Menu

Category Archives: Security

Articles about security

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to a spoofing vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a spoofing vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Meet the Great Duke of… DLL: Microsoft shines light on Astaroth, a devilishly sneaky strain of fileless malware
GE Aviation Passwords, Source Code Exposed in Open Jenkins Server
Rules-Based Policy Approaches Need to Go
Dear El Reg, Will Windows 10 break my VPN? I read it on the web so it must be true
GoBotKR Targets Pirate Torrents to Build a DDoS Botnet

Risk Level: Very Low. Type: Trojan.

Apple Patches iMessage Bug That Bricks iPhones with Out-of-Date Software

Fang-Pen Lin discovered a stack-based buffer-overflow flaw in ZeroMQ, a lightweight messaging kernel library. A remote, unauthenticated client connecting to an application using the libzmq library, running with a

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Post-Data Breach, British Airways Slapped With Record $230M Fine

GLib did not properly restrict directory and file permissions.

Docker could be made to overwrite files as the administrator.

Fang-Pen Lin discovered a stack-based buffer-overflow flaw in ZeroMQ, a lightweight messaging kernel library. A remote, unauthenticated client connecting to an application using the libzmq library, running with a socket listening with CURVE encryption/authentication enabled, can take

An update for python27-python is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

British Airways faces record £183 million GDPR fine after data breach
Medway Council reforms eforms to stop blurting out residents’ details
Malicious campaign targets South Korean users with backdoor-laced torrents

ESET researchers have discovered a malicious campaign distributing a backdoor via torrents, with Korean TV content used as a lure The post Malicious campaign targets South Korean users with backdoor-laced torrents appeared first on WeLiveSecurity

Several security issues were fixed in libvirt.

UK privacy watchdog threatens British Airways with 747-sized fine for massive personal data blurt

An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

Fibaro flummoxed, Georgia courts held for ransom, and more

Bugfixes, and a security fix: Fixed vulnerabilities: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

Bugfixes, and a security fix: Fixed vulnerabilities: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

Bugfixes, and a security fix: Fixed vulnerabilities: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

Bugfixes, and a security fix: Fixed vulnerabilities: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

Fix vfs_fruit, vfs_glusterfs and smbspool —- Update to Samba 4.10.5 Security fixes for CVE-2019-12435 and CVE-2019-12436

Data Breach Lessons from the Trenches

An update that fixes one vulnerability is now available.

WordPress Plugin WP Statistics Patches XSS Flaw
Cisco delivers Patch Tuesday warmup with bundle of 18 bug fixes

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Several security issues were fixed in Irssi.

PGP Ecosystem Targeted in ‘Poisoning’ Attacks
Wide of the net: Football Association of Ireland says player, manager data safe after breach

An update that solves two vulnerabilities and has one errata is now available.

The Logic of a Classic Advanced Persistent Threat Attack
Worried about hackers? Catch a lifeline with this month’s Sophos SOS cybersecurity podcasts
Get rekt: Two years in clink for game-busting DDoS brat DerpTrolling
Derp! DDoS attacker who brought down EA, Sony, and Steam jailed for 27 months

An update that contains security fixes can now be installed.

An update that solves three vulnerabilities and has two fixes is now available.

St John Ambulance service hit by ransomware attack
Reports of cyber attacks fall, says UK.gov survey: GDPR? Fewer nasties? More targeted attacks? We just don’t know

USN-4038-1 introduced a regression in bzip2.

USN-4038-1 introduced a regression in bzip2.

An update that solves three vulnerabilities and has 26 fixes is now available.

An update that solves three vulnerabilities and has 26 fixes is now available.

An update that fixes three vulnerabilities is now available.

It was discovered that there was a XML external entity vulnerability in the lemonldap-ng single-sign on system. This may have led to the disclosure of confidential data, denial of service, server side request forgery, port scanning, etc.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

US Cyber Command warns that the Outlook is not so good – Iranians hitting email flaw
Smashing Security #135: Zombie grannies and unintended leaks

This update includes a rebase from 9.0.13 up to 9.0.21 which resolves two CVEs along with various other bugs/features: * rhbz#1673856 tomcat-9.0.21 is available * rhbz#1713279 CVE-2019-0221 tomcat: XSS in SSI printenv * rhbz#1693326 CVE-2019-0199 tomcat: Apache Tomcat HTTP/2 DoS

How do we stop facial recognition from becoming the next Facebook: ubiquitous and useful yet dangerous, impervious and misunderstood?
YouTube mystery ban on hacking videos has content creators puzzled
Facebook and Instagram suffer massive outage
D-Link must suffer indignity of security audits to settle with the Federal Trade Commission
Apple Transparency Report Now Includes App Store Takedown Requests
NHS warned to act now to keep hackers at bay

A trifecta of issues impact the organization’s cyber-resilience and conspire to put it in the firing line of cyberattacks The post NHS warned to act now to keep hackers at bay appeared first on WeLiveSecurity

Amazon Admits Alexa Voice Recordings Saved Indefinitely

An update that fixes 15 vulnerabilities is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1650