Menu

Category Archives: Security

Articles about security

An update that fixes two vulnerabilities is now available.

security update

Shopped recently in a small online store? Check this list to see if it was one of 570 websites infected with card-skimming Magecart
BEC Hotshot with Opulent Social Media Presence to Face U.S. Charges
Keeper Threat Group Rakes in $7M from Hundreds of Compromised E-Commerce Sites
Microsoft launches free Linux memory forensics tool for detecting malware
The Fed shares insight on how to combat synthetic identity fraud

The Federal Reserve looks at ways to counter what is thought to be the fastest-growing type of financial crime in the country The post The Fed shares insight on how to combat synthetic identity fraud appeared first on WeLiveSecurity

Fret not, Linux fans, Microsoft’s Project Freta is here to peer deep into your memory… to spot malware
Cerberus Banking Trojan Unleashed on Google Play
FBI arrests Famous Instagrammer Ray Hushpuppi over $125m BEC scam
Citrix Bugs Allow Unauthenticated Code Injection, Data Theft
Lazarus hackers use Magecart attack to steal card data from EU, US sites
Credit-Card Skimmer Has Unlikely Target: Microsoft ASP.NET Sites

Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate trust rules as software updates (CVE-2020-12421) SL6 x86_64 firefox-68.10.0-1.el6_10.x86_64.rpm [More…]

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Mozilla: Memory corruption due to missing sign-extension for ValueTags on ARM64 (CVE-2020-12417) * Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate tr [More…]

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has one errata is now available.

Reading Time: ~ 4 min. “What’s an evasive attack? At a very basic level, it’s exactly what it sounds like; it’s a cyberattack that’s designed to hide from you,” says Grayson Milbourne, Security Intelligence Director at Webroot, an OpenText company. Based on Grayson’s initial explanation, you can imagine that evasive tactics are pretty common throughout […]

First-Ever Russian BEC Gang, Cosmic Lynx, Uncovered
Social media giants move to defy Hong Kong’s new national security law
Hundreds of forgotten corners of mega-corp websites fall into the hands of spammers and malware slingers
Want to kill all the weak passwords? This may be the tool for you
Your 2.3m Instagram fans won’t stop the FBI… Web star accused of plotting to launder millions from cyber-crime
You may be distracted by the pandemic but FYI: US Senate panel OK’s backdoors-by-the-backdoor EARN IT Act

security update

No jail for Yahoo employee who used internal system to hack 6k accounts
Android Users Hit with ‘Undeletable’ Adware
Admins Urged to Patch Critical F5 Flaw Under Active Attack
Google VP boycotts Black Hat 2020 because of its name
Lazarus Group Adds Magecart to the Mix
Techie buys Axon body camera from eBay; finds unencrypted police videos
Purple Fox EK Adds Microsoft Exploits to Arsenal
Think of a number: A tale of iffy discount codes, supermarket loyalty cards and Hotels.com

An update that solves one vulnerability and has two fixes is now available.

Encrypted phone service EncroChat dismantled; leading to 800+ arrests
Appearing on the Hacker Valley Studio podcast

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves 13 vulnerabilities and has one errata is now available.

Three UK: We’re sending you this SMS to warn you not to pay attention to unsolicited texts
Make sure you’ve patched your F5 BIG-IP gear. Exploit code for scary bug pair is so trivial, it fits in a tweet

An update for jaeger-all-in-one-rhel7-container and jaeger-query-rhel7-container is now available for Jaeger-1.17. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Security fix for CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag

5 dating apps caught leaking millions of user-sensitive data

An update that fixes one vulnerability is now available.

Updated docker packages fix security vulnerability: A flaw was found in Docker when it creates network bridges that accept IPv6 router advertisements by default. This flaw allows an attacker who can execute code in a container to possibly spoof rogue IPv6 router

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in information disclosure, denial of service or potentially the execution of arbitrary code.

Updated tcpreplay package fixes security vulnerability: tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c (CVE-2020-12740).

