Menu

Category Archives: All

Everything

Wi-Fi kit spilling data with bad crypto – Huawei, eh? No, it’s Cisco. US giant patches Krook spy-hole bug in network gear

An update that fixes two vulnerabilities is now available.

An update that solves 10 vulnerabilities and has two fixes is now available.

An update that fixes two vulnerabilities is now available.

TrickBot Adds ActiveX Control, Hides Dropper in Images
Walgreens Mobile App Leaks Prescription Data
DoppelPaymer ransomware hits SpaceX, Tesla & Boeing’s parts manufacturer
RSA 2020 – Is your machine learning/quantum computer lying to you?

And how would you know if the algorithm was tampered with? The post RSA 2020 – Is your machine learning/quantum computer lying to you? appeared first on WeLiveSecurity

Delicious irony: Credit rating builder Loqbox lets customer details and card numbers slip after ‘sophisticated attack’
Siri and Google Assistant hacked in new ultrasonic attack
Let’s Encrypt issues one billionth free certificate
Ironpie robot vacuum can suck up your privacy
Fresh phish! Stripe scam baked and delivered in under an hour
Facebook sues data analytics firm OneAudience over malicious SDK

Several security issues were fixed in libarchive.

An update that fixes 8 vulnerabilities is now available.

An update that solves two vulnerabilities and has two fixes is now available.

An issue has been found in libapache2-mod-auth-openidc, an OpenID Connect authentication module for Apache. Due to insufficient validatation of URLs an Open Redirect vulnerability

An issues has been found in firebird2.5, an RDBMS based on InterBase 6.0. As UDFs can be used for a remote authenticated code execution (as user firebird), UDFs have been disabled in the default configuration

security update

An update that fixes one vulnerability is now available.

Israeli firm leaks database with addresses of millions of Americans

Updated wireshark packages fix security vulnerabilities: LTE RRC dissector memory leak. WiMax DLMAP dissector crash.

This update is based on upstream 5.5.6 and fixes atleast the following security vulnerability: A flaw was found in the way KVM hypervisor handled instruction emulation for the L2 guest when nested(=1) virtualization is enabled. In the

Updated hiredis packages fix security vulnerability: async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked (CVE-2020-7105).

Updated rsync packages fix security vulnerabilities: It was discovered that rsync incorrectly handled pointer arithmetic in zlib. An attacker could use this issue to cause rsync to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2016-9840,

Updated zsh packages fix security vulnerability: A privilege escalation vulnerability was discovered in zsh, whereby a user could regain a formerly elevated privelege level even when such an action should not be permitted (CVE-2019-20044).

The package chromium before version 80.0.3987.122-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

Bruce Schneier Proposes ‘Hacking Society’ for a Better Tomorrow
Hackers leak up to 4 TB of OnlyFans content for download

It was discovered that libusbmuxd incorrectly handled socket permissions. A remote attacker could use this issue to access services on iOS devices, contrary to expectations.

Beware secret lovers spreading Nemty ransomware
Israeli firm leaks addresses of millions of Americans & Europeans
Southern Water not such a phisherman’s phriend, hauls itself offline to tackle email lure
RSAC 2020: Ransomware a ‘National Crisis,’ CISA Says, Ramps ICS Focus
Patrick Wardle: Apple Devices Hit With Recycled macOS Malware
“Shark Tank” TV star loses almost $400,000 in Business Email Compromise scam
Clearview AI loses entire database of faceprint-buying clients to hackers
Ransomware wipes evidence, lets suspected drug dealers walk free
Firefox rolling out DNS-over-HTTPS privacy by default in the US
Google has right to censor conservative nonprofit on YouTube

An update that fixes 5 vulnerabilities is now available.

An update that solves 9 vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Your phone wakes up. Its assistant starts reading out your text messages. To everyone around. You panic. How? Ultrasonic waves
Police lose evidence to Ryuk ransomware attack; suspects walk free
Google’s War on Android App Permissions, 60 Percent Successful
RSAC 2020: GM’s Transportation Future Hinges on Cybersecurity

security update

security update

kr00k – Billions of Wi-Fi devices affected by encryption vulnerability

An uninitialized pointer vulnerability was discovered in pure-ftpd, a secure and efficient FTP server, which could result in an out-of-bounds memory read and potential information disclosure.

