Menu

Category Archives: Security

Articles about security

An update for apb, containernetworking-plugins, and golang-github-prometheus-promu is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact

Huawei with you! FCC’s American Pai proposes rip-and-replace of scary Chinese comms kit

A micro version update (from 7.4 to 7.4.1) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

Country of Georgia Suffers Widespread Cyberattack
ThreatList: Most Retail Hardware Bug Bounty Flaws Are Critical

Several security issues were fixed in Samba.

An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for mediawiki is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score,

Reading Time: ~ 4 min. In my previous blog post, Why Healthcare Organizations are Easy Targets for Cybercrime, I discussed various reasons that hospitals and healthcare organizations make desirable and lucrative targets for hackers. In this second installment, I’ll go over how criminals are attacking these organizations, the methods they use, and also what needs to be done […]

Updated file packages fix security vulnerability: A buffer overflow was found in file which may result in denial of service or potentially the execution of arbitrary code if a malformed CDF (Composite Document File) file is processed (CVE-2019-18218).

Updated php and pcre2 packages fix security vulnerabilities: – FPM (#78599) env_path_info underflow in fpm_main.c can lead to RCE. (CVE-2019-11043) – MBString (#78633) Heap buffer overflow (read) in mb_eregi.

This kernel update is based on the upstream 5.3.7 and fixes several issues: * various security issues in the usb subsystem * rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow (CVE-2019-17666)

The updated packages fix a security vulnerability: The agroot() function in cgraphobj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv. (CVE-2019-11023)

UK Ministry of Justice brags about new digital forensics unit to thwart tech-savvy jailbirds
What you may be getting wrong about cybersecurity

Attention-grabbing cyberattacks that use fiendish exploits are probably not the kind of threat that should be your main concern – here’s what your organization should focus on instead The post What you may be getting wrong about cybersecurity appeared first on WeLiveSecurity

What a bunch of dopes! Fancy Bear hackers take aim at drug-testing orgs
UniCredit Suffers Third Breach Despite Investing Billions in Cybersecurity

Type: Vulnerability. IBM Cloud Orchestrator is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. QEMU is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Multiple IBM Products are prone to a directory-traversal vulnerability; fixes are available.

Type: Vulnerability. IBM Cloud Orchestrator is prone to local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple IBM Products are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. IBM API Connect is prone to an information-disclosure vulnerability; fixes are available.

How Facebook helps an abusive ex-partner find out your new identity, even after you’ve blocked them
Pwn2Own Expands Into Industrial Control Systems Hacking
City of Joburg says it knows who ransom hack attacker is, refuses to pay off criminals
PHP Bug Allows Remote Code-Execution on NGINX Servers
Update your iPhone 5 before November 3 2019, or lose its internet access
Magecart Gang Targets Skin Care Site Visitors For 5+ Months

An update that fixes one vulnerability is now available.

Cybercriminals Impersonate Russian APT ‘Fancy Bear’ to Launch DDoS Attacks

An update that fixes one vulnerability is now available.

See you at NISC, the National Information Security Conference, next week

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

Remember that competition for non-hoodie hacker pics? Here’s their best entries

The package chromium before version 78.0.3904.70-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, access restriction bypass, authentication bypass, denial of service, information disclosure, privilege escalation and cross-site scripting.

The package firefox before version 70.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, denial of service, insufficient validation and same-origin policy bypass.

The package thunderbird before version 68.2.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, denial of service, insufficient validation and same-origin policy bypass.

The package php before version 7.3.11-1 is vulnerable to arbitrary code execution.

FBI extends voting security push, LA court hacker goes down, and more D-Link failures

This is a cumulative bug-fix update from upstream, including a fix for a pre- authentication remote denial of service issue.

