Menu

Category Archives: Security

Articles about security

Update to 2.6.7

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Google Targets Data-Abusing Apps with Bug Bounty Launch
Which Linux Distros Are Most Focused On Privacy?
Venmo’s Public Transactions Policy Stirs Privacy Concerns
Ex-Amazon worker – suspected of hacking Capital One – faces charges of breaching 30 other companies to mine cryptocurrency

The package libnghttp2 before version 1.39.2-1 is vulnerable to denial of service.

The package go-pie before version 2:1.12.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.

The package go before version 2:1.12.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.

The package gettext before version 0.20.1-1 is vulnerable to arbitrary code execution.

Critical Cisco VM Bug Allows Remote Takeover of Routers
Innovation on the Dark Web: How Bad Actors Are Keeping Pace
Smashing Security #143: Hacking from outer space, Ukrainian cryptomining, and deepfaked Canadians

An update for pango is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes two vulnerabilities is now available.

Ceph could be made to crash if it received specially crafted network traffic.

Today’s Resident Evil: Ransomware crooks think local, not global, prey on schools, towns, libraries, courts, cities…
Ways to Help Keep Your Business Systems Secure
Elderly China Chopper Tool Still Going Strong in Multiple Campaigns
Are US border cops secretly secreting GPS trackers on vehicles without a warrant? EFF lawyers want to know

Ghostscript could be made to access arbitrary files if it opened a specially crafted file.

Two security vulnerabilities were found in the Apache HTTP server. CVE-2019-10092

Come on, hackers, do your worst ‒ Facebook opens Portal gizmo to Pwn2Own exploit fest
TrickBot Targets Verizon, T-Mobile, Sprint Users to Siphon PINs

USN-4110-1 introduced a regression in Dovecot.

Popular CamScanner app for Android infected with nasty malware
Apple Updates Privacy Policies After Siri Audio Recording Backlash
Google Squashes High-Severity Blink Browser Engine Flaw
Defense Takeaways from Three Adversary Playbooks
Dangerous Cryptomining Worm Racks Up 850K Infections, Self-Destructs
Magecart Hits 80 Major eCommerce Sites in Card-Skimming Bonanza

An update for jenkins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for pango is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat Ceph Storage 3.3 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that contains security fixes can now be installed.

An update that fixes 9 vulnerabilities is now available.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

NASA astronaut accused of accessing ex-wife’s bank account from space

An update that solves 5 vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Time to spin the wheel of pwnage! This week, malware can infect your…. Android set-top box!

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Dixons hits back at McAfee’s £30m antivirus sueball: Your AV didn’t work on Windows 10S
Android PDF app with just 100m downloads caught sneaking malware into mobes

security update

Employers Beware: Microsoft Word ‘Resume’ Phish Delivers Quasar RAT

An update that solves 7 vulnerabilities and has three fixes is now available.

Several vulnerabilities have been found in the Apache HTTPD server. CVE-2019-9517

ghostscript: -dSAFER escape via .buildfont1 (701394) (CVE-2019-10216) SL7 x86_64 ghostscript-9.25-2.el7_7.1.i686.rpm ghostscript-9.25-2.el7_7.1.x86_64.rpm ghostscript-cups-9.25-2.el7_7.1.x86_64.rpm ghostscript-debuginfo-9.25-2.el7_7.1.i686.rpm ghostscript-debuginfo-9.25-2.el7_7.1.x86_64.rpm libgs-9.25-2.el7_7.1.i686.rpm libgs-9.25-2.el7_7.1.x86_64.rpm ghostsc [More…]

zziplib: Bus error caused by loading of a misaligned address inzzip/zip.c (CVE-2018-6541) * zziplib: Memory leak triggered in the function __zzip_parse_root_directory in zip.c (CVE-2018-16548) SL7 x86_64 zziplib-0.13.62-11.el7.i686.rpm zziplib-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62-11.el7.x86_64.rpm zziplib-utils-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62- [More…]