Cyber-wrath of Iran for top general’s assassination hasn’t progressed beyond snooping and nicking logins… yet
Clearview AI firm with photos of billions of unsuspecting users got HACKED
How one man could have flooded your phone with Microsoft spam
Facial recognition company Clearview AI hit by data theft

The startup came under scrutiny after it emerged that it had amassed 3 billion photos from social media for facial recognition software The post Facial recognition company Clearview AI hit by data theft appeared first on WeLiveSecurity

IoT Insecurity: When Your Vacuum Turns on You
Slickwraps data breach earns scorn for all
RSA 2020 – Hacking humans

What the human battle against biological viruses can teach us about fighting computer infections – and vice versa The post RSA 2020 – Hacking humans appeared first on WeLiveSecurity

Sophos was gearing up for a private life – then someone remembered the bike scheme
Brave beats other browsers in privacy study
Chrome 80 encryption change blocks AZORult password stealer
Facebook bans coronavirus ‘miracle cure’ ads
Did someone file your taxes before you?

With tax season – and tax scams – in full swing, here’s how fraudsters can steal your tax refund, and how you can avoid becoming a victim The post Did someone file your taxes before you? appeared first on WeLiveSecurity

If you’re serious about browser privacy, you should probably pass on Edge or Yandex, claims Dublin professor
Billions of Devices Open to Wi-Fi Eavesdropping Attacks
RSAC 2020: Smart Baby Monitor Vulnerable to Remote Hackers
HackerOne rewards bughunter who found critical security hole in… HackerOne
Smashing Security #167: Coronavirus scams and an exaggerated lion
Wi-Fi of more than a billion PCs, phones, gadgets can be snooped on. But you’re using HTTPS, SSH, VPNs… right?
Top 10 worst countries for Internet freedom & censorship
After blowing $100m to snoop on Americans’ phone call logs for four years, what did the NSA get? Just one lead
RSAC 2020: Lack of Machine Learning Laws Open Doors To Attacks
Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now
Is bug hunting a viable career choice?

With earnings of top ethical hackers surpassing hundreds of thousands of dollars, some would say yes The post Is bug hunting a viable career choice? appeared first on WeLiveSecurity

Exaggerated Lion and Business Email Compromise – Don’t send that check!
Hackers Cashing In On Healthcare Industry Security Weaknesses
Departing MI5 chief: Break chat app crypto for us, kthxbai
Apple’s iOS pasteboard leaks location data to spy apps
LTE vulnerability allows impersonation of other mobile devices
KrØØk: Serious vulnerability affected encryption of billion+ Wi‑Fi devices

ESET researchers uncover a previously unknown security flaw allowing an adversary to decrypt some wireless network packets transmitted by vulnerable devices The post KrØØk: Serious vulnerability affected encryption of billion+ Wi‑Fi devices appeared first on WeLiveSecurity

Iranian APT Targets Govs With New Malware
Unpatched Security Flaws Open Connected Vacuum to Takeover
Stalkerware Attacks Increased 50 Percent Last Year, Report
Rotherwood Healthcare AWS bucket security fail left elderly patients’ DNR choices freely readable online
Switch to Signal for encrypted messaging, EC tells staff
Taking a GPS tracker off your car isn’t ‘theft,’ court rules

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

It was discovered that pysaml2, a Python implementation of SAML to be used in a WSGI environment, was susceptible to XML signature wrapping attacks, which could result in a bypass of signature verification.

Updated squid packages fix security vulnerabilities: Jeriko One discovered that Squid incorrectly handled memory when connected to an FTP server. A remote attacker could possibly use this issue to obtain sensitive information from Squid memory (CVE-2019-12528).

Mind the gap: Google patches holes in Chrome – exploit already out there for one of them after duo spot code fix
Mystery zero-day in Chrome – update now!
RSAC 2020: Blockchain is ‘Garbage In’, Voting Needs Paper Ballots

security update

Google Patches Chrome Browser Zero-Day Bug, Under Attack
RSAC 2020 Keynote: Changing the World’s False Perception of Cybersecurity