Menu

Category Archives: Security

Articles about security

An update that fixes three vulnerabilities is now available.

New Muhstik Botnet Attacks Target Tomato Routers
PoC Exploits Do More Good Than Harm: Threatpost Poll

apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086) SL7 noarch apache-commons-beanutils-1.8.3-15.el7_7.noarch.rpm apache-commons-beanutils-javadoc-1.8.3-15.el7_7.noarch.rpm – Scientific Linux Development Team

Jeff Bezos, WhatsApp, and Mohammed bin Salman – what you need to know
Capita Education Services accidentally spaffs email addresses in Helpdesk snafu

An update that solves 5 vulnerabilities and has one errata is now available.

python-reportlab: code injection in colors.py allows attacker to execute code (CVE-2019-17626) SL6 x86_64 python-reportlab-2.3-3.el6_10.1.x86_64.rpm python-reportlab-debuginfo-2.3-3.el6_10.1.x86_64.rpm i386 python-reportlab-2.3-3.el6_10.1.i686.rpm python-reportlab-debuginfo-2.3-3.el6_10.1.i686.rpm noarch python-reportlab-docs-2.3-3.el6_10.1.noarch.rpm – Scientific L [More…]

Crown Prince of Saudi Arabia accused of hacking Jeff Bezos’ phone with malware-laden WhatsApp message
16Shop Phishing Gang Goes After PayPal Users

security update

security update

No backdoors needed: Apple ditched plans to fully encrypt iCloud backups after heavy pressure from FBI – claim
Citrix Accelerates Patch Rollout For Critical RCE Flaw
Clearview app lets police find your information with just a photo
FTCODE Ransomware Now Steals Chrome, Firefox Credentials
Microsoft Zero-Day Actively Exploited, Patch Forthcoming
WTF, EFS? Experts warn Windows encryption could spawn nasty new ransomware

A security update is now available for Open Liberty 20.0.0.1 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Hacker Leaks More Than 500K Telnet Credentials for IoT Devices
Exams cancelled? University closing due to Brexit? A mischievous email from Southampton’s Vice-Chancellor

An update for openvswitch2.12 is now available for Fast Datapath for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

3 ways to browse the web anonymously

Are you looking to hide in plain sight? Here’s a rundown of three options for becoming invisible online The post 3 ways to browse the web anonymously appeared first on WeLiveSecurity

Internet-enabled dash cams that allow anyone to track your GPS location in real-time

An update that fixes one vulnerability is now available.

Leave your admin interface’s TLS cert and private key in your router firmware in 2020? Just Netgear things

security update

security update

New sextortion scam claims to record you with hacked Google Nest cam
Citrix emits patches to stop RCE-holes fiddling with Gateway and ADC
Ubisoft sues handful of gamers for DDoSing Rainbow Six: Siege
New Internet Explorer zero‑day remains unpatched

You may want to implement a workaround or stop using the browser altogether, at least until Microsoft issues a a fix The post New Internet Explorer zero‑day remains unpatched appeared first on WeLiveSecurity

Sextortion scam leverages Nest video footage to fool victims into believing they are being spied upon everywhere
LastPass stores passwords so securely, not even its users can access them

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

Good news. Citrix delivers first patches to mop up Shitrix flaw that is being actively exploited
Ubisoft takes DDoS-for-hire website to court over attacks on video game servers
Hospital hacker spared prison after plod find almost 9,000 cardiac images at his home
Google Algorithm Updates vs SEO Strategies
These smart contact lenses equip your eyes with augmented reality

Update to Rack 2.0.8.

UFC champ Kamaru Usman says his Twitter account was hacked, after series of explicit tweets against Conor McGregor

In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests

Hackers are closing the Shitrix security hole to keep everyone out of Citrix servers apart from themselves
Microsoft issues Internet Explorer zero-day warning, but there’s no patch yet

Updated wireshark packages fix security vulnerability: BT ATT dissector crash (CVE-2020-7045). References:

Updated suricata packages fix security vulnerabilities: The suricata package has been updated to version 4.1.6, which fixes security issues and other bugs. See the upstream announcements for details.

