Menu

Category Archives: All

Everything

Gaming controllers manufacturer exposed 1.1M customer records
Overlay Malware Leverages Chrome Browser, Targets Banks and Heads to Spain
How to make a stranger’s insecure 3D printer halt-and-catch-fire – plus more alerts from infosec world

New upstream version, fix CVEs

## 1.4.3 (12, Nov 2019) ### Security Improvements: – Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465).

– https://www.drupal.org/project/ckeditor/releases/7.x-1.19 – https://www.drupal.org/sa-contrib-2020-007

New upstream version, fix CVEs

## 1.4.3 (12, Nov 2019) ### Security Improvements: – Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465).

– https://www.drupal.org/project/ckeditor/releases/7.x-1.19 – https://www.drupal.org/sa-contrib-2020-007

Security fix for CVE-2020-11100)

An update that contains security fixes can now be installed.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

2 San Francisco Int. airport websites hacked with info-stealer code
Dutch Police takes down 15 DDoS-for-hire services in one week

An update that solves one vulnerability and has three fixes is now available.

An update that fixes 5 vulnerabilities is now available.

SFO Websites Hacked: Airport Discloses Data Breach
Apple, Google Team on Coronavirus Tracking – Sparking Privacy Fears
Sextortion emails and porn scams are back – don’t let them scare you!
WooCommerce Falls to Fresh Card-Skimmer Malware

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More…]

A vulnerability in libssh could allow a remote attacker to cause a Denial of Service condition.

3D printed fingerprints can unlock your device with 80% success rate
Critical VMware Bug Opens Up Corporate Treasure to Hackers
Apple App Store Riddled With Money-Sucking Fleeceware Apps
The pains – and pleasures? – of network security: Tell us exactly what you think about this corner of business IT
Travelex Pays $2.3M in Bitcoin to Hackers Who Hijacked Network in January

Reading Time: ~ 2 min. Malicious COVID-19 Websites Surge In recent months, more than 136 thousand new domains have been registered that reference the current COVID-19 outbreak, many of which have yet to be flagged. A large portion of these sites are distributing phishing campaigns with fake bank login forms and inaccurate URLs, including any […]

An update that fixes two vulnerabilities is now available.

The package libssh before version 0.9.4-1 is vulnerable to denial of service.

The package wireshark-cli before version 3.2.3-1 is vulnerable to arbitrary code execution.

The package chromium before version 81.0.4044.92-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure, access restriction bypass and insufficient validation.

The package firefox before version 75.0-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and access restriction bypass.

The package haproxy before version 2.1.4-1 is vulnerable to arbitrary code execution.

Compromised Zoom Credentials Swapped in Underground Forums
Ransomware scumbags leak Boeing, Lockheed Martin, SpaceX documents after contractor refuses to pay
Cloudflare Axes Google reCAPTCHA Due to Privacy, Price
Unique P2P Architecture Gives DDG Botnet ‘Unstoppable’ Status

security update

security update

Signal sends smoke, er, signal: If Congress cripples anonymous speech with EARN IT Act, we’ll shut US ops
Copycat Site Serves Up Raccoon Stealer
A billion-dollar US firm caught exposing highly sensitive database online
Report: Travelex paid hackers $2.3 million worth of Bitcoin after ransomware attack
Zoom takes action after meeting IDs leak in careless screenshots
Fleeceware on your iPhone? Don’t get caught out while penned up at home

An update that fixes 5 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Consumer reviewer Which? finds CAN bus ports on Ford and VW, starts yelling ‘Security! We have a problem…’

An update that fixes 5 vulnerabilities is now available.

Zoom Taps Ex-Facebook CISO Amid Security Snafus, Lawsuit

Security fix for CVE-2020-5247, CVE-2020-5249

This update incorporates fixes from the upstream glibc 2.29 stable release branch, including 3 fixes for medium severity security vulnerabilities. (CVE-2020-10029, CVE-2020-1752, CVE-2020-1751)

Cisco ‘Critical Update’ Phishing Attack Steals Webex Credentials
‘Unbreakable’ Smart Lock Draws FTC Ire for Deceptive Security Claims
Smashing Security #173: 5G fiascos, Zoom gloom, and butt biometrics
52k Iranian ID cards with selfies sold on dark web & hacking forum
Google removes Android VPN with ‘critical vulnerability’ from Play Store
Low-orbit internet banking fraud claim alleged to be a load of space junk
Cloudflare dumps Google’s reCAPTCHA, moves to hCaptcha as free ride ends (and something about privacy)
PowerPoint ‘Weakness’ Opens Door to Malicious Mouse-Over Attack
Dark_Nexus Botnet Compromises Thousands of ASUS, D-Link Routers
Fake Coronavirus vaccine, patients’ blood & saliva sold on dark web
ThreatList: Skype-Themed Apps Hide a Raft of Malware
Slack in the security spotlight – lessons for collaboration servers

Updated firefox packages fix security vulnerabilities: When reading from areas partially or fully outside the source resource with WebGL’s copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized,

Bisq Bitcoin exchange halts trade due to critical vulnerability
Top tips for videoconferencing security

ESET Chief Security Evangelist Tony Anscombe shares advice on how to keep your virtual meet-ups private and safe while you’re holed up at home during the pandemic The post Top tips for videoconferencing security appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

WhatsApp Axes COVID-19 Mass Message Forwarding

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For the oldstable distribution (stretch), these problems have been fixed

‘Fake Fingerprints’ Bypass Scanners with 3D Printing
COVID-19 CISO Checklist for Securing a Remote Workforce
Be careful when pulling images by short name
Linux Malware: The Truth About This Growing Threat>
Update Firefox again – more RCEs and an Android “takeover” bug too
Microsoft prevents Domain of Danger from falling into miscreants’ paws by forking out cash for corp.com
Microsoft project proposed to aid Linux IoT code integrity
As if the world couldn’t get any weirder, this AI toilet scans your anus to identify you
Please, just stop downloading apps from unofficial stores: Android users hit with ‘unkillable malware’
China and Taiwan aren’t great friends. Zoom sends chats through China. So Taiwan has banned Zoom
Serious Exchange Flaw Still Plagues 350K Servers
Login details of verified Zoom accounts posted on Dark Web
Visual Studio Code extension flags NPM vulnerabilities
New year, old threats: Malware peddlers went into overdrive in Q1, says Trend Micro
Flaw hunter bags $75,000 off Apple after duping Safari into spying through iPhone, Mac cameras without permission
xHelper: The Russian Nesting Doll of Android Malware
FIN6 and TrickBot Combine Forces in ‘Anchor’ Attacks
Italian email provider Email.it hacked with data on sale
600,000 people affected in email provider breach

The users’ personal data are now up for grabs on the dark web for anywhere between US$3,500 and US$22,000 worth of Bitcoin The post 600,000 people affected in email provider breach appeared first on WeLiveSecurity

Official Government COVID-19 Mobile Apps Hide a Raft of Threats

The package firefox before version 74.0.1-1 is vulnerable to arbitrary code execution.

Twitter warns users – Firefox might hold on to private messages