Menu

Category Archives: Security

Articles about security

The updated packages fix a security vulnerability: In Sudo before 1.8.31, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however,

Equifax Breach: Four Members of Chinese Military Charged with Hacking
Docker Registries Expose Hundreds of Orgs to Malware, Data Theft
Emotet Now Hacks Nearby Wi-Fi Networks to Spread Like a Worm
Owner of dark web Freedom hosting pleads guilty to host child abuse content
Coronavirus phishing attack disguises as a message from the Center for Disease Control

Security researchers from Snyk discovered that the fix for CVE-2019-9658 was incomplete. Checkstyle, a development tool to help programmers write Java code that adheres to a coding standard, was still vulnerable to XML External Entity (XXE) injection.

How to bring security into agile development and CI/CD
Home anti-virus products put to the test by AV-Comparatives – which received the highest score?

an out-of-bounds write vulnerability due to an integer overflow was reported in libexif, a library to parse exif files. This flaw might be leveraged by remote attackers to cause denial of service, or potentially execute arbitrary code via crafted image files.

Several security issues were fixed in libxml2.

Several security issues were fixed in Qt.

Facebook loses control of its own Twitter account in hacker attack – and more news

Add patch for CVE-2020-6750 and related issues.

Emergency call service in Australia to use AI to detect signs of heart attack

An update that fixes 38 vulnerabilities is now available.

Update to Node.js 12.15.0

Update to Node.js 12.15.0

Update to Node.js 12.15.0

libasr-1.0.4, opensmtpd-6.6.2p1 update

libasr-1.0.4, opensmtpd-6.6.2p1 update

Facebook’s Twitter account is hijacked by notorious OurMine hacking group
Dark web hackers selling payment card data of half a million Indians
Wacom Tablet Data Exfiltration Raises Security Concerns

Resolve buffer overflow in TexOpen() function, CVE-2019-19601

Resolves: #1796107, #1796109 – Security fix for CVE-2019-19921

Update to upstream 2.0.1 release for CVE-2019-10747

Update to upstream 1.3.2 release for CVE-2019-10746

MinGW cross compiled SDL 2.0.10, fixing a number of CVE issues.

Update to 2.40.0. —- MinGW cross compiled gdk-pixbuf 2.36.12 release, fixing various CVE’s.

Google Chrome to block file downloads – from .exe to .txt – over HTTP by default this year. And we’re OK with this
Critical Android Bluetooth Bug Enables RCE, No User Interaction Needed

security update

security update

The Oscar nominated movie you just downloaded could be a malware

Reading Time: ~ 2 min. Tax Season Brings Emotet to the Front As Americans prepare for tax season, Emotet authors have started a new campaign that imitates a W-9 tax form requested by the target. As with most malicious phishing, an attached document asks users to enable macros when viewing the files. This campaign can […]

Google Chrome To Bar HTTP File Downloads
Uncle Sam tells F-35B allies they’ll have to fly the things a lot more if they want to help out around South China Sea
Dutch university paid $220,000 ransom to hackers after Christmas attack
Critical Citrix RCE Flaw Still Threatens 1,000s of Corporate LANs
Day 4 of outage: UK’s Manchester police deploy exciting new carbon-based method to record crime
Phishing Campaign Targets 250 Android Apps with Anubis Malware
Apple fined €25 million for deliberately slowing down old iPhones
The RSAC 2020 Trend Report

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that fixes four vulnerabilities is now available.

