Menu

Category Archives: Security

Articles about security

This is not Huawei to reassure people about Beijing’s spying eyes: Trivial backdoor found in HiSilicon’s firmware for net-connected cams, recorders
Ransomware Attack Hinders Toll Group Operations
Malware infection attempts appear to be shrinking… possibly because miscreants are less spammy and more focused on specific targets

security update

7 best practices for managing a multi-cloud environment
Two Critical Android Bugs Get Patched in February Update
Medtronic Patches Implanted Device, CareLink Programmer Bugs
Oh buoy. Rich yacht bods’ job agency leaves 17,000 sailors’ details exposed in AWS bucket
Israeli government’s Gov.il DNS server found vulnerable
Open-Source Security Projects: Choosing a Brandable .com Domain>
Electric scooters vulnerable to remote hacks

A helmet may not be enough to keep you safe(r) while riding an e-scooter The post Electric scooters vulnerable to remote hacks appeared first on WeLiveSecurity

Twitter API Abused to Uncover User Identities
School’s out as ransomware attack downs IT systems at Scotland’s Dundee and Angus College

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Twitter security hole allowed state-sponsored hackers to match phone numbers to usernames
Use Off-Facebook tool to stop Facebook from tracking your activities
Man admits hacking Nintendo, leaking details of Switch games console

Several security issues were fixed in SpamAssassin.

Facebook privacy settings: Protect your data with these tips

As Facebook turns 16, we look at how to keep your personal information safe from prying eyes The post Facebook privacy settings: Protect your data with these tips appeared first on WeLiveSecurity

Google’s OpenSK lets you BYOSK – burn your own security key

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Twitter says a certain someone tried to discover the phone numbers used by potentially millions of twits
Your mobile network broke the law by selling location data and may be fined millions… or maybe not, shrugs FCC
AZORult Campaign Adopts Novel Triple-Encryption Technique

security update

Tesla Autopilot Duped By ‘Phantom’ Images
Hackers exploiting vulnerability in smart doors to launch DDoS attacks
Ashley Madison Breach Extortion Scam Targets Hundreds
‘Cyber security incident’ takes its Toll on Aussie delivery giant as box-tracking boxen yanked offline
Man uses 99 smartphones to cause traffic jam on Google Maps
Would you get hooked by a phishing scam? Test yourself

As the tide of phishing attacks rises, improving your scam-spotting skills is never a bad idea The post Would you get hooked by a phishing scam? Test yourself appeared first on WeLiveSecurity

iCloud hacker perv cops nearly 3 years in jail for stealing and sharing people’s private, intimate pics

An update that solves 10 vulnerabilities and has 11 fixes is now available.

Coronavirus – hackers exploit fear of infection to spread malware
TrickBot Switches to a New Windows 10 UAC Bypass to Evade Detection
Cover for ‘cyber’ attacks is risky, complex and people don’t trust us, moan insurers

Sudo could allow unintended access to the administrator account.

WannaCry ransomware attack on NHS could have triggered NATO reaction, says German cybergeneral

git: arbitrary code execution via .gitmodules (CVE-2018-17456) SL6 x86_64 git-1.7.1-10.el6_10.x86_64.rpm git-daemon-1.7.1-10.el6_10.x86_64.rpm git-debuginfo-1.7.1-10.el6_10.x86_64.rpm i386 git-1.7.1-10.el6_10.i686.rpm git-daemon-1.7.1-10.el6_10.i686.rpm git-debuginfo-1.7.1-10.el6_10.i686.rpm noarch emacs-git-1.7.1-10.el6_10.noarch.rpm emacs-git-el-1.7.1- [More…]

Several security issues were fixed in the kernel.

Flaws punched holes in Azure cloud, Apple patches pretty much everything, Eurocops cuff Maltese hackers, etc

An update for git is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

Fixes **CVE-2017-18189**.

This update fixes CVE-2020-6851.

This update fixes CVE-2020-6851.

