Menu

Category Archives: Security

Articles about security

It’s Time for Your SOC to Level Up
Wawa Data Breach: Malware Stole Customer Payment Card Info
Apple’s Bug Bounty Opens for Business, $1M Payout Included
What’s that? Encryption’s OK now? UK politicos Brexit from Whatsapp to Signal

Reading Time: ~ 2 min. Honda Customer Database Exposed Officials have been working over the past work to secure a database containing highly sensitive information belonging to more than 26,000 North American customers of the Honda motor company. The database in question was originally created in October and was only discovered on December 11. While […]

Five years for the man who scammed Facebook and Google out of $120m by cunning use of email

An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

There has been an out-of-bounds write in Cyrus SASL leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash was ultimately caused by an off-by-one error

Ambitious scam wants far more than just PayPal logins

An ongoing phishing scam uncovered by ESET researchers seeks to wreak havoc on your money and digital life in one fell swoop The post Ambitious scam wants far more than just PayPal logins appeared first on WeLiveSecurity

An update that fixes 7 vulnerabilities is now available.

While preparing a fix for CVE-2017-6314 an unknown symbol g_uint_checked_mul() was introduced.

An update that solves 24 vulnerabilities and has 58 fixes is now available.

An update that solves 24 vulnerabilities and has 58 fixes is now available.

Names & Phone numbers of 267 million Facebook users exposed
Want to ‘live long and prosper’? Then avoid pirated, malware-laden Star Wars streams and pay to watch
267M Facebook Users’ Phone Numbers Exposed Online

security update

Google & Mozilla ban Avast security extensions over data snooping
The Scammer Force is Strong with Star Wars: The Rise of Skywalker
Honda Leaks Data of 26K North American Customers
Email blackmail brouhaha tears UKIP apart as High Court refuses computer seizure attempt
38,000 people forced to pick up email passwords in person

Malware and legal requirements force academics and students to join a near-endless line in order to pick up their passwords The post 38,000 people forced to pick up email passwords in person appeared first on WeLiveSecurity

An update for fribidi is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat Quay 3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated htmldoc packages fix security vulnerability: In HTMLDOC, there was a one-byte underflow in htmldoc/ps-pdf.cxx caused by a floating point math difference between GCC and Clang (CVE-2019-19630).

Updated libssh packages fix security vulnerability: In an environment where a user is only allowed to copy files and not to execute applications, it would be possible to pass a location which contains commands to be executed in addition (CVE-2019-14889).

Updated freerdp packages fix security vulnerabilities: Multiple memory leaks in libfreerdp/codec/region.c (CVE-2019-17177). Memory leak in HuffmanTree_makeFromFrequencies (CVE-2019-17178).

British bloke accused of extorting victims for ‘Dark Overlord’ hacker crew finally gets his free trip* to America
Das Reboot: Uni forces 38,000 students, staff to queue, show their papers for password reset following ‘cyber attack’
FYI: FBI raiding NSA’s global wiretap database to probe US peeps is probably illegal, unconstitutional, court says
Smashing Security #159: Rap, robbery, and IoT holiday hell
Medical biz LifeLabs fesses up: Hackers slurped 15 million customer records – and we paid them to hand it all back

Reading Time: ~ 3 min. As the year draws to a close, the cybersecurity analysts at Webroot and Carbonite pull out their crystal balls to make their predictions for the year ahead.  Our experts predict many of the trends they’ve been tracking throughout the year—well-researched attacks, RDP compromise, and the importance of user education—will continue […]

You leak our secrets? We’ll leak your book sales, speech fees – into our coffers: Uncle Sam wins royalties fight against Edward Snowden

security update

Why Cloud, Collaboration Breed Insider Threats

Type: Vulnerability. TYPO3 is prone to multiple remote code-execution vulnerabilities; fixes are available.