Android users at risk from Bluetooth hijack attack, and are warned of “short distance worm” threat
Magecart Gang Attacks Olympic Ticket Reseller and Survival Food Sites

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

Android owners – you’ll want to get these latest security patches, especially for this nasty Bluetooth hijack flaw
How Technology Has Altered the Education Landscape
Good: IT admins scrambled to patch 80 per cent of public-facing Citrix boxes to close nightmare hijack hole
Hackers can steal data from air-gapped PC using screen brightness
Metamorfo Returns with Keylogger Trick to Target Financial Firms
U.S. Finance Sector Hit with Targeted Backdoor Campaign
Shoe with GPS embedded insole tracks ‘lost’ alzheimer’s & dementia patients
How your network could be hacked through a Philips Hue smart bulb
Wacom drawing tablets are spying on every app you open, and sending the data back to Wacom
Researchers reckon 500k PCs infested with malware after dodgy downloads install even more nasties from Bitbucket

This package allowed ../ directory traversal to access private resources because resource matching did not ensure that pathnames were in a canonical format.

How your screen’s brightness could be leaking data from your air-gapped computer

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in Pillow.

Charming Kitten Uses Fake Interview Requests to Target Public Figures
Dropbox Passes $1M Milestone for Bug-Bounty Payouts
Smashing Security #164: A bitter pill to swallow
LCD pwn System: How to modulate screen brightness to covertly transmit data from an air-gapped computer… slowly
Yahoo! hack! payout! nearly! approved! and! the! question! is! how! to! spend! 60! cents!?
WhatsApp flaw gave hackers access to files from Windows and Macs
Terrifying bug in WhatsApp allows hackers to steal files. So get patching all nine of you using it on the desktop
Sketchy behavior? Wacom tablet drivers phone home with names, times of every app opened on your computer
CamuBot Banking Trojan Returns In Targeted Attacks
Time to patch your lightbulb? Researchers demonstrate Philips Hue exploit
Hackers can use flaw in Philips smart light bulbs to spread malware
New Lemon Duck Malware Campaign Targets IoT, Large Manufacturers
RIP FTP? File Transfer Protocol switched off by default in Chrome 80
Oh ****… Sudo has a ‘make anyone root’ bug that needs to be patched – if you’re unlucky enough to enable pwfeedback
Man pleads guilty to hacking Nintendo & possession of child pornography
WhatsApp Bug Allows Malicious Code-Injection, One-Click RCE
They can’t collect your bins or fix your roads. They let Google stalk visitors to their websites. Yes, it’s UK local government
Critical Cisco ‘CDPwn’ Protocol Flaws Explained: Podcast
Critical Cisco ‘CDPwn’ Flaws Break Network Segmentation

An update that solves two vulnerabilities and has one errata is now available.

Several security issues were fixed in systemd.

Gamaredon APT Improves Toolset to Target Ukraine Government, Military
How to catch a cybercriminal: Tales from the digital forensics lab

What is it like to defeat cybercrime? A peek into how computer forensics professionals help bring cybercriminals to justice. The post How to catch a cybercriminal: Tales from the digital forensics lab appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

OpenSMTPD could be made to run programs as root if it received specially crafted input over the network.

ipa: Denial of service in IPA server due to wrong use of ber_scanf() (CVE-2019-14867) * ipa: Batch API logging user passwords to /var/log/httpd/error_log (CVE-2019-10195) SL7 x86_64 ipa-client-4.6.5-11.el7_7.4.x86_64.rpm ipa-debuginfo-4.6.5-11.el7_7.4.x86_64.rpm ipa-server-4.6.5-11.el7_7.4.x86_64.rpm ipa-server-trust-ad-4.6.5-11.el7_7.4.x86_64.rpm noarch ipa-client-co [More…]

hw: TSX Transaction Asynchronous Abort (TAA) (CVE-2019-11135) * QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378) SL7 x86_64 qemu-img-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-common-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-debuginfo-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-tools-1.5.3-167.el7_7.4.x86_64.rpm – Scien [More…]

Google Takeout a bit too true to its name after potentially 1000s of private videos shared with complete strangers
Is Chrome really secretly stalking you across Google sites using per-install ID numbers? We reveal the truth
Welp – Google sent your photos & videos to strangers
Community Housing Nonprofit Hit with $1.2M Loss in BEC Scam