Menu

Category Archives: Security

Articles about security

Meet AttackSurfaceMapper; new automated penetration testing tool
Facebook hits two app developers with lawsuit

The legal action, brought over alleged click injection fraud, is said to be among the first of its kind The post Facebook hits two app developers with lawsuit appeared first on WeLiveSecurity

Researchers Bypass Apple FaceID Using Biometrics ‘Achilles Heel’

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Ransomware Sees Triple-Digit Spike in Corporate Detections
The Threat in the Cloud: Phishing Abuses Amazon AWS S3 Buckets
Cryptocurrency exchange Binance offers $290,000 bounty to unmask blackmailer
How powerful are Russian hackers? One new law could transform global crime operations
Black Hat 2019: WhatsApp Users Still Open to Message Manipulation
Transport for London Oyster system pulled offline after credential-stuffing crooks board customers’ accounts

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

DEF CON 2019: 35 Bugs in Office Printers Offer Hackers an Open Door
Varenyky: Spambot à la Française

ESET researchers document malware-distributing spam campaigns targeting people in France The post Varenyky: Spambot à la Française appeared first on WeLiveSecurity

Smashing Security #140: Love, PINs, and 8chan
WTF is Boeing on? Not just customer databases lying around on the web. 787 jetliner code, too, security bugs and all

A minor version update (from 7.3 to 7.4) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

FBI, NSA to hackers: Let us be blunt. Weed need your help. We’ll hire you even if you’ve smoked a little pot in the past

New kdelibs packages are available for Slackware 14.2 and -current to fix a security issue.

Black Hat 2019: Microsoft Protocol Flaw Leaves Azure Users Open to Attack
Black Hat 2019: 5G Security Flaw Allows MiTM, Targeted Attacks

**PHP version 7.2.21** (01 Aug 2019) **Date:** * Fixed bug php#69044 (discrepency between time and microtime). (krakjoe) **EXIF:** * Fixed bug php#78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042) (Stas) * Fixed bug php#78222 (heap-buffer-overflow on exif_scan_thumbnail). (CVE-2019-11041) (Stas) **Fileinfo:** * Fixed bug php#78183 (finfo_file shows

Fixed out of bounds heap read in function rtreenode() Enhance the rtreenode() function of rtree (used for testing) so that it uses the newer sqlite3_str object for better performance and improved error reporting.

**PHP version 7.2.21** (01 Aug 2019) **Date:** * Fixed bug php#69044 (discrepency between time and microtime). (krakjoe) **EXIF:** * Fixed bug php#78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042) (Stas) * Fixed bug php#78222 (heap-buffer-overflow on exif_scan_thumbnail). (CVE-2019-11041) (Stas) **Fileinfo:** * Fixed bug php#78183 (finfo_file shows

Black Hat 2019: Ethical Hackers Must Protect Digital Human Rights

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Hack computers to steal someone’s identity in China? Why? You can just buy one from a bumpkin for, like, $3k
There’s fraud, and then there’s backdoor routers, fenced logins, malware, and bribing AT&T staff seven figures to unlock 2m phones
Hack-age delivery! Wardialing, wardriving… Now warshipping: Wi-Fi-spying gizmos may lurk in future parcels
Black Hat 2019: Security’s Powerful Cultural Transformation
AT&T workers bribed to install malware on company network and unlock iPhones
Top Dangers That Online Gamers Face
Smominru Cryptominer Scrapes Credentials for Half-Million Machines
8chan down after Cloudflare & hosting firms boots it off
10 Typical Mistakes in Scientific Research Paper Writing

An update that solves one vulnerability and has one errata is now available.

New SWAPGS Side-Channel Attack Bypasses Spectre and Meltdown Defenses

Rack could allow cross-site scripting (XSS) attacks.

Security Vulnerabilities Are Increasingly Putting Kids at Risk
Black Hat: LeapFrog Tablet Flaws Let Attackers Track, Message Kids

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

PHP could be made to denial of service, expose sensitive information or execute arbitrary code if it received a specially crafted regular expression.

