Menu

Category Archives: Security

Articles about security

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code.

Facebook to Pay $550M to Settle Class Action Case Over Facial Recognition
Smashing Security #163: Russian heists and Ring wrongs

Two vulnerabilities have recently been discovered in the stream-tcp code of the intrusion detection and prevention tool Suricata.

If only 3 in 100,000 cyber-crimes are prosecuted, why not train cops to bring these crooks to justice once and for all, suggests think-tank veep
Dell, HP Memory-Access Bugs Open Attacker Path to Kernel Privileges
IoT laws are coming: What to expect

No more default logins on new IoT devices if UK legislators get their way The post IoT laws are coming: What to expect appeared first on WeLiveSecurity

An update that solves one vulnerability and has four fixes is now available.

Teleworking threats in the security spotlight in the run-up to the Tokyo Olympics
Anatomy of OpenBSD’s OpenSMTPD hijack hole: How a malicious sender address can lead to remote pwnage
Kali Linux 2020.1 released – Download now
UN didn’t patch SharePoint, got mega-hacked, covered it up, kept most staff in the dark, finally forced to admit it
Apple Security Updates Tackle iOS Device Tracking, RCE Flaws
Stolen card data of millions of Wawa customers sold on dark web
Google Sets Record High in Bug-Bounty Payouts
Canadian insurer paid for ransomware decryptor. Now it’s hunting the scum down
Critical Flaws in Magento e-Commerce Platform Allow Code-Execution
Video: Zoom Researcher Details Web Conference Security Risks, 2020 Threats
Only 6 ransomware attacks on the UK’s NHS since WannaCry worm hit in 2017 – report
Cynet Empowers IT Resellers and Service Providers to Become Fully Qualified MSSPs

Several vulnerabilities have been discovered in the otrs2 package that may lead to unauthorized access, remote code execution and spoofing.

Apache Solr could be made to run programs if it received specially crafted network traffic.

Win $1.5 million hacking an Android phone
Wawa Breach May Have Affected More Than 30 Million Customers
Time to celebrate Data Privacy Day!
How AI will improve API security

The following vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2019-8835

It was discovered that there were a large number of NULL pointer dereferences due to unchecked return values from malloc and friends in hiredis, a minimalistic C client library.

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes two vulnerabilities is now available.

Dear friends in DevSecOps: Don’t forget, security is your responsibility, too – now learn how to do it right
New ‘CacheOut’ Attack Targets Intel CPUs
Cache flow problems continue for Intel: Yet more data-leaking processor design blunders discovered, patches due soon
Trolls-For-Hire Pave Way For Sophisticated Social Media Hacks
Coronavirus claims new victim: ‘DEF CON cancelled’ joke cancelled after DEF CON China actually cancelled
Ring Doorbell App for Android Caught Sharing User Data with Facebook, Data-Miners
New report suggests anti-virus firm Avast is selling user data to 3rd parties
IoT security? We’ve heard of it, says UK.gov waving new regs
Hackers blitz social media accounts of 15 NFL teams

The league and scores of teams were caught off-guard by the re-emergence of an infamous hacking group The post Hackers blitz social media accounts of 15 NFL teams appeared first on WeLiveSecurity

MTTD and MTTR: Two Metrics to Improve Your Cybersecurity
1 in 10 Macs hit by crude malware that poses as Flash Player update, reports Kaspersky

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Libgcrypt could be made to expose sensitive information.

The duke of URL: Zoom meetups’ info leaked out through eavesdrop hole
LoRaWAN Encryption Keys Easy to Crack, Jeopardizing Security of IoT Networks

OpenJPEG had a heap-based buffer overflow in opj_t1_clbl_decode_processor in libopenjp2.so.

Windows 7 definitely won’t ever receive any more bug fixes (errm… apart from this one for its wallpaper)
Zoom Fixes Flaw Opening Meetings to Hackers
How to take charge of your Google privacy settings

Have you had a Google Privacy Checkup lately? If not, when better than Data Privacy Day to audit the privacy of your Google account? The post How to take charge of your Google privacy settings appeared first on WeLiveSecurity

An update that fixes three vulnerabilities is now available.

16 NFL teams have their social media accounts hijacked by OurMine hacking gang

An update for openjpeg2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

NetWars! Let the SANS Tournaments commence: Compete and learn all about forensics, incident response, red teaming – and much more
Remember the Clipper chip? NSA’s botched backdoor-for-Feds from 1993 still influences today’s encryption debates
Google, Mozilla Ban Hundreds of Browser Extensions in Chrome, Firefox
Google halts paid-for Chrome extension updates amid fraud surge: Web Store in lockdown ‘due to the scale of abuse’
As Necurs Botnet Falls from Grace, Emotet Rises
Maryland: Make malware possession a crime! Yes, yes, researchers get a free pass
N.Y. Could Ban Cities from Paying Ransomware Attackers
Job hunting? Beware hiring scams using spoofed company websites

Cybercriminals are putting a new twist on an old trick The post Job hunting? Beware hiring scams using spoofed company websites appeared first on WeLiveSecurity

Nasty old Android malware with new capabilities gets difficult to remove
A Magecart hacking gang may have been caught by police for the first ever time
Cisco Webex bug allowed anyone to join a password-protected meeting
Mandatory IoT Security in the Offing with U.K. Proposal
Microsoft’s Internet Explorer zero-day workaround is breaking printers
Rent out the best properties online in India with these tips

Several security issues were fixed in tcpdump.

Several security issues were fixed in Tomcat.

Several security issues were fixed in MySQL.

An update for nss is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This update fixes CVE-2019-20093.

This update fixes CVE-2019-20093.

Trend Micro anti-virus zero-day exploited in attack on Mitsubishi Electric
Webex flaw allowed anyone to join private online meetings – no password required
Watch out for Shlayer malware targeting Mac devices

An update that fixes 5 vulnerabilities is now available.

This update fixes CVE-2019-20093.

This update fixes CVE-2019-20093.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Teenagers today. Can’t take them anywhere, eh? 18-year-old kid accused of $50m SIM-swap cryptocurrency heist

– Security fix for CVE-2019-19746, CVE-2019-19797 – New upstream release 3.2.7b – Add patch fixing CVE-2019-19746 (rhbz#1787040) – Add patch fixing CVE-2019-19797 (rhbz#1786726)

– Security fix for CVE-2019-19746, CVE-2019-19797 – New upstream release 3.2.7b – Add patch fixing CVE-2019-19746 (rhbz#1787040) – Add patch fixing CVE-2019-19797 (rhbz#1786726)

** MySQL 8.0.19 ** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-19.html

Security fix for CVE-2020-5395:out-of-bounds write in sfd.c

ThreatList: Ransomware Costs Double in Q4, Sodinokibi Dominates
Netgear vulnerability exposed TLS certificates to public

security update

The importance of protecting your devices from cyber attack
Cisco Webex Flaw Lets Unauthenticated Users Join Private Online Meetings
New Bill Proposes NSA Surveillance Reforms
2015-member database floats off through breach in Royal Yachting Association’s hull
We’re dung for! Hackers hit firms with ransomware by exploiting Shitrix flaw
Want your photo removed from our facial recognition database? Just send us your photo and government-issued ID…
Fake Smart Factory Honeypot Highlights New Attack Threats
Sonos backtracks (a little) over its software updates fustercluck