New version 4.9.3, Security fix for CVE-2017-16808, CVE-2018-14468, CVE-2018-14469, CVE-2018-14470, CVE-2018-14466, CVE-2018-14461, CVE-2018-14462, CVE-2018-14465, CVE-2018-14881, CVE-2018-14464, CVE-2018-14463, CVE-2018-14467, CVE-2018-10103, CVE-2018-10105, CVE-2018-14880, CVE-2018-16451, CVE-2018-14882, CVE-2018-16227, CVE-2018-16229, CVE-2018-16301, CVE-2018-16230, CVE-2018-16452,

An update that solves 5 vulnerabilities and has 98 fixes is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

– Updated to latest upstream version (70.0)

Update to OpenJDK October CPU (security update). See: https://openjdk.java.net/groups/vulnerability/advisories/2019-10-15 http://mail.openjdk.java.net/pipermail/jdk-updates-dev/2019-October/002025.html

OpenJDK October CPU security update. See: https://openjdk.java.net/groups/vulnerability/advisories/2019-10-15 http://mail.openjdk.java.net/pipermail/jdk8u-dev/2019-October/010452.html

xpdf 4.02. Lots of security fixes here.

An update that fixes one vulnerability is now available.

Security fix for CVE-2018-16301, CVE-2019-15161, CVE-2019-15162, CVE-2019-15163, CVE-2019-15164, CVE-2019-15165

Security fix for CVE-2018-16301, CVE-2019-15161, CVE-2019-15162, CVE-2019-15163, CVE-2019-15164, CVE-2019-15165

Security fix for CVE-2018-16301, CVE-2019-15161, CVE-2019-15162, CVE-2019-15163, CVE-2019-15164, CVE-2019-15165

security update

security update

An update that fixes 5 vulnerabilities is now available.

Several issues have been found in mosquitto, a MQTT version 3.1/3.1.1 compatible message broker.

An issue has been found in libarchive, a multi-format archive and compression library.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Daniel Mandragona discovered that invalid DSA public keys can cause a panic in dsa.Verify(), resulting in denial of service. For the stable distribution (buster), this problem has been fixed in

A buffer overflow was found in file, a file type classification tool, which may result in denial of service or potentially the execution of arbitrary code if a malformed CDF (Composite Document File) file is processed.

An update that fixes one vulnerability is now available.

An update that fixes 10 vulnerabilities is now available.

An update that fixes 11 vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 28 vulnerabilities is now available.

Backport security fixes from [PR#145](https://github.com/libming/libming/pull/145) Fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132

Emil Lerner, beched and d90pwn found a buffer underflow in php5-fpm, a Fast Process Manager for the PHP language, which can lead to remote code execution.

security update

Is AWS Liable in Capital One Breach?

Type: Vulnerability. NixOS Nix is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. GNU Guix is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Elasticsearch is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple VMware products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cloud Foundry UAA is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Istio is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Qt QtBase module is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Cloud Foundry SMB Volume is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. OpenSSH is prone to an integer overflow vulnerability; fixes are available.

Type: Vulnerability. SLUB Event Registration Extension is prone to an arbitrary-file-upload vulnerability; fixes are available.

Type: Vulnerability. vBulletin is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a heap-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Nessus is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Adobe Creative Cloud Desktop Application is prone to an unspecified security-bypass vulnerability; fixes are available.

Type: Vulnerability. vBulletin is prone to multiple SQL-injection vulnerabilities.

Type: Vulnerability. Dnsmasq is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to information-disclosure vulnerability; fixes are available.

Time to check who left their database open and leaked 7.5m customer records: Hi there, Adobe Creative Cloud!
Uncle Sam demands summary judgement on Snowden memoir: We’re not saying it’s true, but no one should read it
U.N., UNICEF, Red Cross Under Ongoing Mobile Attack
News Wrap: Hotel Robot Hacks, FTC Stalkerware Crackdown
Japanese hotel robots can be hacked to spy on guests in their bedrooms
Ransomware, Mobile Malware Attacks to Surge in 2020

Reading Time: ~ 2 min. MedusaLocker Ransomware Spotted Worldwide While it’s still unclear how MedusaLocker is spreading, the victims have been confirmed around the world in just the last month. By starting with a preparation phase, this variant can ensure that local networking functionality is active and maintain access to network drives. After shutting down […]

An Open-Source Success Story: Apache SpamAssassin Celebrates 18 Years of Effectively Combating Spam Email