Menu

Category Archives: Security

Articles about security

An update for thunderbird is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for systemd is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

RSAC 2020: Editors’ Preview of Hottest Sessions, Speakers and Themes
Burning Man Tickets for $225? Yep, Too Good to Be True
Private details of 10.7 million MGM Hotel guests sold on Dark Web
ISS World Hit with Malware Attack that Shuts Down Global Computer Network

An update that solves one vulnerability and has 10 fixes is now available.

An update that fixes four vulnerabilities is now available.

Haken Malware Family Infests Google Play Store
‘Don’t tell anyone but I have a secret.’ There, that’s my security sorted
ToTok chat app tells users to ignore Google’s spyware warning
Google exiles 600 apps from Play Store for ‘disruptive advertising’ amid push to clean up Android souk’s image
Apple drops a bomb on long-life HTTPS certificates: Safari to snub new security certs valid for more than 13 months
Stuffing nonsense: Persistent cyberpunks are pummelling banks’ public APIs, warns Akamai
Google Bans 600 Android Apps for Obnoxious Ads
RSA Conference loses one more abbreviated tech giant after AT&T disconnects over Wuhan coronavirus fears

New proftpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Researchers recovered 9 billion email & password combos in 2019
We know what you did last summer: MGM’s hotel spinoff lost 10.7m guest records and now they’re on hacker forums
Critical Cisco Bug Opens Software Licencing Manager to Remote Attack
Cybergang Favors G Suite and Physical Checks For BEC Attacks
MGM Resorts data breach exposes details of 10.6 million guests

A number of celebrities, government officials and tech CEOs were also caught up in the incident The post MGM Resorts data breach exposes details of 10.6 million guests appeared first on WeLiveSecurity

GRU won’t believe it: UK and US call out Russia for cyber-attacks on Georgia last year
Keen to check for ‘abnormal’ user behaviours? Microsoft talks insider risk, AWS imports and compliance at infosec shindig RSA
Popular YouTube gaming channel hacked to run crypto scam
Critical Adobe Flaws Fixed in Out-of-Band Update

An update that fixes 6 vulnerabilities is now available.

Smashing Security #166: What the Dickens! Ad ban thank you scam
MGM Resorts hacked: 10.6 million guests have their personal data exposed on hacking forum
Samsung freaks out smartphone owners with mysterious ‘1’ notification
MGM Grand Breach Leaked Details of 10.6 Million Guests Last Summer

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0550

Linux and malware: Should you worry?

Malicious code is nothing to worry about on Linux, right? Hold your penguins. How Linux malware has gone from the sidelines to the headlines. The post Linux and malware: Should you worry? appeared first on WeLiveSecurity

Several security issues were fixed in Squid.

ppp could be made to crash or run programs if it received specially crafted network traffic.

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Samsung will be Putin dreaded Kremlin-approved shovelware on its phones, claims Russia
Oi, Cisco! Who left the ‘high privilege’ login for Smart Software Manager just sitting out in the open?
U.S. Pipeline Disrupted by Ransomware Attack
Assange lawyer: Trump offered WikiLeaker a pardon in exchange for denying Russia hacked Democrats’ email
BlueKeep Flaw Plagues Outdated Connected Medical Devices

security update

When the air gap is the space between the ears: A natural gas plant let ransomware spread from office IT to ops
US Natural Gas-Compression facility cripples after ransomware attack
Don’t use natwest.co.uk for online banking, Natwest bank tells baffled customer
SMS Attack Spreads Emotet, Steals Bank Credentials
Hamas Ensnares Israeli Soldiers with Pretty ‘Ladies’
Hackers clone ProtonVPN website to drop password stealer malware
Cynet Offers Free Threat Assessment for Mid-Sized and Large Organizations

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Latest Tax Scams Target Apps and Tax-Prep Websites

An update for rabbitmq-server is now available for Red Hat OpenStack Platform 15 (Stein). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

What DNS encryption means for enterprise threat hunters

The dawn of the DNS over HTTPS era is putting business security and SOC teams to the challenge The post What DNS encryption means for enterprise threat hunters appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

What do a Lenovo touch pad, an HP camera and Dell Wi-Fi have in common? They’ll swallow any old firmware, legit or saddled with malware

security update

Russia Blocks Encrypted Email Service Tutanota
FC Barcelona Suffers Likely Credential-Stuffing Attack on Twitter

security update

security update

Ring Mandates 2FA After Rash of Hacks
Plastic surgery tech firm leaks images of 100,000s of customers
Iran-Backed APTs Collaborate on 3-Year ‘Fox Kitten’ Global Spy Campaign
Sensitive plastic surgery photos exposed online

Other leaked records include videos, facial and body scans, as well as a range of patients’ personal data The post Sensitive plastic surgery photos exposed online appeared first on WeLiveSecurity

$2.07bn? That’s one Dell of a deal to offload infosec biz RSA
Active Exploits Hit Vulnerable WordPress ThemeGrill Plugin
Shipping is so insecure we could have driven off in an oil rig, says Pen Test Partners
Latest LokiBot malware variant distributed as Epic Games installer
Plugin flaw leaves up to 200,000 WordPress sites at risk of attack

A fix is available, so you may want to make sure that you run the plugin’s latest version The post Plugin flaw leaves up to 200,000 WordPress sites at risk of attack appeared first on WeLiveSecurity

Hacker Scheme Threatens AdSense Customers with Account Suspension

An update that solves two vulnerabilities and has 5 fixes is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in QEMU.

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0515

Lenovo, HP, Dell Peripherals Face Unpatched Firmware Bugs
Hamas hackers posed as women to con IDF into downloading malware
Tutanota cries ‘censorship!’ after secure email biz blocked – for real this time – in Russia
Iranian APT group hacking VPN servers for “Fox Kitten Campaign”
Severe vuln in WordPress plugin Profile Builder would happily hand anyone the keys to your kingdom
FC Barcelona Twitter account hacked – again

The same hackers have also got their mitts on social media accounts of other high-profile sporting targets The post FC Barcelona Twitter account hacked – again appeared first on WeLiveSecurity

Twitter accounts of The Olympics and FC Barcelona hijacked by OurMine hacking group

An update that fixes 6 vulnerabilities is now available.

An update that fixes 25 vulnerabilities is now available.

The package thunderbird before version 68.5.0-1 is vulnerable to multiple issues including arbitrary code execution, cross-site scripting, denial of service and information disclosure.

The package systemd before version 244.2-1 is vulnerable to privilege escalation.

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Tom Lane discovered that “ALTER … DEPENDS ON EXTENSION” sub commands in the PostgreSQL database did not perform authorisation checks. For Debian 8 “Jessie”, this problem has been fixed in version

It is with a heavy heart we must inform you, once again, folks are accidentally spilling thousands of sensitive pics, records onto the internet

security update

Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (stretch), these problems have been fixed

PhotoSquared app leaks photos & home addresses of 100,000s of users

Do not evaluate arithmetic expressions from environment variables at startup

security update

Do not evaluate arithmetic expressions from environment variables at startup