 2.1.29 when sending a file without a file extension (or an unknown file extension) then the file is stored in the list archive with the file extension .obj. Most web servers will try to assign a mime type

security update

Encrypted phone service EnroChat dismantled; leading to 800+ arrests
How to better protect your Roblox account from hackers with two-step verification (2SV)
Websites of eight US cities poisoned by malware skimming the credit card details of residents
22,900 MongoDB databases held to ransom by hacker threatening to report firms for GDPR violations
Hackers hijack Twitter account of Russia’s Ministry of Foreign Affairs, offer to sell stolen data

Update to Samba 4.12.5

Update to Samba 4.12.5

This update fixes CVE-2020-10177, CVE-2020-10994, CVE-2020-10379, CVE-2020-11538 and CVE-2020-10378.

# Python 3.6.11 Python 3.6.11 is the latest security fix release of Python 3.6. – bpo-39073: Disallow CR or LF in email.headerregistry.Address arguments to guard against header injection attacks. – bpo-38576: Disallow control characters in hostnames in http.client, addressing CVE-2019-18348. Such potentially malicious header injection URLs now cause a InvalidURL to be raised. –

3.48.1

Security update for CVE-2020-12695 (CallStranger)

LinkedIn was copying every keystroke of users until iOS 14 exposed it

security update

security update

DuckDuckGo collecting user browsing data without consent
Barclays Bank appeared to be using the Wayback Machine as a ‘CDN’ for some Javascript
Thousands of MongoDB databases ransacked, held for ransom

The cybercriminal behind the ransom raids on almost 23,000 databases threatens to leak the data and alert GDPR regulators The post Thousands of MongoDB databases ransacked, held for ransom appeared first on WeLiveSecurity

Use of open-source libraries leave web apps vulnerable to cyber attacks
Has your Roblox account been hacked to support Donald Trump?
E.U. Authorities Crack Encryption of Massive Criminal and Murder Network
Facebook hoaxes back in the spotlight – what to tell your friends
Fitness firm V Shred exposes 606 GB worth of sensitive customer data

An update that fixes 19 vulnerabilities is now available.

Ring Doorbell’s Police Partnerships Questioned Over Racial Bias

An update that contains security fixes can now be installed.

An update that solves three vulnerabilities and has three fixes is now available.

Google buys AR smart-glasses company North
Fighting BEC and EAC: Why whack-a-mole won’t work
F5 emits fixes for critical flaws in BIG-IP gear: Hopefully yours aren’t internet-facing while you ready a patch
Holy Guacamole! Researchers find Apache remote desktop software was silently pwnable for snooping on sessions

2.23 fixes CVE-2020-14929 (#1850048,#1850047) and new version (#1848786)

Update to latest upstream version

Fix CVE-2020-12695 (UPnP SUBSCRIBE misbehavior in hostapd WPS AP)

Euro police forces infiltrated encrypted phone biz – and now ‘criminal’ EncroChat users are being rounded up

security update

security update

Hold off that rush into the July 4 weekend – you may need this: Microsoft patches pwn-by-picture pitfalls in Win 10

Reading Time: ~ 2 min. WastedLocker Shuts Down US News Sites Over 30 news sites were compromised in the latest WastedLocker attack that affected many sites under a single parent company. Of the more than 30 companies targeted, eight belong to the Fortune 500 group and were in the early stages of a experiencing a […]

Facebook exposed user data to thousands of app developers
Users who don’t understand how to encrypt their emails won’t do it
Trojans, Backdoors and Droppers: The Most-Analyzed Malware
Microsoft releases emergency update to fix two serious Windows flaws

The out-of-band update plugs two remote code execution bugs in the Windows Codecs library, including one rated as critical The post Microsoft releases emergency update to fix two serious Windows flaws appeared first on WeLiveSecurity

Apache Guacamole Opens Door for Total Control of Remote Footprint
Facebook Privacy Glitch Gave 5K Developers Access to ‘Expired’ Data
47% of online MongoDB databases hacked demanding ransom
MongoDB ransom threats step up from blackmail to full-on wiping
FakeSpy Android Malware Spread Via ‘Postal-Service’ Apps
Cisco SMB kit harbors cross-site scripting bug: One wrong link click… and that’s your router pwned remotely
Smashing Security podcast #185: Bieber fever, Roblox, and ransomware

An update for rh-nginx116-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that solves one vulnerability and has 9 fixes is now available.

Several security issues were fixed in Samba.

Firefox could be made to crash or run programs as your login if it opened a malicious website.

A security update is now available for Red Hat Single Sign-On 7.4.1 adapters for Red Hat JBoss Enterprise Application Platform 6 Red Hat Product Security has rated this update as having a security impact of

133m records for sale as fruits of data breach spree keep raining down

Reading Time: ~ 4 min. After surveying more than 10,000 people in 50 states about their cybersecurity habits, we wound up with some pretty surprising results. Like the fact that tech experts demonstrate riskier behaviors than average Americans. But the most significant result of all was the fact that most Americans are more confident than […]

A security update is now available for Red Hat Single Sign-On 7.4.1 adapters for Red Hat JBoss Enterprise Application Platform 7.3 Red Hat Product Security has rated this update as having a security impact of

Reading Time: ~ 3 min. While the proliferation of encrypted DNS is being driven by consumer privacy, businesses will want to take notice. Encrypted DNS – also known as DNS over HTTPS, or DoH – obscures internet traffic from bad actors. But it also has the potential to decrease visibility for IT admins whose responsibility […]

New EvilQuest ransomware hits Mac devices through pirated software
Cisco Warns of High-Severity Bug in Small Business Switch Lineup
Alina Point-of-Sale Malware Spotted in Ongoing Campaign

security update

China’s insidious surveillance against Uyghurs with Android malware
EvilQuest: Inside A ‘New Class’ of Mac Malware
COVID‑19 contact tracing – technology panacea or privacy nightmare?

Can a technological intervention stem the pandemic while avoiding the privacy pitfalls of location tracking? The post COVID‑19 contact tracing – technology panacea or privacy nightmare? appeared first on WeLiveSecurity

Everything You Must Know About Common Venmo Scams
New Android Spyware Tools Emerge in Widespread Surveillance Campaign
Verified Instagram account running copyright infringement phishing scam
Microsoft issues critical fixes for booby-trapped images – update now!
Email Sender Identity is Key to Solving the Phishing Crisis
Microsoft Releases Emergency Security Updates for Windows 10, Server
Google stops pushing scam ads on Americans searching for how to vote

An update for ose-machine-config-operator-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

An update for containernetworking-plugins is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openshift is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenShift Container Platform release 4.2.36 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

An update for python-psutil is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Details of Beijing’s new Hong Kong security law revealed: Signals end to more than two decades of autonomy
Firefox 78 is out – with a mysteriously empty list of security fixes

An update for httpd24-nghttp2 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Tune in and watch live right here this week – it’s your email encryption wake-up call
Things that happen every four years: Olympic Games, Presidential elections, and now new Mac ransomware
After six months of stonewalling by Apple, app dev goes public with macOS privacy protection bypass
It’s happened again: AT&T sued for allegedly transferring victim’s number to thieves in $1.9m cryptocoin heist