Menu

Category Archives: Security

Articles about security

Smashing Security #142: Mercedes secret sensors, smart cities, and ransomware runs riot
First‑of‑its‑kind spyware sneaks into Google Play

ESET analysis breaks down the first known spyware that is built on the AhMyth open-source espionage tool and has appeared on Google Play – twice The post First‑of‑its‑kind spyware sneaks into Google Play appeared first on WeLiveSecurity

An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 and Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Disgruntled bug-hunter drops Steam zero-day to get back at Valve for refusing him a bounty
The Joy of Six… critical security patches: Cisco small biz switches open to hijacking via web UI
Finally. Thanks so much, nerds. Google, Apple, Mozilla end government* internet spying for good

An update for atomic-openshift-web-console is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Fixes CVE-2019-9511, CVE-2019-9513, CVE-2019-9516

Researcher Discloses Second Steam Zero-Day After Valve Bug Bounty Ban

security update

Here’s a top tip: Don’t trust the new guy – block web domains less than a month old. They are bound to be dodgy
The Texas Ransomware Attacks: A Gamechanger for Cybercriminals

Multiple security issues were discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed file/stream is processed.

Cisco Patches Six Critical Bugs in UCS Gear and Switches
New ‘Off-Facebook Activity Tool’ lets users control data collected by websites
Microsoft: Reckon our code is crap? Prove it and $30k could be yours
Backdoor Found in Utility for Linux, Unix Servers

An update that solves one vulnerability and has one errata is now available.

Sorry script kiddies, hacktivism isn’t cool anymore: No one cares about stuff that’s easy-peasy to defend against

Several security issues were fixed in OpenJPEG.

Adult Content Site Exposed Personal Data of 1M Users

An update is now available for Red Hat Ceph Storage 3.3 on Ubuntu 16.04. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Zstandard could be made to execute arbitrary code if it received specially crafted input.

An update that fixes 30 vulnerabilities is now available.

An update is now available for Red Hat Ceph Storage 3.3 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Education and privacy legislation at ChannelCon

As education is becoming an increasingly vital tool in companies’ security toolboxes, the question arises: How can they effectively implement security awareness training? The post Education and privacy legislation at ChannelCon appeared first on WeLiveSecurity

Stuff like sophisticated government spyware is scary and all – but don’t forget, a single .wmv file can pwn you via VLC

A security update for Red Hat 3scale API Management Platform is now available from the Red Hat Container Catalog. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

30+ countries, 160,000 emails, $4.2m in cyber-heists… maybe it’s time for the Silence hacker crew to change its name

– Fix for CVE-2019-10216 added

updated to 1.4 branch snapshot containing several security fixes

Microsoft Offers $30K Rewards For Chromium Edge Beta Flaws
No REST for the wicked: Ruby gem hacked to siphon passwords, secrets from web devs

Security fix for CVE-2019-1010238

– Fix for CVE-2019-10216 added

Fortnite Ransomware Masquerades as an Aimbot Game Hack
How to Prepare for Misconfigurations Clouding the Corporate Skies
Hackers cloned NordVPN website to drop banking trojan

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Reading Time: ~ 3 min. Our kids are more connected than any previous generation. From the moment they wake up, they have an instant connection to the internet through phones, tablets, and laptops. The internet is also now an important part of their learning experience, and many parents often assume that cybersecurity has risen as a priority for school administrators. But with many institutions struggling to modernize legacy […]

Huawei goes all Art of War on us: Switches on ‘battle mode’ and vows to ‘dominate the world’
Ransomware wave hits 23 towns in Texas

The attack, which has victimized mostly smaller local governments, is thought to have been unleashed by a single threat actor The post Ransomware wave hits 23 towns in Texas appeared first on WeLiveSecurity

Apple iOS Patch Blunder Opens Updated iPhones to Jailbreaks
Adwind Spyware-as-a-Service Attacks Utility Grid Operators

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Several security issues were fixed in GIFLIB.

