Menu

Category Archives: Security

Articles about security

Foxit PDF Reader, PhantomPDF Open to Remote Code Execution

The package openvpn before version 2.4.9-1 is vulnerable to denial of service.

What Type of Home Security System Should You Get?
Bitcoin Stealers Hide in 700+ Ruby Developer Libraries
Hackers drain $25 million in assets from dForce
Prioritize alerts and jump-start your investigations with Recorded Future’s free browser extension. Sign up now.
IT services giant Cognizant hit by Maze ransomware attack
Tor Project loses a third of staff in coronavirus cuts: Unlucky 13 out as nonprofit hacks back to core ops

An update that fixes one vulnerability is now available.

Ministry of Defence lowers supplier infosec standards thanks to COVID-19 outbreak
Contact-tracing or contact sport? Defections and accusations emerge among European COVID-chasing app efforts
Hackers selling 267 million Facebook records on hacker forum

It was discovered that there was a path-traversal issue in Apache Shiro, a security framework for the Java programming language. A specially-crafted request could cause an authentication bypass.

An update that fixes 26 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Fraud & hacking guides are the most sold item on dark web
Fake Coronavirus apps hit Android & iOS users with spyware, adware
Busted: Man streamed “worst child abuse content ever seen”

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file’s parent is a symlink to a directory outside of the

Following CVEs were reported against the jackson-databind source package :

Following CVEs were reported against the awl source package: CVE-2020-11728

DHS Urges Pulse Secure VPN Users To Update Passwords

security update

Fixes CVE-2020-1730

Security fix for CVE-2020-5260 From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.4.txt): > With a crafted URL that contains a newline in it, the credential > helper machinery can be fooled to give credential information for > a wrong host. The attack has been made impossible by forbidding > a newline character in any value

Bugfix release from Google for 80.0.3987.162. —- Update to 80.0.3987.162. Fixes the following CVEs: * CVE-2020-6450 * CVE-2020-6451 * CVE-2020-6452

Attacks on Linksys Routers Trigger Mass Password Reset

Reading Time: ~ 2 min. Florida City Sees Lasting Effects of Ransomware Attack Nearly three weeks after the City of Jupiter, Florida suffered a ransomware attack that took many of their internal systems offline, the city has yet to return to normal. City officials announced they would be working to rebuild their systems from backups, […]

Hackers use typosquatting to trojanize 700 libraries in Ruby Repository
That critical VMware vuln allowed anyone on your network to create new admin users, no creds needed
Zoom Bombing Attack Hits U.S. Government Meeting
Hackers Update Age-Old Excel 4.0 Macro Attack
Google declares war on Android fleeceware scamming users through sneaky subscriptions
Google: We’ve blocked 126 million COVID-19 phishing scams in the last week
I’ve sent my worst enemies to Earworm Island

An update that solves two vulnerabilities and has one errata is now available.

Europe publishes draft rules for coronavirus contact-tracing app development, on a relaxed schedule
India says ‘Zoom is a not a safe platform’ and bans government users

New openvpn packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Poorly Secured Docker Image Comes Under Rapid Attack
You’re a botnet, you’ve got a zero-day, so where do you go? After fiber, because that’s where the bandwidth is
New PoetRAT Hits Energy Sector With Data-Stealing Tools

With a crafted URL that contains a newline in it, the credential helper machinery can be fooled to give credential information for a wrong host. The attack has been made impossible by forbidding a newline character in any value passed via the credential protocol (CVE-2020-5260).

