Menu

Category Archives: All

Everything

Malware called InnfiRAT is creeping into cryptocurrency wallets
Asus, Lenovo and Other Routers Riddled with Remotely Exploitable Bugs
Just as Ecuador thought it had seen the back of leaks, over 20m citizen records are exposed
U.S. Sanctions North Korean Group Behind WannaCry, Sony Hacks
Australia didn’t blame China for parliament hack in case it upset trade relations – report

Reading Time: ~ 3 min. Do you remember the last time you’ve interacted with a brand, political cause, or fundraising campaign via text message? Have you noticed these communications occurring more frequently as of late? It’s no accident. Whereas marketers and communications professionals can’t count on email opens or users accepting push notifications from apps, […]

iPhone lockscreen bypass: iOS 13 tricked into showing your contacts
Google fixes Chromebook 2FA flaw in ‘built-in security key’
Simjacker silent phone hack could affect a billion users

An update that fixes one vulnerability is now available.

Tiny Pacific nation forges ahead with national cryptocurrency

IBus would allow local users to capture key strokes of other locally logged in users.

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Exim could be made to run programs as an administrator if it received specially crafted network traffic.

Several vulnerabilities were discovered in Ansible, a configuration management, deployment, and task execution system.

An update that fixes one vulnerability is now available.

You all know why you should encrypt your cloud data – now learn where and how…

Wireshark could be made to crash if it received specially crafted network traffic or input files.

rebase to 0.16 (bz #1741605)

Update to latest upstream version.

rebase to 0.16 (bz #1741605)

Update to 8.05 release (CVE-2019-16239)

BIRD 2.0.6 (2019-09-10) * BGP: Optional Adj-RIB-Out * BGP: Extended optional parameters length * Filter: Sets and set expressions in path masks * Several important bugfixes

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Updated wireshark packages fix security vulnerability: The Gryphon dissector could go into an infinite loop. For other fixes in this update, see the referenced releasenotes.

Updated webkit2 packages fix security vulnerabilities: Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling (CVE-2019-8644).

Updated openldap packages fix security vulnerabilities: It was discovered that OpenLDAP incorrectly handled rootDN delegation. A database administrator could use this issue to request authorization as an identity from another database, contrary to expectations (CVE-2019-13057).

Updated mediawiki packages fix security vulnerabilities: Potential XSS in jQuery (CVE-2019-11358). An account can be logged out without using a token (CSRF) (CVE-2019-12466).

Updated kconfig packages fix security vulnerability: Dominik Penner discovered that KConfig supported a feature to define shell command execution in .desktop files. If a user is provided with a malformed .desktop file (e.g. if it’s embedded into a downloaded archive and it gets

Multiple vulnerabilities have been discovered in faad2, the Freeware Advanced Audio Coder. These vulnerabilities might allow remote attackers to cause denial-of-service, or potentially execute arbitrary code if crafted MPEG AAC files are processed.

This update provides nodejs v6.17.1 fixing atleast the following security issues: The c-ares function ares_parse_naptr_reply(), which is used for parsing NAPTR responses, could be triggered to read memory outside of the given

The updated packages fix security vulnerabilities: The JPXStream::init function in Poppler 0.78.0 and earlier doesn’t check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap,

Updated thunderbird packages fix security vulnerabilities: Covert Content Attack on S/MIME encryption using a crafted multipart/ alternative message (CVE-2019-11739).

New Amazon phishing scam stealing credit card data
WordPress XSS Bug Allows Drive-By Code Execution

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

iPhone iOS 13 Lockscreen Bypass Flaw Exposes Contacts
Whoa, bot wars: As cybercrooks add more AI to their arsenal, the goodies will have to too
The Joker is haunting Google Play Store with malware
Consumer ransomware insurance? You could be painting a target on us all for avaricious crims

Mozilla: Sandbox escape through Firefox Sync (CVE-2019-9812) * Mozilla: Memory safety bugs fixed in Firefox 69, Firefox ESR 68.1, and Firefox ESR 60.9 (CVE-2019-11740) * Mozilla: Same-origin policy violation with SVG filters and canvas to steal cross-origin images (CVE-2019-11742) * Mozilla: XSS by breaking out of title and textarea elements using innerHTML (CVE-2019-11744) * Mozilla: […]