Updated tigervnc packages fix security vulnerabilities: The tigervnc package has been updated to version 1.10.1 to fix multiple unspecified security issues. These issues affect both the client and server and could theoretically allow an malicious peer to take control over the

security update

Update to 79.0.3945.117. Fixes CVE-2020-6377. —- Security fix for CVE-2019-13767. —- Update to Chromium 79. Fixes the usual giant pile of bugs and security issues. This time, the list is: CVE-2019-13725 CVE-2019-13726 CVE-2019-13727 CVE-2019-13728 CVE-2019-13729 CVE-2019-13730 CVE-2019-13732 CVE-2019-13734 CVE-2019-13735 CVE-2019-13764 CVE-2019-13736 CVE-2019-13737

How Modern Technology is Making Business Life Easier
FBI unlocks iPhone 11 Pro Max using Graykey raising privacy concerns
Protect your identity from fraudster with AI-powered Identity Guard
To catch a thief, go to Google with a geofence warrant – and it will give you all the details

An update that fixes one vulnerability is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0124

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0122

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0122

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0124

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0120

It’s Friday, the weekend has landed… and Microsoft warns of an Internet Explorer zero day exploited in the wild
New JhoneRAT Malware Targets Middle East
Feds Cut Off Access to Billions of Breached Records with Site Takedown
Mobile Carrier Customer Service Ushers in SIM-Swap Fraud
Keep Your Home Protected: 5 Best Indoor Home Security Cameras
‘Friendly’ hackers are seemingly fixing the Citrix server hole – and leaving a nasty present behind
Feds seize WeLeakInfo.com for selling stolen databases
Threatpost Poll: Are Published PoC Exploits a Good or Bad Idea?
News Wrap: PoC Exploits, Cable Haunt and Joker Malware
FBI Plans to Inform States of Election Breaches
Travelex won’t say if it has paid a ransom to its attackers
Stolen creds site WeLeakInfo busted by multinational cop op for data reselling
“Hello dear slave”
WeLeakInfo, the site which sold access to passwords stolen in data breaches, is brought down by the FBI

An update that solves 17 vulnerabilities and has one errata is now available.

Reading Time: ~ 2 min. Ryuk Adds New Features to Increase Devastation The latest variant of the devastating Ryuk ransomware has been spotted with a new feature that allows it to turn on devices connected to the infected network. By taking advantage of Wake-on-Lan functionality, Ryuk can is able to mount additional remote devices to […]

Mozilla: IonMonkey type confusion with StoreElementHole and FallibleStoreElement (CVE-2019-17026) * Mozilla: Bypass of @namespace CSS sanitization during pasting (CVE-2019-17016) * Mozilla: Type Confusion in XPCVariant.cpp (CVE-2019-17017) * Mozilla: Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4 (CVE-2019-17024) * Mozilla: CSS sanitization does not escape HTML tags (CVE-2019- [More…]

Mozilla: IonMonkey type confusion with StoreElementHole and FallibleStoreElement (CVE-2019-17026) * Mozilla: Bypass of @namespace CSS sanitization during pasting (CVE-2019-17016) * Mozilla: Type Confusion in XPCVariant.cpp (CVE-2019-17017) * Mozilla: Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4 (CVE-2019-17024) * Mozilla: CSS sanitization does not escape HTML tags (CVE-2019- [More…]

Unlocking news: We decrypt those cryptic headlines about Scottish cops bypassing smartphone encryption

An update that solves one vulnerability and has two fixes is now available.

This update is based on upstream 5.4.12 and fixes atleast the following security vulnerabilities: Intel GPU Hardware prior to Gen11 does not clear EU state during a context switch. This can result in information leakage between

The updated packages fix security vulnerabilities: A signed integer overflow and subsequent segfault that occurred when attempting to decompress images with more than 715827882 pixels using the 64-bit C version of TJBench.

Hacker uses NSA-reported Windows 10 vulnerability to troll NSA
Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don’t work for older kit
Critical Cisco Flaws Now Have PoC Exploit
Google Account Security Keys Launch for iPhone
Satan Ransomware Reborn to Torment Businesses
How to Secure Your VPS and Dedicated Servers from Hackers
Smart Cars: Increasing Comfort — Reducing Security
PoC Exploits Published For Microsoft Crypto Bug
‘Fleeceware’ Apps Downloaded 600M Times from Google Play
PlanetDrugsDirect reveals security breach, warns customers their data may have been exposed