Menu

Category Archives: Security

Articles about security

How to write an information security analyst job description
Amazon now lets you opt-out of having humans review your Alexa conversations
Sharpening the Machete

ESET research uncovers a cyberespionage operation targeting the Venezuelan military The post Sharpening the Machete appeared first on WeLiveSecurity

It’s Black Hat and DEF CON in Vegas this week. And yup, you know what that means. Hotel room searches for guns
LAPD loses job applicant details, Project Zero pokes holes in iOS, AWS S3 whack-a-mole continues, and more
New SystemBC malware targets Windows PCs by evading detection

An update that fixes one vulnerability is now available.

The Best Way to Install and Set-Up WinRAR 64-bit
Internet connected cars can be hacked to gridlock major cities

Several minor issues have been fixed in vim, a highly configurable text editor.

Multiple vulnerabilities have been found in libpng, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been found in Binutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

It’s a bird! It’s a plane! No, it’s two-dozen government surveillance balloons over America
Phisherman’s blues: Bogus Dell support rep extradited from Kenya, admits he conned US colleges out of $900,000

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 8 vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has 10 fixes is now available.

An update that fixes three vulnerabilities is now available.

Critical Bug in Android Antivirus Exposes Address Books
Nation-State APTs Target U.S. Utilities With Dangerous Malware
German privacy probe orders Google to stop listening in on voice recordings for 3 months
Another rewrite for 737 Max software as cosmic bit-flipping tests glitch out systems – report

Reading Time: ~ 2 min. Ransomware Targets Louisiana School Districts At least four school districts in Louisiana fell victim to a series of ransomware attacks in recent weeks, forcing the governor to issue a state of emergency to allow federal agencies to assist local governments during these situations. The IT systems for each of these […]

An update that fixes one vulnerability is now available.

90% of Enterprise iPhone Users Open to iMessage Spy Attack
Apple Suspends Siri Program After Privacy Backlash
Convince your users to obey the cybersecurity rules: Tune in live online and find out how
Apple’s Siri contractors will no longer hear you having sex, making drug deals
Google contractors told to stop listening to conversations captured on your Home assistant… for now, in Europe at least
Our hero returns home £500 richer thanks to senior dev’s appalling security hygiene

SoX could be made to crash if it received a specially crafted MP3 file.

Warning as small planes found vulnerable to hacking

Several vulnerabilities were discovered in Subversion, a version control system. The Common Vulnerabilities and Exposures project identifies the following problems:

Various minor issues have been addressed in the GLib library. GLib is a useful general-purpose C library used by projects such as GTK+, GIMP, and GNOME.

Org’s network connect to GitHub and Pastebin much? It’s a Rocke road to cryptojacking country
Brand-New SystemBC Proxy Malware Spotted Using SOCKS5 for Stealth
Unpatched Flaws in IoT Smart Deadbolt Open Homes to Danger
From Carnaval to Cinco de Mayo – The journey of Amavaldo

The first in an occasional series demystifying Latin American banking trojans The post From Carnaval to Cinco de Mayo – The journey of Amavaldo appeared first on WeLiveSecurity

New British Army psyops unit fires rebrandogun, smoke clears to reveal… I’m sorry, Dave…
Exposed internal database reveals vulnerable unpatched systems at Honda
For $8.6M, Cisco Settles Suit Over Bug-Riddled Video Surveillance Software
Until airbags are fitted to email apps to stop staff opening bad messages, what else can a small biz do to protect itself?

A XSS vulnerability was discovered in SquirrelMail. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mails can be executed within the application context via

Sigil could be made to overwrite files.

Smashing Security #139: Capital One hacked, iMessage flaws, and anonymity my ass!

Several security issues were fixed in Django.

Fed-up graphic design outfit dangles cash to anyone who can free infosec of hoodie pics
Fraudsters are trying to steal $8.7 million every single day through Business Email Compromise

Several security issues were fixed in the Linux kernel.

security update

This update addresses an arbitrary file copy vulnerability in mod_copy in ProFTPD, which allowed for remote code execution and information disclosure without authentication due to not honoring “ constraints. Upstream bug: http://bugs.proftpd.org/show_bug.cgi?id=4372

New Android ransomware uses pornographic posts to infect devices
Malvertising Campaigns Skirt Ad Blockers, Serve Up Mac Malware
If you could forget the $125 from Equifax and just take the free credit monitoring, that would be great – FTC

An update that fixes two vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes three vulnerabilities is now available.

An update that solves three vulnerabilities and has 41 fixes is now available.

Several vulnerabilities were discovered in WPA supplicant / hostapd. Some of them could only partially be mitigated, please read below for details.

$1.7 million still missing after North Carolina county hit by business email compromise scam
Honda’s Security ‘Soft Spots’ Exposed in Unsecured Database
Fix LibreOffice now to thwart silent macro viruses – and here’s how to pwn those who haven’t
Cybercrooks attempted credential-stuffing banks 3.5 BEEELLION times in the last 18 months alone
Chrome 76 Dumps Default Adobe Flash Player Support
Trivial Bug Turns Home Security Cameras Into Listening Posts
New UK Home Sec invokes infosec nerd rage by calling for an end to end-to-end encryption

An update that fixes 10 vulnerabilities is now available.

An update for icedtea-web is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Black Hat USA 2019 Preview
What’s the last piece of software you’d expect to spy on you? Maybe your enterprise security suite? Bad news
Evolving OVAL
Lancaster Uni cordons off breached systems a week after thousands of folks’ data pinched

An update that fixes one vulnerability is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1898

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1883

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1884

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1880

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1896

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1873

Hack a small airplane? Yes, we CAN (bus) – once we physically break into one, get at its wiring, plug in evil kit…

Update to v5.1.20 —- Update to v5.1.19

Update to v5.1.20 —- Update to v5.1.19

Some security issues are found on oniguruma. This new rpm should fix these issues

Watch as 10 cops with guns and military camo storm suspected Capital One hacker’s house…
DHS Warning: Small Aircraft are Ripe for Hacking
Apple iMessage Flaw Allows Remote Attackers to Read iPhone Messages
Capital One data breach: 106m customers affected; suspected hacker arrested
Hacker swipes personal deets of 20,000 peeps from under Los Angeles Police Dept’s nose
Android Ransomware Spreads Via ‘Sex Simulation Game’ Links on Reddit, SMS
Nation-State Actors Go All-In on Mobile Malware

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes 10 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes 52 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Former AWS Engineer Arrested as Capital One Admits Massive Data Breach
Google found a way to remotely attack Apple iOS devices by sending a boobytrapped iMessage