Menu

Category Archives: All

Everything

WordPress Page Builder Plugin Bugs Threaten 1 Million Sites with Full Takeover
Adobe Kills 16 Critical Flaws in Acrobat and Reader, Digital Negative SDK
Thunderspy – why turning your computer off is a cool idea!
Chatbooks Confirms Breach After ‘Shiny Hunters’ Sell Data
Dating app user logins found on hacking forum
Anubis Malware Upgrade Logs When Victims Look at Their Screens

An update that solves 53 vulnerabilities and has 32 fixes is now available.

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

An update for libreswan is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

India releases data-use protocols for its contact-tracing app… after five weeks and 100 million downloads

An update for libreswan is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libreswan is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Papa don’t breach: Contracts, personal info on Madonna, Lady Gaga, Elton John, others swiped in celeb law firm ‘hack’
Incredible how you can steal data via Thunderbolt once you’ve taken the PC apart, attached a flash programmer, rewritten the firmware…
Astaroth’s New Evasion Tactics Make It ‘Painful to Analyze’
Unpatched Bugs in Oracle iPlanet Open Door to Info-Disclosure, Injection
Millions of Thunderbolt-Equipped Devices Open to ‘ThunderSpy’ Attack
Sphinx Malware Returns to Riddle U.S. Targets

Multiple CVE(s) were discovered in the src:wordpress package. CVE-2020-11026

Celebrity personal data taken in ransomware attack
Hacking group puts millions of Zoosk dating profiles up for sale
Chatbooks security breach. Users told to change their passwords
Mama mia! Nintendo in need of a plumber after leak sprays N64, GameCube, Wii code

An update that fixes two vulnerabilities is now available.

Mailman could be made to inject arbitrary content in the login page if it received a specially crafted input.

The Internet of Things in 2020: More vital than ever
Clearview AI won’t sell vast faceprint collection to private companies

Open Liberty 20.0.0.5 Runtime is now available from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Microsoft opens IoT bug bounty program

An update that fixes two vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Researchers detected 400 million malware infections in April 2020

The package firefox before version 76.0-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing and insufficient validation.

Chromium-browser 81.0.4044.138 fixes security issues: Multiple flaws were found in the way Chromium 81.0.4044.129 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code,

**MySQL 8.0.20** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-20.html CVEs fixed: CVE-2020-2759 CVE-2020-2761 CVE-2020-2762 CVE-2020-2763 CVE-2020-2765 CVE-2020-2770 CVE-2020-2774 CVE-2020-2779 CVE-2020-2780 CVE-2020-2804 CVE-2020-2812 CVE-2020-2814 CVE-2020-2853 CVE-2020-2892 CVE-2020-2893

**MySQL 8.0.20** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-20.html CVEs fixed: CVE-2020-2759 CVE-2020-2761 CVE-2020-2762 CVE-2020-2763 CVE-2020-2765 CVE-2020-2770 CVE-2020-2774 CVE-2020-2779 CVE-2020-2780 CVE-2020-2804 CVE-2020-2812 CVE-2020-2814 CVE-2020-2853 CVE-2020-2892 CVE-2020-2893

Are you ready, kids? I said, are you ready? Whoooooo has another update for you to see? Google Chromium! For browsing and tweeting (but not FTP) Google Chromium! If improved security be something you wish Google Chromium! Then run dnf while you flop like a fish! Google Chromium! Google Chromium! Google Chromium! Google Chromium! Ahem. […]

**MySQL 8.0.20** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-20.html CVEs fixed: CVE-2020-2759 CVE-2020-2761 CVE-2020-2762 CVE-2020-2763 CVE-2020-2765 CVE-2020-2770 CVE-2020-2774 CVE-2020-2779 CVE-2020-2780 CVE-2020-2804 CVE-2020-2812 CVE-2020-2814 CVE-2020-2853 CVE-2020-2892 CVE-2020-2893

Hackers infect authentic 2FA app to infect Mac devices with malware
Top celebrities data at risk after REvil ransomware hits famous law firm

security update

security update

Multiple security issues have been found in Thunderbird which could result in spoofing the displayed sender email address, denial of service or potentially the execution of arbitrary code.

