Menu

Category Archives: Security

Articles about security

Type: Vulnerability. ABB Relion 670 Series is prone to a directory-traversal vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to an information-disclosure vulnerability; fixes are available.

Sextortion with a twist of Litecoin
Botnet found using YouTube to illegally mine cryptocurrency
UPbit cryptocurrency exchange hacked; Ether worth $50 million stolen
Google caught a Russian state hacker crew uploading badness to the Play Store
Small businesses also need protection from cyber attacks
ThreatList: Healthcare Breaches Spike in October
5 scams to watch out for this shopping season

Black Friday and Cyber Monday are just around the corner and scammers are gearing up to flood you with bogus offers The post 5 scams to watch out for this shopping season appeared first on WeLiveSecurity

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

psutil could be made to crash or run programs.

Cloudy biz Datrix locks down phishing attack in 15 mins after fat thumb triggers email badness

Tim Düsterhus discovered that haproxy, a TCP/HTTP reverse proxy, did not properly sanitize HTTP headers when converting from HTTP/2 to HTTP/1. This would allow a remote user to perform CRLF injections.

This week, we give thanks to Fortinet for reminding us what awful crypto with hardcoded keys looks like

security update

How To Stop Someone From Spying On Your Cell Phone

Fixes a CVE: CVE-2019-13038 mod_auth_mellon: an Open Redirect via the login?ReturnTo= substring which could facilitate information theft

NSO Group President Defends Controversial Tactics

Type: Vulnerability. Ruby is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. ABB Relion 650 and 670 Series are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Squid is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Ansible Tower is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Dell EMC Storage Monitoring and Reporting (SMR) is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. PuTTY is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. OpenAFS is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Redhat Undertow is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. ZmartZone mod_auth_openidc Module is prone to an open-redirection vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. DotNetNuke is prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. OpenAFS is prone to an information-disclosure vulnerability; fixes are available.

Ginp Android trojan targets banking apps & threatens 2FA/SMS
SDKs Misused to Scrape Twitter, Facebook Account Info
Smashing Security #156: Better safe than Sony
Facebook & Twitter suffer data breach via third-party developers
Cryptocurrency exchange loses US$50 million in apparent hack

UPbit has announced that, as a precaution, all transactions will remain suspended for at least two weeks The post Cryptocurrency exchange loses US$50 million in apparent hack appeared first on WeLiveSecurity

IoT Smartwatch Exposes Kids’ Personal, GPS Data
Federal Data Privacy Bill Takes Aim at Tech Giants
Dexphot Malware Hijacked 80K+ Devices to Mine Cryptocurrency

An update that fixes four vulnerabilities is now available.

An update that fixes 18 vulnerabilities is now available.

An update that fixes 16 vulnerabilities is now available.

NSS could be made to crash or run programs if it received specially crafted input.

‘Ethical’ hackers say: It’s just hacker. To be one is no longer a bad thing

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Risk Level: Very Low. Type: Trojan.

security update

Austin Man Indicted for Stealing Unreleased Music from Artists
Magecart Group Switches Up Tactics with MiTM, Phishing

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Google Chrome is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. FasterXML Jackson is prone to multiple XML External Entity injection vulnerabilities.

Type: Vulnerability. Google Chrome is prone to an out-of-bounds memory access vulnerability; fixes are available.

Type: Vulnerability. Google Chrome is prone to a security-bypass vulnerability; fixes are available.

Contract for the Web wants your endorsement

Risk Level: Very Low. Type: Trojan.

Managing the Human Security Factor in the Age of Ransomware

Several security issues were fixed in Ruby.

Facebook and Twitter warn some users’ private data was accessed via third-party app SDK
Black Friday Shoppers Targeted By Scams and Fake Domains
Stantinko botnet adds cryptomining to its pool of criminal activities

ESET researchers have discovered that the criminals behind the Stantinko botnet are distributing a cryptomining module to the computers they control The post Stantinko botnet adds cryptomining to its pool of criminal activities appeared first on WeLiveSecurity

An update that fixes 7 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Stop us if you’ve heard this one: Facebook and Twitter profiles silently slurped by shady code
TrickBot Evolves to Go After SSH Keys

security update

Type: Vulnerability. The Jetpack plugin for WordPress is prone to an unspecified security vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. HP ThinPro Linux is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. McAfee Client Proxy is prone to a local authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. libgd is prone to multiple denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. Infinispan is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. The Linux Kernel is prone to a local race-condition vulnerability; fixes are available.

NYPD Fingerprint Database Taken Offline to Thwart Ransomware
How to decrypt your data from Hakbit & Jigsaw ransomware for free
PoS Malware Exposes Customer Data of Catch Restaurants
Smash-and-grab car thieves use Bluetooth to target cars containing tech gadgets
Hackers attack OnePlus again – this time stealing customer details

An update that fixes one vulnerability is now available.

An update that fixes 42 vulnerabilities is now available.

An update that fixes 18 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

OnePlus website hacked to breach user data AGAIN!

An out-of-bounds write vulnerability was discovered in php-imagick, a PHP extension to create and modify images using the ImageMagick API, which could result in denial of service, or potentially the execution of arbitrary code.

CyberwarCon – the future of nation‑state nastiness

How the field of play has changed and why endpoint protection still often comes down to doing the basics, even in the face of increasingly complex threats The post CyberwarCon – the future of nation‑state nastiness appeared first on WeLiveSecurity

Several security issues were fixed in libvpx.

Get ahead of the cyber-criminals using training and advice from SANS Manchester in 2020

Type: Vulnerability. Symantec Critical System Protection is prone to an unspecified authentication-bypass vulnerability; fixes are available.

Hackers now use web skimmers to steal credit card data
Hackers access customer data in latest T-Mobile data breach
Cyborg ransomware posing as Windows update hits PCs
How to Write a Resume for a Cybersecurity Position
A reason for the season: Reason antivirus offers 70% off to keep you safe during holiday shopping rush