Menu

Category Archives: Security

Articles about security

Smart Doorbells on Amazon, eBay, Harbor Serious Security Issues
Baidu Apps in Google Play Leak Sensitive Data
Blackrota Golang Backdoor Packs Heavy Obfuscation Punch

An update that solves 21 vulnerabilities and has 21 fixes is now available.

OctopusWAF: A Customizable Open-Source WAF for High Performance Applications>

An update that solves 17 vulnerabilities and has 15 fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Tesla Hacked and Stolen Again Using Key Fob
Fake Minecraft mods installed on over one million Android devices

net-snmp: Improper Privilege Management in EXTEND MIB may lead to privileged commands execution (CVE-2020-15862) SL6 x86_64 net-snmp-5.5-60.el6_10.2.x86_64.rpm net-snmp-debuginfo-5.5-60.el6_10.2.i686.rpm net-snmp-debuginfo-5.5-60.el6_10.2.x86_64.rpm net-snmp-libs-5.5-60.el6_10.2.i686.rpm net-snmp-libs-5.5-60.el6_10.2.x86_64.rpm net-snmp-devel-5.5-60.el6_10.2.i686.rpm [More…]

This update upgrades Thunderbird to version 78.4.3. * Mozilla: Write side effects in MCallGetProperty opcode not accounted for (CVE-2020-26950) SL6 x86_64 thunderbird-78.4.3-1.el6_10.x86_64.rpm thunderbird-debuginfo-78.4.3-1.el6_10.x86_64.rpm i386 thunderbird-78.4.3-1.el6_10.i686.rpm – Scientific Linux Development Team

Imagine things are bad enough that you need a payday loan. Then imagine flaws in systems of loan lead generators leave your records in the open… for years

An update that fixes 5 vulnerabilities is now available.

Marketers for an Open Web ask UK competition watchdog to block launch of Google’s anti-tracking Privacy Sandbox
Crooks social-engineer GoDaddy staff into handing over control of crypto-biz domain names
Critical VMware Zero-Day Bug Allows Command Injection; Patch Pending
Apple’s global security boss accused of bribing cops with 200 free iPads in exchange for concealed gun permits
GoDaddy Employees Tricked into Compromising Cryptocurrency Sites

REvil Ransomware Strikes Hosting Provider In recent days the web hosting provider Managed.com has been working to recover from a ransomware attack targeting many of their core systems. While the company was able to stop the spread of the attack by shutting down their systems and client websites, it remains unclear what information may have […]

Security flaws in smart doorbells may open the door to hackers

The peace of mind that comes with connected home security gadgets may be false – your smart doorbell may make an inviting target for unwanted visitors The post Security flaws in smart doorbells may open the door to hackers appeared first on WeLiveSecurity

Manchester United versus a “sophisticated” cyber attack
TA416 APT Rebounds With New PlugX Malware Variant
Spotify Users Hit with Rash of Account Takeovers
FBI warns of criminals spoofing its website domain names
Manchester United: IT Systems Disrupted in Cyberattack
Joe Biden Campaign Subdomain Down After Hacktivist Defacement
Penetration testing isn’t enough, you need to activate full offensive operations

An update that solves 15 vulnerabilities and has 75 fixes is now available.

An update for microcode_ctl is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for microcode_ctl is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact

An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.4 Advances Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

US Air Force deploys robot security dogs to guard base
No Xmas office party? Missing infosec pals and colleagues? Want to listen to DJs who also happen to be cyber warriors?
Head thumping, heart racing? Here’s how not to panic when you’re under cyber attack

security update

security update

Update to 87.0.4280.66. Fixes bugs and security holes. Yay! CVE-2020-16012 CVE-2020-16018 CVE-2020-16019 CVE-2020-16020 CVE-2020-16021 CVE-2020-16022 CVE-2020-16015 CVE-2020-16014 CVE-2020-16023 CVE-2020-16024 CVE-2020-16025 CVE-2020-16026 CVE-2020-16027 CVE-2020-16028 CVE-2020-16029 CVE-2020-16030 CVE-2020-16031 CVE-2020-16032 CVE-2020-16033 CVE-2020-16034 CVE-2020-16035

– Update to upstream 2.1-31. 20201118 – Removal of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode at revision 0x68[1]; – Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x32 up to 0x34[2]. [1] The microcode has been removed after reports of system hangs: https://github.com/intel/Intel-Linux-Processor- Microcode-Data-Files/issues/44 [2] Addresses CVE-2020-8695 for this platform.

Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.

Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.

Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.

Manchester United working with infosec experts to ‘minimize ongoing IT disruption’ caused by ‘cyber attack’

Multiple vulnerabilities were discovered in Zabbix, a network monitoring solution. An attacker may remotely execute code on the zabbix server, and redirect to external links through the zabbix web frontend.

Three issues have been found in golang-1.8, a Go programming language compiler version 1.8

Two issues have been found in golang-1.7, a Go programming language compiler version 1.7

A heap-based buffer overflow flaw was discovered in MuPDF, a lightweight PDF viewer, which may result in denial of service or the execution of arbitrary code if malformed documents are opened.

security update

IBM Power9 processors beset by Cardiac Osprey data-leaking flaw as Spectre still haunts speculative chips
Google Services Weaponized to Bypass Security in Phishing, BEC Campaigns
VMware Fixes Critical Flaw in ESXi Hypervisor
Good Heavens! 10M Impacted in Pray.com Data Exposure
End to end encryption? In Android’s default messaging app? Don’t worry, nobody else noticed either
New Grelos Skimmer Variants Siphon Credit Card Data
The worst passwords of 2020: Is it time to change yours?

They’re supremely easy to remember, as well as easy to crack. Here’s how to improve your password security. The post The worst passwords of 2020: Is it time to change yours? appeared first on WeLiveSecurity

Robot vacuum cleaners can eavesdrop on your conversations, researchers reveal
Facebook Messenger Bug Allows Spying on Android Users

An update that fixes three vulnerabilities is now available.

An update that fixes 16 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that solves two vulnerabilities and has 12 fixes is now available.

NCSC’s London HQ was chosen because GCHQ spies panicked at the prospect of grubby Shoreditch offices
A guide to security technologies in Red Hat Enterprise Linux

An update that fixes three vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

UK reveals new ‘National Cyber Force’, announces Space Command and mysterious AI agency
You can protect the company from hackers, but can you protect the company from the CEO?
VMware reveals critical hypervisor bugs found at Chinese white hat hacking comp. One lets guests run code on hosts
In 2016 Australia’s online census failed. Preparations for the 2021 edition have been rated ‘partly effective’
Robot Vacuums Suck Up Sensitive Audio in ‘LidarPhone’ Hack
German COVID-19 Contact-Tracing Vulnerability Allowed RCE
US Senate approves deepfake bill to defend against manipulated media

security update

GO SMS Pro Android App Exposes Private Photos, Videos and Messages
Tis’ the Season for Online Holiday Shopping; and Phishing
AWS includes open-source Suricata for stateful inspection with Network Firewall service
Code42 Incydr Series: Protect IP with Code42 Incydr
Get the free Security Intelligence Handbook from Recorded Future
Food-Supply Giant Americold Admits Cyberattack
IoT Cybersecurity Improvement Act Passed, Heads to President’s Desk
Cyberup campaign: 80% of infosec pros fear they might fall foul of UK’s outdated Computer Misuse Act
APT Exploits Microsoft Zerologon Bug: Targets Japanese Companies
Cybercriminals Batter Automakers With Ransomware, IP Theft Cyberattacks
Egregor ransomware attack hijacks printers to spit out ransom notes

An update that solves one vulnerability and has two fixes is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that solves one vulnerability, contains one feature and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

In any other year, many of us would be gearing up for airline travel, big family dinners, cocktail hours or potlucks with friends, and much more. But with all the challenges this year has brought in terms of how we work and connect during a global pandemic, I’m guessing all our plans look a little […]

How security and compliance automation can help achieve a more secure hybrid cloud
Anti-adversarial machine learning defenses start to take root
Compsci guru wants ‘right to be forgotten’ for old email, urges Google and friends to expire, reveal crypto-keys
China-linked hacking gang ‘APT10’ named as probable actor behind extended attacks on Japanese companies

It’s common for savvy online shoppers to check third-party reviews before making an online purchasing decision. That’s smart, but testing the efficacy of security software can be a bit more difficult than determining if a restaurant had decent service or if clothing brand’s products are true to size. So, with the arguably more significant consequences […]

Smashing Security podcast #205: Zoom password pinching and Parler problems