Updated tomcat packages fix security vulnerability: When using Apache Tomcat versions 9.0.0.M1 to 9.0.34, if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a

Updated mailman package fixes security vulnerability: Up to mailman 2.1.29 when sending a file without a file extension (or an unknown file extension) then the file is stored in the list archive with the file extension .obj. Most web servers will try to assign a mime type

security update

Encrypted phone service EnroChat dismantled; leading to 800+ arrests
How to better protect your Roblox account from hackers with two-step verification (2SV)
Websites of eight US cities poisoned by malware skimming the credit card details of residents
22,900 MongoDB databases held to ransom by hacker threatening to report firms for GDPR violations
Hackers hijack Twitter account of Russia’s Ministry of Foreign Affairs, offer to sell stolen data

Update to Samba 4.12.5

Update to Samba 4.12.5

This update fixes CVE-2020-10177, CVE-2020-10994, CVE-2020-10379, CVE-2020-11538 and CVE-2020-10378.

# Python 3.6.11 Python 3.6.11 is the latest security fix release of Python 3.6. – bpo-39073: Disallow CR or LF in email.headerregistry.Address arguments to guard against header injection attacks. – bpo-38576: Disallow control characters in hostnames in http.client, addressing CVE-2019-18348. Such potentially malicious header injection URLs now cause a InvalidURL to be raised. –

3.48.1

Security update for CVE-2020-12695 (CallStranger)

LinkedIn was copying every keystroke of users until iOS 14 exposed it

security update

security update

DuckDuckGo collecting user browsing data without consent
Barclays Bank appeared to be using the Wayback Machine as a ‘CDN’ for some Javascript
Thousands of MongoDB databases ransacked, held for ransom

The cybercriminal behind the ransom raids on almost 23,000 databases threatens to leak the data and alert GDPR regulators The post Thousands of MongoDB databases ransacked, held for ransom appeared first on WeLiveSecurity

Use of open-source libraries leave web apps vulnerable to cyber attacks
Has your Roblox account been hacked to support Donald Trump?
E.U. Authorities Crack Encryption of Massive Criminal and Murder Network
Fitness firm V Shred exposes 606 GB worth of sensitive customer data

An update that fixes 19 vulnerabilities is now available.

Ring Doorbell’s Police Partnerships Questioned Over Racial Bias

An update that contains security fixes can now be installed.

An update that solves three vulnerabilities and has three fixes is now available.

Fighting BEC and EAC: Why whack-a-mole won’t work
F5 emits fixes for critical flaws in BIG-IP gear: Hopefully yours aren’t internet-facing while you ready a patch
Holy Guacamole! Researchers find Apache remote desktop software was silently pwnable for snooping on sessions

2.23 fixes CVE-2020-14929 (#1850048,#1850047) and new version (#1848786)

Update to latest upstream version

Fix CVE-2020-12695 (UPnP SUBSCRIBE misbehavior in hostapd WPS AP)

Euro police forces infiltrated encrypted phone biz – and now ‘criminal’ EncroChat users are being rounded up

security update

security update

Hold off that rush into the July 4 weekend – you may need this: Microsoft patches pwn-by-picture pitfalls in Win 10

Reading Time: ~ 2 min. WastedLocker Shuts Down US News Sites Over 30 news sites were compromised in the latest WastedLocker attack that affected many sites under a single parent company. Of the more than 30 companies targeted, eight belong to the Fortune 500 group and were in the early stages of a experiencing a […]

Facebook exposed user data to thousands of app developers
Users who don’t understand how to encrypt their emails won’t do it
Trojans, Backdoors and Droppers: The Most-Analyzed Malware
Microsoft releases emergency update to fix two serious Windows flaws

The out-of-band update plugs two remote code execution bugs in the Windows Codecs library, including one rated as critical The post Microsoft releases emergency update to fix two serious Windows flaws appeared first on WeLiveSecurity

Apache Guacamole Opens Door for Total Control of Remote Footprint
Facebook Privacy Glitch Gave 5K Developers Access to ‘Expired’ Data
47% of online MongoDB databases hacked demanding ransom
FakeSpy Android Malware Spread Via ‘Postal-Service’ Apps
Cisco SMB kit harbors cross-site scripting bug: One wrong link click… and that’s your router pwned remotely
Smashing Security podcast #185: Bieber fever, Roblox, and ransomware

An update for rh-nginx116-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which