opensc: Buffer overflows handling responses from Muscle Cards in card- muscle.c:muscle_list_files() (CVE-2018-16391) * opensc: Buffer overflows handling responses from TCOS Cards in card- tcos.c:tcos_select_file() (CVE-2018-16392) * opensc: Buffer overflows handling responses from Gemsafe V1 Smartcards in pkcs15-gemsafeV1.c:gemsafe_get_cert_len() (CVE-2018-16393) * opensc: Buffer overflow h [More…]

gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password (CVE-2019-3827) SL7 x86_64 gvfs-1.36.2-3.el7.i686.rpm gvfs-smb-1.36.2-3.el7.x86_64.rpm gvfs-afp-1.36.2-3.el7.x86_64.rpm gvfs-mtp-1.36.2-3.el7.x86_64.rpm gvfs-devel-1.36.2-3.el7.x86_64.rpm gvfs-client-1.36.2-3.el7.x86_64.rpm gvfs [More…]

Malicious App on Google Play Tallies 100 Million Downloads
Imperva Firewall Breach Exposes Customer API Keys, SSL Certificates
We will hack back if you tamper with our shiz, NATO declares to world’s black hats
Why is learning Python important in Data Science?
Oil and Gas Firms Targeted By New LYCEUM Threat Group

Security fix for CVE-2019-13509

An update that fixes three vulnerabilities is now available.

Yes, TfL asked people to write down their Oyster passwords – but don’t worry, they didn’t inhale

An update for ruby is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Can’t bear to part with that well-worn copy of Windows 7? Microsoft might let you keep it updated an extra year
Breaking news: Apple un-breaks break on jailbreak break

security update

Fraught ‘naut who sought consort’s report says: I was up to naught, I will thwart fault tort

An update that contains security fixes can now be installed.

New kernel packages are available for Slackware 14.2 to fix a security issue.

Apple Fixes iOS Flaw That Opened iPhones to Jailbreaks

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

IRS Impersonation Attacks Spread Malware Nationwide
ThreatList: Half of All Social Media Logins Are Fraud
Hostinger Data Breach: 14M Customer Passwords, Personal Data at Risk
Company that was laughed off-stage sues Black Hat

Multiple vulnerabilities have been found in xymon, the network monitoring application. Remote attackers might leverage these vulnerabilities in the CGI parsing code (including buffer overflows and XSS) to cause denial of service, or any other unspecified impact.

Hacktivist skids nip at Mounties’ ankles, Emotet ransomware rides again, and more
Biz forked out $115k to tout ‘Time AI’ crypto at Black Hat. Now it sues organizers because hackers heckled it
Hostinger resets passwords following security breach

Update to v1.15.2 + carry upstream #81330

Even Rouault found an issue in tiff, a library providing support for the Tag Image File Format. Wrong handling off integer overflow checks, that are based on undefined

Solving the Cyber Security Problem: Mission Impossible

Addresses CVE-2019-14462 and CVE-2019-14463

Addresses CVE-2019-14462 and CVE-2019-14463

Update to Node.js 10.6.13

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has two fixes is now available.

Security gone in 600 seconds: Make-me-admin hole found in Lenovo Windows laptop crapware. Delete it now

An update that solves three vulnerabilities and has two fixes is now available.

It was discovered that there was a remote arbitrary code vulnerability in commons-beanutils, a set of utilities for manipulating JavaBeans code.

The package nginx before version 1.16.1-1 is vulnerable to denial of service.

The package nginx-mainline before version 1.17.3-1 is vulnerable to denial of service.

The package firefox before version 68.0.2-1 is vulnerable to information disclosure.

The package subversion before version 1.12.2-1 is vulnerable to denial of service.

The package libreoffice-still before version 6.2.6-1 is vulnerable to multiple issues including arbitrary command execution and information disclosure.