Menu

Category Archives: Security

Articles about security

An update that fixes 7 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Several vulnerabilities were discovered in evince, a simple multi-page document viewer. CVE-2017-1000159

Roses are red, IBM is Big Blue. It’s out of RSA Conference after coronavirus review: IBMers will not attend infosec event over ‘health concerns’

Reading Time: ~ 2 min. Estée Lauder Leaves Massive Database Unprotected Earlier this week researchers discovered an unsecured database containing over 440 million records belonging to Estee Lauder, a major make-up manufacturer. Though the company has confirmed that no customer data was stored in that database, they are still unsure on how long it was […]

Google burns down more than 500 private-data-stealing, ad-defrauding Chrome extensions installed by 1.7m netizens

Fix CVE-2019-20388 and CVE-2020-7595

500 Google Chrome extensions found to be spreading malware
Huawei Controversy Highlights 5G Security Implications
500 Malicious Chrome Extensions Impact Millions of Users

security update

security update

Apple iPhone Users Targeted with Bogus Dating App for Valentine’s Day
SMS Phishing Campaign Targets Mobile Bank App Users in North America

Risk Level: Very Low. Type: Trojan.

News Wrap: Valentine’s Day Scams and Emotet’s Wi-Fi Hack
Institute of International Education leaks data of thousands of students
Austrian foreign ministry: ‘State actor’ hack on government IT systems is over
Hackers Can Seize Control of Ballots Cast Using the Voatz Voting App, Researchers Say
Call us immediately if your child uses Kali Linux, squawks West Mids Police
How romance scammers break your heart – and your bank account

What are some of the most common warning signs that your online crush could be a dating scammer? The post How romance scammers break your heart – and your bank account appeared first on WeLiveSecurity

AT&T insists it’s not blocking Tutanota after secure email biz cries foul, cites loss of net neutrality as cause
Voatz of no confidence: MIT boffins eviscerate US election app, claim fiends could exploit flaws to derail democracy
Fix Microsoft Outlook When Stuck on Loading Profile

– Update to 73.0

Rebase to radare2-4.2.1 and cutter-re 1.10.1. It fixes CVE-2019-19590 and CVE-2019-19547. It also fix a problem in cutter-re that did not display the window icon on Wayland.

Rebase to radare2-4.2.1 and cutter-re 1.10.1. It fixes CVE-2019-19590 and CVE-2019-19547. It also fix a problem in cutter-re that did not display the window icon on Wayland.

**Horde_Data 2.1.5** * [jan] Fix Remote Code Execution vulnerability (CVE-2020-8518, Reported by: Andrea Cardaci/SSD).

security update

security update

Critical WordPress Plugin Bug Afflicts 700K Sites
FBI: Cybercrime losses tripled over the last 5 years

On the upside, the Bureau recovered more than US$300 million in funds lost to online scams last year The post FBI: Cybercrime losses tripled over the last 5 years appeared first on WeLiveSecurity

Resolve buffer overflow in TexOpen() function, CVE-2019-19601

Rebase to radare2-4.2.1 and cutter-re 1.10.1. It fixes CVE-2019-19590 and CVE-2019-19547. It also fix a problem in cutter-re that did not display the window icon on Wayland.

Cosmetic giant Estée Lauder exposed 440 million records online
Gaza Cybergang targeting Palestinian authority figures
Privacy Experts Skeptical of Proposed Data Protection Agency
Puerto Rico government falls for $2.6 million email scam
Almost 2 billion malware installs thwarted by Google Play Protect in 2019

That’s for apps from third-party marketplaces; another 790,000 policy-breaking apps were stopped from reaching Google Play The post Almost 2 billion malware installs thwarted by Google Play Protect in 2019 appeared first on WeLiveSecurity

Puerto Rico Gov Hit By $2.6M Phishing Scam
Secure email service Tutanota complains it is being blocked by AT&T in parts of the United States
Smashing Security #165: Cheapfakes, deepfakes, and Ashley Madison
A dirty dozen of Bluetooth bugs threaten to reboot, freeze, or hack your trendy gizmos from close range
Google: Efforts Against Bad Android Apps on Play Store Are Working
Digital addiction: How to get your children off their screens

What are some of the common signs that your child may be a screen addict and what can you do to limit their screen time? The post Digital addiction: How to get your children off their screens appeared first on WeLiveSecurity

An update is now available for Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update of the Red Hat OpenShift Container Platform 3.11 and 4.1 container images is now available for Red Hat AMQ Online. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated flash-player-plugin package fixes a security vulnerability: Type confusion that leads to arbitrary code execution in the context of the current user. (CVE-2020-3757)

The updated packages fix a security vulnerability: In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service

Updated python-waitress packages fix security vulnerabilities: If a front-end server does not parse header fields with an LF the same way as it does those with a CRLF it can lead to the front-end and the back-end server parsing the same HTTP message in two different ways.