D’oh! Apple botches iOS update, leaves iPhones open to jailbreaking

Flask, a micro web framework for Python contains a CWE-20: Improper Input Validation vulnerability that can result in Large amount of memory usage possibly leading to denial of service. This attack appear

NLTK could be made to overwrite files.

Several security issues were fixed in CUPS.

Breaker, breaker. Apple’s iOS 12.4 update breaks jailbreak break, un-breaks the break. 10-4
The Pwn Star State: Nearly two dozen Texas towns targeted by tiresome ransomware
VLC Media Player Allows Desktop Takeover Via Malicious Video Files
Apple Sues Corellium Over iOS ‘Replica’ Security Testing Software

security update

Dear Planet Earth: Patch Webmin now – zero-day exploit emerges for potential hijack hole in server control panel
Post GandCrab, Cybercriminals Scouring the Dark Web for the Next Top Ransomware

Nova could be made to expose sensitive information.

Google Nest Security Cam Bugs Allow Device Takeover
Dodging bad passwords with Google’s new tool
New malware records screen activity as victim watches porn

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

20 month prison sentence for British hacker who made fortune helping SIM-swap fraudsters

An update that solves one vulnerability and has two fixes is now available.

An update that contains security fixes can now be installed.

Docker could be made to crash or run programs as your login.

Coordinated Ransomware Attack Hits 23 Texas Government Agencies
Teen TalkTalk hacker ordered to pay £400k after hijacking popular Instagram account

docker-credential-helpers could be made to crash or run programs as your login

KNOB turns up the heat on Bluetooth encryption, hotels leak guest info, city hands $1m to crook, and much, much more

Several security issues were fixed in OpenLDAP.

Several security issues were fixed in LibreOffice.

KConfig and KDE libraries could be made to crash or run programs if it opened a specially crafted file.

iFrame clickjacking countermeasures appear in Chrome source code. And it only took *checks calendar* three years
Subcontractor’s track record under spotlight as London Mayoral e-counting costs spiral

An update for rh-php71-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

This update fixes **CVE-2019-14744 (kconfig arbitrary shell code execution)** in the KDE 3 compatibility version of kdelibs used by legacy KDE 3 applications. The full list of fixes in this `kdelibs3` build: * fixes **CVE-2019-14744** – `kconfig`: malicious `.desktop` files (and others) would execute code. KConfig had a well-meaning feature that allowed configuration files to […]

Security fix for CVE-2019-1010189

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has 11 fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that solves three vulnerabilities and has 41 fixes is now available.

This update fixes 2 security issues. A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure (CVE-2019-10192).

Updated postgresql packages fix security vulnerabilities: Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function

Updated mariadb packages fix security vulnerabilities: An easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise mariadb server. Successful attacks of this vulnerability can result in unauthorized

This update provides and update to mythtv 30, and updates the bundled ffmpeg to 3.2. It also fixes atleast the following issue: The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 4.0.2 does not check for an empty audio packet, leading to an assertion

It was discovered that elfutils incorrectly handled certain malformed files. If a user or automated system were tricked into processing a specially crafted file, elfutils could be made to crash or consume resources, resulting in a denial of service (CVE-2017-7607, CVE-2017-7608, CVE-2017-7609, CVE-2017-7610, CVE-2017-7611, CVE-2017-7612, CVE-2017-7613,

A vulnerability in hostapd and wpa_supplicant could lead to a Denial of Service condition.

Multiple vulnerabilities have been found in MariaDB and MySQL, the worst of which could result in privilege escalation.

Multiple vulnerabilities have been found in VLC, the worst of which could result in the arbitrary execution of code.

security update

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2473

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2471

Reading Time: ~ 2 min. With job growth projected to surge 24% over the next seven years, software engineering is one of the most demanded professional fields in the U.S. Exceptionally competitive pay and the chance to pursue careers across many industries are just a few benefits of being a software engineer. We explore how […]