An update that fixes two vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

Updated flash-player-plugin package fixes security vulnerabilities: Same origin method execution that leads to arbitrary code execution?in the context of the current user. (CVE-2019-8069)

Astaroth Spy Trojan Uses Facebook, YouTube Profiles to Cover Tracks
Just how private are your browsing habits?
North Korean Spear-Phishing Attack Targets U.S. Firms
Intel: SSH-stealing NetCAT bug not really a problem
Charmin’. Garmin admits customers’ full credit card data nicked from South African web store
News Wrap: IoT Radio Telnet Backdoor And ‘SimJacker’ Active Exploit
Leaky database full of fake Groupon emails turns out to belong to crooks

This package ignored the value of the Hash header, which allows an attacker to spoof it. An attacker can not only embed arbitrary Armor Headers, but also prepend arbitrary text to cleartext messages without invalidating the signatures.

Reading Time: ~ 3 min. AI and machine learning offer tremendous promise for humanity in terms of helping us make sense of Big Data. But, while the processing power of these tools is integral for understanding trends and predicting threats, it’s not sufficient on its own. Thoughtful design of threat intelligence—design that accounts for the […]

Reading Time: ~ 2 min. Ransomware Closes Arizona School District As many students began returning for the fall semester, classes were cancelled in the Flagstaff Unified School District in Arizona after a ransomware attack disabled some of the district’s computer systems. Officials haven’t yet released any additional information on the ransom demanded or if any […]

Cybercriminals Adding Sophistication to BEC Threats
A Critical Exim Vulnerability, Lilocked Ransomware on the Rise, but Linux Not to Blame
Mozilla Private Network VPN gives Firefox another privacy boost

Samuel R Lovejoy discovered a security vulnerability in dnsmasq. Carefully crafted packets by DNS servers might result in out of bounds read operations, potentially leading to a crash and denial

Fin7 sysadmin pleads guilty to running IT for billion-dollar crime syndicate
From PowerShell to auditing: Expand your cybersecurity know-how at SANS London 2019
From pen-test to penitentiary: Infosec duo cuffed after physically breaking into courthouse during IT security assessment
Snoops can bypass iOS 13 lock screen to eyeball your address book. Apple hasn’t fix it yet. Valid flaw? You decide

An update that fixes one vulnerability is now available.

Those fake spying cell towers in Washington DC? Ex-intel staffers claim they’re Israeli
Eco-activists arrested by Brit cops after threatening to close Heathrow with drones

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Simjacker vulnerability lets attackers track your location with an SMS
Library-Themed University Phishing Attack Expands to Massive Scale
California Passes Bill to Ban Police Use of Facial Recognition
1B Mobile Users Vulnerable to Ongoing ‘SimJacker’ Surveillance Attack
UNICEF Leaks Personal Data of 8,000 Users via Email Blunder

Reading Time: ~ 3 min. According to a report from hired.com, the demand for security engineers is up 132%. Additionally, the need for engineers who specialize in data analytics and machine learning has increased by 38% and 27%, respectively. Given recent trends in cybersecurity, it’s no wonder, and demand at Webroot is no exception. To […]

September 2019’s Patch Tuesday: 2 zero-days, 17 critical bugs
Massive email fraud bust snares 281 suspects
Google experiments with DNS-over-HTTPS in Chrome
Error-laden phone location data suspended from use in Danish courts
How to download online video & audio files with new tool from SaveFrom.net
Mystery database left open turns out to be massive Groupon fraud ticket fraud ring
Watch live today: How to make your voice heard – and keep your staff safe from hackers

Risk Level: Very Low. Type: Trojan.

Smashing Security #145: Apple and Google willy wave while home assistants spy – DoH!
ThreatList: Apple Adware, Phishing, APT Attacks Threaten macOS Users
Major Groupon, Ticketmaster Fraud Scheme Exposed By Insecure Database
100s of Flashlight apps on Play Store ask for dangerous permissions

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Several security issues were fixed in curl.

Infosec prophet Bruce Schneier (peace be upon him) is only as famous as half of Salt-N-Pepa
198 Million Car-Buyer Records Exposed Online for All to See
Intel CPUs Vulnerable to Sensitive Data Leakage in NetCAT Attack
Toyota parts supplier loses $37 million in email scam
Lemonade is changing the way we insure our homes
Operation reWired: 281 suspected email scammers arrested around the world