Updated vim and neovim package fixes security vulnerability: It was discovered that Vim before 8.1.1365 and Neovim before 0.3.6 did not restrict the `:source!` command when executed in a sandbox. This allows remote attackers to take advantage of the modeline feature to

Jailcore database leaks PII of inmates & correctional officers across US
2FA is being pushed out to all Google Nest users to better protect their accounts
Mozilla Firefox 73 Browser Update Fixes High-Severity RCE Bugs
SoundCloud Tackles DoS, Account Takeover Issues
Watch as virtual reality helps mom meet her deceased daughter
Katie Moussouris: The Bug Bounty Conflict of Interest
Report to Your Management with the Definitive ‘IR Management and Reporting’ Presentation Template
FBI: $3.5B Lost in 2019 to Known Cyberscams, Ransomware
Netgear’s routerlogin.com HTTPS cert snafu now has a live proof of concept
Patch now! Microsoft releases fixes for 99 security flaws, some being actively exploited by hackers

An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An denial of service via an algorithmic complexity attack on email address parsing have been identified in libemail-address-list-perl.

An update that fixes 38 vulnerabilities is now available.

An update for ose-baremetal-installer-container and ose-cli-artifacts-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact

An update for ose-installer-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

Microsoft Patch Tuesday fixes IE zero‑day and 98 other flaws

February may be the shortest month of the year, but it brings a bumper crop of patches The post Microsoft Patch Tuesday fixes IE zero‑day and 98 other flaws appeared first on WeLiveSecurity

If you’re running Windows, I feel bad for you, son. Microsoft’s got 99 problems, better fix each one
Emotet Trojan now exploits WiFi networks to infect nearby devices
Microsoft Addresses Active Attacks, Air-Gap Danger with 99 Patches
Intel Patches High-Severity Flaw in Security Engine
Estée Lauder Exposes 440M Records, with Email Addresses, Network Info
B-but it doesn’t get viruses! Not so, Apple fanbois: Mac malware is growing faster than nasties going for Windows
U.S. FDA: No link between smartphone radiation & cancer
Crypto AG backdooring rumours were true, say German and Swiss news orgs after explosive docs leaked
Adobe Addresses Critical Flash, Framemaker Flaws
China denies it was behind the Equifax hack, as four men charged for data breach
Tens of millions of biz Dell PCs smacked by privilege-escalation bug in bundled troubleshooting tool
Prison inmates’ sensitive data left exposed on leaky cloud bucket
Graham Cluley on Tripwire’s Talking Cybersecurity Podcast
Dell Patches SupportAssist Flaw That Allows Arbitrary Code Execution
Dashlane password manager’s Chrome extension has disappeared

Yubico PIV Tool could be made to crash or run programs as an administrator if it received specially crafted input.

Competing in esports: 3 things to watch out for

If you’re looking to become a pro gamer, there are risks you shouldn’t play down The post Competing in esports: 3 things to watch out for appeared first on WeLiveSecurity

spice-client: Insufficient encoding checks for LZ can cause different integer/buffer overflows (CVE-2018-10893) SL6 x86_64 spice-glib-0.26-8.el6_10.2.i686.rpm spice-glib-0.26-8.el6_10.2.x86_64.rpm spice-gtk-0.26-8.el6_10.2.i686.rpm spice-gtk-0.26-8.el6_10.2.x86_64.rpm spice-gtk-debuginfo-0.26-8.el6_10.2.i686.rpm spice-gtk-debuginfo-0.26-8.el6_10.2.x86_64.rpm spic [More…]

An update for spice-gtk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for nss-softokn is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Forgotten motherboard driver turns out to be perfect for slipping Windows ransomware past antivirus checks
US charges 4 Chinese military hackers over 2017 Equifax breach
Five Open-Source Projects AI Enthusiasts Might Want to Know About>
Game over, LAN, game over! Windows software nasty Emotet spotted spreading via brute-forced Wi-Fi networks
BYO-Bug Tactic Attacks Windows Kernel with Outdated Driver
Active PayPal Phishing Scam Targets SSNs, Passport Photos
These truly are the end times for TLS 1.0, 1.1: Firefox hopes to ‘eradicate’ weak HTTPS standard by blocking it
Hackers caught using CNET website to spread nasty malware
US govt accuses four Chinese army soldiers of hacking Equifax and siphoning 145m Americans’ personal info