FBI warns of romance scams using online daters as money mules

Up to 30 percent of romance fraud victims in 2018 are estimated to have been used as money mules The post FBI warns of romance scams using online daters as money mules appeared first on WeLiveSecurity

SWAPGS attack: The Spectre-like flaw affecting Intel CPUs

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libssh2 is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for augeas is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for systemd is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for perl is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

Your mid-week infosec news bonanza: Cisco bugs, VMware-Nvidia guest escapes, KDE hijacking, and more
Deja-wooo-oooh! Intel chips running Windows potentially vulnerable to scary Spectre variant
They say piracy killed the Amiga. Know what else it’s killing? Malware sales. Awww, diddums
Democrats and Doctors Behind Latest Wave of Leaked Data
Cryptolocking WordPress Plugin Locks Up Blog Posts
Add passwords to list of stuff CafePress made hash of storing, says infoseccer. 11m+ who used Facebook ‘n’ pals to sign in were lucky
Mass Spoofing Campaign Takes Aim at Walmart
Millions of Android Smartphones Vulnerable to Trio of Qualcomm Bugs

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

You really should listen to the award-winning “Smashing Security” podcast

Mercurial could be made to overwrite files.

500,000 Monzo banking customers told to change their PINs

An update that solves two vulnerabilities and has one errata is now available.

An update for perl-Archive-Tar is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for dhcp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for linux-firmware is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libtiff is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for python-requests is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Need to automatically and securely verify a download is legit? You bet rget this new tool
It’s 2019 – and you can completely pwn a Qualcomm-powered Android over the air
PIN the blame on us, says Monzo in mondo security blunder: Bank card codes stored in log files as plain text
F-B-Yikes! FBI bod allegedly hid spy camera under desk to snap coworker’s upskirt pics
Googlers hate it! This one weird trick lets websites dodge Chrome 76’s defenses, detect you’re in Incognito mode

security update

E3 Website Leaks Private Addresses for Thousands of Journalists
How to avoid getting burned at Black Hat, destroyed at DEF CON or blindsided by Bsides

Reading Time: ~ 3 min. 1949, 1971, 1979, 1981, 1983 and 1991. Yes, these are numbers. You more than likely even recognize them as years. However, without context you wouldn’t immediately recognize them as years in which Sicily’s Mount Etna experienced major eruptions. Data matters, but only if it’s paired with enough context to create […]

Tobias Maedel discovered that the mod_copy module of ProFTPD, a FTP/SFTP/FTPS server, performed incomplete permission validation for the CPFR/CPTO commands.

July CPU update. See: http://openjdk.java.net/groups/vulnerability/advisories/2019-07-16 and https://mail.openjdk.java.net/pipermail/jdk-updates-dev/2019-July/001423.html

This release includes four security fixes: – Prevent an attack where a federated server could send redactions for arbitrary events in v1 and v2 rooms. – Prevent a denial-of-service attack where cycles of redaction events would make Synapse spin infinitely. – Prevent an attack where users could be joined or parted from public rooms without […]

This kernel update is based on the upstream 5.1.20 and fixes atleast the following security issue: With Xen, virtual device backends and device models running in domain 0, or other backend driver domains, need to be able to map guest memory

Puzzling Gwmndy Botnet Focuses on Low-Volume Proxy Connections
The sea is dangerous and no one likes robots, so why not send a drone on rescue missions?
Microsoft Lab Offers $300K For Working Azure Exploits
Google and ARM Tackle Android Bugs with Memory-Tagging
GermanWiper isn’t ransomware. It’s worse than that
Class-action sueball flung at Capital One and GitHub over theft of 106 million folks’ details
We’ve, um, changed our password policy, says CafePress amid reports of 23m pwned accounts

A system hardening measure could be bypassed.

What we Can Learn from the Recent VLC Security Vulnerability Fiasco: A Conversation with VideoLAN President Jean-Baptiste Kempf
MegaCortex Ransomware Revamps for Mass Distribution