Menu

Category Archives: Security

Articles about security

Zoom Removes Data-Mining LinkedIn Feature
Terabytes of OnlyFans data being sold on hacking forum
In COVID-19 Scam Scramble, Cybercrooks Recycle Phishing Kits

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Rethinking VPN: Tailscale startup packages Wireguard with network security
44M Digital Wallet Items Exposed in Key Ring Cloud Misconfig
Zoom promises to improve its security and privacy as usage (and concern) soars
Emerging MakeFrame Skimmer from Magecart Sets Sights on SMBs

An update is now available for Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Smashing Security #172: UncleF***Face

An update for haproxy is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

“World’s most secure online backup” provider exposes 135M records
Microsoft finds itself in odd position of sparing elderly, insecure protocols: Grants stay of execution to TLS 1.0, 1.1
For the past five years, every FBI secret spy court request to snoop on Americans has sucked, says watchdog
Wiper Malware Called “Coronavirus” Spreads Among Windows Victims

security update

Coronavirus ‘Financial Relief’ Phishing Attacks Spike
Cloudflare family-friendly DNS service flubs first filtering foray: Vital LGBTQ, sex-ed sites blocked ‘by mistake’
Cyberscum target Microsoft SQL Server boxen – and some careless sysadmins were reinfected after cleaning it out
Marriott Hotels hacked AGAIN: Two compromised employee logins abused to siphon off 5.2m guests’ personal info
Critical WordPress Plugin Bug Can Lock Admins Out of Websites
Hackers mining Monero on Microsoft SQL databases for last 2 years

The krb5 PAM module (pam_krb5.so) had a buffer overflow that might have caused remote code execution in situations involving supplemental prompting by a Kerberos library.

Two Zoom Zero-Day Flaws Uncovered
Marriott hacked again, 5.2 million guests affected

Bad actors accessed a range of personally identifiable information, including names, dates of birth and a lot more The post Marriott hacked again, 5.2 million guests affected appeared first on WeLiveSecurity

A vulnerability was discovered in python-bleach, a whitelist-based HTML-sanitizing library. Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to a regular expression denial

Top Email Protections Fail in Latest COVID-19 Phishing Campaign
At the Supreme Court, Morrisons pops data breach liability win into its trolley – but it’s not a get-out-of-compo free card for businesses
Coronavirus con artists continue to spread infections of their own

The scam machine shows no signs of slowing down, as fraudsters dispense bogus health advice, peddle fake testing kits and issue malware-laced purchase orders The post Coronavirus con artists continue to spread infections of their own appeared first on WeLiveSecurity

Reading Time: ~ 4 min. It’s a nightmare, it’s inconvenient, and it’s inevitable. Losing or having your smart device stolen poses a significant, looming privacy risk— we just don’t like to think about it. However, this is an instance where hiding your head in the sand will only make you more susceptible to attack. The […]

Marriott hacked AGAIN – Millions of guests’ data accessed by hackers

An update that fixes one vulnerability is now available.

Apple’s latest macOS Catalina update mysteriously borks SSH for some unlucky fans. What could be the cause?

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the idm:DL1 module is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Zoom’s end-to-end encryption isn’t actually end-to-end at all. Good thing the PM isn’t using it for Cabinet calls. Oh, for f…

An update for nss-softokn is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Australian state will install home surveillance hardware to make sure if you’re in virus isolation, you stay there
Singapore government scraps physical 2FA tokens for government services
Watering-Holes Target Asian Ethnic Victims with Flash Update Decoy
Houseparty denies hacking user accounts; offers $1 million reward
Epic Games floats $1m bounty to ID source of ‘commercial smear’ claiming Houseparty chat app has been hacked
Zoom Scrutinized As Security Woes Mount
8-Year-Old VelvetSweatshop Bug Resurrected in LimeRAT Campaign
Marriott Hotels hacked AGAIN: Two compromised employee logins abused to siphon off guests’ personal info

An issue has been found in apng2gif, a tool for converting APNG images to animated GIF format.

Several issues have been found in gst-plugins-bad0.10, a package containing GStreamer plugins from the “bad” set.

Millions of Guests Impacted in Marriott Data Breach, Again
The UK Cabinet is meeting on Zoom… here’s the meeting ID

An update that fixes 9 vulnerabilities is now available.

