Menu

Category Archives: Security

Articles about security

It was discovered that there was a stack-based buffer over-read in memcached, the in-memory object caching system. For Debian 8 “Jessie”, this issue has been fixed in memcached version

Multiple vulnerabilities have been found in Exim, the worst of which allows remote attackers to execute arbitrary code.

Week in security

This week, we present an introduction to the MITRE ATT&CK framework, the review of the mobile threats and vulnerabilities detected for mobile during the first half of 2019, and Firefox 69 new features. The post Week in security appeared first on WeLiveSecurity

security update

ThreatList: Police Use of Facial Recognition is Just Fine, Say Most Americans

An update that fixes one vulnerability is now available.

China’s APT3 Pilfers Cyberweapons from the NSA
Back-to-School Scams Target Students with Library-Themed Emails
News Wrap: Deepfake CEO Voice Scam, Facebook Phone Data Exposed

Exim could be made to run programs as an administrator if it received specially crafted network traffic.

Hackers can break into Android devices by sending a text
Semi‑annual balance of mobile security 2019

Malware detections for iOS increased, as did the number of vulnerabilities detected in this operating system, while in the case of Android, the number of reported vulnerabilities decreased, although the number of highly critical bugs reported increased. The post Semi‑annual balance of mobile security 2019 appeared first on WeLiveSecurity

Multiple vulnerabilities have been found in WebkitGTK+, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in Apache, the worst of which could result in a Denial of Service condition.

A buffer overflow in Pango might allow an attacker to execute arbitrary code.

Multiple vulnerabilities have been found in VLC, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in Perl, the worst of which could result in the arbitrary execution of code.

Reading Time: ~ 2 min. Deepfake BEC Scam  A new variant of the well-known BEC scam has implemented a feature that has yet to be used in an email scam: voice fraud. Using an extremely accurate deepfake voice of a company’s CEO, scammers were able to successfully convince another company to wire $250,000 with the promise of a quick return. Unfortunately, that transfer was […]

Facebook, Microsoft Challenge Industry to Detect, Prevent ‘Deepfakes’

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

It was discovered that there was a heap-based buffer overread vulnerability in expat, an XML parsing library. A specially-crafted XML input could fool the parser into changing

7 Tips to Increase Your WordPress Security
Exim marks the spot… of remote code execution: Patch due out today for ‘give me root’ flaw in mail server
Firefox 69: Third‑Party Tracking Cookies and Cryptomining Now Blocked by Default

Firefox new Enhanced Tracking Protection (ETP) feature launched to all users of the browser to offer better privacy and protection from cryptojacjing. The post Firefox 69: Third‑Party Tracking Cookies and Cryptomining Now Blocked by Default appeared first on WeLiveSecurity

* Security fix for CVE-2019-14267 * Security fix for CVE-2019-14934

Update to 1.8.6 release which fixes a bug in 1.8.5. 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling.

Update LXC to version 3.0.4. The release announcement can be found [here](https://discuss.linuxcontainers.org/t/lxc-3-0-4-has-been-released/5080).

Massachusetts city tells ransomware scumbags to RYUK off, our IT staff will handle this easily

security update

Too bad, so sad, exploit devs: Google patches possibly several million dollars’ worth of security flaws in Android
Insights and Tips on Video Compression using VLC
Zerodium to pay up to $2.5 million for reporting 0-day Android exploits
Joker Spyware Found in 24 Google Play Apps
FunkyBot Malware Intercepts Android Texts, 2FA Codes

security update

Type: Vulnerability. Microsoft ASP.NET Core and .NET Framework are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core and .NET Framework are prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core and .NET Framework are prone to a remote denial-of-service vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has 19 fixes is now available.

Unsecured database leaks phone numbers of 419 million Facebook users
$5.3M Ransomware Demand: Massachusetts City Says No Thanks

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, bypass of the same-origin policy, sandbox escape, information disclosure or denial of service.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

MSP or System Integrator? Add Incident Response to Your Portfolio at No Cost
Hundreds of millions of Facebook users’ phone numbers found lying around on the internet
Leaky Server Exposes 419M Phone Numbers of Facebook Users

An update that fixes two vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Today’s data whoopsie is brought to you by CircleCI: Source safe, but look out for phishers

An update that fixes 12 vulnerabilities is now available.

An update that solves three vulnerabilities and has one errata is now available.

Smashing Security #144: Google helps the FBI, Twitter Jack’s hijack, and car data woes

npm/fstream could be made to overwrite files.

An update that solves 12 vulnerabilities and has 19 fixes is now available.

Newb admits he ran Satori botnet that turned thousands of hacked devices into a 100Gbps+ DDoS-for-hire cannon
Twitter disables tweeting via SMS (temporarily at least), in wake of Jack Dorsey account hijack
Android Zero-Day Bug Opens Door to Privilege Escalation Attack, Researchers Warn
Brave accuses Google of trampling Europe’s GDPR with stealthy netizen-stalking adverts

security update

Let’s recap reCAPTCHA gotcha: Our cunning AI can defeat Google’s anti-bot tech, say uni boffins
Critical Bugs Open Food-Safety Systems to Remote Attacks
Facebook allows users to opt out of facial recognition in photos
Blindly accepting network update texts could have pwned your mobe, say researchers
BRATA Android RAT Steals Banking Info in Real Time
Half of Android Handsets Susceptible to Clever SMS Phishing Attack
CEO ‘Deep Fake’ Swindles Company Out of $243K
Android Zero-Days Now Worth More Than iPhone Exploits
CEO voice deepfake blamed for scam that stole $243,000
Chinese tech firm Huawei says it was hacked by the United States

The package jenkins before version 2.192-1 is vulnerable to multiple issues including cross-site request forgery and cross-site scripting.

The package grafana before version 6.3.4-1 is vulnerable to denial of service.

Red flag: Home Office inks £45m border tech extension with IBM

An update that solves three vulnerabilities and has two fixes is now available.

Several newly-referenced issues have been fixed in the FreeType 2 font engine.

Earn $2.5 million if you find a remote zero-day exploit for Android

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Bus pass or bus ass? Hackers peeved about public transport claim to have reverse engineered ticket app for free rides

An update for openstack-nova is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Alf-Andre Walla discovered a remotely triggerable assert in the Varnish web accelerator; sending a malformed HTTP request could result in denial of service.

Fancy buying a compact and bijou cardboard box home in a San Francisco alley? This $2.5m Android bounty will get you nearly there

The 5.2.11 stable kernel update contains a number of important fixes across the tree. —- The 5.2.10 stable kernel update contains a number of important fixes across the tree. —- The 5.2.9 stable kernel update contains a number of important fixes across the tree. —- The 5.2.8 stable kernel update contains a number of important […]

The 5.2.11 stable kernel update contains a number of important fixes across the tree. —- The 5.2.10 stable kernel update contains a number of important fixes across the tree. —- The 5.2.9 stable kernel update contains a number of important fixes across the tree. —- The 5.2.8 stable kernel update contains a number of important […]

The 5.2.11 stable kernel update contains a number of important fixes across the tree. —- The 5.2.10 stable kernel update contains a number of important fixes across the tree. —- The 5.2.9 stable kernel update contains a number of important fixes across the tree. —- The 5.2.8 stable kernel update contains a number of important […]

security update

Facebook Drops Default Facial Recognition Tag Suggestions
Hackers steal 560,000 user accounts in XKCD forum breach

security update

IoT Security Challenges in a 5G Era: Expert Advice
Firefox 69 Release Kills Default Tracking Cookies, Flash Support
How to Get a Handle on Patch Management