Menu

Category Archives: All

Everything

CVE-2020-12100: Parsing mails with a large number of MIME parts could have resulted in excessive CPU usage or a crash due to running out of stack memory. CVE-2020-12673: Dovecot’s NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. CVE-2020-10967: lmtp/submission:

Squid version update to 4.13 and security fixes

Hackers hijack Indian PM Narendra Modi Twitter account
Homeland Security demands a 911 for reporting security holes in federal networks: ‘Vulns in internet systems cause real-world impacts’
Smashing Security podcast #194: Carry on droning
U.S. Agencies Must Adopt Vulnerability-Disclosure Policies by March 2021
BEC Wire Transfers Average $80K Per Attack
Triple-Threat Cryptocurrency RAT Mines, Steals and Harvests
WordPress websites attacked via File Manager plugin vulnerability
Joker Spyware Plagues More Google Play Apps

An update that fixes one vulnerability is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

Phishing scam uses Sharepoint and One Note to go after passwords
Live Webinar: XDR and Beyond
Cisco Warns of Active Exploitation of Flaw in Carrier-Grade Routers

New F33 selinux-policy build.

Things are getting back to normal: Chinese hackers revert to bugging Tibetans after brief Euro campaign
Free ebook: Aligning cyber skills with the MITRE ATT&CK framework
China-based APT Debuts Sepulcher Malware in Spear-Phishing Attacks

security update

Magento Sites Vulnerable to RCE Stemming From Magmi Plugin Flaws
Security flaw allows bypassing PIN verification on Visa contactless payments

The vulnerability could allow criminals to rack up fraudulent charges on the cards without needing to know the PINs The post Security flaw allows bypassing PIN verification on Visa contactless payments appeared first on WeLiveSecurity

U.S. Voter Databases Offered for Free on Dark Web, Report
Magecart Credit-Card Skimmer Adds Telegram as C2 Channel
Hackers tricked Apple into approving malicious Adobe Flash Player update
FBI: Ring Smart Doorbells Could Sabotage Cops

An update that fixes two vulnerabilities is now available.

An update that solves 6 vulnerabilities and has 7 fixes is now available.

Pioneer Kitten APT Sells Corporate Network Access

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for bash is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Samsung supremo Lee Jae-yong indicted for fraud over role in 2015 merger deal that made him heir apparent

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Hack this email account… plz plz plz!
Someone’s getting a free trip to the US – well, not quite free. Brit bloke extradited to face $2m+ cyber-scam charges
Critical vuln that lets miscreants hijack computers via Slack? *Sucks in air* We’ll give you $1,750 for it
Apple Accidentally Notarizes Shlayer Malware Used in Adware Campaign
Charming Kitten Returns with WhatsApp, LinkedIn Effort
Stolen Fortnite Accounts Earn Hackers Millions Per Year
Critical Slack Bug Allows Access to Private Channels, Conversations

An update that fixes two vulnerabilities is now available.

– New upstream version (80.0)

New F32 selinux-policy build

This release includes the latest stable version of Apache **httpd**, version **2.4.46**. A security issue is addressed in this update: * **CVE-2020-11984** mod_proxy_uwsgi: Malicious request may result in information disclosure or RCE of existing file on the server running under a malicious process environment. For the full list of changes in this release, see

Updates to the latest upstream release of Eclipse. See the upstream release notes for details: https://www.eclipse.org/eclipseide/2020-06/noteworthy/ Also contains security fixes for CVE-2019-17566 and CVE-2019-17638.

Updates to the latest upstream release of Eclipse. See the upstream release notes for details: https://www.eclipse.org/eclipseide/2020-06/noteworthy/ Also contains security fixes for CVE-2019-17566 and CVE-2019-17638.

Microsoft reprieves SHA-1 deprecation in Edge 85 security baseline
The five best Kubernetes security practices

security update

security update

security update

security update

Use of unsafe yaml load was fixed in ros-actionlib, the Robot OS actionlib library. For Debian 9 stretch, this problem has been fixed in version

Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository (CVE-2020-24614). The fossil package has been updated to version 2.10.2, containing fixes for

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Several vulnerabilites have been reported against FreeRDP, an Open Source server and client implementation of the Microsoft RDP protocol. CVE-2014-0791

An update that solves one vulnerability and has one errata is now available.

