Menu

Category Archives: Security

Articles about security

An update that fixes 7 vulnerabilities is now available.

Whoops! LastPass accidentally deleted its browser extension from the Chrome store. But it’s back now

update to enigmail 2.1.5 Includes a security fix for “Unsigned MIME parts displayed as signed”

Update to 12.14.1 Add new subpackage `nodejs-full-i18n` to provide non-English locale and Unicode support.

Update to 12.14.1 Add new subpackage `nodejs-full-i18n` to provide non-English locale and Unicode support.

New upstream release with security fixes for CVE-2019-15945, CVE-2019-15946, CVE-2019-19479, CVE-2019-19480, CVE-2019-19481

An update that solves three vulnerabilities and has one errata is now available.

Russian super-crook behind $20m internet fraud den Cardplanet and malware-exchange forum pleads guilty

Reading Time: ~ 2 min. Point-of-Sale Breach Targets U.S. Cannabis Industry Late last month, researchers discovered a database owned by the company THSuite that appeared to contain information belonging to roughly 30,000 cannabis customers in the U.S. With no authentication, the researchers were able to find contact information as well as cannabis purchase receipts, including […]

Study shows prominent apps are selling your data to 3rd parties
Critical, Unpatched ‘MDhex’ Bugs Threaten Hospital Devices
U.S. Gov Agency Targeted With Malware-Laced Emails
Shlayer, No. 1 Threat for Mac, Targets YouTube, Wikipedia
Did Saudi Crown Prince use Israeli spyware to hack Jeff Bezos’s iPhone?
Ransomware: The average ransom payment has doubled in just three months
Cisco Warns of Critical Network Security Tool Flaw
Traffic jams could be worse than normal, because of the Shitrix vulnerability
We need to make it even easier for UK terror cops to rummage about in folks’ phones, says govt lawyer
Ooh, watch out Google. You’ve got competition. Verizon has a new ‘privacy-focused’ search engine

USN-4233-1 marked SHA1 as untrusted in GnuTLS with no workaround.

Microsoft exposed 250 million customer support records

Databases containing 14 years’ worth of customer support logs were publicly accessible with no password protection The post Microsoft exposed 250 million customer support records appeared first on WeLiveSecurity

Google: Flaws in Apple’s Private-Browsing Technology Allow for Third-Party Tracking

An update for ansible is now available for Ansible Engine 2 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.9 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.8 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.7 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

A free tool for detecting Shitrix-related compromises on your business network

Several security issues were fixed in python-apt.

Smashing Security #162: Robocalls, health hacks, and facial recognition fears
Still losing sleep over that awful Citrix bug? This scanner is here to help… you realize you’ve already been pwned
Pwn2Own Miami Contestants Haul in $180K for Hacking ICS Equipment
Who honestly has a crown prince in their threat model? UN report officially fingers Saudi royal as Bezos hacker
Vivin Nets Thousands of Dollars Using Cryptomining Malware
Safari’s Intelligent Tracking Protection is misspelled, says Google: It should be Dumb Browser Stalking Enabler
Owner of DDoS mitigation firm launched DDoS attacks on others

security update

Academics call for UK’s Computer Misuse Act 1990 to be reformed
sLoad Malware Revamped as Powerful ‘StarsLord’ Loader
Dating apps share personal data with advertisers, study says

Some of the most popular dating services may be violating GDPR or other privacy laws The post Dating apps share personal data with advertisers, study says appeared first on WeLiveSecurity

Plastic surgery patients at risk after ransomware attack
Microsoft Leaves 250M Customer Service Records Open to the Web
WindiLeaks: Microsoft exposes 250 million customer support records dating back to 2005 (Not on purpose though)
Teenager charged over $50 million SIM-swap cryptocurrency theft
Microsoft data breach exposes 250 million customer service and support records
250 million Microsoft customer support records leaked in plain text

An update that fixes three vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

New Muhstik Botnet Attacks Target Tomato Routers
PoC Exploits Do More Good Than Harm: Threatpost Poll

apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086) SL7 noarch apache-commons-beanutils-1.8.3-15.el7_7.noarch.rpm apache-commons-beanutils-javadoc-1.8.3-15.el7_7.noarch.rpm – Scientific Linux Development Team

Jeff Bezos, WhatsApp, and Mohammed bin Salman – what you need to know
Capita Education Services accidentally spaffs email addresses in Helpdesk snafu

An update that solves 5 vulnerabilities and has one errata is now available.

python-reportlab: code injection in colors.py allows attacker to execute code (CVE-2019-17626) SL6 x86_64 python-reportlab-2.3-3.el6_10.1.x86_64.rpm python-reportlab-debuginfo-2.3-3.el6_10.1.x86_64.rpm i386 python-reportlab-2.3-3.el6_10.1.i686.rpm python-reportlab-debuginfo-2.3-3.el6_10.1.i686.rpm noarch python-reportlab-docs-2.3-3.el6_10.1.noarch.rpm – Scientific L [More…]

Crown Prince of Saudi Arabia accused of hacking Jeff Bezos’ phone with malware-laden WhatsApp message
16Shop Phishing Gang Goes After PayPal Users

security update

security update

No backdoors needed: Apple ditched plans to fully encrypt iCloud backups after heavy pressure from FBI – claim
Citrix Accelerates Patch Rollout For Critical RCE Flaw
Clearview app lets police find your information with just a photo
FTCODE Ransomware Now Steals Chrome, Firefox Credentials
Microsoft Zero-Day Actively Exploited, Patch Forthcoming
WTF, EFS? Experts warn Windows encryption could spawn nasty new ransomware

A security update is now available for Open Liberty 20.0.0.1 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Hacker Leaks More Than 500K Telnet Credentials for IoT Devices
Exams cancelled? University closing due to Brexit? A mischievous email from Southampton’s Vice-Chancellor

An update for openvswitch2.12 is now available for Fast Datapath for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

3 ways to browse the web anonymously

Are you looking to hide in plain sight? Here’s a rundown of three options for becoming invisible online The post 3 ways to browse the web anonymously appeared first on WeLiveSecurity

Internet-enabled dash cams that allow anyone to track your GPS location in real-time

An update that fixes one vulnerability is now available.

Leave your admin interface’s TLS cert and private key in your router firmware in 2020? Just Netgear things

security update

security update

New sextortion scam claims to record you with hacked Google Nest cam
Citrix emits patches to stop RCE-holes fiddling with Gateway and ADC
Ubisoft sues handful of gamers for DDoSing Rainbow Six: Siege
New Internet Explorer zero‑day remains unpatched

You may want to implement a workaround or stop using the browser altogether, at least until Microsoft issues a a fix The post New Internet Explorer zero‑day remains unpatched appeared first on WeLiveSecurity

Sextortion scam leverages Nest video footage to fool victims into believing they are being spied upon everywhere
LastPass stores passwords so securely, not even its users can access them

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

Good news. Citrix delivers first patches to mop up Shitrix flaw that is being actively exploited
Ubisoft takes DDoS-for-hire website to court over attacks on video game servers
Hospital hacker spared prison after plod find almost 9,000 cardiac images at his home
Google Algorithm Updates vs SEO Strategies
These smart contact lenses equip your eyes with augmented reality

Update to Rack 2.0.8.

UFC champ Kamaru Usman says his Twitter account was hacked, after series of explicit tweets against Conor McGregor

In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests

Hackers are closing the Shitrix security hole to keep everyone out of Citrix servers apart from themselves
Microsoft issues Internet Explorer zero-day warning, but there’s no patch yet