Menu

Category Archives: Security

Articles about security

An update that solves two vulnerabilities and has two fixes is now available.

Pupil mental health monitor promises app rewrite after hardcoded login creds discovered

An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS. Red Hat Product Security has rated this update as having a security impact

DoorDash doesn’t just pick up your food orders, it delivers your data to hackers, too
Accept certain inalienable truths: Prices will rise, politicians will philander… And US voting machines will be physically insecure
Tune in next month: Learn all about the hackers staring down Singapore, Australia

Security fix for CVE-2019-1010228

An update for kibana is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

DoorDash Data Breach Impacts Personal Data of Almost 5M Users

Security fix for CVE-2019-1010228

Dunkin do-nots: Deep-fried cake maker did not warn its sugar addicts that crooks raided web accounts, says NY AG

security update

An update for golang-github-openshift-oauth-proxy-container is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for logging-elasticsearch5-container is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Reading Time: ~ 3 min. You have probably seen or heard news reports about STEM education (Science, Technology, Engineering, and Math), and how important STEM jobs are for the economy; or maybe you’ve heard reports on schools that are making strides to improve their STEM programs for kids. It’s important for parents with school-aged children to fully understand what a STEM education is and why access to […]

Rash of Exploits Targets Critical vBulletin RCE Bug

Risk Level: Very Low. Type: Trojan.

5G and IoT: How to Approach the Security Implications
Cisco Patches 13 High-Severity Router and Switch Bugs
Hearing aid manufacturer hit by cyber attack slashes profits by $95 million
Phish Uses Google’s URL Decoding to Swim Past Defenses
Vimeo Slapped With Lawsuit Over Biometrics Privacy Policy

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Who is reading your CEO’s email? And how to stop it
WordPress sites hacked through defunct Rich Reviews plugin

An update for gRPC, included in sriov-network-device-plugin-container, is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

CISOs: Support Vendor Security Ops for Best Cloud Results
Four words from Cisco to strike fear into the most hardened techies: Guest account as root
Now Uncle Sam would like a word with Brit teen TalkTalk hacker about a huge crypto-coin heist
Cyber-Risk Business Cases: Using Economic Impact to Justify TIG Investment
Chrome Bug, Not Avid Software, Causes Damage to MacOS File Systems
AI Leaps into Banking: When to know You Can Trust It

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2836

TalkTalk still struggles to shut down legacy email addresses on request

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

A command injection vulnerability in Nokogiri allows commands to be executed in a subprocess by Ruby’s `Kernel.open` method. For Debian 8 “Jessie”, this problem has been fixed in version

US senators green-light recruitment of crack infosec teams, both public and private
Smashing Security #147: Don’t Snapchat and drive
Magecart Group Targets Routers Behind Public Wi-Fi Networks
How to Secure a Website by Monitoring DNS Records
Confused why Trump fingered CrowdStrike in that Ukraine call? You’re not the only one…

Update to current release. Python3 compatible Installable with f31+ —- Update to 2.5.0 (pre-release)

Two security vulnerabilities were found in OpenSSL, the Secure Sockets Layer toolkit. CVE-2019-1547

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Firefox could be made to hijack the mouse pointer it if opened a malicious website.

‘Narrator’ Windows Utility Trojanized to Gain Full System Control

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Unpatched Bug Under Active Attack Threatens WordPress Sites with XSS
Hacker House shoved under UK Parliament’s spotlight following Boris Johnson funding allegs
Cybercrooks Target U.S. Veterans with Fake Hiring Website

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

Microsoft rushes out patch for Internet Explorer zero‑day

There is no word on which threat actor is abusing the severe vulnerability for attacks The post Microsoft rushes out patch for Internet Explorer zero‑day appeared first on WeLiveSecurity

What You Need to Know About Next Gen EDR
Teenage TalkTalk hacker accused of $800,000 cryptocurrency theft in the United States
Apple to Patch Bug Granting Full Access to 3rd-Party Keyboards

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

File Roller could be made to overwrite sensitive files if it received a specially crafted TAR file.

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that solves 7 vulnerabilities and has one errata is now available.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Hot patches for ColdFusion: Adobe drops trio of fixes for three serious flaws
Google takes sole stand on privacy, rejects new rules for fear of ‘authoritarian’ review

It was discovered that SPIP, a website engine for publishing, would allow unauthenticated users to modify published content and write to the database, perform cross-site request forgeries, and enumerate registered users.

We finally got one! Russian ‘fesses up to cracking bank servers, netting big bucks

security update

security update

This vBulletin vBug is vBad: Zero-day exploit lets miscreants hijack vulnerable web forums
GandCrab Operators Resurface with REvile Malware
An illegal prostitution ring took Kazakhstan offline
Adobe Unscheduled Update Fixes Critical ColdFusion Flaws
DoH! Mozilla assures UK minister that DNS-over-HTTPS won’t be default in Firefox for Britons
CafePress finally warns customers that it was hacked
Can you code a way to foil online terrorist vids? The Home Office might just have £600K for you
Dtrack RAT is Behind Virulent ATM-Espionage Campaign
Zebrocy Retools for New Political Attacks
Do companies take cybersecurity seriously enough?

Many companies are ranking cybersecurity as a top 5 priority but their actions do not measure up to the claim, a survey finds The post Do companies take cybersecurity seriously enough? appeared first on WeLiveSecurity

Malicious Ad Blockers for Chrome Caught in Ad Fraud Scheme
Why do cloud leaks keep happening? Because no one has a clue how their instances are configured
No summer vacations for Zebrocy

ESET researchers describe the latest components used in a recent Sednit campaign The post No summer vacations for Zebrocy appeared first on WeLiveSecurity

World of Warcraft’s suspected DDoS attacker has been arrested
How to Protect Your Online Store from Cyber Threats
Nine words to ruin your Monday: Emergency Internet Explorer patch amid in-the-wild attacks
4 Helpful Tips to Make Your WiFi Fast and Efficient
How to Increase Your Business’s Online Brand Awareness
Microsoft Internet Explorer Zero-Day Flaw Addressed in Out-of-Band Security Update

Type: Vulnerability. Microsoft .NET Core is prone to a remote denial-of-service vulnerability; fixes are available.

The Benefits of Using a VPN at Home
More U.S. Utility Firms Targeted in Evolving LookBack Spearphishing Campaign
Several months after the fact, CafePress finally acknowledges huge data theft to its customers
I’m keynoting about cybercrime at the CRN MSP conference in London next week