Menu

Category Archives: All

Everything

An update that solves one vulnerability and has one errata is now available.

An update that fixes 8 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Irony, thy name is SANS: 28k records nicked from infosec training org after staffer’s email account phished
TikTok Surreptitiously Collected Android User Data Using Google-Prohibited Tactic

Reading Time: ~ 4 min. Even though the 2020 Back to School season may look very different from those in years past, there are a few things that will remain the same. First, since Back to School is often when parents and caregivers stock up on new clothes, tech, and school supplies for students, it’s […]

If you haven’t yet patched this critical hole in SAP NetWeaver Application Server, today is not your day
This is node joke. Tor battles to fend off swarm of Bitcoin-stealing evil exit relays making up about 25% of outgoing capacity at its height
Citrix warns of patch-ASAP-grade bugs in its working-from-home products, just as we’re all working from home

security update

Agent Tesla Spyware Adds Fresh Tricks to Its Arsenal
We spent way too long on this Microsoft, Intel, Adobe, SAP, Red Hat Patch Tuesday article. Just click on it, pretend to read it, apply updates
Two 0-Days Under Active Attack, Among 120 Bugs Patched by Microsoft

security update

Critical Intel Flaw Afflicts Several Motherboards, Server Systems, Compute Modules
Critical Adobe Acrobat and Reader Bugs Allow RCE
Black Hat 2020: Fixing voting – boiling the ocean?

With the big voting day rapidly approaching, can the security of the election still be shored up? If so, how? The post Black Hat 2020: Fixing voting – boiling the ocean? appeared first on WeLiveSecurity

Facial recognition – another setback for law enforcement
Cybersecurity Skills Gap Worsens, Fueled by Lack of Career Development
NCC Group admits its training data was leaked online after folders full of Crest pentest certification exam notes posted to Github
Samsung Quietly Fixes Critical Galaxy Flaws Allowing Spying, Data Wiping

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Researcher Publishes Bypass for Patch for vBulletin 0-Day Flaw

Reading Time: ~ 2 min. There’s no doubt we’ve all had to change our work habits as a result of the global coronavirus pandemic. Companies have had to adapt rapidly to smooth the transition to work from home. But companies will have to do more than adapt if they’re going to make cyber resilience a […]

Police face-recog tech use in Welsh capital of Cardiff was unlawful – Court of Appeal
“To be, or not to be,” vulnerable… How customers and partners can understand and track Red Hat security vulnerabilities
China now blocking ESNI-enabled TLS 1.3 connections, say Great-Firewall-watchers
Google Fixes Mysterious Audio Recording Blip in Smart Speakers
Peer-to-peer takes on a whole new meaning when used to spy on 3.7 million or more cameras, other IoT gear
Google Chrome Browser Bug Exposes Billions of Users to Data Theft
Brit bank Barclays probed amid claims bosses used high-tech to spy on staff, measure productivity
DDoS Attacks Cresting Amid Pandemic
TeamViewer Flaw in Windows App Allows Password-Cracking
Pen Test Partners: Boeing 747s receive critical software updates over 3.5″ floppy disks

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes four vulnerabilities is now available.

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Samba could be made to crash if it received specially crafted network traffic.

An update for libvncserver is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Pay ransomware crooks, or restore the network? Guess which way this city chose after weighing up the costs
Monday review – catch up with the latest articles

Reading Time: ~ 2 min. Multiple Individuals Charged for Twitter Hack Three people were charged with last month’s Twitter hack, which generated over $100,000 in bitcoin by hijacking high-profile accounts. Of the 130 accounts used to spread the Bitcoin scam, major names included Elon Musk and Bill Gates, who have been portrayed in similar past […]

xrdp-sesman service in xrdp can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them

Qualcomm Bugs Open 40 Percent of Android Handsets to Attack
Attackers Horn in on MFA Bypass Options for Account Takeovers
Have I Been Pwned Set to Go Open-Source

ruby-kramdown processes the template option inside Kramdown documents by default, which allows unintended read access (such as template=”/etc/passwd”) or unintended embedded Ruby code execution (such as a string that begins with template=”string://

An update that fixes 26 vulnerabilities is now available.

Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt

# rpki-client 6.7p1 * Security fix: Incorrect use of `EVP_PKEY_cmp` allowed an authentication bypass

The following CVE(s) have been reported against src:wpa. CVE-2019-10064

An update that fixes 7 vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

A use-after-free was found in iproute2, possibly allowing a Denial of Service condition.

A buffer overflow in gThumb might allow remote attacker(s) to execute arbitrary code.

Multiple vulnerabilities have been found in Apache, the worst of which could result in the arbitrary execution of code.

What happens when holes perfect for spyware are found in the engine room of millions of Qualcomm-based phones? Let’s find out
How did you spend your time at university? Pizza, booze, sleeping? This Oxford student is snooping on satellites

security update

Blackbaud data breach: What you should know

Here’s what to be aware of if your personal data was compromised in the breach at the cloud software provider The post Blackbaud data breach: What you should know appeared first on WeLiveSecurity

An update that contains security fixes can now be installed.

An update that fixes 12 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Hackers Dump 20GB of Intel’s Confidential Data Online
Augmenting AWS Security Controls
Business Email Compromise – fighting back with machine learning
Android user chucks potential $10bn+ sueball at Google over ‘spying’, ‘harvesting data’… this time to build supposed rival to TikTok called ‘Shorts’

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3253

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3344

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3233

So you’ve decided you want to write a Windows rootkit. Good thing this chap’s just demystified it in a talk
Chrome Web Store slammed again after 295 ad-injecting, spammy extensions downloaded 80 million times
Trump administration labels WeChat, TikTok ‘threats’ to national security, bans transactions with both
Capital One fined $80m for shoddy public cloud security. Yeah, same bank in that 106m customer-record hack
Black Hat 2020: Influence Campaigns Are a Cybersecurity Problem
Foreshadow returns to the foreground: Secrets-spilling speculative-execution Intel flaw lives on, say boffins
When it comes to hacking societies, Russia remains the master at sowing discord and disinformation online
Black Hat 2020: Mercedes-Benz E-Series Rife with 19 Bugs
Canon Admits Ransomware Attack in Employee Note, Report

security update

Beyond KrØØk: Even more Wi‑Fi chips vulnerable to eavesdropping

At Black Hat USA 2020, ESET researchers delved into details about the KrØØk vulnerability in Wi-Fi chips and revealed that similar bugs affect more chip brands than previously thought The post Beyond KrØØk: Even more Wi‑Fi chips vulnerable to eavesdropping appeared first on WeLiveSecurity

Black Hat 2020: Satellite Comms Globally Open to $300 Eavesdropping Hack
Intel NDA blueprints – 20GB of source code, schematics, specs, docs – spill onto web from partners-only vault
NSA shares advice on how to limit location tracking

The intelligence agency warns of location tracking risks and offers tips for how to reduce the amount of data shared The post NSA shares advice on how to limit location tracking appeared first on WeLiveSecurity

Yunus ‘ad±rc± found an issue in the SUBSCRIBE method of UPnP, a network protocol for devices to automatically discover and communicate with each other. Insuficient checks on this method allowed attackers to use vulnerable UPnP services for DoS attacks or possibly to bypass

High-Severity Cisco DoS Flaw Plagues Small-Business Switches

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 10 vulnerabilities is now available.

An update that solves 19 vulnerabilities and has 92 fixes is now available.

Think carefully about cyber insurance, says NCSC. But don’t worry about buying off ransomware crooks
A scam letter! Warn your vulnerable loved ones to be on their guard
Black Hat 2020: ‘Zero-Click’ MacOS Exploit Chain Uses Microsoft Office Macros
Porn blast disrupts bail hearing of alleged Twitter hacker