Menu

Category Archives: Security

Articles about security

Type: Vulnerability. Google Android is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. WordPress is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a session-fixation vulnerability; fixes are available.

Type: Vulnerability. Sudo is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Siemens SINEMA Remote Connect Server is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Redhat Wildfly is prone to a privilege-escalation; fixes are available.

Type: Vulnerability. Juniper Junos is prone to an HTML-injection vulnerability; fixes are available.

Sure is quiet from Adobe. No security fixes this month? Great job. Oh no, wait, what’s that stampede sound…

Risk Level: Very Low. Type: Trojan.

Streaming devices track viewing habits, study finds

Do you know what kind of data your streaming device may be collecting while you binge watch? The post Streaming devices track viewing habits, study finds appeared first on WeLiveSecurity

Ye olde Blue Screen of Death is back – this time, a bad Symantec update is to blame

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for jss is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Pitney Bowes Hit with Ransomware Attack
A Deepfake Deep Dive into the Murky World of Digital Imitation

Aspell could be made to expose sensitive information if it received a specially crafted input.

An update that fixes 83 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Type: Vulnerability. Adobe Experience Manager Forms is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Adobe Experience Manager is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple information-disclosure vulnerabilities; fixes are available.

Sudo? More like Su-doh: There’s a fun bug that gives restricted sudoers root access (if your config is non-standard)
Apple insists it’s totally not doing that thing it wasn’t accused of: We’re not handing over Safari URLs to Tencent – just people’s IP addresses

Type: Vulnerability. Juniper Junos is prone to a local authorization-bypass vulnerability; fixes are available.

Type: Vulnerability. Google Chrome is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. WebKit is prone to multiple cross-site scripting and memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Apple Swift is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Apple macOS/iCloud for Windows/iTunes are prone to a buffer overflow vulnerability; fixes are available.

Type: Vulnerability. WebKit is prone to an information-disclosure and a security vulnerability; fixes are available.

Type: Vulnerability. WebKit is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Apple macOS is prone to multiple security vulnerabilities; fixes are available.

Pitney Bowes: Can we be frank? Ransomware has borked our dead-tree post systems
Tearoff of Nottingham: University to lose chunk of IT dept to outsourcing
Alleged “Psycho” hacker in court over EtherDelta cryptocurrency robbery
Apple Shares Some Browsing History with Chinese Company
Connecting the dots: Exposing the arsenal and methods of the Winnti Group

New ESET white paper released describing updates to the malware arsenal and campaigns of this group known for its supply-chain attacks The post Connecting the dots: Exposing the arsenal and methods of the Winnti Group appeared first on WeLiveSecurity

Imperva cloud firewall pwned, D-Link bug uncovered – plus more

An update that fixes 5 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

This update provides the final 1.3.2 release (previously the package was 1.3.2 beta). It also includes the previously-omitted database schema directory (resolving [#1415753](https://bugzilla.redhat.com/show_bug.cgi?id=1415753)) and rddmarc tools, and backports proposed fixes for a [crasher bug](https://bugzilla.redhat.com/show_bug.cgi?id=1673293) and [security issue

Backport security fixes from [PR#145](https://github.com/libming/libming/pull/145) Fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132

Patch CVE-2019-12412.

– Rebase radare2 to 3.9.0 – Rebase cutter-re to 1.9.0 – fix CVE-2019-14745 in radare2 on F30

– Rebase radare2 to 3.9.0 – Rebase cutter-re to 1.9.0 – fix CVE-2019-14745 in radare2 on F30

– Update jackson-parent to version 2.10. – Update jackson-bom to version 2.10.0. – Update jackson-annotations to version 2.10.0. – Update jackson-core to version 2.10.0. – Update jackson-databind to version 2.10.0. Resolves CVE-2019-14540, CVE-2019-16335, CVE-2019-16942, CVE-2019-16943.

– Update jackson-parent to version 2.10. – Update jackson-bom to version 2.10.0. – Update jackson-annotations to version 2.10.0. – Update jackson-core to version 2.10.0. – Update jackson-databind to version 2.10.0. Resolves CVE-2019-14540, CVE-2019-16335, CVE-2019-16942, CVE-2019-16943.

