Menu

Category Archives: Security

Articles about security

Scotiabank slammed for ‘muppet-grade security’ after internal source code and credentials spill onto open internet
Every Ecuadorian has been compromised in massive data breach
GitHub gobbles biz used by NASA, Google, etc to search code for bugs and security holes in Mars rovers, apps…
Uni sysadmins, don’t relax. Cybercrooks are still after your crown jewels, warns NCSC
Rethinking Responsibilities and Remedies in Social-Engineering Attacks

Risk Level: Very Low. Type: Trojan.

Remote access flaws found in popular routers, NAS devices

In almost all tested units, the researchers achieved their goal of obtaining remote root-level access The post Remote access flaws found in popular routers, NAS devices appeared first on WeLiveSecurity

Analytics exec nicked as Ecuador tries to rush through privacy laws after massive data leak
Emotet Returns from Summer Vacation, Ramps Up Stolen Email Tactic

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Edward Snowden Sued by U.S. Over New Memoir
CookieMiner malware targets Macs, steals passwords and SMS messages, mines for cryptocurrency
Popular Ad blockers caught ad frauding millions of Chrome users
New! RFP Template for Selecting EDR/EPP and APT Security
Massive Gaming DDoS Exploits Widespread Technology
Malware Moves: The Rise of LookBack – And Return of Emotet

Several security issues were fixed in Tomcat 9.

How to get away with hacking a US satellite

An update that fixes two vulnerabilities is now available.

This update upgrades Thunderbird to version 60.9.0. * Mozilla: Covert Content Attack on S/MIME encryption using a crafted multipart/alternative message (CVE-2019-11739) * Mozilla: Memory safety bugs fixed in Firefox 69, Firefox ESR 68.1, and Firefox ESR 60.9 (CVE-2019-11740) * Mozilla: Same-origin policy violation with SVG filters and canvas to steal cross-origin images (CVE-2019-11742) * Mo […]

wpa_supplicant could be made to be disconnected and require reconnection to the network if it received a specially crafted management frame.

Multiple security issues have been found in Thunderbird which could potentially result in the execution of arbitrary code, cross-site scripting, information disclosure and a covert content attack on S/MIME encryption using a crafted multipart/alternative message.

How to break out of a hypervisor: Abuse Qemu-KVM on-Linux pre-5.3 – or VMware with an AMD driver
How to Ship Your Ecommerce Goods At Lightning Speed

wpa_supplicant could be made to be disconnected and require reconnection to the network if it received a specially crafted management frame.

Your ugly mug may be scanned yet again – but at least you’ll be able to board faster at Gatwick

An update that solves three vulnerabilities and has two fixes is now available.

Revealed: The 25 most dangerous software bug types – mem corruption, so hot right now

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Risk Level: Very Low. Type: Trojan.

Panda Threat Group Mines for Monero With Updated Payload, Targets

– double free due to subsequent call of realloc() (CVE-2019-5481) – fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)

security update

US government sues ex-IT guy for breaking his NDA (Yes, we mean Edward Snowden)
Seriously, this sh!t again? 24m medical records, 700m+ scan pics casually left online
Vulns out of the box: 12 in 13 small biz network devices terribly insecure by default – research
New Linux malware is evading detection to mine cryptocurrency

Risk Level: Very Low. Type: Trojan, Virus, Worm.

AMD Radeon Graphics Cards Open VMware Workstations to Attack

Reading Time: ~ 3 min. An unfortunate reality of all smart devices is that, the smarter they get, and the more integrated into our lives they become, the more devastating a security breach can be. Smart cars are no exception. On the contrary, they come with their own specific set of vulnerabilities. Following high-profile incidents […]

HP printer small print says kit phones home data on whatever you print – and then some
Cisco Extends Patch for IPv6 DoS Vulnerability
Google Calendar Settings Gaffes Exposes Users’ Meetings, Company Details
Nearly all of Ecuador’s citizens caught up in data leak

The humongous collection of extensive personal details about millions of people could be a gold mine for scam artists The post Nearly all of Ecuador’s citizens caught up in data leak appeared first on WeLiveSecurity

Medical images and details of 24.3 million patients left exposed on the internet

An update that fixes one vulnerability is now available.

