Menu

Category Archives: Security

Articles about security

SAS@home Virtual Summit Showcases New Threat Intel, Industry Changes
Latest Apple Text-Bomb Crashes iPhones via Message Notifications
Hackers set up fake NHS website to spread malware

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

Following ESET’s discovery, a Monero mining botnet is disrupted

ESET researchers discover, and play a key role in the disruption of, a 35,000-strong botnet spreading in Latin America via infected USB drives The post Following ESET’s discovery, a Monero mining botnet is disrupted appeared first on WeLiveSecurity

News Wrap: Nintendo Account Hacks, Apple Zero Days, NFL Security
Nintendo accounts hacked: 160,000 accounts accessed by hackers
Latest iOS Text Bomb Bug Crashing iPhones with Sindhi Characters
Nintendo Confirms Breach of 160,000 Accounts
Apple Pushes Back Against Zero-Day Exploit Claims

Reading Time: ~ 2 min. Los Angeles Suburb Hit with Ransomware Last month, the City of Torrance, California fell victim to a ransomware attack that shut down many of their internal systems and demanded 100 Bitcoins to not publish the stolen data. Along with the roughly 200GB of data it stole from the city, the […]

Text ‘bomb’ crashes iPhones, iPads, Macs and Apple Watches – what you need to know

Several vulnerabilities have been discovered in the OpenJDK Java runtime, resulting in denial of service, insecure TLS handshakes, bypass of sandbox restrictions or HTTP response splitting attacks.

Canada’s .ca overlord rolls out free privacy-protecting DNS-over-HTTPS service for folks in Great White North

Reading Time: ~ 4 min. Did you know there are three primary types of hacker—white hats, black hats, and grey hats—and that there are subcategories within each one? Despite what you may have heard, not all hackers have intrinsically evil goals in mind. In fact, there are at least 300,000 hackers throughout the world who […]

New Zoom vulnerability lets hackers record any meeting anonymously
iOS Mail app flaws may have left iPhone users vulnerable for years

A pair of vulnerabilities in the default email app on iOS devices is believed to have been exploited against high-profile targets The post iOS Mail app flaws may have left iPhone users vulnerable for years appeared first on WeLiveSecurity

Valve Confirms CS:GO, Team Fortress 2 Source-Code Leak
Buying a secondhand device? Here’s what to keep in mind

If you’re trying to be responsible towards the planet, also be responsible to yourself and take these steps so that the device doesn’t end up costing you more than you’ve saved The post Buying a secondhand device? Here’s what to keep in mind appeared first on WeLiveSecurity

Serious flaws found in multiple smart home hubs: Is your device among them?

In worst-case scenarios, some vulnerabilities could even allow attackers to take control over the central units and all peripheral devices connected to them The post Serious flaws found in multiple smart home hubs: Is your device among them? appeared first on WeLiveSecurity

Public Sector Ransomware Attacks Rage On: Can Your Organization Repel Them?
WHO, CDC and Bill and Melinda Gates Foundation Victims of Credential Dump, Report
A Dozen Nation-Backed APTs Tap COVID-19 to Cover Spy Attacks
Skype Phishing Attack Targets Remote Workers’ Passwords
iOS exploit lets attackers access default iPhone mail app
Fake Skype, Signal Apps Used to Spread Surveillanceware

Multiple vulnerabilities have been found in Git which might all allow attackers to access sensitive information.

Maze ransomware – what you need to know

The package lib32-openssl before version 1.1.1.g-1 is vulnerable to denial of service.

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More…]

Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities were found in OpenSSL, the worst of which could allow remote attackers to cause a Denial of Service condition.

python-twisted: HTTP request smuggling when presented with two Content-Length headers (CVE-2020-10108) * python-twisted: HTTP request smuggling when presented with a Content-Length and a chunked Transfer-Encoding header (CVE-2020-10109) SL7 x86_64 python-twisted-web-12.1.0-7.el7_8.x86_64.rpm – Scientific Linux Development Team

