Menu

Category Archives: Security

Articles about security

Popular ThemeREX WordPress Plugin Opens Websites to RCE
Firefox Bug Opens iPhone AirPods to Third-Party Snooping
High-Severity Flaws Plague Intel Graphics Drivers
You only LVI twice: Meltdown The Sequel strikes Intel chips – and full mitigation against data-meddling flaw will cost you 50%+ of performance
Hackers hit hackers in new malware campaign
Flaw in popular VPN service may have exposed customer data

NordVPN praised its bug bounty program and said that a fix had been shipped within two days The post Flaw in popular VPN service may have exposed customer data appeared first on WeLiveSecurity

Variant of Paradise Ransomware Targets Office IQY Files
7 Cybersecurity Trends to Look Out for in 2020
Android anti-virus products put to the test – which are the best at stopping new malicious apps?
Spear-Phishing Attack Lures Victims With ‘HIV Results’
Avast’s AntiTrack promised to protect your privacy. Instead, it opened you to miscreant-in-the-middle snooping
AMD, boffins clash over chip data-leak claims: New side-channel holes in decades of cores, CPU maker disagrees
Hackers are exploiting critical vulnerability in Microsoft Exchange server
NSO Group fires back at Facebook: You lied to the court, claims spyware slinger, and we’ve got the proof
Microsoft: 99.9 percent of hacked accounts didn’t use MFA

Only 11 percent of all enterprise accounts have multi-factor authentication enabled The post Microsoft: 99.9 percent of hacked accounts didn’t use MFA appeared first on WeLiveSecurity

Microsoft Exchange Server Flaw Exploited in APT Attacks
Months-long trial of alleged CIA Vault 7 exploit leaker ends with hung jury: Ex-sysadmin guilty of contempt, lying to FBI
Dark Web search engine Kilos lets users find hidden marketplaces
Comcast Xfinity published the contact details of 200,000 customers who paid for them to be kept private
UK Defence Committee probe into national security threat of Huawei sure to uncover lots of new and original insights
AMD Downplays CPU Threat Opening Chips to Data Leak Attacks
Coronavirus map used to spread malware
Spyware maker NSO runs scared from Facebook over WhatsApp hacking charges, fails to show up in court
UK.gov is not sharing Brits’ medical data among different agencies… but it’s having a jolly good think about it
Check Point chap: Small firms don’t invest in infosec then hope they won’t get hacked. Spoiler alert: They get hacked
Virgin Media & T-Mobile data breach exposes customers data

An update that fixes one vulnerability is now available.

Don’t be fooled, experts warn, America’s anti-child-abuse EARN IT Act could burn encryption to the ground
Next-Gen Ransomware Packs a ‘Human’ Punch, Microsoft Warns
FYI: When Virgin Media said it leaked ‘limited contact info’, it meant p0rno filter requests, IP addresses, IMEIs as well as names, addresses and more
2 in 5 Android devices found vulnerable worldwide – That’s over a billion
UK spy auditor gives state snoops a big pat on the back for job well done – except MI5
Spread of Coronavirus-Themed Cyberattacks Persists with New Attacks
Critical Zoho Zero-Day Flaw Disclosed
Virgin Media left 900,000 consumers’ details exposed in unsecured database
201 million US demographic, personal records leaked online
Over one billion Android devices at risk as they no longer receive security updates
NordVPN quietly plugged vuln where an HTTP POST request without authentication would return detailed customer data

sudo: Stack based buffer overflow when pwfeedback is enabled (CVE-2019-18634) SL6 x86_64 sudo-1.8.6p3-29.el6_10.3.x86_64.rpm sudo-debuginfo-1.8.6p3-29.el6_10.3.x86_64.rpm sudo-debuginfo-1.8.6p3-29.el6_10.3.i686.rpm sudo-devel-1.8.6p3-29.el6_10.3.i686.rpm sudo-devel-1.8.6p3-29.el6_10.3.x86_64.rpm i386 sudo-1.8.6p3-29.el6_10.3.i686.rpm sudo-debuginfo-1.8.6p3-29.e [More…]

The updated package fixes a security vulnerability: A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning. (CVE-2019-20479)

Updated pure-ftpd packages fix security vulnerabilities: An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called,

The updated packages fix several issues including security vulnerabilities: In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. (CVE-2019-19221)

Updated dojo package fixes security vulnerability: dojox was vulnerable to Cross-site Scripting. This was due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them (CVE-2019-10785).

The updated packages fix a security vulnerability: Mutation XSS in bleach.clean when noscript and raw tag whitelisted. (CVE-2020-6802)

Boots suspends loyalty card payments after hackers try to compromise accounts
More than a billion hopelessly vulnerable Android gizmos in the wild that no longer receive security updates – research
Like a Virgin, hacked for the very first time… UK broadband ISP spills 900,000 punters’ records into wrong hands from insecure database
Android users, if you could pause your COVID-19 panic buying for one minute to install these critical security fixes, that would be great
Man hacks Indian tech support scam call center; leaks CCTV footage
Let’s Encrypt: OK, maybe nuking three million HTTPS certs at once was a tad ambitious. Let’s take time out
Zynga Faces Lawsuit Over Massive Words with Friends Breach
Chris Eng: Patch Management Challenges Drive ‘Security Debt’
Staffer emails compromised and customer details exposed in T-Mobile US’s third security whoopsie in as many years
Hackers dropping info-stealer malware with fake security certificate alerts
High-Severity Cisco Webex Flaws Fixed
‘Unfixable’ boot ROM security flaw in millions of Intel chips could spell ‘utter chaos’ for DRM, file encryption, etc

An update that fixes two vulnerabilities is now available.

