Menu

Category Archives: Security

Articles about security

The seven deadly sins letting hackers hijack America’s govt networks: These unpatched bugs leave systems open
Microsoft and chums use US trademark law to trash Trickbot malware network

An update that contains security fixes can now be installed.

An update that solves 12 vulnerabilities and has 59 fixes is now available.

Home security cams hacked in Singapore, and stolen footage sold on adult websites
‘You’ve got the old cheeky Corona’: Ireland’s pandemic advice SMS service can be spoofed, warns researcher
Android ransomware learns new tricks to lock devices
Ransomware Attackers Buy Network Access in Cyberattack Shortcut

An update that solves two vulnerabilities and has one errata is now available.

Beware, drone fliers, of Scotland’s black-headed gulls. For they will tear your craft from Mother Nature’s skies
One year after server hackers left NordVPN red-faced, firm’s first colocated setup is online
Britannia should rule the (cyber) waves, minister tells Singapore event in bid to drum up Commonwealth support
Five Eyes nations plus Japan and India call for Big Tech to bake backdoors into everything
Securing A Linux Web Server: Preventing Information Leakage>

An update that fixes one vulnerability is now available.

Frediano Ziglio discovered multiple buffer overflow vulnerabilities in the QUIC image decoding process of spice, a SPICE protocol client and server library, which could result in denial of service, or possibly, execution of arbitrary code.

security update

An update that fixes 5 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

A potential Cross-Site Scripting (XSS) vulnerability was found in rails, a ruby based MVC framework. Views that allow the user to control the default (not found) value of the `t` and `translate` helpers could be susceptible to XSS attacks. When an HTML-unsafe string is passed as the

Oleg Kalnichevski discovered that httpcomponents-client, a Java library for building HTTP-aware applications, can misinterpret a malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Taking a screwdriver to unlock your IoT sex toy is nuts

An update that solves one vulnerability and has one errata is now available.

Global Privacy Control emerges as latest attempt to let netizens choose whether they want to be tracked online
Five bag $300,000 in bug bounties after finding 55 security holes in Apple’s web apps, IT infrastructure

In Eclipse Web Tools Platform, a component of the Eclipse IDE, XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user

Reading Time: ~ 2 min. New Jersey Hospital Pays Massive Ransom Officials have decided to pay roughly $670,000 in ransom following a ransomware attack on the University Hospital in New Jersey. The hospital was likely forced into this decision after being unable to restore from backups the 240GB of data stolen in the attack on […]

Fitbit Spyware Steals Personal Data via Watch Face
Sophisticated Android Ransomware Executes with the Home Button
Software AG hit with ransomware: Crooks leak staffers’ passports, want millions for stolen files
Google adds password breach alerts to Chrome for Android, iOS

The feature is part of the browser’s security improvements that were first built into its desktop version The post Google adds password breach alerts to Chrome for Android, iOS appeared first on WeLiveSecurity

Crown Prosecution Service solicitor accused of targeting judge ex-wife’s lover through work computer systems
Twitter closing my account for copyright violation? No, it’s a phishing attack
Facebook Debuts Bug-Bounty ‘Loyalty Program’

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Amazon Prime Day Spurs Spike in Phishing, Fraud Attacks
MontysThree APT Takes Unusual Aim at Industrial Targets
Feds Sound Alarm Over Emotet Attacks on State, Local Govs
Google Rolls Out Fixes for High-Severity Android System Flaws
BAHAMUT Spies-for-Hire Linked to Extensive Nation-State Activity
Wormable Apple iCloud Bug Allows Automatic Photo Theft

Backport fix for CVE-2020-26159

Backport fix for CVE-2020-26159

Here’s US Homeland Security collaring a suspected arsonist after asking Google for the IP addresses of folks who made a specific search

autobuilt v2.1.0,Security fix for CVE-2020-14370

Email-spamming COVID profiteers deleted database with ‘key evidence’ when UK watchdog came knocking
Want to set up a successful bug bounty? Make sure you write it for the flaw finders and not the lawyers
RAINBOWMIX Apps in Google Play Serve Up Millions of Ad Fraud Victims
Hey, pull your nose out of BlackBerry’s poor financials and pay attention to this all-singing security doodah
Cisco Fixes High-Severity Webex, Security Camera Flaws
HEH P2P Botnet Sports Dangerous Wiper Function
Working from a hotel? Beware the dangers of public Wi‑Fi

As more and more hotels are turning rooms into offices, the FBI is warning remote workers of cyber-threats lurking in the shadows The post Working from a hotel? Beware the dangers of public Wi‑Fi appeared first on WeLiveSecurity

Microsoft Azure Flaws Open Admin Servers to Takeover

An update that solves 9 vulnerabilities and has 105 fixes is now available.