Type: Vulnerability. TYPO3 is prone to an SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Google Chrome is prone to a use-after-free vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. The permissions by term for Drupal is prone to an access-bypass vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.

Type: Vulnerability. IBM MQ is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.

Type: Vulnerability. Lenovo Power Management Driver is prone to a local buffer-overflow vulnerability; fixes are available.

Ring Plagued by Security Issues, Flood of Hacks
Microsoft Issues Out-of-Band Update for SharePoint Bug
TP-Link Routers Give Cyberattackers an Open Door to Business Networks

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Jet2 hacker who deleted every account on UK company’s domain cops 5 months in jail
System hijacking flaws found in pre-installed Acer & ASUS software
LifeLabs Pays Hackers Who Accessed 15M Customers’ Lab Test Results
BlackBerry tells UK High Court that security outfit SentinelOne is its direct rival
Log us out: Private equity snaffles Lastpass owner LogMeIn

It was discovered that there was a potential account hijack vulnerabilility in Django, the Python-based web development framework.

Kernel: KVM: OOB memory access via mmio ring buffer (CVE-2019-14821) Bug Fix(es): * KEYS: prevent creating a different user’s keyrings SL-6.10 * BUG: unable to handle kernel NULL pointer dereference at (null) * long I/O stalls with bnx2fc from not masking off scope bits of retry delay value SL6 x86_64 kernel-2.6.32-754.25.1.el6.x86_64.rpm kernel-debug-2.6.32-754.25.1.el6.x86_64. [More…]

freetype: a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c leading to information disclosure (CVE-2015-9381) * freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read (CVE-2015-9382) SL6 x86_64 freetype-2.3.11-19.el6_10.i686.rpm freetype-2.3.11-19.el6_10.x86_64.rpm freet [More…]

An update for rh-maven35-apache-commons-beanutils is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Security fix for CVE-2019-5544

An update that fixes 37 vulnerabilities is now available.

Half a billion here, half a billion there – pretty soon you’re talking real money: US Congress earmarks $425m for 2020 election security
Rooster Teeth Attack Showcases New Magecart Approach

Type: Vulnerability. Avaya IP Office Application Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability.

Type: Vulnerability. Atlassian Application Links is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Apache Superset is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. IBM API Connect is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. IBM Case Manager is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Apache Superset is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Omron PLC CJ and CS Series are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. ZOHO ManageEngine EventLog Analyzer is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. SQLite is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Mozilla Firefox is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Ansible Tower is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Broadcom CA Automic Sysload is prone to an arbitrary command-execution vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Omron PLC CJ, CS and NJ Series are prone to an authentication-bypass vulnerability; fixes are available.

Epilepsy Foundation Bombarded with Seizure-Triggering Twitter Posts
Massive leak exposes browsing history of millions of users
Alexa, Google Home Eavesdropping Hack Not Yet Fixed

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

It was discovered that python-ecdsa, a cryptographic signature library for Python, incorrectly handled certain signatures. A remote attacker could use this issue to cause python-ecdsa to either not warn about incorrect signatures, or generate exceptions resulting in a

Destroyed: A method of destroying Whatsapp group chats forever, say infosec bods of vuln patch
It’s time to disconnect RDP from the internet

Brute-force attacks and BlueKeep exploits usurp convenience of direct RDP connections; ESET releases a tool to test your Windows machines for vulnerable versions The post It’s time to disconnect RDP from the internet appeared first on WeLiveSecurity

London’s Met Police splash the cash on e-learning ‘cyber’ training for 4k staffers

It was found that libssh, a tiny C SSH library, does not sufficiently sanitize path parameters provided to the server, allowing an attacker with only SCP file access to execute arbitrary commands on the server.

An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for freetype is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

security update

It’s 2019 so, of course, this Wells Fargo employee accused of stealing customer cash posed with wads of dosh on Instagram, Facebook

security update

Type: Vulnerability. WordPress is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability.

Type: Vulnerability. Dovecot is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability.