Menu

Category Archives: All

Everything

Type: Vulnerability. The Booking and Availability Management Tools module for Drupal is prone to an access-bypass vulnerability; fixes are available.

Type: Vulnerability. ISC BIND is prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. Schneider Electric ProClima is prone to multiple remote code-execution vulnerabilities; fixes are available.

Type: Vulnerability. NetApp SnapManager for Oracle is prone to an unspecified local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Fortinet FortiMail is prone to multiple remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Trend Micro Anti-Threat Toolkit is prone to a remote code-execution vulnerability.

Bedside Hotel Robot Hacked to Stream In-Room Video

Reading Time: ~ 3 min. Entrepreneur Jim Rohn once said, “Time is more valuable than money. You can get more money, but you cannot get more time.” I think anyone involved in running a business can relate to this statement, but it carries a particularly deep meaning to those of us who deal with cybersecurity. […]

Fujitsu Wireless Keyboard Plagued By Unpatched Flaws
ThreatList: Google’s Advertising Network Dominates Global Data Collection

An update that solves 16 vulnerabilities and has four fixes is now available.

Firefox, Chrome Bugs Allow Arbitrary Code-Execution
Alexa and Google Home phishing apps demonstrated by researchers
Hacker breached servers used by NordVPN

The package pacman before version 5.2.0-1 is vulnerable to arbitrary command execution.

The package go before version 2:1.13.3-1 is vulnerable to denial of service.

The package go-pie before version 2:1.13.3-1 is vulnerable to denial of service.

The package xpdf before version 4.02-1 is vulnerable to arbitrary code execution.

Facebook pulls fake news networks linked to Russia and Iran
15 Years Later, Metasploit Still Manages to be a Menace
Haxis of evil: Russia, China, Iran and North Korea are ‘continuous threat’ to UK, say spies

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Travel database exposed PII on US government employees

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Smart cities must be cyber‑smart cities

As cities turn to IoT to address long-standing urban problems, what are the risks of leaving cybersecurity behind at the planning phase? The post Smart cities must be cyber‑smart cities appeared first on WeLiveSecurity

Upstream details at : https://access.redhat.com/errata/RHSA-2019:3157

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2964

Upstream details at : https://access.redhat.com/errata/RHSA-2019:3127

Upstream details at : https://access.redhat.com/errata/RHSA-2019:3128

Deepfakes, quantum computing cracking codes, ransomware… Find out what’s really freaking out Uncle Sam
Messed Western: Vuln hunters say hotel giant’s Autoclerk code exposed US soldiers’ info, travel plans, passwords…

security update

security update

FTC Cracks Down on Stalkerware With Retina-X App Bans
Open Redirect Bug in Bridge Theme Plugin Opens Admins to Spearphishing

Type: Vulnerability. Cisco Identity Services Engine is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. IBM Maximo Anywhere is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Cisco Identity Services Engine is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco SPA122 ATA with Router Devices are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Cisco Identity Services Engine is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple Sonatype Products are prone to an unspecified remote code execution vulnerability; fixes are available.

Type: Vulnerability. Cisco Identity Services Engine is prone to multiple HTML-injection vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Firepower Management Center is prone to multiple cross-site scripting vulnerabilities; fixes are available.

Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. CA Performance Management is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Broken Link Checker plugin for WordPress is prone to a cross-site scripting vulnerability.

Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Cisco Small Business Smart and Managed Switches are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. TYPO3 freeCap CAPTCHA extension is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Cisco Firepower Management Center is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco Aironet Access Points are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco Firepower Management Center is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Cisco TelePresence CE Software is prone to a local command-injection vulnerability; fixes are available.

Minigame: Celebrate Firefox 70’s release by finding a website with 70+ trackers blocked
No ‘Silver Bullet’ Fix for Alexa, Google Smart Speaker Hacks
Japanese hotel chain sorry that hackers may have watched guests through bedside robots
Magecart 5 Linked to Carbanak Gang

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

US nuclear weapons command finally ditches 8-inch floppies
Storing your stuff securely in the cloud
NordVPN reveals breach at datacenter provider

The company says that the incident, going back to March 2018, affected only 1 out of its 3,000 servers The post NordVPN reveals breach at datacenter provider appeared first on WeLiveSecurity

An update that solves 40 vulnerabilities and has 225 fixes is now available.

Vatican launches smart rosary – complete with brute-force flaw
Three Service Account Secrets Straight from Hackers and Security Pros
Cynet’s free vulnerability assessment offering helps organizations significantly increase their security
Survey Finds People are Privacy Hypocrites
Woman ordered to type in iPhone passcode so police can search device

An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 and Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that solves one vulnerability and has 21 fixes is now available.

An update that fixes one vulnerability is now available.

Google chief warns visitors about smart speakers in his home

OpenJDK: Incorrect handling of nested jar: URLs in Jar URL handler (Networking, 8223892) (CVE-2019-2978) * OpenJDK: Incorrect handling of HTTP proxy responses in HttpURLConnection (Networking, 8225298) (CVE-2019-2989) * OpenJDK: Missing restrictions on use of custom SocketImpl (Networking, 8218573) (CVE-2019-2945) * OpenJDK: NULL pointer dereferen [More…]

An update is now available for Red Hat Satellite 6.6 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

OpenJDK: Incorrect handling of nested jar: URLs in Jar URL handler (Networking, 8223892) (CVE-2019-2978) * OpenJDK: Incorrect handling of HTTP proxy responses in HttpURLConnection (Networking, 8225298) (CVE-2019-2989) * OpenJDK: Missing restrictions on use of custom SocketImpl (Networking, 8218573) (CVE-2019-2945) * OpenJDK: NULL pointer dereference in DrawGlyphList (2D, 8222690) (CVE-2019- [More…]

Just say the ‘magic password’: Boffins turn up potential backdoor in SQL Server 2012, 2014

An update for python is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

An update for wget is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Just a friendly reminder there were no at-the-time classified secrets on Clinton’s email server. Yes, the one everyone lost their minds over
ATTK of the Pwns: Trend Micro’s antivirus tools ‘will run malware – if its filename is cmd.exe’
Action Fraud? Inaction Fraud
Row erupts over who to blame after NordVPN says: One of our servers was hacked via remote management tool
Gustuff Android Banker Switches Up Technical Approach

security update

U.S. Government, Military Personnel Data Leaked By Autoclerk

Type: Vulnerability. Cisco Expressway Series and Telepresence VCS are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Cisco TelePresence Collaboration Endpoint Software is prone to multiple local arbitrary file-overwrite vulnerabilities; fixes are available.

Type: Vulnerability. Apache Thrift is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco TelePresence Collaboration Endpoint Software is prone to a local arbitrary file-write vulnerability; fixes are available.

Type: Vulnerability. Cisco TelePresence Collaboration Endpoint Software is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Cisco Wireless LAN Controller Software is prone to a local directory-traversal vulnerability; fixes are available.

Type: Vulnerability. AVEVA IEC870IP Driver for Vijeo Citect and Citect SCADA is prone to a stack-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Apache Thrift is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.