Menu

Category Archives: Security

Articles about security

An update that fixes two vulnerabilities is now available.

An update that fixes 27 vulnerabilities is now available.

Nvidia Warns Gamers of Severe GeForce Experience Flaws
Ransomware Takes Down Network of French IT Giant
Securing medical devices: Can a hacker break your heart?

Why are connected medical devices vulnerable to attack and how likely are they to get hacked? Here are five digital chinks in the armor. The post Securing medical devices: Can a hacker break your heart? appeared first on WeLiveSecurity

Ed Snowden doesn’t need to worry about being turfed out of Russia any more
After Dutch bloke claims he hacked Trump’s Twitter by guessing password, web biz says there’s ‘no evidence’
China reveals audit of 320,000 local apps, with 34 booted from app stores and hundreds of devs warned they could suffer same fate
After first floating $20bn penalty, DoJ suggests $60m fine for UMC’s theft of Micron’s DRAM secrets
Is it Iran or Russia’s hackers we need to worry about? The Russians, definitely the Russians, says US intelligence

security update

security update

Researcher: I Hacked Trump’s Twitter by Guessing Password
Facebook, News and XSS Underpin Complex Browser Locker Attack
Microsoft Teams Phishing Attack Targets Office 365 Users
Google patches Chrome zero‑day under attack

In addition to patching the actively exploited bug, the update also brings fixes for another four security loopholes The post Google patches Chrome zero‑day under attack appeared first on WeLiveSecurity

Fake Instagram follower services slapped with lawsuit
Chrome 86 Aims to Bar Abusive Notification Content
Donald Trump’s Twitter password is “maga2020!”, and there’s no 2FA, claims hacker
French IT outsourcer Sopra Steria hit by ‘cyberattack’, Ryuk ransomware suspected

An update that fixes three vulnerabilities is now available.

An update that fixes 11 vulnerabilities is now available.

Feds: Iran Behind ‘Proud Boys’ Email Attacks on Democratic Voters

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Fort Bragg fails to keep a firm grip on its Twitter account, as it blames hacker for saucy tweets

An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Over one million WordPress sites receive forced update to security plugin after severe vulnerability discovered
Samsung to introduce automatic call blocking on Android 11-capable flagships
Sopra Steria hit by cyber attack. IT services group suspected of falling victim to ransomware
Iran sent threatening pro-Trump emails to American Democrats, Russia close behind, says US intelligence
Smashing Security podcast #201: Robin Hood, Flippy, and the web ad bubble
Thought the FBI were the only ones able to unlock encrypted phones? Pretty much every US cop can get the job done

security update

security update

Bug Parade: NSA Warns on Cresting China-Backed Cyberattacks
Coronavirus outbreak triggered a rush of online attacks against retail loyalty schemes, Akamai reckons
Cisco Warns of Severe DoS Flaws in Network Security Software
How much does Oracle love you? Thiiiis much: Latest patch bundle has 402 fixes
Oracle Kills 402 Bugs in Massive October Patch Update
How safe is your USB drive?

What are some of the key security risks to be aware of when using USB flash drives and how can you mitigate the threats? The post How safe is your USB drive? appeared first on WeLiveSecurity

Egregor Claims Responsibility for Barnes & Noble Attack, Leaks Data

An update that solves 6 vulnerabilities and has 36 fixes is now available.

An update that solves 6 vulnerabilities and has 36 fixes is now available.

Cybercriminals Step Up Their Game Ahead of U.S. Elections

Several security issues were fixed in iTALC.

Google Patches Actively-Exploited Zero-Day Bug in Chrome Browser
The Recorded Future Express browser extension – elite security intelligence for zero cost

A flaw was found in the way the Linux kernel Bluetooth implementation handled L2CAP packets with A2MP CID. A remote attacker in adjacent range could use this flaw to crash the system causing denial of service or potentially execute arbitrary code on the system by sending a specially crafted L2CAP packet. The highest threat from […]

GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the middle to present a different invalid certificate to intercept incoming and outgoing mail. (CVE-2020-24661)

8 video chat apps compared: Which is best for security?

An update for rh-postgresql96-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

How cybercriminals play the domain game
OpenStack haven OpenDev yanks Gerrit code review tool after admin account compromised for two weeks
Top tip, everyone: Chinese hackers are hitting these 25 vulns, so make sure you patch them ASAP, says NSA
Ransomware Group Makes Splashy $20K Donation to Charities

security update

VMware patches, among other things, ESXi flaw that can be abused by miscreants on the network to hijack hosts
Adobe Fixes 16 Critical Code-Execution Bugs Across Portfolio
Facebook: A Top Launching Pad For Phishing Attacks
Microsoft issues two emergency Windows patches

The flaws, neither of which is being actively exploited, were fixed merely days after the monthly Patch Tuesday rollout The post Microsoft issues two emergency Windows patches appeared first on WeLiveSecurity

Pharma Giant Pfizer Leaks Customer Prescription Info, Call Transcripts
Remember insider threat? Old news now. Focus on malware detection, says EU infosec agency
Office 365 OAuth Attack Targets Coinbase Users
Mobile Browser Bugs Open Safari, Opera Users to Malware
Confronting Data Risk in the New World of Work
Google’s Waze Can Allow Hackers to Identify and Track Users
You’ve open sourced your relational database manager with PostgreSQL – but how can you keep it secure?
Notpetya, Olympics hacking, Novichok probe meddling… America throws the book at six alleged Kremlin hackers

Reading Time: ~ 3 min. Fine-tuning privacy for any preference A DNS filtering service that accommodates DNS over HTTPS (DoH) can strengthen an organization’s ability to control network traffic and turn away threats. DoH can offer businesses far greater control and flexibility over their privacy than the old system. The most visible use of DNS […]

Rapper Scams $1.2M in COVID-19 Relief, Gloats with ‘EDD’ Video
DOJ Charges 6 Sandworm APT Members in NotPetya Cyberattacks
GravityRAT Comes Back to Earth with Android, macOS Spyware
Overlay Malware Targets Windows Users with a DLL Hijack Twist
Ryuk Ransomware Gang Uses Zerologon Bug for Lightning-Fast Attack
UK test and trace data can be handed to police, reveals memorandum
Microsoft Exchange, Outlook Under Siege By APTs
First, Patch Tuesday. Now, Oh Hell, Monday: Microsoft emits bonus fixes for Visual Studio, Windows 10 security bugs
Game Titles Watch Dogs: Legion, Albion Both Targeted by Hackers
Albion Online gamers told to change passwords following forum hack

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

**Version 5.0.3** (2020-10-09) – issue #15983 Require twig ^2.9 – issue Fix option to import files locally appearing as not available – issue #16048 Fix to allow NULL as a default bit value – issue #16062 Fix “htmlspecialchars() expects parameter 1 to be string, null given” on Export xml – issue #16078 Fix no charts […]

Google reveals the most powerful DDoS attack in history… albeit three years late

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Will there be no end to govt attempts to break encryption? Hand over your data or the kiddies get it, threaten Five Eyes spies
Microsoft is the Most-Imitated Brand for Phishing Emails
Hackney Council can’t pay housing benefit after cyber attack

Several vulnerabilities have been discovered in the Linux kernel that may lead to the execution of arbitrary code, privilege escalation, denial of service or information leaks.

createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]

createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]

createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]

createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]

createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]

createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]

security update

RavenDB 5.0: A Versatile Open-Source NoSQL Database with an Intense Focus on Security>

An update that solves four vulnerabilities and has 9 fixes is now available.