Menu

Category Archives: Security

Articles about security

Google Algorithm Updates vs SEO Strategies
These smart contact lenses equip your eyes with augmented reality

Update to Rack 2.0.8.

UFC champ Kamaru Usman says his Twitter account was hacked, after series of explicit tweets against Conor McGregor

In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests

Hackers are closing the Shitrix security hole to keep everyone out of Citrix servers apart from themselves
Microsoft issues Internet Explorer zero-day warning, but there’s no patch yet

Updated wireshark packages fix security vulnerability: BT ATT dissector crash (CVE-2020-7045). References:

Updated suricata packages fix security vulnerabilities: The suricata package has been updated to version 4.1.6, which fixes security issues and other bugs. See the upstream announcements for details.

Updated tigervnc packages fix security vulnerabilities: The tigervnc package has been updated to version 1.10.1 to fix multiple unspecified security issues. These issues affect both the client and server and could theoretically allow an malicious peer to take control over the

security update

Update to 79.0.3945.117. Fixes CVE-2020-6377. —- Security fix for CVE-2019-13767. —- Update to Chromium 79. Fixes the usual giant pile of bugs and security issues. This time, the list is: CVE-2019-13725 CVE-2019-13726 CVE-2019-13727 CVE-2019-13728 CVE-2019-13729 CVE-2019-13730 CVE-2019-13732 CVE-2019-13734 CVE-2019-13735 CVE-2019-13764 CVE-2019-13736 CVE-2019-13737

How Modern Technology is Making Business Life Easier
FBI unlocks iPhone 11 Pro Max using Graykey raising privacy concerns
Protect your identity from fraudster with AI-powered Identity Guard
To catch a thief, go to Google with a geofence warrant – and it will give you all the details

An update that fixes one vulnerability is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0124

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0122

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0122

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0124

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0120

It’s Friday, the weekend has landed… and Microsoft warns of an Internet Explorer zero day exploited in the wild
New JhoneRAT Malware Targets Middle East
Feds Cut Off Access to Billions of Breached Records with Site Takedown
Mobile Carrier Customer Service Ushers in SIM-Swap Fraud
Keep Your Home Protected: 5 Best Indoor Home Security Cameras
‘Friendly’ hackers are seemingly fixing the Citrix server hole – and leaving a nasty present behind
Feds seize WeLeakInfo.com for selling stolen databases
Threatpost Poll: Are Published PoC Exploits a Good or Bad Idea?
News Wrap: PoC Exploits, Cable Haunt and Joker Malware
FBI Plans to Inform States of Election Breaches
Travelex won’t say if it has paid a ransom to its attackers
Stolen creds site WeLeakInfo busted by multinational cop op for data reselling
“Hello dear slave”
WeLeakInfo, the site which sold access to passwords stolen in data breaches, is brought down by the FBI

An update that solves 17 vulnerabilities and has one errata is now available.

Reading Time: ~ 2 min. Ryuk Adds New Features to Increase Devastation The latest variant of the devastating Ryuk ransomware has been spotted with a new feature that allows it to turn on devices connected to the infected network. By taking advantage of Wake-on-Lan functionality, Ryuk can is able to mount additional remote devices to […]

Mozilla: IonMonkey type confusion with StoreElementHole and FallibleStoreElement (CVE-2019-17026) * Mozilla: Bypass of @namespace CSS sanitization during pasting (CVE-2019-17016) * Mozilla: Type Confusion in XPCVariant.cpp (CVE-2019-17017) * Mozilla: Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4 (CVE-2019-17024) * Mozilla: CSS sanitization does not escape HTML tags (CVE-2019- [More…]

Mozilla: IonMonkey type confusion with StoreElementHole and FallibleStoreElement (CVE-2019-17026) * Mozilla: Bypass of @namespace CSS sanitization during pasting (CVE-2019-17016) * Mozilla: Type Confusion in XPCVariant.cpp (CVE-2019-17017) * Mozilla: Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4 (CVE-2019-17024) * Mozilla: CSS sanitization does not escape HTML tags (CVE-2019- [More…]

Unlocking news: We decrypt those cryptic headlines about Scottish cops bypassing smartphone encryption

An update that solves one vulnerability and has two fixes is now available.

This update is based on upstream 5.4.12 and fixes atleast the following security vulnerabilities: Intel GPU Hardware prior to Gen11 does not clear EU state during a context switch. This can result in information leakage between

The updated packages fix security vulnerabilities: A signed integer overflow and subsequent segfault that occurred when attempting to decompress images with more than 715827882 pixels using the 64-bit C version of TJBench.

