Menu

Category Archives: All

Everything

Vietnam alleged to have hacked Chinese organisations in charge of COVID-19 response
Zero-click, zero-day flaws in iOS Mail ‘exploited to hijack’ VIP smartphones. Apple rushes out beta patch
CS:GO & Team Fortress 2 source code leaked – Virus alert for TF2
Stripe is absolutely logging your mouse movements on websites’ payment pages – for your own good, says CEO
Fast-Moving DDoS Botnet Exploits Unpatched ZyXel RCE Bug
After intense scrutiny, Zoom tightens up security with version 5. New features include not, er, spilling video calls to network snoops
This Zoom trick would have spared swearing politician’s blushes
Apple Patches Two iOS Zero-Days Abused for Years
Connected Home Hubs Open Houses to Full Remote Takeover
LA County Hit with DoppelPaymer Ransomware Attack
How gamification can boost your cybersecurity training

Security is not a game, but learning about it could be – here’s why adding the fun factor can help employees become more cyber-aware The post How gamification can boost your cybersecurity training appeared first on WeLiveSecurity

Notorious dark web child abuser arrested after int’l operation
Microsoft Issues Out-Of-Band Security Update For Office, Paint 3D
How to protect your Nintendo account from hackers with two-step verification (2SV)
Attention, lockdown DIY fans: UK hardware flinger Robert Dyas had credit card data and more skimmed from website
New iOS vulnerability being exploited to spy on Uyghurs in China
Small Businesses Tapping COVID-19 Loans Hit with Data Exposure
Porn scammers making $100,000 a month from sextortion emails
Attack of the clones: If you were relying on older Xilinx FPGAs to keep your product’s hardware code encrypted and secret, here’s some bad news
309 million Facebook users’ phone numbers found online
Yes, there’s lots of COVID-19-themed scuminess around – but otherwise the level of cybercrime is the same
Gaming company targeted by Chinese Winnti hackers
Free ebook for every reader: Unleash the power of your Apple fleet with Jamf

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Netflix says subscriptions just boomed but tells investors it’s no money heist and they should expect stranger things

An update for openshift-enterprise-hyperkube-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openshift is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Exercise tech firm Kinomap leaks 40GB database with 42M records
Banking.BR Android Trojan Emerges in Credential-Stealing Attacks
NFL Tackles Cybersecurity Concerns Ahead of 2020 Draft Day

security update

IBM == Insecure Business Machines: No-auth remote root exec exploit in Data Risk Manager drops after Big Blue snubs bug report
RCE Exploit Released for IBM Data Risk Manager
At last – a use for all those phishing emails you’ve been getting!
Work from home: Should your digital assistant be on or off?

Being at your beck and call is central to the “personality” of your digital friend, but there are situations when the device could use some time off The post Work from home: Should your digital assistant be on or off? appeared first on WeLiveSecurity

Hey there! Are you using WhatsApp? Your account may be hackable

Can someone take control of your WhatsApp account by just knowing your phone number? We ran a small test to find out. The post Hey there! Are you using WhatsApp? Your account may be hackable appeared first on WeLiveSecurity

Hacker returns $25 million after their IP address is exposed
Frippin’ heck: Watch out, chin-stroking prog rock fans. King Crimson distributor Burning Shed says it’s been hacked
Nintendo accounts are being hacked for fraudulent transactions
Oil and Gas Firms Targeted With Agent Tesla Spyware
Deepfakes and AI: Fighting Cybersecurity Fire with Fire

An update for git is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Cyberattackers Ramp Up to 1.5M COVID-19 Emails Per Day

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Something a bit phishy in your inbox? You can now email suspected frauds straight to Blighty’s web takedown cops

Reading Time: ~ 4 min. “One of the things about working in internet technology is nothing lasts forever… [Students] come to me and they say, ‘I want to do something that has an impact 20, 50, or 100 years from now.’ I say well maybe you should compose music because none of this technology stuff […]

The package webkit2gtk before version 2.28.1-1 is vulnerable to arbitrary code execution.

Facebook to alert us if we’ve been exposed to fake coronavirus news

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Bernd Edlinger discovered that malformed data passed to the SSL_check_chain() function during or after a TLS 1.3 handshake could cause a NULL dereference, resulting in denial of service.

Typosquatting RubyGems laced with Bitcoin-nabbing malware have been downloaded thousands of times
Weeks before US oil contract prices went negative, a spear-phishing crew went after oil firms. What did they get?
Google productises its own not-a-VPN secure remote access tool
Bad news: Cognizant hit by ransomware gang. Worse: It’s Maze, which leaks victims’ data online after non-payment

security update

security update

CFAA latest: Supremes to tackle old chestnut of what ‘authorized use’ of a computer really means in America
Mootbot Botnet Targets Fiber Routers with Dual Zero-Days
Maze Ransomware Attack Hits Cognizant
Dark web scammers selling ventilators & MP3 files to kill Coronavirus
Foxit PDF Reader, PhantomPDF Open to Remote Code Execution

The package openvpn before version 2.4.9-1 is vulnerable to denial of service.

What Type of Home Security System Should You Get?
Bitcoin Stealers Hide in 700+ Ruby Developer Libraries
Maze ransomware hits US giant Cognizant
Hackers drain $25 million in assets from dForce
Fan vibrations can be used to transmit data from air-gapped machines
Prioritize alerts and jump-start your investigations with Recorded Future’s free browser extension. Sign up now.
IT services giant Cognizant hit by Maze ransomware attack
New sextortion scam: “High level of risk. Your account has been hacked.”
Bot creates millions of fake eyeballs to rip off smart-TV advertisers
Tor Project loses a third of staff in coronavirus cuts: Unlucky 13 out as nonprofit hacks back to core ops
Monday review – the hot 13 stories of the week

An update that fixes one vulnerability is now available.

Ministry of Defence lowers supplier infosec standards thanks to COVID-19 outbreak
Contact-tracing or contact sport? Defections and accusations emerge among European COVID-chasing app efforts
Hackers selling 267 million Facebook records on hacker forum

It was discovered that there was a path-traversal issue in Apache Shiro, a security framework for the Java programming language. A specially-crafted request could cause an authentication bypass.

An update that fixes 26 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Fraud & hacking guides are the most sold item on dark web
Fake Coronavirus apps hit Android & iOS users with spyware, adware
Busted: Man streamed “worst child abuse content ever seen”

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file’s parent is a symlink to a directory outside of the

Following CVEs were reported against the jackson-databind source package :

Following CVEs were reported against the awl source package: CVE-2020-11728

DHS Urges Pulse Secure VPN Users To Update Passwords

security update

Fixes CVE-2020-1730

Security fix for CVE-2020-5260 From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.4.txt): > With a crafted URL that contains a newline in it, the credential > helper machinery can be fooled to give credential information for > a wrong host. The attack has been made impossible by forbidding > a newline character in any value

Bugfix release from Google for 80.0.3987.162. —- Update to 80.0.3987.162. Fixes the following CVEs: * CVE-2020-6450 * CVE-2020-6451 * CVE-2020-6452

Attacks on Linksys Routers Trigger Mass Password Reset
Critical bug in Google Chrome – get your update now

Reading Time: ~ 2 min. Florida City Sees Lasting Effects of Ransomware Attack Nearly three weeks after the City of Jupiter, Florida suffered a ransomware attack that took many of their internal systems offline, the city has yet to return to normal. City officials announced they would be working to rebuild their systems from backups, […]

Hackers use typosquatting to trojanize 700 libraries in Ruby Repository
That critical VMware vuln allowed anyone on your network to create new admin users, no creds needed