Chromium-browser 81.0.4044.92 fixes security issues: Multiple flaws were found in the way Chromium 80.0.3987.149 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code,

Hackers steal 10 TB of data in ransomware attack on energy giant

– New Firefox and NSS upstream update – More info at https://www.mozilla.org/en- US/firefox/75.0/releasenotes/

– New Firefox and NSS upstream update – More info at https://www.mozilla.org/en- US/firefox/75.0/releasenotes/

Cisco IP Phone Harbors Critical RCE Flaw
Authorities bust multi-million online Coronavirus face mask scam
Govt minister’s Zoom webinar hijacked to display porn
A Zoom zero-day exploit is up for sale for $500,000
Streaming TV Fraudsters Steal Millions of Ad Dollars in ‘ICEBUCKET’ Attack
Alleged Zoom Zero-Days for Windows, MacOS for Sale, Report
49 crypto-wallet pickpocketing browser extensions booted from the Chrome web store

Reading Time: ~ 3 min. One of the most notable findings to come from the Webroot 2020 Threat Report was the significant rise in the number of active phishing sites over 2019—a 640% rise, to be exact. This reflects a year-over-year rise in active phishing sites, but it’s important to keep this (dangerous) threat in […]

Bad news: So much of your personal data has been hacked that lesson manuals on how to use it are the latest hot property
‘Double Extortion’ Ransomware Attacks Spike
Password security is critical in a remote work environment – see where businesses are putting themselves at risk

An update that fixes one vulnerability is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that solves 8 vulnerabilities and has two fixes is now available.

An update for ipmitool is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

United Nations reportedly tears up Tencent’s invite to its big 75th birthday bash
Stuck inside with time on your hands? The US govt would like to remind you it’s paying $5m for Nork hacking scalps
Smashing Security #174: Garry Kasparov and Animal Crossing
Malicious Google Web Extensions Harvest Cryptowallet Secrets
Taxpayers Targeted With Improved NetWire RAT Variant

security update

Linksys forces password reset for Smart Wi-Fi accounts after router DNS hack pointed users at COVID-19 malware
49 malware infected Chrome extensions found stealing user data
Tencent Ups Top Bug-Bounty Award to $15K
How to host safer Zoom meetings
Think before filling in that convenient flight refund form with all your delicious details – there’s a scam going about
Intel Fixes High-Severity Flaws in NUC, Discontinues Buggy Compute Module
PPE, COVID-19 Medical Supplies Targeted by BEC Scams
Know Your Enemy: Honeynets>
Decade of the RATs: Is Linux Secure?>
Top 5 Open-Source Serverless Security Tools>
IBM extends z15 mainframe family, intensifies Linux security>
EA Sports down – Gaming giant hit by massive DDoS attacks
Another day, another Google cull: Chocolate Factory axes 49 malicious Chrome extensions from web store
Apple: We respect your privacy so much we’ve revealed a little about what we can track when you use Maps

An update that fixes 26 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

At least someone’s making out like a bandit: Scammers have pocketed $13m in Coronavirus fraud from the US this year

A directory traversal vulnerability resulting from insufficient input sanitization was discovered in the Horde Application Framework. An authenticated remote attacker could use this flaw to execute code in the

A remote code execution vulnerability was discovered in the Horde Application Framework. An authenticated remote attacker could use this flaw to cause execution of uploaded CSV data.

A vulnerability was discovered in graphicsmagick, a collection of image processing tools, that results in a heap overflow in 32-bit applications because of a signed overflow on range check in the HuffmanDecodeImage

April 2020 and – rest assured – your Windows PC can still be pwned by something so innocuous as an unruly font

security update

An update that fixes one vulnerability is now available.

April Patch Tuesday: Microsoft Battles 4 Bugs Under Active Exploit
Over half a million Zoom accounts being sold on hacker forum
Adobe Fixes ‘Important’ Flaws in ColdFusion, After Effects and Digital Editions
TA505 Crime Gang Deploys SDBbot for Corporate Network Takeover
Cyberattacks Target Healthcare Orgs on Coronavirus Frontlines
Americans report US$13 million in losses from coronavirus scams

The median loss to fraudulent schemes that exploit the global health crisis is almost US$600 The post Americans report US$13 million in losses from coronavirus scams appeared first on WeLiveSecurity

Watch: Flaw exploited to post fake COVID-19 clips from TikTok accounts