Menu

Category Archives: Security

Articles about security

Gaming giant Zynga data breach: 218 million records stolen
Virus Bulletin 2019: Geost Android Botnet Goes After Millions of Euros
Virus Bulletin 2019: Japanese Attacks Highlight Savvy APT Strategy
Zendesk clocks 10,000 accounts accessed by miscreants before November 2016
If you really can’t let go of Windows 7, Microsoft will keep things secure for another three years
Google Adds Password Checkup Feature to Chrome Browser
A pervert Yahoo employee hacked 6,000 accounts using internal system
Have you been Thomas Crooked? Watch out for cybercrims slinging holiday-themed fakes
Hack Breaks PDF Encryption, Opens Content to Attackers
The benefits of security behavior analytics for devops
Do apps need all the permissions?

Why you should ensure that all those apps on your smartphone only run with the permissions they reasonably need to do their job The post Do apps need all the permissions? appeared first on WeLiveSecurity

Jamf emits mystery security fix for Pro macOS, iOS wrangler, keeps admins in dark by censoring chatter

Type: Vulnerability. Xpdf is prone to a buffer-underflow vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability; fixes are available.

Type: Vulnerability. OnApp is prone to a remote command-execution vulnerability; fixes are available.

Type: Vulnerability. Dell EMC ECS is prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. Google Android is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Ghidra is prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Python is prone to multiple cross-site scripting vulnerabilities; fixes are available.

Ransomware Attacks Leave U.S. Hospitals Turning Away Patients
Hackers Turn to OpenDocument Format to Avoid AV Detection

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

vBulletin zero-day KOs Comodo user forums – that’s 245,000 accounts at risk of compromise
Leaky database exposes tax records of 20 million Russians
Google Play Malicious Apps Racked Up 335M+ Installs in September

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that solves 5 vulnerabilities and has three fixes is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

If your org hasn’t had a security incident in the last year: Good for you, you’re in the minority

An update that fixes 6 vulnerabilities is now available.

Cyber Security Awareness Month starts today!

October is upon us, reminding us to make choices every day that will scare cybersecurity threats away The post Cyber Security Awareness Month starts today! appeared first on WeLiveSecurity

HMRC ‘disciplined’ almost 100 employees for computer misuse over 24 months

Reading Time: ~ 3 min. “Antivirus programs use techniques to stop viruses that are very “virus-like” in and of themselves, and in most cases if you try to run two antivirus programs, or full security suites, each believes the other is malicious and they then engage in a battle to the death (of system usability, […]

Malvertising Attack Hijacks 1B+ Sessions With Webkit Exploit

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Brighton perv cops community service for ‘hacking’ women’s Facebook accounts

An update for httpd24-httpd and httpd24-nghttp2 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat JBoss Core Services Pack Apache Server 2.4.29 Service Pack 3 packages for RHEL 6, RHEL 7, Microsoft Windows and Oracle Solaris are now available. Red Hat Product Security has rated this release as having a security impact

This is the Six-Month notification for the retirement of Red Hat Enterprise Linux 5.9 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 5.9.

Dive deep into the world of cyber attackers at the CyberThreat Summit

Risk Level: Very Low. Type: Trojan.

It’s been a couple of days, so Apple releases yet another iOS update
Stop us if you’ve heard this one before: Yet another critical flaw threatens Exim servers
Holy smokes! Ex-IT admin gets two years prison for trashing Army chaplains’ servers

security update

Type: Vulnerability. Google Android is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Dell EMC Integrated Data Protection Appliance is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Google Android is prone to multiple local privilege-escalation vulnerabilities; fixes are available.

Type: Vulnerability. Exim is prone to a heap-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Cloud Foundry UAA is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Google Android is prone to multiple local privilege-escalation vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Flash Player is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Apple iOS is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Apple Safari is prone to is prone to multiple security vulnerabilities; fixes are available.

Thousands of Windows PCs infected by Nodersok/Divergent fileless malware
New Bug Found in NSA’s Ghidra Tool
Dark web data center in former NATO bunker seized for hosting child porn
Senate Passes Bill Aimed At Combating Ransomware Attacks
600 armed German cops storm Cyberbunker hosting biz on illegal darknet market claims
Critical Exim Flaw Opens Servers to Remote Code Execution
Thanks-thanks to TalkTalk teen hacker: UK cops’ first auction of ill-gotten Bitcoin nets £240k
Hack strikes Words with Friends and Draw Something, amid claims 218 million players’ details breached
Microsoft changes encryption, another D-Link bug, phishing dangers, and more

An update that fixes 24 vulnerabilities is now available.

An update that fixes 24 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Two vulnerabilities were found in the WPA protocol implementation found in wpa_supplication (station) and hostapd (access point). CVE-2019-13377

Security fix for CVE-2019-14822

– double free due to subsequent call of realloc() (CVE-2019-5481) – fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)

New upstream version 1.12.8. Fixes second Denial of Service attack: https://www.redhat.com/archives/libguestfs/2019-September/msg00272.html

security update

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

New upstream version 1.14.2. Fixes second Denial of Service attack: https://www.redhat.com/archives/libguestfs/2019-September/msg00272.html

Update to latest upstream version.

An open redirect, that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control,

Hackers used fake job website to scam jobless US veterans

security update

security update

Got a pre-A12 iPhone? Love jailbreaks? Happy Friday! ‘Unpatchable tethered Boot ROM exploit’ released
Hacker publishes ‘unpatchable’ permanent jailbreak for iPhone 4s to iPhone X
What’s that smell? Perfume merchant senses the scent of a digital burglary
iOS Exploit ‘Checkm8’ Could Allow Permanent iPhone Jailbreaks
Masad Spyware Uses Telegram Bots for Command-and-Control

Risk Level: Very Low. Type: Trojan.

Dunkin’ Donuts Gets Hit with Lawsuit Over 2015 Attack
Arcane Stealer V Takes Aim at the Low End of the Dark Web
Microsoft Blacklists Dozens of New File Extensions in Outlook

An update that solves one vulnerability and has one errata is now available.

News Wrap: GandCrab Operators Resurface, Utilities Firms Hit By LookBack Malware

Reading Time: ~ 2 min. Copyright Phishing Campaign Hits Instagram Many Instagram accounts were recently compromised after receiving a notice that their accounts would be suspended for copyright infringement if they didn’t complete an objection form within 24 hours. By setting a timeframe, the attackers are hoping that flustered victims would quickly begin entering account […]

Thousands of PCs Affected by Nodersok/Divergent Malware