Menu

Category Archives: All

Everything

These truly are the end times for TLS 1.0, 1.1: Firefox hopes to ‘eradicate’ weak HTTPS standard by blocking it
Hackers caught using CNET website to spread nasty malware
US govt accuses four Chinese army soldiers of hacking Equifax and siphoning 145m Americans’ personal info

The updated packages fix a security vulnerability: In Sudo before 1.8.31, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however,

Equifax Breach: Four Members of Chinese Military Charged with Hacking
Docker Registries Expose Hundreds of Orgs to Malware, Data Theft
Emotet Now Hacks Nearby Wi-Fi Networks to Spread Like a Worm
Owner of dark web Freedom hosting pleads guilty to host child abuse content
Coronavirus phishing attack disguises as a message from the Center for Disease Control
Google Chrome to start blocking downloads served via HTTP

Security researchers from Snyk discovered that the fix for CVE-2019-9658 was incomplete. Checkstyle, a development tool to help programmers write Java code that adheres to a coding standard, was still vulnerable to XML External Entity (XXE) injection.

Facebook encrypted messaging will ‘create hiding places for child abuse’
FBI director warns of sustained Russian disinformation threat
Frustrated author cybersquats novelist’s website
How to bring security into agile development and CI/CD
Home anti-virus products put to the test by AV-Comparatives – which received the highest score?

an out-of-bounds write vulnerability due to an integer overflow was reported in libexif, a library to parse exif files. This flaw might be leveraged by remote attackers to cause denial of service, or potentially execute arbitrary code via crafted image files.

Several security issues were fixed in libxml2.

Several security issues were fixed in Qt.

Facebook loses control of its own Twitter account in hacker attack – and more news

Add patch for CVE-2020-6750 and related issues.

Emergency call service in Australia to use AI to detect signs of heart attack

An update that fixes 38 vulnerabilities is now available.

Update to Node.js 12.15.0

Update to Node.js 12.15.0

Update to Node.js 12.15.0

libasr-1.0.4, opensmtpd-6.6.2p1 update

libasr-1.0.4, opensmtpd-6.6.2p1 update

Facebook’s Twitter account is hijacked by notorious OurMine hacking group
Dark web hackers selling payment card data of half a million Indians
Wacom Tablet Data Exfiltration Raises Security Concerns

Resolve buffer overflow in TexOpen() function, CVE-2019-19601

Resolves: #1796107, #1796109 – Security fix for CVE-2019-19921

Update to upstream 2.0.1 release for CVE-2019-10747

Update to upstream 1.3.2 release for CVE-2019-10746

MinGW cross compiled SDL 2.0.10, fixing a number of CVE issues.

Update to 2.40.0. —- MinGW cross compiled gdk-pixbuf 2.36.12 release, fixing various CVE’s.

Google Chrome to block file downloads – from .exe to .txt – over HTTP by default this year. And we’re OK with this
Critical Android Bluetooth Bug Enables RCE, No User Interaction Needed

security update

security update

The Oscar nominated movie you just downloaded could be a malware

Reading Time: ~ 2 min. Tax Season Brings Emotet to the Front As Americans prepare for tax season, Emotet authors have started a new campaign that imitates a W-9 tax form requested by the target. As with most malicious phishing, an attached document asks users to enable macros when viewing the files. This campaign can […]

Google Chrome To Bar HTTP File Downloads
RobbinHood – the ransomware that brings its own bug
Uncle Sam tells F-35B allies they’ll have to fly the things a lot more if they want to help out around South China Sea
Dutch university paid $220,000 ransom to hackers after Christmas attack
Critical Citrix RCE Flaw Still Threatens 1,000s of Corporate LANs
Day 4 of outage: UK’s Manchester police deploy exciting new carbon-based method to record crime
Phishing Campaign Targets 250 Android Apps with Anubis Malware
Apple fined €25 million for deliberately slowing down old iPhones
The RSAC 2020 Trend Report

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that fixes four vulnerabilities is now available.

Researchers transmit data covertly by altering screen brightness
Android users at risk from Bluetooth hijack attack, and are warned of “short distance worm” threat
Facebook, Google, YouTube order Clearview to stop scraping faceprints
Wacom driver caught monitoring third-party software use
Cybercrooks busted for multimillion-dollar identity fraud
Magecart Gang Attacks Olympic Ticket Reseller and Survival Food Sites

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

Android owners – you’ll want to get these latest security patches, especially for this nasty Bluetooth hijack flaw
How Technology Has Altered the Education Landscape
Good: IT admins scrambled to patch 80 per cent of public-facing Citrix boxes to close nightmare hijack hole
Hackers can steal data from air-gapped PC using screen brightness
Metamorfo Returns with Keylogger Trick to Target Financial Firms
U.S. Finance Sector Hit with Targeted Backdoor Campaign
Shoe with GPS embedded insole tracks ‘lost’ alzheimer’s & dementia patients
Update now – WhatsApp flaw gave attackers access to local files
How your network could be hacked through a Philips Hue smart bulb
Wacom drawing tablets are spying on every app you open, and sending the data back to Wacom
Twitter bans deepfakes, but only those ‘likely to cause harm’
Researchers reckon 500k PCs infested with malware after dodgy downloads install even more nasties from Bitbucket

This package allowed ../ directory traversal to access private resources because resource matching did not ensure that pathnames were in a canonical format.

How your screen’s brightness could be leaking data from your air-gapped computer

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in Pillow.

Google’s Chrome 80 clamps down on cookies and notification spam
Charming Kitten Uses Fake Interview Requests to Target Public Figures
Dropbox Passes $1M Milestone for Bug-Bounty Payouts
Android pulls 24 ‘dangerous’ malware-filled apps from Play Store
Smashing Security #164: A bitter pill to swallow
LCD pwn System: How to modulate screen brightness to covertly transmit data from an air-gapped computer… slowly
Yahoo! hack! payout! nearly! approved! and! the! question! is! how! to! spend! 60! cents!?
WhatsApp flaw gave hackers access to files from Windows and Macs
Terrifying bug in WhatsApp allows hackers to steal files. So get patching all nine of you using it on the desktop
Sketchy behavior? Wacom tablet drivers phone home with names, times of every app opened on your computer
CamuBot Banking Trojan Returns In Targeted Attacks
Time to patch your lightbulb? Researchers demonstrate Philips Hue exploit
Hackers can use flaw in Philips smart light bulbs to spread malware
New Lemon Duck Malware Campaign Targets IoT, Large Manufacturers
RIP FTP? File Transfer Protocol switched off by default in Chrome 80
Oh ****… Sudo has a ‘make anyone root’ bug that needs to be patched – if you’re unlucky enough to enable pwfeedback
Man pleads guilty to hacking Nintendo & possession of child pornography