Menu

Category Archives: All

Everything

Several security issues were fixed in CUPS.

Breaker, breaker. Apple’s iOS 12.4 update breaks jailbreak break, un-breaks the break. 10-4
The Pwn Star State: Nearly two dozen Texas towns targeted by tiresome ransomware
VLC Media Player Allows Desktop Takeover Via Malicious Video Files
Apple Sues Corellium Over iOS ‘Replica’ Security Testing Software

security update

Dear Planet Earth: Patch Webmin now – zero-day exploit emerges for potential hijack hole in server control panel
Post GandCrab, Cybercriminals Scouring the Dark Web for the Next Top Ransomware

Nova could be made to expose sensitive information.

Google Nest Security Cam Bugs Allow Device Takeover
Dodging bad passwords with Google’s new tool
New malware records screen activity as victim watches porn

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

20 month prison sentence for British hacker who made fortune helping SIM-swap fraudsters

An update that solves one vulnerability and has two fixes is now available.

An update that contains security fixes can now be installed.

Docker could be made to crash or run programs as your login.

Coordinated Ransomware Attack Hits 23 Texas Government Agencies
Teen TalkTalk hacker ordered to pay £400k after hijacking popular Instagram account

docker-credential-helpers could be made to crash or run programs as your login

Did Facebook know about “View As” bug before 2018 breach?
Multiple HTTP/2 DoS flaws found by Netflix
61 impacted versions of Apache Struts left off security advisories
KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more

Several security issues were fixed in OpenLDAP.

Several security issues were fixed in LibreOffice.

KConfig and KDE libraries could be made to crash or run programs if it opened a specially crafted file.

iFrame clickjacking countermeasures appear in Chrome source code. And it only took *checks calendar* three years
Subcontractor’s track record under spotlight as London Mayoral e-counting costs spiral

An update for rh-php71-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

This update fixes **CVE-2019-14744 (kconfig arbitrary shell code execution)** in the KDE 3 compatibility version of kdelibs used by legacy KDE 3 applications. The full list of fixes in this `kdelibs3` build: * fixes **CVE-2019-14744** – `kconfig`: malicious `.desktop` files (and others) would execute code. KConfig had a well-meaning feature that allowed configuration files to […]

Security fix for CVE-2019-1010189

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has 11 fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that solves three vulnerabilities and has 41 fixes is now available.

This update fixes 2 security issues. A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure (CVE-2019-10192).

Updated postgresql packages fix security vulnerabilities: Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function

Updated mariadb packages fix security vulnerabilities: An easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise mariadb server. Successful attacks of this vulnerability can result in unauthorized

This update provides and update to mythtv 30, and updates the bundled ffmpeg to 3.2. It also fixes atleast the following issue: The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 4.0.2 does not check for an empty audio packet, leading to an assertion

It was discovered that elfutils incorrectly handled certain malformed files. If a user or automated system were tricked into processing a specially crafted file, elfutils could be made to crash or consume resources, resulting in a denial of service (CVE-2017-7607, CVE-2017-7608, CVE-2017-7609, CVE-2017-7610, CVE-2017-7611, CVE-2017-7612, CVE-2017-7613,

A vulnerability in hostapd and wpa_supplicant could lead to a Denial of Service condition.

Multiple vulnerabilities have been found in MariaDB and MySQL, the worst of which could result in privilege escalation.

Multiple vulnerabilities have been found in VLC, the worst of which could result in the arbitrary execution of code.

security update

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2473

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2471

Reading Time: ~ 2 min. With job growth projected to surge 24% over the next seven years, software engineering is one of the most demanded professional fields in the U.S. Exceptionally competitive pay and the chance to pursue careers across many industries are just a few benefits of being a software engineer. We explore how […]

Bluetana app detects gas pumps card skimmers in 3 seconds

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Fake News and Influence: Information Warfare in the Digital Age
Chrome add-on warns netizens when they use a leaked password. Sometimes, they even bother to change it

security update

An update that fixes 10 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves 8 vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

NSA asks Congress to permanently reauthorize spying program that was so shambolic, the snoops had shut it down
ThreatList: 4.1B Records Exposed in Breaches in First Half of 2019
Breached Passwords Still in Use By Hundreds of Thousands
News Wrap: DejaBlue Bugs and Biometrics Data Breaches
Top tip: Don’t upload your confidential biz files to free malware-scanning websites – everything is public

An update that solves 8 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

It was discovered that the code fixes to address CVE-2018-16858 and CVE-2019-9848 were not complete. For the oldstable distribution (stretch), these problems have been fixed

**MariaDB 10.3.17** Release notes: https://mariadb.com/kb/en/mariadb-10317-release-notes/ **MariaDB Connector/C 3.1.3** Release notes: https://mariadb.com/kb/en/mariadb- connector-c-313-release-notes/ **MariaDB Connector/ODBC 3.1.2** Release notes: https://mariadb.com/kb/en/mariadb-connector-odbc-312-release-notes/ —–

nginx could be made to crash if it received specially crafted network traffic.

fixes for CVE-2019-14232 to 14235

And you thought the cops were bad… Civil rights group warns of facial recog ‘epidemic’ across UK private sites

Reading Time: ~ 2 min. Hookup App Leaks User Locations Geo-locating and other sensitive data has been leaked from the hookup app 3fun, exposing the information for more than 1.5 million users. While some dating apps using trilateration to find nearby users, 3fun showed location data capable of tracing a user to a specific building […]

iPhone holes and Android malware – how to keep your phone safe

Multiple vulnerabilities have been found in imagemagick, an image processing toolkit. CVE-2019-12974

Google removes option to disable Nest cams’ status light
Police site DDoSer/bomb hoaxer caught after jeering on social media
Microsoft won’t shift on AI recordings policy
European Central Bank confirms website hack and data breach
Police costs for Gatwick drone fiasco double to nearly £900k – and still no one’s been charged
Security? We’ve heard of it! But why be a party pooper when there’s printing to be done
Update Windows 10: 800 million devices at risk of critical vulnerability

Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, information disclosure or the execution of arbitrary code.

HTTP Bugs Open Websites to DoS Attacks
Energy Sector Phish Swims Past Microsoft Email Security via Google Drive
Apache Security Advisories Red Flag Wrong Versions in Patching Gaffe

A buffer over-read in the t1-parser of freetype, a font engine, has been found and fixed by checking limits more sensible.

Choice Hotels Breach Showcases Need for Shared Responsibility Model
Clickjacking Evolves to Hook Millions of Top-Site Visitors
Firefox fixes “master password” security bypass bug

Reading Time: ~ 4 min. Cybersecurity has become the hot industry – tips and tricks on how to get the most out of your cybersecurity internship (and land a job after graduation).  Students today are faced with grueling course loads, pressure to get real-world experience and a looming competitive job market. The need for hands-on […]

“NULL” vanity plate hack to dodge parking tickets backfires to the tune of $12,000

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the mysql:8.0 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,