Menu

Category Archives: Security

Articles about security

Southern Water not such a phisherman’s phriend, hauls itself offline to tackle email lure
RSAC 2020: Ransomware a ‘National Crisis,’ CISA Says, Ramps ICS Focus
Patrick Wardle: Apple Devices Hit With Recycled macOS Malware
“Shark Tank” TV star loses almost $400,000 in Business Email Compromise scam

An update that fixes 5 vulnerabilities is now available.

An update that solves 9 vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Your phone wakes up. Its assistant starts reading out your text messages. To everyone around. You panic. How? Ultrasonic waves
Police lose evidence to Ryuk ransomware attack; suspects walk free
Google’s War on Android App Permissions, 60 Percent Successful
RSAC 2020: GM’s Transportation Future Hinges on Cybersecurity

security update

security update

kr00k – Billions of Wi-Fi devices affected by encryption vulnerability

An uninitialized pointer vulnerability was discovered in pure-ftpd, a secure and efficient FTP server, which could result in an out-of-bounds memory read and potential information disclosure.

Cyber-wrath of Iran for top general’s assassination hasn’t progressed beyond snooping and nicking logins… yet
Clearview AI firm with photos of billions of unsuspecting users got HACKED
Facial recognition company Clearview AI hit by data theft

The startup came under scrutiny after it emerged that it had amassed 3 billion photos from social media for facial recognition software The post Facial recognition company Clearview AI hit by data theft appeared first on WeLiveSecurity

IoT Insecurity: When Your Vacuum Turns on You
RSA 2020 – Hacking humans

What the human battle against biological viruses can teach us about fighting computer infections – and vice versa The post RSA 2020 – Hacking humans appeared first on WeLiveSecurity

Sophos was gearing up for a private life – then someone remembered the bike scheme
Did someone file your taxes before you?

With tax season – and tax scams – in full swing, here’s how fraudsters can steal your tax refund, and how you can avoid becoming a victim The post Did someone file your taxes before you? appeared first on WeLiveSecurity

If you’re serious about browser privacy, you should probably pass on Edge or Yandex, claims Dublin professor
Billions of Devices Open to Wi-Fi Eavesdropping Attacks
RSAC 2020: Smart Baby Monitor Vulnerable to Remote Hackers
HackerOne rewards bughunter who found critical security hole in… HackerOne
Smashing Security #167: Coronavirus scams and an exaggerated lion
Wi-Fi of more than a billion PCs, phones, gadgets can be snooped on. But you’re using HTTPS, SSH, VPNs… right?
Top 10 worst countries for Internet freedom & censorship
After blowing $100m to snoop on Americans’ phone call logs for four years, what did the NSA get? Just one lead
RSAC 2020: Lack of Machine Learning Laws Open Doors To Attacks
Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now
Is bug hunting a viable career choice?

With earnings of top ethical hackers surpassing hundreds of thousands of dollars, some would say yes The post Is bug hunting a viable career choice? appeared first on WeLiveSecurity

Exaggerated Lion and Business Email Compromise – Don’t send that check!
Hackers Cashing In On Healthcare Industry Security Weaknesses
Departing MI5 chief: Break chat app crypto for us, kthxbai
KrØØk: Serious vulnerability affected encryption of billion+ Wi‑Fi devices

ESET researchers uncover a previously unknown security flaw allowing an adversary to decrypt some wireless network packets transmitted by vulnerable devices The post KrØØk: Serious vulnerability affected encryption of billion+ Wi‑Fi devices appeared first on WeLiveSecurity

Iranian APT Targets Govs With New Malware
Unpatched Security Flaws Open Connected Vacuum to Takeover
Stalkerware Attacks Increased 50 Percent Last Year, Report
Rotherwood Healthcare AWS bucket security fail left elderly patients’ DNR choices freely readable online

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

It was discovered that pysaml2, a Python implementation of SAML to be used in a WSGI environment, was susceptible to XML signature wrapping attacks, which could result in a bypass of signature verification.

Updated squid packages fix security vulnerabilities: Jeriko One discovered that Squid incorrectly handled memory when connected to an FTP server. A remote attacker could possibly use this issue to obtain sensitive information from Squid memory (CVE-2019-12528).