DigitalOcean suffers data breach after leaving internal document online

– Release 0.24.1

**Version 1.4.4** This is a **service and security update** to the stable version 1.4 of Roundcube Webmail. It contains four fixes for recently reported security vulnerabilities as well a number of general improvements from our issue tracker. – Fix bug where attachments with Content-Id were attached to the message on reply (#7122) – Fix identity […]

**Version 1.4.4** This is a **service and security update** to the stable version 1.4 of Roundcube Webmail. It contains four fixes for recently reported security vulnerabilities as well a number of general improvements from our issue tracker. – Fix bug where attachments with Content-Id were attached to the message on reply (#7122) – Fix identity […]

One malicious MMS is all it takes to pwn a Samsung smartphone: Bug squashed amid Android patch batch

– Release 0.24.1

**Version 1.4.4** This is a **service and security update** to the stable version 1.4 of Roundcube Webmail. It contains four fixes for recently reported security vulnerabilities as well a number of general improvements from our issue tracker. – Fix bug where attachments with Content-Id were attached to the message on reply (#7122) – Fix identity […]

security update

DEF CON is canceled… No, for real. The in-person event is canceled. We’re not joking. It’s canceled. We mean it
Black Hat USA, DEF CON 28 Go Virtual
DDoS-for-hire service SuperiorStresser operator gets suspended sentence
Could this be the world’s most harmless IoT botnet?
Digital transformation could be accelerated by COVID‑19

The pandemic has highlighted the need for businesses to act with alacrity and prepare for the long haul – and to do so with cybersecurity in mind The post Digital transformation could be accelerated by COVID‑19 appeared first on WeLiveSecurity

5 common password mistakes you should avoid

Password recycling or using easy-to-guess passwords are just two common mistakes you may be making when protecting your digital accounts The post 5 common password mistakes you should avoid appeared first on WeLiveSecurity

Hackers Breach 3.5 Million MobiFriends Dating App Credentials
Report: Microsoft’s GitHub Account Gets Hacked
Flaws in 2 famous WordPress plugins put millions of sites at risk
E-commerce firm StorEnvy hacked; 1.5m plain-text accounts leaked
You won’t believe who’s heading up the UK’s Coronavirus tracing app…
Hackers hit Europe’s largest healthcare provider with Snake ransomware
Podcast: Shifting Cloud Security Left With Infrastructure-as-Code
If you miss the happier times of the 2000s, just look up today’s SCADA gear which still have Stuxnet-style holes
More crypto-stealing Chrome extensions swatted by Google

Updated libvncserver packages fix security vulnerability: libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value (CVE-2019-20788).

Updated roundcubemail packages fix security vulnerabilities: – Cross-Site Scripting (XSS) via malicious HTML content (CVE-2020-12625) – CSRF attack can cause an authenticated user to be logged out

Updated samba packages fix security vulnerabilities: A client combining the ‘ASQ’ and ‘Paged Results’ LDAP controls can cause a use-after-free in Samba’s AD DC LDAP server (CVE-2020-10700).

Updated qt4 packages fix security vulnerabilities: A double-free or corruption during parsing of a specially crafted illegal XML document (CVE-2018-15518).

Multiple security issues were discovered in the microdns plugin of the VLC media player, which could result in denial of service or potentially the execution of arbitrary code via malicious mDNS packets (CVE-2020-6071, CVE-2020-6072, CVE-2020-6073, CVE-2020-6077, CVE-2020-6078, CVE-2020-6079, CVE-2020-6080).

Updated matio packages fix a security vulnerability: Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c (CVE-2019-13107).

Bored at home? Cisco has just the thing: A shed-load of security fixes to install, from a Kerberos bypass to crashes
World’s Largest Private Torrent Site Filelist.ro Seized
FYI: Your browser can pick up ultrasonic signals you can’t hear, and that sounds like a privacy nightmare to some
Blue Mockingbird Monero-Mining Campaign Exploits Web Apps

security update

security update

security update

Hackers claim to breach Microsoft’s GitHub account; steal 500GB of data
Cisco Fixes High-Severity Flaws In Firepower Security Software, ASA
More and more organizations are falling to ransomware – will you be next?
Zoom Beefs Up End-to-End Encryption to Thwart ‘Zoombombers’
Vcrypt ransomware brings along a buddy to do the encryption
Over 300 websites taken down in just two weeks as UK public report suspicious emails
For six years Samsung smartphone users have been at risk from critical security bug. Patch now
Hackers Dumpster Dive for Taxpayer Data in COVID-19 Relief Money Scams
Smashing Security #177: Elon Musk, Roblox, and Love Bug author found
How to customize crypto policies in RHEL 8.2
Senior MP tells UK Defence Committee on 5G security: Russia could become China’s cyber-attack dog
Naikon APT Hid Five-Year Espionage Attack Under Radar
Fake news Facebook accounts used coronavirus to attract followers
Police nab InfinityBlack hackers
So you’ve set up MFA and solved the Elvish riddle, but some still think passwords alone are secure enough

Update to 2.53.2 If you have Lightning and/or Chatzilla extensions previously disabled, they are enabled after the update. Disable it again if needed (in about:addons), or remove completely (which can improve startup time).

Update to Samba 4.11.8

Update to Samba 4.11.8

ceph-14.2.9 GA Security fix for CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS Security fix for CVE-2020-1759 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions

Update to Samba 4.10.15