Fix a potential out of bounds write when checking a maliciously corrupted file system. This is probably not exploitable on 64-bit platforms, but may be exploitable on 32-bit binaries depending on how the compiler lays out the stack variables. (Addresses CVE-2019-5188) A maliciously corrupted file systems can trigger buffer overruns in the quota code used […]

security update

January 2020 CPU security update. See http://mail.openjdk.java.net/pipermail/jdk8u-dev/2020-January/010979.html https://openjdk.java.net/groups/vulnerability/advisories/2020-01-14

Update to Samba 4.11.6 —- Update to Samba 4.11.5 – Security fixes for CVE-2019-14902, CVE-2019-14907 and CVE-2019-19344

A stack-based buffer overflow vulnerability in sudo, a program designed to provide limited super user privileges to specific users, triggerable when configured with the pwfeedback option enabled. An unprivileged user

Joe Vennix discovered a stack-based buffer overflow vulnerability in sudo, a program designed to provide limited super user privileges to specific users, triggerable when configured with the “pwfeedback” option enabled. An unprivileged user can take advantage of this flaw to obtain

A heap-based buffer overflow vulnerability was discovered in the idn2_to_ascii_4i() function in libidn2, the GNU library for Internationalized Domain Names (IDNs), which could result in denial of service, or the execution of arbitrary code when processing a long

An issue was found in the IonMonkey JIT compiler of the Mozilla Firefox web browser which could lead to arbitrary code execution. For Debian 8 “Jessie”, this problem has been fixed in version

security update

security update

Advanced Obfuscation Marks Widespread Info-Stealing Campaign
Evil Corp Returns With New Malware Infection Tactic
Cyber criminals using Coronavirus emergency to spread malware

In Qt5’s plugin loader code as found in qtbase-opensource-src, it was possible to (side-)load plugins from “the” local folder in addition to a system-widely defined library path.

Iranian Hackers Target U.S. Gov. Vendor With Malware
Remember those infosec fellas who were cuffed while testing the physical security of a courthouse? The burglary charges have been dropped

* Fix issues while trying to play a video on NextCloud. * Make sure the GL video sink uses a valid WebKit shared GL context. * Fix vertical alignment of text containing arabic diacritics. * Fix build with icu 65.1. * Fix page loading errors with websites using HSTS. * Fix web process crash when […]

Reading Time: ~ 2 min. Indonesian Magecart Hackers Arrested At least three individuals were arrested in connection to the infamous Magecart information stealing malware. Thanks to the combined efforts of several international law enforcement agencies, numerous servers issuing commands to awaiting Magecart scripts have been taken down in both Indonesia and Singapore. While these are […]

Top 10 Best Writing Tools

Several vulnerabilities were fixed in libjackson-json-java. CVE-2017-7525

Travelex hobbles back online, one month after ransomware hit it hard
Zero Day Initiative Bug Hunters Rake in $1.5M in 2019
$20,000 up for grabs in Xbox Live security hole hunt
€13 million Maltese bank cyber-heist – six men arrested in UK
Sodinokibi Ransomware Group Sponsors Hacking Contest
China’s Winnti hackers (apparently): Forget the money, let’s get political and start targeting Hong Kong students for protest info
Sonos goofs again – this time revealing customers’ email addresses in Cc: blunder
A year after Bank of Valletta ‘cyber heist’, cuffs applied as cash-cleansing case continues
Microsoft Offers Rewards of Up to $20,000 in New Xbox Bug Bounty Program
Avast acknowledges collecting user data; shuts down Jumpshot
Attempts to define international infosec rules of the road bogged down by endless talkshops, warn diplomats

An update that solves one vulnerability and has three fixes is now available.

200K WordPress Sites Vulnerable to Plugin Flaw

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanag es memory, as demonstrated by IRC DCC commands in EMU_IRC.

* Fix issues while trying to play a video on NextCloud. * Make sure the GL video sink uses a valid WebKit shared GL context. * Fix vertical alignment of text containing arabic diacritics. * Fix build with icu 65.1. * Fix page loading errors with websites using HSTS. * Fix web process crash when […]

Update to 79.0.3945.130. Fixes the following security issues: * CVE-2020-6378 * CVE-2020-6379 * CVE-2020-6380

This is January 2020 OpenJDK security update for java-latest-openjdk packages. The sources are updated to the 13.0.2+8 tag.

Update to bugfix release 2.9.3. See https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst

Enterprise laptops vulnerable to critical direct memory access attack

security update

security update

Coronavirus Campaigns Spread Emotet, Malware
Bezos, WhatsApp Cyberattacks Show Growing Mobile Sophistication
Cisco Patches Two High-Severity Bugs in its Small Business Switch Lineup
UN hacked, becomes target of massive state-sponsored spying op
97% of airports showing signs of weak cybersecurity
U.N. Hack Stemmed From Microsoft SharePoint Flaw
The autofill email goof that exposed vulnerable students and cost the University of East Anglia £140,000
Difficult season: Antivirus-flinger Avast decides to ‘wind down’ Jumpshot
ProtonMail and StartMail blocked as Russia hunts for bomb threat spammers
The NHS has only suffered six ransomware attacks since the WannaCry worm, investigation reveals