Hacker uses NSA-reported Windows 10 vulnerability to troll NSA
Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don’t work for older kit
Critical Cisco Flaws Now Have PoC Exploit
Google Account Security Keys Launch for iPhone
Satan Ransomware Reborn to Torment Businesses
How to Secure Your VPS and Dedicated Servers from Hackers
Smart Cars: Increasing Comfort — Reducing Security
PoC Exploits Published For Microsoft Crypto Bug
‘Fleeceware’ Apps Downloaded 600M Times from Google Play
PlanetDrugsDirect reveals security breach, warns customers their data may have been exposed

git: Remote code execution in recursive clones with nested submodules (CVE-2019-1387) SL7 x86_64 git-1.8.3.1-21.el7_7.x86_64.rpm git-daemon-1.8.3.1-21.el7_7.x86_64.rpm git-debuginfo-1.8.3.1-21.el7_7.x86_64.rpm git-gnome-keyring-1.8.3.1-21.el7_7.x86_64.rpm git-svn-1.8.3.1-21.el7_7.x86_64.rpm noarch emacs-git-1.8.3.1-21.el7_7.noarch.rpm emacs-git-el-1.8.3.1-21.el [More…]

OpenJDK: Use of unsafe RSA-MD5 checkum in Kerberos TGS (Security, 8229951) (CVE-2020-2601) * OpenJDK: Serialization filter changes via jdk.serialFilter property modification (Serialization, 8231422) (CVE-2020-2604) * OpenJDK: Improper checks of SASL message properties in GssKrb5Base (Security, 8226352) (CVE-2020-2590) * OpenJDK: Incorrect isBuiltinStreamHandler causing URL normalization iss [More…]

Hackers jailed for hacking National Lottery & withdrawing £13

An update for rh-dotnet30-dotnet and rh-dotnet31-dotnet is now available for .NET Core on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

How RHEL 8 is designed for FIPS 140-2 requirements

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Cyberawareness in Australia: The good and the bad

An ESET-commissioned survey sheds light on the browsing habits of Australians and how they protect themselves online The post Cyberawareness in Australia: The good and the bad appeared first on WeLiveSecurity

An update that solves three vulnerabilities and has three fixes is now available.

Spanking the pirates of corporate security? Try a Plimsoll
Attention security startup founders: Give your fledgling Brit biz a boost with Tech Nation’s free Cyber 2.0 school
Top Euro court advised: Cops, spies yelling ‘national security’ isn’t enough to force ISPs to hand over massive piles of people’s private data
Smashing Security #161: Love, lucky dips, and 23andMe
What do Brit biz consultants and X-rated cam stars have in common? Wide open… AWS S3 buckets on public internet
Yo, sysadmins! Thought Patch Tuesday was big? Oracle says ‘hold my Java’ with huge 334 security flaw fix bundle
Critical WordPress Bug Leaves 320,000 Sites Open to Attack
A Practical Guide to Zero-Trust Security
Podcast: NSA Reports Major Crypto-Spoofing Bug to Microsoft
Baby pics, videos & location data from Peekaboo Moments app leaked online
U.N. Weathers Storm of Emotet-TrickBot Malware
Equifax Settles Class-Action Breach Lawsuit for $380.5M
Peekaboo Moments app left baby videos, photos, and 800,000 users’ email addresses exposed on the internet
PussyCash adult webcam data breach exposes highly sensitive data of models
Trump Slams Apple for Refusing to Unlock Suspected Shooter’s iPhones
Google to end support for third‑party cookies in Chrome

The company will also soon launch anti-fingerprinting measures aimed at detecting and mitigating covert tracking and workarounds The post Google to end support for third‑party cookies in Chrome appeared first on WeLiveSecurity

Faketoken malware sends expensive & offensive texts at your expense

An update that solves one vulnerability and has three fixes is now available.

Travelex warns customers of phone scam threat in wake of ransomware attack

Applications using libpcap could be made to crash if given specially crafted data.

Oski Data-Stealing Malware Emerges to Target North America, China

An update that fixes three vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0085

Several security issues were fixed in PHP.

Today’s webcast: Hackers don’t care if you’re big or small. Tune in to find out how to protect your mid-sized biz
Updated your WordPress plugins lately? Here are 320,000 auth-bypassing reasons why you should
Critical Windows 10 security fix pushed out after NSA warns Microsoft of spying vulnerability
Oracle Ties Previous All-Time Patch High with January Updates
Microsoft patches severe Windows flaw after tip‑off from NSA

The US intelligence agency expects attackers to waste no time in developing tools aimed at exploiting the vulnerability The post Microsoft patches severe Windows flaw after tip‑off from NSA appeared first on WeLiveSecurity

Microsoft’s new tool detects & reports pedophiles from online chats
Welcome to the 2020s: Booby-trapped Office files, NSA tipping off Windows cert-spoofing bugs, RDP flaws…
Intel Fixes High-Severity Flaw in Performance Analysis Tool
Card Skimmer Hits Australian Bushfire Donation Site
Microsoft Patches Major Crypto Spoofing Bug

security update

Apple calls BS on FBI, AG: We’re totally not dragging our feet in murder probe iPhone decryption. PS: No backdoors