An update that solves 9 vulnerabilities and has 105 fixes is now available.

K8s on a plane! US Air Force slaps Googly container tech on yet another war machine to ‘run advanced ML algorithms’
Hackers disguise malware attack as new details on Donald Trump’s COVID-19 illness
Apple’s T2 custom secure boot chip is not only insecure – it cannot be fixed without replacing the silicon

An update for go-toolset-1.13 and go-toolset-1.13-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

CVE-2019-11840 An issue was discovered in supplementary Go cryptography libraries, aka golang-googlecode-go-crypto. If more than 256 GiB of keystream is

Reading Time: ~ 4 min. Like many of the technologies we discuss on this blog—think phishing scams or chatbots—deepfakes aren’t necessarily new. They’re just getting a whole lot better. And that has scary implications for both private citizens and businesses alike. The term “deepfakes,” coined by a Reddit user in 2017, was initially most often […]

Red Hat AMQ Interconnect 1.9.0 release packages are available for A-MQ Interconnect on RHEL 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Smashing Security podcast #199: A few tech cock-ups, and one cock lock-up

security update

Had your face stolen lately?

It’s easy to reset your password or PIN after a data breach. But reset your face? Not so much. The post Had your face stolen lately? appeared first on WeLiveSecurity

Wisepay ‘outage’ is actually the school meal payments biz trying to stop an intruder from stealing customer card details
Recorded Future Express gives you elite security intelligence at zero cost

An update that solves four vulnerabilities and has two fixes is now available.

An update that fixes 9 vulnerabilities, contains 10 features is now available.

An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

PoetRAT Resurfaces in Attacks in Azerbaijan Amid Escalating Conflict
IRS COVID-19 Relief Payment Deadlines Anchor Convincing Phish
Infosec researchers pwned Comcast’s voice-activated remote control so it could snoop on household chit-chat
Comcast TV Remote Hack Opens Homes to Snooping

Several security vulnerabilities have been discovered in puma, highly concurrent HTTP server for Ruby/Rack applications. CVE-2020-11076

Disgraced cop, 55, spared prison term after admitting he abused police systems to snoop on his girlfriend’s ex

An update that fixes one vulnerability is now available.

Spice could be made to crash or run programs if it received specially crafted network traffic.

UK, French, Belgian blanket spying systems ruled illegal by Europe’s top court
US gov’t warns against paying off ransomware attackers

Companies facilitating ransomware payments run the risk of facing stern penalties for violating US regulations The post US gov’t warns against paying off ransomware attackers appeared first on WeLiveSecurity

Grindr’s Bug Bounty Pledge Doesn’t Translate to Security
Male Chastity Device Comes with Massive Security Flaws
Verizon: Just 25% of global businesses comply fully with the Payment Card Industry Data Security Standard
Boom! Mobile Customer Data Lost to Fullz House/Magecart Attack
5 steps to secure your connected devices

As we steadily adopt smart devices into our lives, we shouldn’t forget about keeping them secured and our data protected The post 5 steps to secure your connected devices appeared first on WeLiveSecurity

Microsoft Zerologon Flaw Under Attack By Iranian Nation-State Actors
COVID-19 Clinical Trials Slowed After Ransomware Attack
APT Attack Injects Malware into Windows Error Reporting
Unpatched Apple T2 Chip Flaw Plagues Macs

An update that fixes one vulnerability is now available.

An update for spice and spice-gtk is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that solves one vulnerability and has two fixes is now available.

Security fix for CVE-2020-5238 – ghc-cmark-gfm updated to 0.2.2 which rebases the bundled cmark-gfm to 0.29.0.gfm.1 https://github.com/github/cmark- gfm/security/advisories/GHSA-7gc6-9qr5-hc85

Security fix for CVE-2020-5238 – ghc-cmark-gfm updated to 0.2.2 which rebases the bundled cmark-gfm to 0.29.0.gfm.1 https://github.com/github/cmark- gfm/security/advisories/GHSA-7gc6-9qr5-hc85

Security fix for CVE-2020-5238 – ghc-cmark-gfm updated to 0.2.2 which rebases the bundled cmark-gfm to 0.29.0.gfm.1 https://github.com/github/cmark- gfm/security/advisories/GHSA-7gc6-9qr5-hc85