Menu

Category Archives: Security

Articles about security

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes 10 vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

Man arrested over UK’s Lancaster University data breach hack allegations

Several security issues were fixed in Patch.

Data breaches can haunt firms for years

The compromised company may bear the financial brunt of the breach within the first year after the incident occurs, but the price tag is still far from final The post Data breaches can haunt firms for years appeared first on WeLiveSecurity

Police arrest man after Lancaster University hacking attack

An update that fixes 5 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Several security issues were fixed in Patch.

Sky worries users with phishy-looking password reset email

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

An update is now available for CloudForms Management Engine 5.10. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

With more hints dropped online on how to exploit BlueKeep, you’ve patched that Windows RDP flaw, right?
Low Barr: Don’t give me that crap about security, just put the backdoors in the encryption, roars US Attorney General
Citrix Confirms Password-Spraying Heist of Reams of Internal IP
Dodgy vids can hijack PCs via VLC security flaw, US, Germany warn. Software’s makers not app-y with that claim
WordPress Plugin Flaws Exploited in Ongoing Malvertising Campaign
Malware-Loader ‘Brushaloader’ Grows More Menacing
Popular Samsung, LG Android Phones Open to ‘Spearphone’ Eavesdropping

Reading Time: ~ 4 min. You’ve likely heard of the dark web. This ominous sounding shadow internet rose in prominence alongside cryptocurrencies in the early 2010s, eventually becoming such an ingrained part of our cultural zeitgeist that it even received its own feature on an episode of Law & Order: SVU. But as prominent as […]

Jann Horn discovered that the ptrace subsystem in the Linux kernel mishandles the management of the credentials of a process that wants to create a ptrace relationship, allowing a local user to obtain root privileges under certain scenarios.

VLC Media Player Plagued By Unpatched Critical RCE Flaw

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 12 vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Lancaster Uni data breach hits at least 12,500 wannabe students
It’s 2019 and you can still pwn an iPhone with a website: Apple patches up iOS, Mac bugs in July security hole dump

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Cloud hosting provider iNSYNQ hit by MegaCortex ransomware
Equifax to world+dog: If we give you this $700m, can you pleeeeease stop suing us about that mega-hack thing?
Critical RCE Flaw in Palo Alto Gateways Hits Uber
700 million reasons for Equifax to remember to patch its vulnerable IT systems in future
Tackling the Collaboration Conundrum

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Large-Scale Government Hacks Hit Russia, Bulgaria
VLC player has a critical flaw – and there’s no patch yet

On the flip side, there are currently no known cases of the vulnerability being exploited in the wild The post VLC player has a critical flaw – and there’s no patch yet appeared first on WeLiveSecurity

Amazon Alexa, Google Home On Collision Course With Regulation
Equifax to Pay $700 Million in 2017 Data Breach Settlement
iCloud account hacker jailed for three years after preying on rappers and sports celebrities

Several security issues were fixed in Squid.

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

No, the Met Police wasn’t hacked. But its Twitter account and website were hijacked

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

Cisco ‘in talks’ to borg with web app protector Signal Sciences for its web app firewall tech

Several vulnerabilities were found in libxslt the XSLT 1.0 processing library. CVE-2016-4610

What makes a secure & successful website: A Guide

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

ClamAV could be made to expose sensitive information if it received a specially crafted CHM file.

An update for rh-nodejs8-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-redis5-redis is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Marketing biz bares folks’ data in the act of asking for their GDPR comms preferences

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

security update

Hackers steal 7.5TB of data from Russian Intel Agency FSB’s contractor

An update that fixes 10 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that solves 21 vulnerabilities and has two fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Palo Alto gateway security alert, FSB hack, scourge of data-stealing web plugins, and more

Vulnerabilities have been discovered in nss, the Mozilla Network Security Service library.

Jann Horn discovered that the ptrace subsystem in the Linux kernel mishandles the management of the credentials of a process that wants to create a ptrace relationship, allowing a local user to obtain root privileges under certain scenarios.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has four fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes four vulnerabilities is now available.

In the cooler for the next three years: Hacker of iCloud accounts used by athletes and rappers

Update to Samba 4.9.11 —- Update to Samba 4.9.9 Security fixes for CVE-2019-12435

Update to Samba 4.9.11 —- Update to Samba 4.9.9 Security fixes for CVE-2019-12435

Iran-Linked APT34 Invites Victims to LinkedIn for Fresh Malware Infections
When Harry met celly: NSA hoarder thrown in the clink for 9 years – after taking classified work home for decades