Menu

Category Archives: Security

Articles about security

Type: Vulnerability. Cisco Unified Communications Manager is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco Unified Communications Manager is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco Unified Contact Center Express is prone to an HTTP response-splitting vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco Adaptive Security Appliance is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Moxa EDR 810 Series is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Prime Infrastructure is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Cisco Prime Infrastructure is prone to a cross-site scripting vulnerability; fixes are available.

GPS cyberstalking of girlfriend brings surveillance and indictment for alleged American mobster
Here we go again: US govt tells Facebook to kill end-to-end encryption for the sake of the children
Iran tried to hack hundreds of politicians, journalists email accounts last month, warns Microsoft

The package ruby2.5 before version 2.5.7-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, cross-site scripting, denial of service and insufficient validation.

The package ruby-rdoc before version 6.1.2-1 is vulnerable to cross- site scripting.

New malware mimics Windows scanner to infect PCs with ransomware
Google Warns of Android Zero-Day Bug Under Active Attack
Dead simple: Plenty of Magecart miscreants still looking to skim off your credit card deets
Virus Bulletin 2019: VoIP Espionage Campaign Hits U.S. Utilities Supplier

An update that fixes 27 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 27 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

Former Yahoo employee admits he hacked 6000 users’ accounts, stole nude photos and videos
TalkTalk says WalkWalk if you’ve got a mouldy Tiscali email address, or pay £50 a year to keep it

Reading Time: ~ 2 min. DoorDash Data Breach Nearly five months after a breach, DoorDash has just now discovered that unauthorized access to sensitive customer information has taken place. Among the stolen data were customer names, payment history, and contact info, as well as the last four digits of both customer payment cards and employee […]

Several security issues were fixed in the Linux kernel.

Implementing corporate laptop encryption using LUKS
AG Barr, Officials to Facebook: Don’t Encrypt Messaging
Virus Bulletin 2019: Magecart Infestations Saturate the Web
Egyptian government caught tracking opponents and activists through phone apps
Life’s certainties: Death, taxes, and Cisco patching more serious vulnerabilities
FBI softens stance on ransomware: it’s (sort of) okay to pay off crims to get your data back
Kaspersky warns of encryption-busting Reductor malware
New Reductor Malware Hijacks HTTPS Traffic

A vulnerability was discovered by Lukas Kupczyk of the Advanced Research Team at CrowdStrike Intelligence in OpenConnect, an open client for Cisco AnyConnect, Pulse, GlobalProtect VPN. A malicious HTTP server

An update that fixes one vulnerability is now available.

Type: Vulnerability. Cisco Firepower Management Center is prone to multiple remote code-execution vulnerabilities; fixes are available.

Type: Vulnerability. Cisco FXOS and Firepower Threat Defense Software are prone to multiple local command-injection vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Firepower Threat Defense Software is prone to multiple security-bypass vulnerabilities; fixes are available.

Type: Vulnerability. Multiple Cisco Unified Communications Products are prone to a cross-site request-forgery vulnerability.

Type: Vulnerability. Cisco Firepower Management Center is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Cisco Firepower Management Center is prone to multiple SQL-injection vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Firepower Management Center is prone to a command-injection vulnerability; fixes are available

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Google Chrome OS is prone to a remote integer-overflow vulnerability; fixes are available.

Type: Vulnerability. WhatsApp is prone to an integer overflow vulnerability.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a remote command-injection vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a command-injection vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a hard-coded credentials vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a security vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to an SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.

New Android banking botnet ‘Geost’ hits thousands of devices

Updated thunderbird packages fix security vulnerability: Spoofing a message author via a crafted S/MIME message (CVE-2019-11755) It also fixes various other bugs, as listed in the releasenotes.

Foxit PDF Reader Vulnerable to 8 High-Severity Flaws
Hospitals in US, Australia hobbled by ransomware

The incidents send medical staff back to the days of pen and paper The post Hospitals in US, Australia hobbled by ransomware appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

A short history of hacked billboards and road signs
FBI: Don’t pay ransomware demands, stop encouraging cybercriminals to target others
WhatsApp Flaw Opens Android Devices to Remote Code Execution

patch: do_ed_script in pch.c does not block strings beginning with a ! character (CVE-2018-20969) * patch: OS shell command injection when processing crafted patch files (CVE-2019-13638) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. SL7 […]

Red Hat expands coverage of CVE fixes
Generate SELinux policies for containers with Udica

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in ClamAV.

An update for patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Casbaneiro: Dangerous cooking with a secret ingredient

Número dois in our series demystifying Latin American banking trojans The post Casbaneiro: Dangerous cooking with a secret ingredient appeared first on WeLiveSecurity

It was discovered that there was a remotely-exploitable null pointer dereference in libapreq2, a library for manipulating HTTP requests. For Debian 8 “Jessie”, this issue has been fixed in libapreq2 version

Huygens if true: Dutch police break up bulletproof hosting outfit and kill Mirai botnet

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. EMC RSA BSAFE Crypto-C Micro and Micro Edition Suite are prone to multiple security vulnerabilities; fixes are available.

FBI called in to investigate 2018 Mountain State mobile voting system hacking
Smashing Security #148: Billboard boobs, face forensics, and Alexa gets way too personal
Reason Security opens beta for business edition & cuts yearly subscription price
Android users installed 172 malicious apps 335m times last month
Google Maps gets Incognito fig leaf: We’ll give you vague peace of mind if you hold off those privacy laws

Security fix for CVE-2019-15026

Security fix for CVE-2019-13132

**GLPI version 9.4.4** This is a **security release**, upgrading is highly recommended Non exhaustive list of changes: * [security] Prevent account takeover vulnerability , * [security] Prevent execution of XSS on rich text, * fix cache key lenght issues, * fix user picture removal at login, * several fixes on recurring tickets, * fix some […]

Zendesk Exposes 10,000 Accounts to Unknown Third Party

security update

security update

Why This New Cybergang is Heralding a New Age For BEC
Most SMB cybersecurity defence fail short to thwart malware & file-based attacks
Medic! Uncle Sam warns hospitals not to use outdated IPnet freely on their networks

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Jenkins is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Pivotal Application Service is prone to an access-bypass vulnerability; fixes are available.

Type: Vulnerability. Foxit Reader is prone to a remote code-execution vulnerability.

Former! Yahoo! engineer! admits! to! hacking! user! emails! for! smutty! snaps!