Menu

Category Archives: All

Everything

Security fix for CVE-2019-14869

rebase to upstream version 8.1911.0 ————————————————- new modules available: * ClickHouse output * generic REST API http output * docker API input * misc. external program input (takes output of specified binary as log source)

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Database with 1.2 billion people’s data leaked online without password
T-Mobile US hacked, Monero wallet app infected, public info records on 1.2bn people leak from database…

There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump.

It was discovered that pam-python, a PAM Module that runs the Python interpreter, has an issue in regard to the default environment variable handling of Python. This issue could allow for local root escalation in certain PAM setups.

RDP loves company: Kaspersky finds 37 security holes in VNC remote desktop software
ID Thieves Turn to Snail Mail as Juicy Target for Financial Crimes
Three Areas to Consider, to Focus Your Cyber-Plan

This update fixes CVE-2019-17545.

This update fixes CVE-2019-17545.

This update fixes CVE-2019-17545.

Update to latest stable (78.0.3904.97). This build contains a number of bug fixes and security updates. Changes can be viewed here: https://chromium.googles ource.com/chromium/src/+log/78.0.3904.86..78.0.3904.92?n=10000

Critical Flaws in VNC Threaten Industrial Environments

Type: Vulnerability. Multiple Asterisk Products are prone to an authorization-bypass vulnerability; fixes are available.

Type: Vulnerability. Asterisk Manager Interface is prone to an arbitrary command-execution vulnerability; fixes are available.

Type: Vulnerability. Asterisk Open Source is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Apache Shiro is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to an information-disclosure vulnerability and a denial-of-service vulnerability; fixes are availabl

Type: Vulnerability. Lexmark Services Monitor is prone to a directory-traversal vulnerability.

Type: Vulnerability. Apache Impala is prone to an authorization-bypass vulnerability; fixes are available.

Type: Vulnerability. ISC BIND is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Apache NiFi is prone to multiple information-disclosure vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Email Security Appliance is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. IBM WebSphere Application Server is prone to a directory-traversal vulnerability; fixes are available.

Type: Vulnerability. IBM Cloud Pak System is prone to an information-disclosure vulnerability; fixes are available.

Reading Time: ~ 1 min. Webroot has evolved its secure login offering from a secondary security code to a full two-factor authentication (2FA) solution for both business and home users. Webroot’s 2FA has expanded in two areas. We have: Implemented a time-based, one-time password (TOTP) solution that generates a passcode which is active for only […]

Data-Enriched Profiles on 1.2B People Exposed in Gigantic Leak
VIDEO: “Not All Cybercriminals Are Evil Geniuses”
Twitter finally upgrades its 2FA security feature. Mobile number no longer required!
Download: 2019 Security Team Assessment Template
Google plans to take Android back to ‘mainline’ Linux kernel
Iran’s APT33 sharpens focus on industrial control systems
Raccoon Stealer Malware Scurries Past Microsoft Messaging Gateways
News Wrap: Amazon Ring Risks, Stalkerware, and D-Link Router Flaws

Reading Time: ~ 2 min. Shade Ransomware Takes Crown as Most Distributed Variant Over the course of 2019, one ransomware variant, known as Shade, has taken over 50 percent of market share for ransomware delivered via email. Otherwise known as Troldesh, this variant receives regular updates to further improve it’s encrypting and methods of generating […]

Google Will Award $1M-Plus to People Who Can Hack Titan M Security Chip
Why cryptocoin scams work, and how to avoid them
Convicted Nigerian fraudster keeps a-fraudin’ from behind bars

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Bad news: ‘Unblockable’ web trackers emerge. Good news: Firefox with uBlock Origin can stop it. Chrome, not so much

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Senators Demand Amazon Disclose Ring Privacy Policies

Type: Vulnerability. Cisco IOS XR Software is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Cisco Unity Express is prone to a local command-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco Webex Centers are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Cisco Email Security Appliance is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Cisco SD-WAN Solution is prone to a cross-site request-forgery vulnerability; fixes are available.

Type: Vulnerability. Cisco Stealthwatch Enterprise is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Cisco DNA Spaces Connector is prone to a local command-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco Small Business RV Series Routers are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Cisco Unified Communications Manager is prone to an SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco Webex Teams for Windows is prone to a local arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Cisco DNA Spaces Connector is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to multiple information-disclosure vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Unified Communications Domain Manager is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco DNA Spaces: Connector is prone to an SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Lenovo LenovoPaper software is prone to an unspecified local privilege-escalation vulnerability.

Type: Vulnerability. Lenovo System Interface Foundation is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Unbound IPSEC Module is prone to a command-injection vulnerability; fixes are available.

Type: Vulnerability. Lenovo CCSDK is prone to an unspecified local privilege-escalation vulnerability.

Type: Vulnerability. Fortinet FortiOS is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Multiple Fortinet products are prone to hard-coded cryptographic key vulnerability; fixes are available.

Type: Vulnerability. Fortinet FortiOS is prone to a hardcoded cryptographic key vulnerability; fixes are available.

Type: Vulnerability. Multiple Cloud Foundry Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Lenovo ThinkPad USB-C Dock is prone to a unspecified denial-of-service vulnerability; fixes are available.

Microsoft Outlook for Android Bug Opens Door to XSS

Risk Level: Very Low. Type: Trojan.

Bon sang! French hospital contracts 6,000 PC-locking ransomware infection
Linux Webmin Servers Under Attack by Roboto P2P Botnet
Gnip Banking Trojan Shows Ongoing, Aggressive Development
DNS-over-HTTPS is coming to Windows 10
Android camera bug could have turned phones against their users
Official Monero site delivers malicious cash-grabbing wallet
Popular Apps on Google Play Store Remain Unpatched
Registers as “Default Print Monitor”, but is a malicious downloader. Meet DePriMon

ESET researchers have discovered a new downloader with a novel, not previously seen in the wild installation technique The post Registers as “Default Print Monitor”, but is a malicious downloader. Meet DePriMon appeared first on WeLiveSecurity

UK tax collectors warn contractors about being ripped-off – and not by HMRC for a change
Orange is the new green: Nigeria scammer bags $1m while operating behind bars
Smashing Security #155: Juicejacking, YouTube hacking, password slacking
Amnesty slams Facebook, Google over ‘pervasive surveillance’ business model
Tories change Twitter name to ‘factcheckUK’ during live TV debate
Security Firms, Nonprofits Team to Fight Stalkerware
Mozilla Bug Bounty Program Doubles Payouts, Adds Firefox Monitor

security update

Apache Solr Bug Gets Bumped Up to High Severity

Type: Vulnerability. Multiple IBM Products are prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Broadcom Brocade SANnav is prone to a security weakness; fixes are available.

Type: Vulnerability. Google Android is prone to multiple security-bypass vulnerabilities; fixes are available.

Type: Vulnerability. Schneider Electric Floating License Manager is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Dell EMC iDRAC is prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. Broadcom Brocade SANnav is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook for Android is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Atlassian Jira Service Desk Server and Jira Service Desk Data Center are prone to multiple security vulnerabilities; fixes are available.