A minor security issue and a severe packaging bug have been fixed in tinyproxy, a lightweight http proxy daemon.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Watch out; cyber criminals are Zoom-bombing video conferences
With Kubernetes Operators comes great responsibility
Has Houseparty really been hacked? $1 million reward offered to unearth who is behind widespread claims
Covid-19 Poll Results: One in Four Prioritize Health Over Privacy
Have you backed up your smartphone lately?

With World Backup Day upon us, we walk you through the ways to back up your iPhone or Android phone so that your personal information remains safe The post Have you backed up your smartphone lately? appeared first on WeLiveSecurity

Personal details & phone numbers of 42M Iranians sold on a hacking forum
Nation-State Attacks Drop in Latest Google Analysis
Zoom Kills iOS App’s Data-Sharing Facebook Feature
Zeus Sphinx Banking Trojan Arises Amid COVID-19
Working from home? Hackers can drop malware with fake Zoom apps
Cyber volunteers needed to help protect our health services during the Coronavirus outbreak
Work from home: Videoconferencing with security in mind

With COVID-19 concerns canceling face-to-face meetings, be aware of the security risks of videoconferencing and how to easily overcome them The post Work from home: Videoconferencing with security in mind appeared first on WeLiveSecurity

An update that solves three vulnerabilities and has one errata is now available.

“Secure” cloud storage provider exposes customer data in plain-text

Multiple vulnerabilities have been found in QEMU, the worst of which could result in the arbitrary execution of code.

Poured your info out on a call to 118 118 Money? Bad luck. Credit provider ‘fesses up that hacker nabbed customer service phone recordings

Multiple vulnerabilities have been found in FFmpeg, the worst of which allows remote attackers to execute arbitrary code.

Multiple vulnerabilities have been found in libxls, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in GNU IDN Library 2, the worst of which could result in the remote execution of arbitrary code.

A buffer overflow in GNU Screen might allow remote attackers to corrupt memory.

I made a guest appearance on Technado, talking cybersecurity from the safety of my shed
You know all those stories of leaky cloud buckets taken offline? Well, some may still be there, just badly hidden
First-ever SANS Women in Cybersecurity survey reveals significant mentorship gaps

An update that solves two vulnerabilities and has one errata is now available.

Fix CVE-2018-19655

Fix CVE-2018-19655

Hackers sending malware infected USBs with Best Buy Gift Cards

Fix CVE-2018-19655

* New upstream release 5.3.1 (rhbz#1814882) * Fixes CVE-2020-1747 (rhbz#1807367,1809011)

An update that fixes 7 vulnerabilities is now available.

“Operation Poisoned News” infecting iPhones with LightSpy spyware
How To Keep Your Router And WiFi Safe From Hackers
Yeah, that Zoom app you’re trusting with work chatter? It lives with ‘vampires feeding on the blood of human data’

security update

Reading Time: ~ 2 min. World Health Organization Sees Rise in Cyberattacks Officials for the World Health Organization (WHO) have announced that many of their sites and servers have been under attack by unsuccessful hackers trying to capitalize on the latest health scare. The attack stemmed from the use of several malicious domains that attempted […]

Dark web hosting firm quits after hackers delete its database
Apple Unpatched VPN Bypass Bug Impacts iOS 13, Warn Researchers

An update that fixes one vulnerability is now available.

Cybersecurity insurance firm Chubb investigates its own ransomware attack
Cyber crime marketplace DEER.IO seized, admin arrested from JFK airport

ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c (CVE-2020-5208) SL7 x86_64 ipmitool-1.8.18-9.el7_7.x86_64.rpm ipmitool-debuginfo-1.8.18-9.el7_7.x86_64.rpm noarch bmc-snmp-proxy-1.8.18-9.el7_7.noarch.rpm exchange-bmc-os-info-1.8.18-9.el7_7.noarch.rpm – Scientific Linux Development Team

Zeek and Jitsi: 2 open source projects we need now

The 5.5.11 stable kernel update contains a number of important fixes across the tree.

* New upstream release 5.3.1 (rhbz#1814882) * Fixes CVE-2020-1747 (rhbz#1807367,1809011)