Menu

Category Archives: Security

Articles about security

Reading Time: ~ 2 min. Have you noticed a decrease in your child’s happiness or an increase in their anxiety? Cyberbullying might be the cause to these behavioral changes. Bullying is no longer confined to school playgrounds and neighborhood alleys. It has long moved into the online world, thanks to the easy access to technology. […]

ThreatList: A Third of Biometric Systems Targeted by Malware in Q3

Type: Vulnerability. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities; fixes are available.

Type: Vulnerability. IBM Cloud Pak System is prone to an unspecified cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Moodle is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Multiple Kaspersky Products are prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.

Type: Vulnerability. Apache cordova-plugin-inappbrowser is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Redhat KeyCloak is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple Trend Micro Products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Django is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel 2016 is prone to an information-disclosure vulnerability.

Android Ups the Mobile Security Ante with Default TLS Encryption
Critical Android Flaw Leads to ‘Permanent DoS’
Notorious spy tool taken down in global operation

IM-RAT, which could be had for as little as US$25, was bought by nearly 15,000 people The post Notorious spy tool taken down in global operation appeared first on WeLiveSecurity

SMS and personal data of millions of Americans leaked online
Supply Chain Account Takeover: How Criminals Exploit Third-Party Access
‘StrandHogg’ Vulnerability Allows Malware to Pose as Legitimate Android Apps
Step-by-Step Guide to Creating the Best Web Pages
AWS has new tool for those leaky S3 buckets so, yeah, you might need to reconfigure a few things
Jail for bomb hoaxer who targeted Super Bowl, Houses of Parliament, and schools for Jewish children
UK parcel firm Yodel plugs tracking app’s random yaps about where on map to snap up strangers’ tat
Russian FaceApp selfie-slurper poses ‘potential counterintelligence threat’, FBI warns
Welcome back from the holiday, Americans! Here’s who leaked data while you were away
Microsoft OAuth Flaw Opens Azure Accounts to Takeover
Europol wipes out 30,000+ piracy sites, three suspects cuffed to walk the legal plank

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a heap-based memory-corruption vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a remote stack-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a denial-of-service vulnerability; fixes are available.

Authorities Break Up Imminent Monitor Spyware Organization
CISA Pushing U.S. Agencies to Adopt Vulnerability Disclosure Policies
Smart TVs: The Cyberthreat Lurking in Your Living Room, Feds Warn
Judge to interview Assange over claims Spanish security firm snooped on him during Ecuador embassy stint
Insecure Database Exposes Millions of Private SMS Messages

A security update is now available for Red Hat Single Sign-On 7.3 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

New Red Hat Single Sign-On 7.3.5 packages are now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

New Red Hat Single Sign-On 7.3.5 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

New Red Hat Single Sign-On 7.3.5 packages are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

5 personal (and cheap) data privacy tools that scale for business

Smart selections when starting small can ease the pain as you scale up your company’s privacy infrastructure The post 5 personal (and cheap) data privacy tools that scale for business appeared first on WeLiveSecurity

Cryptocurrency exchange locks its cold wallet as CEO “goes missing”

389-ds-base: Read permission check bypass via the deref plugin (CVE-2019-14824) SL7 x86_64 389-ds-base-1.3.9.1-12.el7_7.x86_64.rpm 389-ds-base-debuginfo-1.3.9.1-12.el7_7.x86_64.rpm 389-ds-base-devel-1.3.9.1-12.el7_7.x86_64.rpm 389-ds-base-libs-1.3.9.1-12.el7_7.x86_64.rpm 389-ds-base-snmp-1.3.9.1-12.el7_7.x86_64.rpm – Scientific Linux Development Team

Challenge yourself and level up your IT security skills at this SANS London training event
The blame game: When hackers steal your data, is it a corporate failure – or the attackers’ fault?

The backport of the CVE-2019-13161 fix caused a regression and has been reverted. For Debian 8 “Jessie”, this problem has been fixed in version

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

updated to 3.04 (CVE-2019-19035)

An update that fixes one vulnerability is now available.

The updated packages fix a security vulnerability: file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used. (CVE-2019-12450)

Updated httpie packages fix security vulnerability: HTTPie is vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing

Updated python-sqlalchemy packages fix security vulnerabilities: SQL Injection via the order_by parameter (CVE-2019-7164). SQL Injection via the group_by parameter (CVE-2019-7548).

Updated glibc packages fixes the following security issue: On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local

gnupg2 is updated to 2.2.18 and fix security vulnerability: Web of Trust forgeries using collisions in SHA-1 signatures (CVE-2019-14855) * Note that this change removes all SHA-1 based key signature newer than 2019-01-19 from the web-of-trust. This includes all key signature created

With KENT CamEye Travelling in a Cab Just Got a Lot Safer!

security update

Private details of Palo Alto Networks employees leaked online

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. F5 BIG-IP APM is prone to an unauthorized file-access vulnerability; fixes are available.

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. HAProxy is prone to a CRLF-injection vulnerability; fixes are available.

Type: Vulnerability. F5 BIG-IP is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. F5 BIG-IP is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. F5 SSL Orchestrator is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a local denial-of-service vulnerability.

Type: Vulnerability. FreeIPA is prone to a denial-of-service vulnerability; fixes are available.

480.1 million mobile VPN downloaded worldwide in 12 months
Customers complain after alarms go offline, as security firm hit by ransomware attack
Amazon Plans Ring Facial Recognition-Based ‘Watch List:’ Report

An update that fixes four vulnerabilities is now available.

How Will Blockchain Technology Revolutionize Logistics?

Several vulnerabilities have been identified in the VNC code of ssvnc, an encryption-capable VNC client..

Handling of Netscape Certificate Sequences in CERT_DecodeCertPackage() may haved crash with a NULL deref leading to a Denial-of-Service.

Palo Alto Networks employee data breach highlights risks posed by third party vendors

Several vulnerabilities have been identified in the VNC code of vino, a desktop sharing utility for the GNOME desktop environment.

React Prereleases-Preparing for the Future

Fix a grub hidden-menu regression and a bug in blscfg variable expansion —- Security fix for CVE-2019-14865

Updates the nss package to upstream NSS 3.47.1. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47.1_release_notes

Type: Vulnerability. F5 BIG-IP AFM is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Ghostscript is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. FreeIPA is prone to a information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple F5 Products are prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Kaspersky Protection extension for Google Chrome is prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. Pivotal Ops Manager is prone to local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. IBM Spectrum Protect is prone to a clickjacking vulnerability; fixes are available.

Type: Vulnerability. Multiple Kaspersky Products are prone to multiple security vulnerabilities; fixes are available.