It was discovered that there was an out-of-bounds write vulnerability in pdfresurrect, a tool for extracting or scrubbing versioning data from PDF documents.

xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs (CVE-2018-1311) SL7 x86_64 xerces-c-3.1.1-10.el7_7.i686.rpm xerces-c-3.1.1-10.el7_7.x86_64.rpm xerces-c-debuginfo-3.1.1-10.el7_7.i686.rpm xerces-c-debuginfo-3.1.1-10.el7_7.x86_64.rpm xerces-c-devel-3.1.1-10.el7_7.i686.rpm xerces-c-devel-3.1.1-10.el7_7.x86_64.rpm noar [More…]

nodejs: HTTP request smuggling using malformed Transfer-Encoding header (CVE-2019-15605) SL7 x86_64 http-parser-2.7.1-8.el7_7.2.i686.rpm http-parser-2.7.1-8.el7_7.2.x86_64.rpm http-parser-debuginfo-2.7.1-8.el7_7.2.i686.rpm http-parser-debuginfo-2.7.1-8.el7_7.2.x86_64.rpm http-parser-devel-2.7.1-8.el7_7.2.i686.rpm http-parser-devel-2.7.1-8.el7_7.2.x86_64.rpm – Scient [More…]

Trump, Sanders Are the Top Brands for Cybercriminals
Enable that MF-ing MFA: 1.2 million Azure Active Directory accounts compromised every month, reckons Microsoft
Let’s Encrypt Pushes Back Deadline to Revoke Some TLS Certificates

An update for the virt:8.1 and virt-devel:8.1 modules is now available for Advanced Virtualization for RHEL 8.1.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Guildma: The Devil drives electric

The fourth installment of our occasional series demystifying Latin American banking trojans The post Guildma: The Devil drives electric appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

Sadly, the web has brought a whole new meaning to the phrase ‘nothing is true; everything is permitted’
Time to limber up in the battle against cybercriminals
Alleged Vault 7 leaker trial finale: Want to know the CIA’s password for its top-secret hacking tools? 123ABCdef
Smashing Security #168: The Bitcoin fraud factory
Fake reviews & third-party apps cause 50% of threats against Android
Download this update from mybrowser.microsoft.com. Oh, sorry, that was malware on a hijacked sub-domain. Oops
Critical Netgear Bug Impacts Flagship Nighthawk Router
Microsoft OneNote Used To Sidestep Phishing Detection
CIA’s 11-year old hacking campaign against China exposed
If Tesco was hacked, your data could be being flogged for just £2.70 – research
Fraud Prevention Month: How to protect yourself from scams

ESET Chief Security Evangelist Tony Anscombe sat down with us to share his insights on how to avoid falling prey to online fraud The post Fraud Prevention Month: How to protect yourself from scams appeared first on WeLiveSecurity

Loyalty Cards Targeted in Tesco Clubcard Attack
Voice assistants can be hacked with ultrasonic waves

With access to text messages and the ability to make fraudulent phone calls, attackers could wreak more damage than you’d think The post Voice assistants can be hacked with ultrasonic waves appeared first on WeLiveSecurity

It has been 15 years, and we’re still reporting homograph attacks – web domains that stealthily use non-Latin characters to appear legit
UK data watchdog slaps a £500,000 fine on Cathay Pacific for 2018 9.4m customer data leak

An update for http-parser is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Police raid tech support scam centre who had their CCTV hacked by vigilantes

An update for http-parser is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Cathay Pacific slammed for security failures following hack which exposed 9.4 million people worldwide

An update that solves 22 vulnerabilities and has 152 fixes is now available.

Fancy that: Hacking airliner systems doesn’t make them magically fall out of the sky

An update that solves 22 vulnerabilities and has 152 fixes is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Hackers are using Word documents to drop NetSupport Manager RAT
Cobalt Ulster Strikes Again With New ForeLord Malware
Let’s Encrypt to Revoke Millions of TLS Certs
Let’s Encrypt? Let’s revoke 3 million HTTPS certificates on Wednesday, more like: Check code loop blunder strikes
MediaTek Bug Actively Exploited, Affects Millions of Android Devices
Have I Been Pwned No Longer For Sale
Brave comes out on top in browser privacy study

By contrast, two web browsers share identifiers that are tied to the device hardware and so persist even across fresh installs The post Brave comes out on top in browser privacy study appeared first on WeLiveSecurity

GCHQ’s infosec arm has 3 simple tips to secure those insecure smart home gadgets
Apple removes Clearview AI iPhone app from App Store

An update that solves one vulnerability and has one errata is now available.