Menu

Category Archives: Security

Articles about security

198 Million Car-Buyer Records Exposed Online for All to See
Intel CPUs Vulnerable to Sensitive Data Leakage in NetCAT Attack
Toyota parts supplier loses $37 million in email scam
Lemonade is changing the way we insure our homes
Operation reWired: 281 suspected email scammers arrested around the world
CISO/CIO: Get an iPad and Apple Watch with an App Monitoring your Security 24/7
Strangest Phishing Lures of 2019: From Divorce Papers to Real Estate Decoys
Feds Indict 281 People for Involvement in Massive E-Mail Fraud Scheme
How Can SEO Help Increase Website Security?
Selfies for kids – A guide for parents

Are you – and especially your children – aware of the risks that may come with sharing selfies? The post Selfies for kids – A guide for parents appeared first on WeLiveSecurity

D-Link, Comba network gear leave passwords open for potentially whole world to see

An update for rh-dotnet21-dotnet and rh-dotnet22-dotnet is now available for .NET Core on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for dotnet is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that solves three vulnerabilities and has 9 fixes is now available.

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the pki-deps:10.6 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for poppler is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for libwmf is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

USN 4115-1 introduced a regression in the Linux kernel.

An update for the openshift and atomic-enterprise-service-catalog packages is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Required: Massive email fraud bust. Tired: Cops who did the paperwork. Expired: 281 suspected con men’s freedom
It’s 2019, and Windows PCs can be pwned via a shortcut file, a webpage, an evil RDP server…

security update

security update

security update

security update

Insider Threats Are Rising – But They Shouldn’t Be
Rolling in DoH: Chrome 78 to experiment with DNS-over-HTTPS – hot on the heels of Firefox
Microsoft Addresses Two Zero-Days Under Active Attack
ThreatList: Amidst Data Breaches, Account Creation Fraud Soars in 2019
Adobe Fixes Critical Flash Player Code Execution Flaws
The NetCAT is out of the bag: Intel chipset exploited to sniff SSH passwords as they’re typed over the network
600,000 GPS child trackers found vulnerable to location tracking

An update that fixes 24 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

U.S. Manufacturer Most Recent Target of LokiBot Malspam Campaign

An update is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Vulnerabilities in D-Link, Comba Routers Can Leak Credentials

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in Python.

An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for polkit is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Mozilla Firefox to begin slow rollout of DNS-over-HTTPS by default at the end of the month
Equifax is going to make you work for that 125 bucks it owes each of you: Biz sneaks out Friday night rule change
That Telegram feature that let you delete your private messages on recipients’ phones? It didn’t work properly
PsiXBot Adds PornModule, Google DNS Service to Its Arsenal
Stealth Falcon Targets Middle East with Windows BITS Feature

It was discovered that the code fixes for LibreOffice to address CVE-2019-9852 were not complete. Additional information can be found at https://www.libreoffice.org/about-us/security/advisories/CVE-2019-9854/

Telnet Backdoor Opens More Than 1M IoT Radios to Hijack
Wikipedia, World of Warcraft Downed By Weekend DDoS Attacks
Wikipedia and World of Warcraft Classic targeted by DDoS attacks

An update that fixes 8 vulnerabilities is now available.

Critical Exim Flaw Opens Millions of Servers to Takeover
What a bunch of DoSers: Wikipedia says it was walloped by ‘bad faith’ actors over weekend
Cloud security: Inside the shared responsibility model

Memcached could be made to expose sensitive information if it received a specially crafted UNIX socket.

Apple Claims Google is Spreading FUD Over Patched iPhone Bugs
Symantec shares up as private equity suitors sniff consumer tentacle

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Hackers who hit Texas with ransomware attack demanded $2.5 million, got nothing
ESET discovered an undocumented backdoor used by the infamous Stealth Falcon group

ESET researchers discovered a backdoor linked to malware used by the Stealth Falcon group, an operator of targeted spyware attacks against journalists, activists and dissidents in the Middle East The post ESET discovered an undocumented backdoor used by the infamous Stealth Falcon group appeared first on WeLiveSecurity

Apple and Google trade barbs over bugs, digital lothario arrested and Bluekeep gets busy

An update for go-toolset-1.11 and go-toolset-1.11-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Update to 2.0.16

Update to 2.0.16

Chromium update to 76.0.3809.132.

Wikipedia suffers DDoS attack causing worldwide service disruption

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An authentication bypass was discovered in D-Bus.

Multiple vulnerabilities have been found in Simple DirectMedia Layer, the worst of which could result in the arbitrary execution of code.

Updated dovecot packages fix security vulnerability: IMAP protocol parser does not properly handle NUL byte when scanning data in quoted strings, leading to out of bounds heap memory writes.

Updated tomcat packages fix security vulnerabilities: The HTTP/2 implementation accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for

This release fixes a heap buffer over-read in BlitNtoN() function when processing an invalid BMP image. It also updates a URL in the RPM metadata.

**Version 1.3.10** – Managesieve: Fix so “Create filter” option does not show up when Filters menu is disabled (#6723) – Enigma: Fix bug where revoked users/keys were not greyed out in key info – Enigma: Fix error message when trying to encrypt with a revoked key (#6607) – Enigma: Fix “decryption oracle” bug [CVE-2019-10740] (#6638) […]

Security fix for CVE-2019-15043

Resolves: rhbz#1609774 nsd-4.2.2 is available

Fixes for CVE-2019-6472, CVE-2019-6473 and CVE-2019-6474

This release fixes a heap buffer over-read in BlitNtoN() function when processing an invalid BMP image. It also updates a URL in the RPM metadata.

Security fix for CVE-2019-15043

An update that fixes one vulnerability is now available.

It was discovered that various procedures in Ghostscript, the GPL PostScript/PDF interpreter, do not properly restrict privileged calls, which could result in bypass of file system restrictions of the dSAFER sandbox.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

It was discovered that there was a stack-based buffer over-read in memcached, the in-memory object caching system. For Debian 8 “Jessie”, this issue has been fixed in memcached version

Multiple vulnerabilities have been found in Exim, the worst of which allows remote attackers to execute arbitrary code.

Week in security

This week, we present an introduction to the MITRE ATT&CK framework, the review of the mobile threats and vulnerabilities detected for mobile during the first half of 2019, and Firefox 69 new features. The post Week in security appeared first on WeLiveSecurity

security update

ThreatList: Police Use of Facial Recognition is Just Fine, Say Most Americans

An update that fixes one vulnerability is now available.