Menu

Category Archives: Security

Articles about security

git: Remote code execution in recursive clones with nested submodules (CVE-2019-1387) SL7 x86_64 git-1.8.3.1-21.el7_7.x86_64.rpm git-daemon-1.8.3.1-21.el7_7.x86_64.rpm git-debuginfo-1.8.3.1-21.el7_7.x86_64.rpm git-gnome-keyring-1.8.3.1-21.el7_7.x86_64.rpm git-svn-1.8.3.1-21.el7_7.x86_64.rpm noarch emacs-git-1.8.3.1-21.el7_7.noarch.rpm emacs-git-el-1.8.3.1-21.el [More…]

OpenJDK: Use of unsafe RSA-MD5 checkum in Kerberos TGS (Security, 8229951) (CVE-2020-2601) * OpenJDK: Serialization filter changes via jdk.serialFilter property modification (Serialization, 8231422) (CVE-2020-2604) * OpenJDK: Improper checks of SASL message properties in GssKrb5Base (Security, 8226352) (CVE-2020-2590) * OpenJDK: Incorrect isBuiltinStreamHandler causing URL normalization iss [More…]

Hackers jailed for hacking National Lottery & withdrawing £13

An update for rh-dotnet30-dotnet and rh-dotnet31-dotnet is now available for .NET Core on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

How RHEL 8 is designed for FIPS 140-2 requirements

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Cyberawareness in Australia: The good and the bad

An ESET-commissioned survey sheds light on the browsing habits of Australians and how they protect themselves online The post Cyberawareness in Australia: The good and the bad appeared first on WeLiveSecurity

An update that solves three vulnerabilities and has three fixes is now available.

Spanking the pirates of corporate security? Try a Plimsoll
Attention security startup founders: Give your fledgling Brit biz a boost with Tech Nation’s free Cyber 2.0 school
Top Euro court advised: Cops, spies yelling ‘national security’ isn’t enough to force ISPs to hand over massive piles of people’s private data
Smashing Security #161: Love, lucky dips, and 23andMe
What do Brit biz consultants and X-rated cam stars have in common? Wide open… AWS S3 buckets on public internet
Yo, sysadmins! Thought Patch Tuesday was big? Oracle says ‘hold my Java’ with huge 334 security flaw fix bundle
Critical WordPress Bug Leaves 320,000 Sites Open to Attack
A Practical Guide to Zero-Trust Security
Podcast: NSA Reports Major Crypto-Spoofing Bug to Microsoft
Baby pics, videos & location data from Peekaboo Moments app leaked online
U.N. Weathers Storm of Emotet-TrickBot Malware
Equifax Settles Class-Action Breach Lawsuit for $380.5M
Peekaboo Moments app left baby videos, photos, and 800,000 users’ email addresses exposed on the internet
PussyCash adult webcam data breach exposes highly sensitive data of models
Trump Slams Apple for Refusing to Unlock Suspected Shooter’s iPhones
Google to end support for third‑party cookies in Chrome

The company will also soon launch anti-fingerprinting measures aimed at detecting and mitigating covert tracking and workarounds The post Google to end support for third‑party cookies in Chrome appeared first on WeLiveSecurity

Faketoken malware sends expensive & offensive texts at your expense

An update that solves one vulnerability and has three fixes is now available.

Travelex warns customers of phone scam threat in wake of ransomware attack

Applications using libpcap could be made to crash if given specially crafted data.

Oski Data-Stealing Malware Emerges to Target North America, China

An update that fixes three vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0085

Several security issues were fixed in PHP.

Today’s webcast: Hackers don’t care if you’re big or small. Tune in to find out how to protect your mid-sized biz
Updated your WordPress plugins lately? Here are 320,000 auth-bypassing reasons why you should
Critical Windows 10 security fix pushed out after NSA warns Microsoft of spying vulnerability
Oracle Ties Previous All-Time Patch High with January Updates
Microsoft patches severe Windows flaw after tip‑off from NSA

The US intelligence agency expects attackers to waste no time in developing tools aimed at exploiting the vulnerability The post Microsoft patches severe Windows flaw after tip‑off from NSA appeared first on WeLiveSecurity

