Menu

Category Archives: All

Everything

security update

Google Patches Chrome Browser Zero-Day Bug, Under Attack
RSAC 2020 Keynote: Changing the World’s False Perception of Cybersecurity
Android 11 to clamp down on background location access
Apple tries to have VirnetX VPN patent ruling overturned again, US Supremes say no… again
Sen. Schumer Pushes for TSA Employee Ban on TikTok App at Work
Free Download: The Ultimate Security Pros’ Checklist
Password killer FIDO2 comes bounding into Azure Active Directory hybrid environments
The “Cloud Snooper” malware that sneaks into your Linux servers

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Microsoft uses its expertise in malware to help with fileless attack detection on Linux

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) Mozilla: Out-of-bounds read when processing certain email messages (CVE-2020-6793) Mozilla: Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords (CVE-2020-6794) Mozilla: Crash processing S/MIME messages with multiple signatures (CVE-2020-6795) Mozilla: Incorrect p [More…]

python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c (CVE-2020-5312) python-pillow: reading specially crafted image files leads to allocation of large amounts of memory and denial of service (CVE-2019-16865) SL7 x86_64 python-pillow-2.0.0-20.gitd1c6db8.el7_7.x86_64.rpm python-pillow-debuginfo-2.0.0-20.gitd1c6db8.el7_7.x86_64.rpm python-pillow- [More…]

Smart speakers mistakenly eavesdrop up to 19 times a day
Google denies illegally slurping data off free student Chromebooks
Apple Takes Heat Over ‘Vulnerable’ iOS Cut-and-Paste Data
Open-Source AI Projects For Linux>
PayPal rejects report that exposed critical account takeover vulnerabilities
Data Breach Occurs at Agency in Charge of Secure White House Communications
Page Speed Optimization Best Practices
KidsGuard stalkerware leaks data on secretly surveilled victims
Samsung cops to data breach after unsolicited ‘1/1’ Find my Mobile push notification

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 5 vulnerabilities is now available.

It was discovered that the jQuery version embedded in OTRS, a ticket request system, was prone to a cross site scripting vulnerability in jQuery.extend().

Google purges 600 Android apps for “disruptive” pop-up ads
Apple chops Safari’s TLS certificate validity down to one year

libapache2-mod-auth-mellon could be made to redirect users to malicious sites.

libpam-radius-auth could be made to crash if it received specially crafted network traffic.

Do I need a VPN? A simple explanation & some real-life uses
Is your phone listening to you?

Do social media listen in on our conversations in order to target us with ads? Or are we just a bit paranoid? A little test might speak a thousand words. The post Is your phone listening to you? appeared first on WeLiveSecurity

An update that fixes 6 vulnerabilities is now available.

Google rolls out Titan keys to Europe, Japan. Plus: Group Policy bug is a feature, not a flaw, says Microsoft

security update

security update

Resolves: #1795838, #1802904 – Security fix for CVE-2020-8945

* Always use a light theme for rendering form controls. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-3862, CVE-2020-3864, CVE-2020-3865, CVE-2020-3867, CVE-2020-3868

Add patch for CVE-2020-6750 and related issues.

Update to 10.19.0

Update to 10.19.0

Update to Node.js 12.5.0

A vulnerability was found in pam_radius: the password length check was done incorrectly in the add_password() function in pam_radius_auth.c, resulting in a stack based buffer overflow.

Federal Agency that maintains secure communication for Trump got hacked

Ilja Van Sprundel reported a logic flaw in the Extensible Authentication Protocol (EAP) packet parser in the Point-to-Point Protocol Daemon (pppd). An unauthenticated attacker can take advantage of this flaw to trigger a stack-based buffer overflow, leading to denial of service

security update

Lawsuit Claims Google Collects Minors’ Locations, Browsing History
Active Attacks Target Popular Duplicator WordPress Plugin
Duped into running bogus virus scans at Office Depot? Dry your eyes with a small check from $35m settlement

– New upstream release (73.0.1)

This update backports a patch for CVE-2020-8112.

This update backports a patch for CVE-2020-8112.

ISS World “malware attack” leaves employees offline

Backport patches for CVE-2020-5313, CVE-2020-5312, CVE-2020-5311, CVE-2020-5310, CVE-2019-19911

Google kicks out 600 malicious apps from Play Store

An update for python-pillow is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for systemd is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The Amazon Prime phishing attack that wasn’t…
RSAC 2020: Editors’ Preview of Hottest Sessions, Speakers and Themes
Burning Man Tickets for $225? Yep, Too Good to Be True
Private details of 10.7 million MGM Hotel guests sold on Dark Web
ISS World Hit with Malware Attack that Shuts Down Global Computer Network

An update that solves one vulnerability and has 10 fixes is now available.

An update that fixes four vulnerabilities is now available.

Larry Tesler, of copy-and-paste fame, dies at 74
US and UK call out Russian hackers for Georgia attacks
Data of 10.6m MGM hotel guests posted for sale on Dark Web forum
Haken Malware Family Infests Google Play Store
Adobe fixes critical flaws in Media Encoder and After Effects
Washington state Senate passes bill to rein in facial recognition
‘Don’t tell anyone but I have a secret.’ There, that’s my security sorted
ToTok chat app tells users to ignore Google’s spyware warning
Google exiles 600 apps from Play Store for ‘disruptive advertising’ amid push to clean up Android souk’s image
Apple drops a bomb on long-life HTTPS certificates: Safari to snub new security certs valid for more than 13 months
Stuffing nonsense: Persistent cyberpunks are pummelling banks’ public APIs, warns Akamai
Google Bans 600 Android Apps for Obnoxious Ads
RSA Conference loses one more abbreviated tech giant after AT&T disconnects over Wuhan coronavirus fears

New proftpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Researchers recovered 9 billion email & password combos in 2019
We know what you did last summer: MGM’s hotel spinoff lost 10.7m guest records and now they’re on hacker forums
Critical Cisco Bug Opens Software Licencing Manager to Remote Attack
Cybergang Favors G Suite and Physical Checks For BEC Attacks
MGM Resorts data breach exposes details of 10.6 million guests

A number of celebrities, government officials and tech CEOs were also caught up in the incident The post MGM Resorts data breach exposes details of 10.6 million guests appeared first on WeLiveSecurity

GRU won’t believe it: UK and US call out Russia for cyber-attacks on Georgia last year
Ransomware attack forces 2-day shutdown of natural gas pipeline
Keen to check for ‘abnormal’ user behaviours? Microsoft talks insider risk, AWS imports and compliance at infosec shindig RSA
Nearly half of hospital Windows systems still vulnerable to RDP bugs
Popular YouTube gaming channel hacked to run crypto scam
Critical Adobe Flaws Fixed in Out-of-Band Update

An update that fixes 6 vulnerabilities is now available.

Smashing Security #166: What the Dickens! Ad ban thank you scam
MGM Resorts hacked: 10.6 million guests have their personal data exposed on hacking forum
Samsung freaks out smartphone owners with mysterious ‘1’ notification
MGM Grand Breach Leaked Details of 10.6 Million Guests Last Summer
Firefox 73.0.1 fixes crashes, blank web pages and DRM niggles

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0550

Linux and malware: Should you worry?

Malicious code is nothing to worry about on Linux, right? Hold your penguins. How Linux malware has gone from the sidelines to the headlines. The post Linux and malware: Should you worry? appeared first on WeLiveSecurity