Menu

Category Archives: Security

Articles about security

Adult Sites Lack Privacy, Open the Door for Harassment and Tracking
All very MoD-ern: RAF test pilot headed into space with Virgin, £30m small sat demo project
Bug in NVIDIA’s Tegra Chipset Opens Door to Malicious Code Execution
Israel’s NSO Group: Our malware? Slurp your cloud backups plus phone data? They’ve misunderstood

Reading Time: ~ 2 min. Over 100 Million Accounts Exposed in Evite Breach More than 100 million users of Evite were exposed after the company’s servers were compromised earlier this year. While the company doesn’t store financial information, plenty of other personally identifiable information was found in the leaked database dump. The initial figures for […]

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Your biz won’t be hacked by a super-leet exploit. It’ll be Bob in sales opening a dodgy email
Slack response. Passwords reset four years after data breach
Excluding Huawei from UK’s 5G will harm security, MPs warn

It was discovered that there was an integer overflow vulnerability in exiv2, a tool to manipulate images containing (eg.) EXIF metadata. This could have resulted in a denial of service via a specially-

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

2015 database hack is the terrible gift that keeps giving for Slack: Tens of thousands of passwords now reset

Update to v5.1.18 —- Update to v5.1.17

Update to v5.1.18 —- Update to v5.1.17

– fixes security issues CVE-2019-10190 and CVE-2019-10191 – https://lists.nic.cz/pipermail/knot-resolver-announce/2019/000009.html

Slack data breach: Company resets thousands of passwords
Security Watch: Elon Musk’s NeuraLink Links Brains to iPhones via Bluetooth

– fixes security issues CVE-2019-10190 and CVE-2019-10191 – https://lists.nic.cz/pipermail/knot-resolver-announce/2019/000009.html

It’s never good when ‘Magecart’ and ‘bulletproof’ appear in the same sentence, but here we are
Mirai Botnet Sees Big 2019 Growth, Shifts Focus to Enterprises
Slack Initiates Mass Password Reset

Several security issues were fixed in LibreOffice.

Google Triples Some Bug Bounty Payouts
Ke3chang APT Linked to Previously Undocumented Backdoor
Bulgaria hack: 20-year-old infosec whizz cuffed after ‘adult population’s’ finance deets nicked
EvilGnomes Linux malware record activities & spy on users

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Those facial recognition trials in the UK? They should be banned, warns Parliamentary committee
Thousands of NHS computers are still running Windows XP from beyond the grave
Microsoft demos end-to-end voting verification system ElectionGuard, code will be on GitHub

An update that solves two vulnerabilities and has three fixes is now available.

‘Member Ke3chang? They’re still at it, you know. Euro diplomats targeted by ‘China-based’ hacker crew
Okrum: Ke3chang group targets diplomatic missions

Tracking the malicious activities of the elusive Ke3chang APT group, ESET researchers have discovered new versions of malware families linked to the group, and a previously unreported backdoor The post Okrum: Ke3chang group targets diplomatic missions appeared first on WeLiveSecurity

Security researcher arrested after data on every adult in Bulgaria hacked from government site
Dutch cops collar fella accused of crafting and flogging Office macro nasties to cyber-crooks
Fresh stalkerware crop pops up on Google’s Android Play Store, swiftly yanked offline
Don’t give it away, give it away, give it away now, bot busting biz tells reCAPTCHA data serfs
Smashing Security #137: Porn trolling lawyers, Insta hacking, and Ctrl-Alt-LED
Wormable BlueKeep Bug Still Threatens Legions of Windows Systems

security update

Several security issues were fixed in Thunderbird.

BlueKeep patching isn’t progressing fast enough

Keeping up with BlueKeep; or how many internet-facing systems, and in which countries and industries, remain ripe for exploitation? The post BlueKeep patching isn’t progressing fast enough appeared first on WeLiveSecurity

For pity’s sake, groans Mimecast, teach your workforce not to open obviously dodgy emails
Firmware Bugs Plague Server Supply Chain, 7 Vendors Impacted
Bluetooth Flaws Could Allow Global Tracking of Apple, Windows 10 Devices

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Massive Malvertising Campaign Reaches 100M Ads, Manipulates Supply Chain

An update that fixes three vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Email scammers extract over $300m a month from American suits’ pockets

An update that fixes 10 vulnerabilities is now available.

An update that solves 7 vulnerabilities and has three fixes is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1775

The package chromium before version 75.0.3770.142-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

The package squid before version 4.8-1 is vulnerable to arbitrary code execution.

The package firefox before version 68.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, cross-site request forgery, sandbox escape, arbitrary filesystem access, content spoofing, cross-site scripting, denial of service, information disclosure, insufficient validation and silent downgrade.

StrongPity APT Returns with Retooled Spyware

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1774

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1777

A use-after-free in onig_new_deluxe() in regext.c allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker

Apple pushes out another silent update to address flaws in RingCentral and other video conferencing apps
Meet IRpair & Phantom; powerful anti-facial recognition glasses

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

It was totally Samsung’s fault that crims stole your personal info from a Samsung site, says Samsung-blaming Sprint
Let’s open the Mystery Data Security Blunder box, and see what’s inside today… Ah! Hotel reservations and more
LenovoEMC Storage Gear Leaks Sensitive Financial Data
Hackers used Samsung website to access Sprint’s customer data
Maybe double-check that HMRC email? UK taxman remains a fave among the phisherfolk
The Future is Female: A Key to the Cybersecurity Workforce Challenge
WhatsApp, Telegram Coding Blunders Can Expose Personal Media Files
How your Instagram account could have been hijacked

A researcher found that it was possible to subvert the platform’s password recovery mechanism and take control of user accounts The post How your Instagram account could have been hijacked appeared first on WeLiveSecurity

JetBlue Bomb Scare Set Off with Apple AirDrop

An update that solves one vulnerability and has two fixes is now available.

Several security issues were fixed in NSS.

Patch now before you get your NAS kicked: Iomega storage boxes leave millions of files open to the internet

An update is now available for Red Hat JBoss BPM Suite. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in Redis.

Amadeus! Amadeus! Pwn me Amadeus! Airline check-in bug may have exposed all y’all boarding passes to spies

An update for vim is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for keepalived is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libssh2 is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for perl is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for 389-ds-base is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in NSS.

Risk Level: Very Low. Type: Trojan.

This update includes a fix for a security vulnerability, CVE-2018-20843: > Fix extraction of namespace prefixes from XML names; XML names with multiple colons could end up in the wrong namespace, and take a high amount of RAM and CPU resources while processing, opening the door to use for denial-of-service attacks For more information on […]

Rebase to radare2 3.6.0 and fixes CVE-2019-12790 and CVE-2019-12802

Privacy Experts: Facebook’s $5B Fine Unlikely to Do Much
Turla APT Returns with New Malware, Anti-Censorship Angle

security update