Menu

Monthly Archives: August 2020

An update that fixes one vulnerability is now available.

Software Properties could be made to manipulate the display.

Monday review – catch up on our latest articles and videos

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Reply-All storm sparked by student smut sees school system shut down Google Classroom for up to a week
Feds seize ‘largest ever’ haul of crypto-dosh from terrorists – including coins from ‘fake’ pandemic mask web store

An update that solves two vulnerabilities and has 6 fixes is now available.

Several vulnerabilities were fixed in JRuby, a 100% pure-Java implementation of Ruby. CVE-2017-17742

Updated webkit2 packages fix security vulnerabilities: The webkit2 package has been updated to version 2.28.3, fixing several security issues and other bugs.

The znc package has been updated to version 1.8.1, containing several bugfixes and enhancements. See the upstream change logs for details. References: – https://bugs.mageia.org/show_bug.cgi?id=26886

In libEtPan, a mail library, a STARTTLS response injection was discovered that affects IMAP, SMTP, and POP3. For Debian 9 stretch, this problem has been fixed in version

Updated mumble package fixes security vulnerability: OCB2 is known to be broken under certain conditions: https://eprint.iacr.org/2019/311

An update that fixes 14 vulnerabilities is now available.

In HtmlUnit, a GUI-Less browser for Java programs, malicious JavaScript code was able to execute arbitrary Java code on the application. For Debian 9 stretch, this problem has been fixed in version

Several vulnerabilities were discovered in net-snmp, a suite of Simple Network Management Protocol applications, which could lead to privilege escalation.

security update

PoC Exploit Targeting Apache Struts Surfaces on GitHub

Update to latest upstream stable version.

Mac Users Targeted by Spyware Spreading via Xcode Projects

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Critical Flaws in WordPress Quiz Plugin Allow Site Takeover
Mekotio: These aren’t the security updates you’re looking for…

Another in our occasional series demystifying Latin American banking trojans The post Mekotio: These aren’t the security updates you’re looking for… appeared first on WeLiveSecurity

UPDATE: Canon Ransomware Attack Results in Leaked Data, Report
Microsoft Defender casts a jaundiced eye over Citrix, slams services in quarantine on suspicion of being malware
Instagram Retained Deleted User Data Despite GDPR Rules

Several security issues were fixed in Salt.

Oracle and Salesforce targeted in €10bn GDPR lawsuit backed by profit-making litigation fund

An update that solves one vulnerability and has four fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

CREST: We are investigating NCC Group certification cheat sheet scandal – and not with NCC personnel
Australian government wants power to run cyber-response for businesses under attack
This NSA, FBI security advisory has four words you never want to see together: Fancy Bear Linux rootkit

Patch for CVE-2020-17353

Security fix for CVE-2019-20907, CVE-2020-14422. Provide a versioned pathfix3.7.py command.

NSA, FBI Warn of Linux Malware Used in Espionage Attacks

security update

CactusPete APT Hones Toolset, Resurfaces with New Espionage Targets
Vivaldi composes sweet ad-blocking symphony for users of browser’s Android version
Tor and anonymous browsing – just how safe is it?
What is the cost of a data breach?

The price tag is higher if the incident exposed customer data or if it was the result of a malicious attack, an annual IBM study finds The post What is the cost of a data breach? appeared first on WeLiveSecurity

Zoom Faces More Legal Challenges Over End-to-End Encryption
New Global Threat Landscape Report Reveals ‘Unprecedented’ Cyberattacks
ReVoLTE Attack Allows Hackers to Listen in on Mobile Calls
High-Severity TinyMCE Cross-Site Scripting Flaw Fixed

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has three fixes is now available.

An update that solves two vulnerabilities and has 6 fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Several security issues were fixed in Apache HTTP Server.

An update that fixes 6 vulnerabilities is now available.

Amazon Alexa ‘One-Click’ Attack Can Divulge Personal Data
You weren’t hacked because you lacked space-age network defenses. Nor because cyber-gurus picked on you. It’s far simpler than that
Twitter working to fix issue with 2FA feature

An apparent glitch is preventing a number of users from signing into their accounts The post Twitter working to fix issue with 2FA feature appeared first on WeLiveSecurity

Citrix Warns of Critical Flaws in XenMobile Server

An update that solves two vulnerabilities and has 6 fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has one errata is now available.

An update that fixes 8 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Irony, thy name is SANS: 28k records nicked from infosec training org after staffer’s email account phished
TikTok Surreptitiously Collected Android User Data Using Google-Prohibited Tactic

Reading Time: ~ 4 min. Even though the 2020 Back to School season may look very different from those in years past, there are a few things that will remain the same. First, since Back to School is often when parents and caregivers stock up on new clothes, tech, and school supplies for students, it’s […]

If you haven’t yet patched this critical hole in SAP NetWeaver Application Server, today is not your day
This is node joke. Tor battles to fend off swarm of Bitcoin-stealing evil exit relays making up about 25% of outgoing capacity at its height
Citrix warns of patch-ASAP-grade bugs in its working-from-home products, just as we’re all working from home

security update

Agent Tesla Spyware Adds Fresh Tricks to Its Arsenal
We spent way too long on this Microsoft, Intel, Adobe, SAP, Red Hat Patch Tuesday article. Just click on it, pretend to read it, apply updates
Two 0-Days Under Active Attack, Among 120 Bugs Patched by Microsoft

security update

Critical Intel Flaw Afflicts Several Motherboards, Server Systems, Compute Modules
Critical Adobe Acrobat and Reader Bugs Allow RCE
Black Hat 2020: Fixing voting – boiling the ocean?

With the big voting day rapidly approaching, can the security of the election still be shored up? If so, how? The post Black Hat 2020: Fixing voting – boiling the ocean? appeared first on WeLiveSecurity

Facial recognition – another setback for law enforcement
Cybersecurity Skills Gap Worsens, Fueled by Lack of Career Development
NCC Group admits its training data was leaked online after folders full of Crest pentest certification exam notes posted to Github
Samsung Quietly Fixes Critical Galaxy Flaws Allowing Spying, Data Wiping

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Researcher Publishes Bypass for Patch for vBulletin 0-Day Flaw

Reading Time: ~ 2 min. There’s no doubt we’ve all had to change our work habits as a result of the global coronavirus pandemic. Companies have had to adapt rapidly to smooth the transition to work from home. But companies will have to do more than adapt if they’re going to make cyber resilience a […]

Police face-recog tech use in Welsh capital of Cardiff was unlawful – Court of Appeal
“To be, or not to be,” vulnerable… How customers and partners can understand and track Red Hat security vulnerabilities
China now blocking ESNI-enabled TLS 1.3 connections, say Great-Firewall-watchers
Google Fixes Mysterious Audio Recording Blip in Smart Speakers
Peer-to-peer takes on a whole new meaning when used to spy on 3.7 million or more cameras, other IoT gear
Google Chrome Browser Bug Exposes Billions of Users to Data Theft
Brit bank Barclays probed amid claims bosses used high-tech to spy on staff, measure productivity
DDoS Attacks Cresting Amid Pandemic
TeamViewer Flaw in Windows App Allows Password-Cracking
Pen Test Partners: Boeing 747s receive critical software updates over 3.5″ floppy disks