New Threat Actor Fraudulently Buys Digital Certificates to Spread Malware
UK Home Office web form snafu allows you to both agree and disagree – strongly – all at once
LastPass Fixes Bug That Leaks Credentials

An update for rh-nginx114-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for qpid-proton is now available for Satellite Tools 6.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

USN-4113-1 introduced a regression in Apache.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

An update for qpid-proton is now available for Red Hat Satellite 6.3 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for qpid-proton is now available for Red Hat Satellite 6.4 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

– Update to 0.12.0b – Clean up SPEC – Remove patches – Use sed for make Phonon default – Use KF5 instead of KDE4 – Renew URLs – CVE-2019-9133

– Update to 0.12.0b – Clean up SPEC – Remove patches – Use sed for make Phonon default – Use KF5 instead of KDE4 – Renew URLs – CVE-2019-9133

An update for qpid-proton is now available for Red Hat Satellite 6.5 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

security update

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

How much pass could LastPass pass if LastPass passed last pass? Login-leaking security hole fixed
Marketing Analytics Company Leaks Deep Profiles of Entire Ecuador Population
Malware called InnfiRAT is creeping into cryptocurrency wallets
Asus, Lenovo and Other Routers Riddled with Remotely Exploitable Bugs
Just as Ecuador thought it had seen the back of leaks, over 20m citizen records are exposed
U.S. Sanctions North Korean Group Behind WannaCry, Sony Hacks
Australia didn’t blame China for parliament hack in case it upset trade relations – report

Reading Time: ~ 3 min. Do you remember the last time you’ve interacted with a brand, political cause, or fundraising campaign via text message? Have you noticed these communications occurring more frequently as of late? It’s no accident. Whereas marketers and communications professionals can’t count on email opens or users accepting push notifications from apps, […]

An update that fixes one vulnerability is now available.

IBus would allow local users to capture key strokes of other locally logged in users.

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Exim could be made to run programs as an administrator if it received specially crafted network traffic.

Several vulnerabilities were discovered in Ansible, a configuration management, deployment, and task execution system.

An update that fixes one vulnerability is now available.

You all know why you should encrypt your cloud data – now learn where and how…

Wireshark could be made to crash if it received specially crafted network traffic or input files.

rebase to 0.16 (bz #1741605)

Update to latest upstream version.

rebase to 0.16 (bz #1741605)

Update to 8.05 release (CVE-2019-16239)

BIRD 2.0.6 (2019-09-10) * BGP: Optional Adj-RIB-Out * BGP: Extended optional parameters length * Filter: Sets and set expressions in path masks * Several important bugfixes

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Updated wireshark packages fix security vulnerability: The Gryphon dissector could go into an infinite loop. For other fixes in this update, see the referenced releasenotes.

Updated webkit2 packages fix security vulnerabilities: Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling (CVE-2019-8644).

Updated openldap packages fix security vulnerabilities: It was discovered that OpenLDAP incorrectly handled rootDN delegation. A database administrator could use this issue to request authorization as an identity from another database, contrary to expectations (CVE-2019-13057).

Updated mediawiki packages fix security vulnerabilities: Potential XSS in jQuery (CVE-2019-11358). An account can be logged out without using a token (CSRF) (CVE-2019-12466).

Updated kconfig packages fix security vulnerability: Dominik Penner discovered that KConfig supported a feature to define shell command execution in .desktop files. If a user is provided with a malformed .desktop file (e.g. if it’s embedded into a downloaded archive and it gets

Multiple vulnerabilities have been discovered in faad2, the Freeware Advanced Audio Coder. These vulnerabilities might allow remote attackers to cause denial-of-service, or potentially execute arbitrary code if crafted MPEG AAC files are processed.

This update provides nodejs v6.17.1 fixing atleast the following security issues: The c-ares function ares_parse_naptr_reply(), which is used for parsing NAPTR responses, could be triggered to read memory outside of the given

The updated packages fix security vulnerabilities: The JPXStream::init function in Poppler 0.78.0 and earlier doesn’t check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap,

Updated thunderbird packages fix security vulnerabilities: Covert Content Attack on S/MIME encryption using a crafted multipart/ alternative message (CVE-2019-11739).

New Amazon phishing scam stealing credit card data