An update that solves three vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

Faidon Liambotis discovered that Lilypond, a program for typesetting sheet music, did not restrict the inclusion of Postscript and SVG commands when operating in safe mode, which could result in the execution of arbitrary code when rendering a typesheet file with

Multiple security issues were found in the OpenEXR image library, which could result in denial of service and potentially the execution of arbitrary code when processing malformed EXR image files.

Multiple security issues have been found in Thunderbird which could result in the execution of arbitrary code or the unintended installation of extensions.

Reading Time: ~ 3 min. If you’ve landed on this blog, then there’s a good chance you’re already aware that DNS is undergoing a major overhaul. DNS 2.0—aka encrypted DNS, DNS over HTTPS, or DoH—is a method for encrypting DNS requests with the same HTTPS standard used by numerous websites, such as online banking, to […]

Before you head off for the weekend, you have patched your Pulse Secure VPNs, right? Wouldn’t want you to be pwned via a phishing link
Linux Server Security: A Getting Started Guide>

security update

Instagram ‘Help Center’ Phishing Scam Pilfers Credentials
DDoS extortion campaign targets financial firms, retailers

The extortionists attempt to scare the targets into paying by claiming to represent some of the world’s most notorious APT groups The post DDoS extortion campaign targets financial firms, retailers appeared first on WeLiveSecurity

Elon Musk Confirms, Tesla Factory a Target of Foiled Cyberattack
Sloppy Southern Water found leaking customers’ bills and account details

Reading Time: ~ 2 min. Thousands of Android Users fall Victim to Giveaway Fraud Upwards of 65,000 Android users were potentially compromised after installing a malicious app promising free giveaways. Over the year the scam was in effect, roughly 5,000 apps were spoofed to lure victims into downloading in exchange for a phony giveaway. In […]

An update that solves one vulnerability and has 36 fixes is now available.

An update that solves one vulnerability and has 35 fixes is now available.

Fake Android notifications – first Google, then Microsoft affected
DoJ Aims to Seize 280 Cryptocurrency Accounts Used by Hackers

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed (CVE-2020-15664).

evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a “begin TLS” response, eds reads additional data and evaluates it in a TLS context, aka “response injection”. (CVE-2020-14928)

Southern Water customers could view others’ personal data by tweaking URL parameters

An update that fixes one vulnerability is now available.

* The `readUvarint` function would run infinitely given specific input. The function is now terminating if more than 10 bytes of input have been read. Fixes [issue #35](https://github.com/ulikunitz/xz/issues/35) (CVE-2020-16845). * Supports the check-ID None and fixes “Checksum None is invalid” [issue #27](https://github.com/ulikunitz/xz/issues/27).

BeagleBoyz: 2020’s hottest country-rap band, or N. Korea hackers stealing millions. Only one way to find out…

security update

Ex-Cisco Employee Pleads Guilty to Deleting 16K Webex Teams Accounts
New Chrome, Firefox versions fix security bugs, bring productivity features

Chrome gets a new way of managing tabs while Firefox now features a new add-ons blocklist The post New Chrome, Firefox versions fix security bugs, bring productivity features appeared first on WeLiveSecurity

Facebook Hits Back At Apple’s iOS 14 Privacy Update
Magecart’s Success Paves Way For Cybercriminal Credit Card ‘Sniffer’ Market

The handler for the XkbSetNames request does not validate the request length before accessing its contents (CVE-2020-14345). An integer underflow exists in the handler for the XIChangeHierarchy request (CVE-2020-14346).

There is an integer overflow and a double free vulnerability in the way LibX11 handles locales. The integer overflow is a necessary precursor to the double free (CVE-2020-14363). References:

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed (CVE-2020-15664).

The read_xbm_body function in gui/image/qxbmhandler.cpp has a buffer over-read (CVE-2020-17507). References: – https://bugs.mageia.org/show_bug.cgi?id=27173

NSS could be made to expose sensitive information if it received a specially crafted input.

Russian cybercrime suspect arrested in $1m ransomware conspiracy

An update is now available for CloudForms Management Engine 5.10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Malicious Attachments Remain a Cybercriminal Threat Vector Favorite