Menu

Category Archives: Security

Articles about security

Top 5 Open-Source Serverless Security Tools>
IBM extends z15 mainframe family, intensifies Linux security>
EA Sports down – Gaming giant hit by massive DDoS attacks
Another day, another Google cull: Chocolate Factory axes 49 malicious Chrome extensions from web store
Apple: We respect your privacy so much we’ve revealed a little about what we can track when you use Maps

An update that fixes 26 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

At least someone’s making out like a bandit: Scammers have pocketed $13m in Coronavirus fraud from the US this year

A directory traversal vulnerability resulting from insufficient input sanitization was discovered in the Horde Application Framework. An authenticated remote attacker could use this flaw to execute code in the

A remote code execution vulnerability was discovered in the Horde Application Framework. An authenticated remote attacker could use this flaw to cause execution of uploaded CSV data.

A vulnerability was discovered in graphicsmagick, a collection of image processing tools, that results in a heap overflow in 32-bit applications because of a signed overflow on range check in the HuffmanDecodeImage

April 2020 and – rest assured – your Windows PC can still be pwned by something so innocuous as an unruly font

security update

An update that fixes one vulnerability is now available.

April Patch Tuesday: Microsoft Battles 4 Bugs Under Active Exploit
Over half a million Zoom accounts being sold on hacker forum
Adobe Fixes ‘Important’ Flaws in ColdFusion, After Effects and Digital Editions
TA505 Crime Gang Deploys SDBbot for Corporate Network Takeover
Cyberattacks Target Healthcare Orgs on Coronavirus Frontlines
Americans report US$13 million in losses from coronavirus scams

The median loss to fraudulent schemes that exploit the global health crisis is almost US$600 The post Americans report US$13 million in losses from coronavirus scams appeared first on WeLiveSecurity

Watch: Flaw exploited to post fake COVID-19 clips from TikTok accounts
Exclusive: Personal data of 1.41m US doctors sold on hacker forum
Safe Remote Access to Critical Infrastructure Networks in a Time of Global Crisis
4 million Quidd user accounts dumped on hacker forum for download
TikTok Flaw Allows Threat Actors to Plant Forged Videos in User Feeds

Reading Time: ~ 3 min. Despite the intent of ensuring safe transit of information to and from a trusted website, encrypted protocols (usually HTTPS) do little to validate that the content of certified websites is safe. With the widespread usage of HTTPS protocols on major websites, network and security devices relying on interception of user […]

An update for podman is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Let’s authenticate: Beyond Identity pitches app-wrapped certificate authority

An update that fixes one vulnerability is now available.

Malware Risks Triple on WFH Networks: Experts Offer Advice

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat Satellite 6.7 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Is “global privacy” an oxymoron?

While in France, a citizen of Brazil who resides in California books a bungee jump in New Zealand. Is it a leap of faith into the unknown, for both the operator and the thrill-seeker? The post Is “global privacy” an oxymoron? appeared first on WeLiveSecurity

Red Hat AMQ Broker 7.4.3 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Zoom adds Choose Your Own Routing Adventure to keep chats out of China
So how do the coronavirus smartphone tracking apps actually work and should you download one to help?
Oracle Tackles a Massive 405 Bugs for Its April Quarterly Patch Update
Gaming controllers manufacturer exposed 1.1M customer records
Overlay Malware Leverages Chrome Browser, Targets Banks and Heads to Spain
How to make a stranger’s insecure 3D printer halt-and-catch-fire – plus more alerts from infosec world

New upstream version, fix CVEs

## 1.4.3 (12, Nov 2019) ### Security Improvements: – Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465).

– https://www.drupal.org/project/ckeditor/releases/7.x-1.19 – https://www.drupal.org/sa-contrib-2020-007

New upstream version, fix CVEs

## 1.4.3 (12, Nov 2019) ### Security Improvements: – Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465).

– https://www.drupal.org/project/ckeditor/releases/7.x-1.19 – https://www.drupal.org/sa-contrib-2020-007

Security fix for CVE-2020-11100)

An update that contains security fixes can now be installed.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

2 San Francisco Int. airport websites hacked with info-stealer code
Dutch Police takes down 15 DDoS-for-hire services in one week

An update that solves one vulnerability and has three fixes is now available.

An update that fixes 5 vulnerabilities is now available.

SFO Websites Hacked: Airport Discloses Data Breach
Apple, Google Team on Coronavirus Tracking – Sparking Privacy Fears
WooCommerce Falls to Fresh Card-Skimmer Malware

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More…]

A vulnerability in libssh could allow a remote attacker to cause a Denial of Service condition.

3D printed fingerprints can unlock your device with 80% success rate
Critical VMware Bug Opens Up Corporate Treasure to Hackers
Apple App Store Riddled With Money-Sucking Fleeceware Apps
The pains – and pleasures? – of network security: Tell us exactly what you think about this corner of business IT
Travelex Pays $2.3M in Bitcoin to Hackers Who Hijacked Network in January

Reading Time: ~ 2 min. Malicious COVID-19 Websites Surge In recent months, more than 136 thousand new domains have been registered that reference the current COVID-19 outbreak, many of which have yet to be flagged. A large portion of these sites are distributing phishing campaigns with fake bank login forms and inaccurate URLs, including any […]

An update that fixes two vulnerabilities is now available.

The package libssh before version 0.9.4-1 is vulnerable to denial of service.

The package wireshark-cli before version 3.2.3-1 is vulnerable to arbitrary code execution.

The package chromium before version 81.0.4044.92-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure, access restriction bypass and insufficient validation.

The package firefox before version 75.0-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and access restriction bypass.

The package haproxy before version 2.1.4-1 is vulnerable to arbitrary code execution.

Compromised Zoom Credentials Swapped in Underground Forums
Ransomware scumbags leak Boeing, Lockheed Martin, SpaceX documents after contractor refuses to pay
Cloudflare Axes Google reCAPTCHA Due to Privacy, Price
Unique P2P Architecture Gives DDG Botnet ‘Unstoppable’ Status

security update

security update

Signal sends smoke, er, signal: If Congress cripples anonymous speech with EARN IT Act, we’ll shut US ops
Copycat Site Serves Up Raccoon Stealer
A billion-dollar US firm caught exposing highly sensitive database online
Report: Travelex paid hackers $2.3 million worth of Bitcoin after ransomware attack
Zoom takes action after meeting IDs leak in careless screenshots

An update that fixes 5 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Consumer reviewer Which? finds CAN bus ports on Ford and VW, starts yelling ‘Security! We have a problem…’

An update that fixes 5 vulnerabilities is now available.

Zoom Taps Ex-Facebook CISO Amid Security Snafus, Lawsuit

Security fix for CVE-2020-5247, CVE-2020-5249

This update incorporates fixes from the upstream glibc 2.29 stable release branch, including 3 fixes for medium severity security vulnerabilities. (CVE-2020-10029, CVE-2020-1752, CVE-2020-1751)

Cisco ‘Critical Update’ Phishing Attack Steals Webex Credentials
‘Unbreakable’ Smart Lock Draws FTC Ire for Deceptive Security Claims
Smashing Security #173: 5G fiascos, Zoom gloom, and butt biometrics
52k Iranian ID cards with selfies sold on dark web & hacking forum
Low-orbit internet banking fraud claim alleged to be a load of space junk
Cloudflare dumps Google’s reCAPTCHA, moves to hCaptcha as free ride ends (and something about privacy)
PowerPoint ‘Weakness’ Opens Door to Malicious Mouse-Over Attack