Mind the gap: Google patches holes in Chrome – exploit already out there for one of them after duo spot code fix
RSAC 2020: Blockchain is ‘Garbage In’, Voting Needs Paper Ballots

security update

Google Patches Chrome Browser Zero-Day Bug, Under Attack
RSAC 2020 Keynote: Changing the World’s False Perception of Cybersecurity
Apple tries to have VirnetX VPN patent ruling overturned again, US Supremes say no… again
Sen. Schumer Pushes for TSA Employee Ban on TikTok App at Work
Free Download: The Ultimate Security Pros’ Checklist
Password killer FIDO2 comes bounding into Azure Active Directory hybrid environments

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Microsoft uses its expertise in malware to help with fileless attack detection on Linux

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) Mozilla: Out-of-bounds read when processing certain email messages (CVE-2020-6793) Mozilla: Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords (CVE-2020-6794) Mozilla: Crash processing S/MIME messages with multiple signatures (CVE-2020-6795) Mozilla: Incorrect p [More…]

python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c (CVE-2020-5312) python-pillow: reading specially crafted image files leads to allocation of large amounts of memory and denial of service (CVE-2019-16865) SL7 x86_64 python-pillow-2.0.0-20.gitd1c6db8.el7_7.x86_64.rpm python-pillow-debuginfo-2.0.0-20.gitd1c6db8.el7_7.x86_64.rpm python-pillow- [More…]

Apple Takes Heat Over ‘Vulnerable’ iOS Cut-and-Paste Data
Open-Source AI Projects For Linux>
PayPal rejects report that exposed critical account takeover vulnerabilities
Data Breach Occurs at Agency in Charge of Secure White House Communications
Page Speed Optimization Best Practices
Samsung cops to data breach after unsolicited ‘1/1’ Find my Mobile push notification

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 5 vulnerabilities is now available.

It was discovered that the jQuery version embedded in OTRS, a ticket request system, was prone to a cross site scripting vulnerability in jQuery.extend().

libapache2-mod-auth-mellon could be made to redirect users to malicious sites.

libpam-radius-auth could be made to crash if it received specially crafted network traffic.

Do I need a VPN? A simple explanation & some real-life uses
Is your phone listening to you?

Do social media listen in on our conversations in order to target us with ads? Or are we just a bit paranoid? A little test might speak a thousand words. The post Is your phone listening to you? appeared first on WeLiveSecurity

An update that fixes 6 vulnerabilities is now available.

Google rolls out Titan keys to Europe, Japan. Plus: Group Policy bug is a feature, not a flaw, says Microsoft

security update

security update

Resolves: #1795838, #1802904 – Security fix for CVE-2020-8945

* Always use a light theme for rendering form controls. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-3862, CVE-2020-3864, CVE-2020-3865, CVE-2020-3867, CVE-2020-3868

Add patch for CVE-2020-6750 and related issues.

Update to 10.19.0

Update to 10.19.0

Update to Node.js 12.5.0

A vulnerability was found in pam_radius: the password length check was done incorrectly in the add_password() function in pam_radius_auth.c, resulting in a stack based buffer overflow.

Federal Agency that maintains secure communication for Trump got hacked

Ilja Van Sprundel reported a logic flaw in the Extensible Authentication Protocol (EAP) packet parser in the Point-to-Point Protocol Daemon (pppd). An unauthenticated attacker can take advantage of this flaw to trigger a stack-based buffer overflow, leading to denial of service

security update

Lawsuit Claims Google Collects Minors’ Locations, Browsing History
Active Attacks Target Popular Duplicator WordPress Plugin
Duped into running bogus virus scans at Office Depot? Dry your eyes with a small check from $35m settlement

– New upstream release (73.0.1)

This update backports a patch for CVE-2020-8112.

This update backports a patch for CVE-2020-8112.

Backport patches for CVE-2020-5313, CVE-2020-5312, CVE-2020-5311, CVE-2020-5310, CVE-2019-19911

Google kicks out 600 malicious apps from Play Store

An update for python-pillow is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,