Menu

Category Archives: Security

Articles about security

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Google’s Plan to Crunch Health Data on Millions of Patients Draws Fire

Risk Level: Very Low. Type: Trojan.

Reading Time: ~ 3 min. Why do so many businesses allow unfettered access to their networks? You’d be shocked by how often it happens. The truth is: your employees don’t need unrestricted access to all parts of our business. This is why the Principle of Least Privilege (POLP) is one of the most important, if […]

Get 70% off NordVPN Virtual Private Network Service + 3 months free – Deal Alert
Facebook bug turns on iPhone camera in the background

A recent update to the Facebook’s iOS app introduced a bug that had some users worried The post Facebook bug turns on iPhone camera in the background appeared first on WeLiveSecurity

IoT Security Woes Plague Healthcare Industry

In libssh2, SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in libjpeg-turbo.

Federal Court: Suspicionless Search of Traveler Devices by Border Agents Is Unconstitutional

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

UK Info Commish quietly urged court to swat away 100k Morrisons data breach sueball
Londoner accused of accessing National Lottery users’ accounts

DPDK could be made to consume resources if it received specially crafted input.

Update to version 1.9.4. Resolves CVE-2019-10086.

bluez 5.52: * improvements for bluetooth mesh * audio bug fixes * general bug fixes —- ell 0.26: * Fix issue with memory leak and TLS certificates. * Fix issue with buffer size and TLS PRF handling. * Add support for D-Bus non-root ObjectManager. iwd 1.0: * Add support for stable D-Bus interfaces. * Add […]

bluez 5.52: * improvements for bluetooth mesh * audio bug fixes * general bug fixes —- ell 0.26: * Fix issue with memory leak and TLS certificates. * Fix issue with buffer size and TLS PRF handling. * Add support for D-Bus non-root ObjectManager. iwd 1.0: * Add support for stable D-Bus interfaces. * Add […]

bluez 5.52: * improvements for bluetooth mesh * audio bug fixes * general bug fixes —- ell 0.26: * Fix issue with memory leak and TLS certificates. * Fix issue with buffer size and TLS PRF handling. * Add support for D-Bus non-root ObjectManager. iwd 1.0: * Add support for stable D-Bus interfaces. * Add […]

Russian bloke charged in US with running $20 million stolen card-as-a-service online souk

Update to version 1.9.4. Resolves CVE-2019-10086.

The 5.3.11 stable kernel update contains a number of important security updates across the tree, including mitigations for the most recent hardware issues disclosed on Nov 12. —- The 5.3.9 update contains a number of important fixes across the tree —- Update to upstream 2.1-22. 20190618

The 5.3.11 stable kernel update contains a number of important security updates across the tree, including mitigations for the most recent hardware issues disclosed on Nov 12. —- The 5.3.9 update contains a number of important fixes across the tree —- Update to upstream 2.1-22. 20190618

security update

Shock! US border cops need ‘reasonable suspicion’ of a crime before searching your phone, laptop
This November, give thanks for only having one exploited Microsoft flaw for Patch Tues. And four Hyper-V escapes
Insider Threats, a Cybercriminal Favorite, Not Easy to Mitigate
Microsoft Patches RCE Bug Actively Under Attack
Plugging the Data Leak in Manufacturing
Don’t trust the Trusted Platform Module – it may leak your VPN server’s private key (depending on your configuration)

Type: Vulnerability. Microsoft Visual Studio Code is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. SAP Business Client is prone to an unspecified security vulnerability; fixes are available.

Type: Vulnerability. SAP Diagnostics Agent is prone to an OS command-injection vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a use multiple denial-of-service vulnerabilities; fixes are available.

Intel Warns of Critical Info-Disclosure Bug in Security Engine
Magento Warns E-Commerce Sites to Upgrade ASAP to Prevent Attacks
Adobe Patches Critical Bugs in Illustrator, Media Encoder

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

True to its name, Intel CPU flaw ZombieLoad comes shuffling back with new variant
Don’t miss this patch: Bad Intel drivers give hackers a backdoor to the Windows kernel

Risk Level: Very Low. Type: Trojan.

From AV to oy-vey: McAfee antivirus has security hole of its own
That “sophisticated” Labour cyber-attack – don’t panic
Microsoft to Apply California’s Privacy Law to All U.S. Users
‘Sophisticated’ cyber attack on UK Labour Party platforms was probably just a DDoS, says official
150 infosec bods now know who they’re up against thanks to BT Security cc/bcc snafu
Can regulations improve cybersecurity? In APAC, opinions vary

An ESET-commissioned survey among enterprises also shows that while respondents in most countries agree on the need to bolster cyber-defenses, some are reluctant to adopt cybersecurity solutions The post Can regulations improve cybersecurity? In APAC, opinions vary appeared first on WeLiveSecurity

An update that solves one vulnerability and has two fixes is now available.

Type: Vulnerability. Adobe Media Encoder is prone to multiple information-disclosure vulnerabilities; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Adobe Illustrator is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Adobe Illustrator is prone to multiple memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. SAP Treasury and Risk Management is prone to an authorization-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. SAP UI5 HTTP Handler is prone to an unspecified content-spoofing vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. SAP NetWeaver AS Java is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. SAP Business Objects Business Intelligence Platform is prone to an cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. SAP Enable Now is prone to an unspecified cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. SAP Diagnostics Agent is prone to an unspecified information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. SAP Quality Management is prone to an unspecified SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Adobe Animate is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. SAP BusinessObjects Business Intelligence Platform is prone to an XML External Entity injection vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Adobe Media Encoder is prone to an unspecified remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Adobe Bridge CC is prone to multiple unspecified memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Microsoft ActiveX Installer Service is prone to a local privilege-escalation vulnerability; fixes are available.

DDoS Attacks Target Amazon, SoftLayer and Telecom Infrastructure
BlueKeep freakout had little to no impact on patching, say experts

built version 0.10.5 fix CVE-2019-18837 —- built version 0.10.4 —- built version 0.10.3

**MySQL 8.0.18** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html CVEs fixed: CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957 CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968 CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 CVE-2019-2997

This update brings security updates for OpenJDK 13 and updates it to most current version 13.0.1.9.

built version 0.10.5 fix CVE-2019-18837

**MySQL 8.0.18** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html CVEs fixed: CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957 CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968 CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 CVE-2019-2997

rebase to 1.16.1

This update brings security updates for OpenJDK 13 and updates it to most current version 13.0.1.9.

security update

Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to an integer overflow vulnerability; fixes are available.

Type: Vulnerability. Fortinet FortiClient for macOS is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Apache CXF is prone to a denial-of-service vulnerability and an unauthorized access vulnerability; fixes are available.

Type: Vulnerability. Multiple Medtronic Products are prone to multiple security vulnerabilities; fixes are available.