Microsoft’s new tool detects & reports pedophiles from online chats
Welcome to the 2020s: Booby-trapped Office files, NSA tipping off Windows cert-spoofing bugs, RDP flaws…
Intel Fixes High-Severity Flaw in Performance Analysis Tool
Card Skimmer Hits Australian Bushfire Donation Site
Microsoft Patches Major Crypto Spoofing Bug

security update

Apple calls BS on FBI, AG: We’re totally not dragging our feet in murder probe iPhone decryption. PS: No backdoors
Google to Nix Chrome Support for Third-Party Cookies by 2022
LastPass releases its 3rd Annual Global Password Security report
Public Bug Bounty Takes Aim at Kubernetes Container Project
US hands UK ‘dossier’ on Huawei: Really! Still using their kit? That’s just… one… step… beyond
Millions of modems at risk of remote hijacking

Multiple cable modem models from various manufacturers found vulnerable to takeover attacks The post Millions of modems at risk of remote hijacking appeared first on WeLiveSecurity

Adobe Patches Five Critical Illustrator CC Flaws
Boing Boing bounces back after hack attempted to infect users with fake Adobe Flash update
5 cyber tools your business needs in 2020 to keep safe

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Apple Denies FBI Request to Unlock Shooter’s iPhone—Again

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0086

27% of Windows users are still running Windows 7. They need to stop now

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

Windows 7 end of life: Time to move on

Today, Microsoft is officially pulling the plug on its support for Windows 7. What’s your plan? The post Windows 7 end of life: Time to move on appeared first on WeLiveSecurity

Several security issues were fixed in SDL_image.

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in gThumb and Pix

Relying on AT&T, Verizon and T-Mob US to protect you from SIM swapping? You better get used to disappointment
Scammers Dupe Texas School District Out of $2.3M
Joker Android Malware Snowballs on Google Play
Someone needs to go back to school: Texas district fleeced for $2.3m after staff fall for devious phishing email
CES Surveillance Hype Worries Privacy Advocates
Privacy activists beg Google to ban un-removable bloatware from Android
New Android malware on Play Store disables Play Protect to evade detection
5 major US wireless carriers vulnerable to SIM swapping attacks

When it comes to protection against this insidious type of scam, the telcos’ authentication procedures leave a lot be desired, a study finds The post 5 major US wireless carriers vulnerable to SIM swapping attacks appeared first on WeLiveSecurity

‘Cable Haunt’ Bug Plagues Millions of Home Modems
Unpatched Citrix Flaw Now Has PoC Exploits
Travelex wants you to know that everything’s going really really well
Man who hacked National Lottery for just £5 is jailed for nine months
Cable Haunt: Hundreds of millions of cable modems may be vulnerable to hijacking attack
Whirlybird-driving infosec boss fined after ranty Blackpool Airport air traffic control antics

An update that solves one vulnerability and has 10 fixes is now available.

An update that fixes one vulnerability is now available.

Updated makepasswd fix insecure default length of password By default, makepasswd generates password with a length between 6 to 8 characters (48 to 64bits). This update raise the default to 16 characters (128 bits).

GraphicsMagick has been updated to fix security issues. References: – https://bugs.mageia.org/show_bug.cgi?id=26056 – http://www.graphicsmagick.org/NEWS.html#december-24-2019

This update is based on upstream 5.4.10 and fixes atleast the following security issues: ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE)

Updated unbound package to version 1.9.6 to fix various potential security vulnerabilities. References: – https://bugs.mageia.org/show_bug.cgi?id=25974

Shitrix: Hackers target unpatched Citrix systems over weekend
Personal data of millions of Americans exposed from PC in China
UK data watchdog kicks £280m British Airways and Marriott GDPR fines into legal long grass
If you haven’t shored up that Citrix hole, you were probably hacked over the weekend: Exploit code now available

An update that fixes four vulnerabilities is now available.

Fixes bugzilla 1126076

Update to v1.15.7 (CVE-2018-1002102 kubernetes: improper validation of URL redirection in the Kubernetes API server allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints)

New bugfix and security upstream release, see http://www.graphicsmagick.org/NEWS.html#december-24-2019

1.5.7, fix for CVE-2019-13107

Release of 19.05.5. Closes security issues CVE-2019-19727, CVE-2019-19728.

Google hackers successfully use remote exploit to hack iPhone

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

Hundreds of millions of Broadcom-based cable modems at risk of remote hijacking, eggheads fear

security update

Getting a VPN in Japan

New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.