GCC 10 gets security bug trap. And look what just fell into it: OpenSSL and a prod-of-death flaw in servers and apps
Smashing Security #175: Zoom deepfakes, Zardoz, and ‘Rona tracing
Why should the UK pensions watchdog be able to spy on your internet activities? Same reason as the Environment Agency and many more
Get your free work-from-home IT security awareness training kit, courtesy of SANS
Vietnam alleged to have hacked Chinese organisations in charge of COVID-19 response
Zero-click, zero-day flaws in iOS Mail ‘exploited to hijack’ VIP smartphones. Apple rushes out beta patch
CS:GO & Team Fortress 2 source code leaked – Virus alert for TF2
Stripe is absolutely logging your mouse movements on websites’ payment pages – for your own good, says CEO
Fast-Moving DDoS Botnet Exploits Unpatched ZyXel RCE Bug
After intense scrutiny, Zoom tightens up security with version 5. New features include not, er, spilling video calls to network snoops
This Zoom trick would have spared swearing politician’s blushes
Apple Patches Two iOS Zero-Days Abused for Years
Connected Home Hubs Open Houses to Full Remote Takeover
LA County Hit with DoppelPaymer Ransomware Attack
How gamification can boost your cybersecurity training

Security is not a game, but learning about it could be – here’s why adding the fun factor can help employees become more cyber-aware The post How gamification can boost your cybersecurity training appeared first on WeLiveSecurity

Notorious dark web child abuser arrested after int’l operation
Microsoft Issues Out-Of-Band Security Update For Office, Paint 3D
How to protect your Nintendo account from hackers with two-step verification (2SV)
Attention, lockdown DIY fans: UK hardware flinger Robert Dyas had credit card data and more skimmed from website
New iOS vulnerability being exploited to spy on Uyghurs in China
Small Businesses Tapping COVID-19 Loans Hit with Data Exposure
Attack of the clones: If you were relying on older Xilinx FPGAs to keep your product’s hardware code encrypted and secret, here’s some bad news
Yes, there’s lots of COVID-19-themed scuminess around – but otherwise the level of cybercrime is the same
Free ebook for every reader: Unleash the power of your Apple fleet with Jamf

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Netflix says subscriptions just boomed but tells investors it’s no money heist and they should expect stranger things

An update for openshift-enterprise-hyperkube-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openshift is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Exercise tech firm Kinomap leaks 40GB database with 42M records
Banking.BR Android Trojan Emerges in Credential-Stealing Attacks
NFL Tackles Cybersecurity Concerns Ahead of 2020 Draft Day

security update

IBM == Insecure Business Machines: No-auth remote root exec exploit in Data Risk Manager drops after Big Blue snubs bug report
RCE Exploit Released for IBM Data Risk Manager
Work from home: Should your digital assistant be on or off?

Being at your beck and call is central to the “personality” of your digital friend, but there are situations when the device could use some time off The post Work from home: Should your digital assistant be on or off? appeared first on WeLiveSecurity

Hey there! Are you using WhatsApp? Your account may be hackable

Can someone take control of your WhatsApp account by just knowing your phone number? We ran a small test to find out. The post Hey there! Are you using WhatsApp? Your account may be hackable appeared first on WeLiveSecurity

Hacker returns $25 million after their IP address is exposed
Frippin’ heck: Watch out, chin-stroking prog rock fans. King Crimson distributor Burning Shed says it’s been hacked
Nintendo accounts are being hacked for fraudulent transactions
Oil and Gas Firms Targeted With Agent Tesla Spyware
Deepfakes and AI: Fighting Cybersecurity Fire with Fire

An update for git is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Cyberattackers Ramp Up to 1.5M COVID-19 Emails Per Day

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Something a bit phishy in your inbox? You can now email suspected frauds straight to Blighty’s web takedown cops

Reading Time: ~ 4 min. “One of the things about working in internet technology is nothing lasts forever… [Students] come to me and they say, ‘I want to do something that has an impact 20, 50, or 100 years from now.’ I say well maybe you should compose music because none of this technology stuff […]

The package webkit2gtk before version 2.28.1-1 is vulnerable to arbitrary code execution.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Bernd Edlinger discovered that malformed data passed to the SSL_check_chain() function during or after a TLS 1.3 handshake could cause a NULL dereference, resulting in denial of service.

Typosquatting RubyGems laced with Bitcoin-nabbing malware have been downloaded thousands of times
Weeks before US oil contract prices went negative, a spear-phishing crew went after oil firms. What did they get?
Google productises its own not-a-VPN secure remote access tool
Bad news: Cognizant hit by ransomware gang. Worse: It’s Maze, which leaks victims’ data online after non-payment

security update

security update

CFAA latest: Supremes to tackle old chestnut of what ‘authorized use’ of a computer really means in America
Mootbot Botnet Targets Fiber Routers with Dual Zero-Days
Maze Ransomware Attack Hits Cognizant
Dark web scammers selling ventilators & MP3 files to kill Coronavirus