– Update jackson-parent to version 2.10. – Update jackson-bom to version 2.10.0. – Update jackson-annotations to version 2.10.0. – Update jackson-core to version 2.10.0. – Update jackson-databind to version 2.10.0. Resolves CVE-2019-14540, CVE-2019-16335, CVE-2019-16942, CVE-2019-16943.

The update for openssl released as DSA 4539-1 introduced a regression where AES-CBC-HMAC-SHA ciphers were not enabled. Updated openssl packages are now available to correct this issue.

Update to latest upstream version.

Stalker zoomed in on Japanese idol’s eyes to find out where she lived
Software, Supply-Chain Dangers Top List of 5G Cyber Risks

Type: Vulnerability. Intel Active System Console is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Intel Smart Connect Technology is prone to a local privilege-escalation vulnerability.

Type: Vulnerability. Multiple Intel NUC Products are prone to multiple unspecified local security vulnerabilities; fixes are available

Type: Vulnerability. Juniper SBR Carrier is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Imperva: Data Breach Caused by Cloud Misconfiguration

A security vulnerability was discovered in lucene-solr, an enterprise search server. The DataImportHandler, an optional but popular module to pull in data

An update that fixes one vulnerability is now available.

Fin7 Cybergang Retools With New Malicious Code

Reading Time: ~ 2 min. E-Scooter Security Vulnerability A security researcher recently found an API vulnerability within the software of Voi e-scooters that allowed him to add over $100,000 in ride credits to his account. The vulnerability stems from a lack of authentication after creating an account which allows users to enter an unlimited number […]

Iran-Linked ‘Charming Kitten’ Touts New Spearphishing Tactics

ruby-openid performed discovery first, and then verification. This allowed an attacker to change the URL used for discovery and trick the server into connecting to the URL. This server in turn could be a private server not publicly accessible.

Type: Vulnerability. Oracle has released an advance notification regarding the October 2019 Critical Patch Update that addresses 240 new vulnerabilities.

vBulletin Flaw Exploited in Dutch Sex-Work Forum Breach
Stalker attacks Japanese pop singer – after tracking her down using reflection in her eyes
Cryptomining Crook Steals Game Developer’s Identity to Carry Out Dirty Work

Reading Time: ~ 4 min. Online games aren’t new. Consumers have been playing them since as early as 1960. However, the market is evolving—games that used to require the computing power of dedicated desktops can now be powered by smartphones, and online gaming participation has skyrocketed. This unfortunately means that the dangers of online gaming […]

Risk Level: Very Low.

Finfisher malware authors fire off legal threats to silence German journos
Sophisticated Spy Kit Targets Russians with Rare GSM Plugin
Some fokken arse has bared the privates of 250,000 users’ from Dutch brothel forum
China’s Sway Over Tech Companies Tested with Apple, Blizzard
Just let us have Huawei and get on with 5G, UK mobe networks tell MPs
Apple iTunes Bug Actively Exploited in BitPaymer/iEncrypt Campaign
HP Touchpoint Analytics Opens PCs to Code Execution Attack

Fix KDC crash when logging PKINIT enctypes (CVE-2019-14844) This is a purely denial-of-service issue, though it is unauthenticated, and is unlikely to trigger by accident.

Update to 2.0.10 to fix security issues.

An update for ovirt-web-ui is now available for Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for ovirt-engine-ui-extensions is now available for Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Several security issues were fixed in Python.

Octavia could allow unintended access to network services.

ESET discovers Attor, a spy platform with curious GSM fingerprinting

ESET researchers discover a previously unreported cyberespionage platform used in targeted attacks against diplomatic missions and governmental institutions, and privacy-concerned users The post ESET discovers Attor, a spy platform with curious GSM fingerprinting appeared first on WeLiveSecurity

Former BAE Systems contractor charged with ‘damaging disclosure’ of UK defence secrets

It was discovered that clamav, the open source antivirus engine, is affected by the following security vulnerabilities: CVE-2019-12625