Menu

Category Archives: Security

Articles about security

security update

Risk Level: Very Low. Type: Trojan.

Office 365 Phishing Protection – Is Native Microsoft Protection Safe?
Smart Lock Turns Out to be Not So Smart, or Secure
While we were raging about Putin’s meddling and Kremlin hackers, Five Eyes were pwning Yandex, Russia’s Google
Leaky Amazon S3 Buckets Expose Data of Netflix, TD Bank
Scammers Prey on Instagram Vanity and ‘Verified Account’ Status
2001: Linux is cancer, says Microsoft. 2019: Hey friends, ah, can we join the official linux-distros mailing list, plz?

Reading Time: ~ 2 min. We are  excited to announce Webroot® DNS Protection now runs on Google Cloud Platform (GCP). Leveraging GCP in this way will provide Webroot customers with security, performance, and reliability.  Security Preventing denial of service (DoS) attacks is a core benefit of Webroot DNS Protection. Now, the solution benefits from Google Cloud […]

New Microsoft Excel Attack Vector Surfaces
Thousands of IoT Devices Bricked By Silex Malware
Microsoft enhances OneDrive to secure your critical files

The new feature is intended to protect the kind of data that you hold particularly dear The post Microsoft enhances OneDrive to secure your critical files appeared first on WeLiveSecurity

ViceLeaker Android malware steals call recordings, photos, videos & texts

An update that solves one vulnerability and has two fixes is now available.

UK’s MoD is helping itself to cops’ fingerprint database ‘unlawfully’, rules biometrics chief

An update for atomic-openshift is now available for OpenShift Container Platform. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

After €24 million stolen by typosquatting a cryptocurrency exchange, six people arrested

An update that fixes 5 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Several security issues were fixed in poppler.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Your server remote login isn’t root:password, right? Cool. You can keep your data. Oh sh… your IoT gear, though?
Smashing Security #134: Sextortion, silicone face masks, and a DDoS doofus
New Windows 10 bug causes PCs to take longer to shut down
Google Announces DNS over HTTPS ‘General Availability’
Hey China, while you’re in all our servers, can you fix these support tickets? IBM, HPE, Tata CS, Fujitsu, NTT and their customers pwned

Reading Time: ~ 2 min. We are excited to announce Webroot® DNS Protection now runs on Google Cloud Platform (GCP). Leveraging GCP in this way will provide Webroot customers with unfailing security, performance, and reliability. Security “The big thing about Google Cloud is that it dynamically manages denial of service (DoS) attacks,” said Webroot Sales […]

Decoding America’s spies: What does the NSA’s cryptic memo really mean? Citizens illegally spied on again
Two US cities opt to pay $1m to ransomware operators

A few days apart, two cities in Florida cave in to extortionists’ demands in hopes of restoring access to municipal computer systems The post Two US cities opt to pay $1m to ransomware operators appeared first on WeLiveSecurity

Epyc crypto flaw? AMD emits firmware fix for server processors after Googler smashes RAM encryption algorithms
Cisco Warns of Critical Flaws in Data Center Network Manager
Iran-linked APT33 Shakes Up Cyberespionage Tactics

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that solves 9 vulnerabilities and has two fixes is now available.

Risk Level: Very Low. Type: Trojan.

It could be Rotterdam or anywhere, Wiltshire or in Bath: Euro cops cuff 6 for cybersquatting, allegedly nicking €24m in Bitcoin
EA Games Patches Account-Hijacking Bug
New attack spreads LokiBot & NanoCore malware in ISO image files
Second Florida City Pays Hackers $500k Post-Ransomware Attack
$1.1 million in two weeks – Florida cities pay out big to ransomware gangs
Wipro wasn’t a one-off: Same hacking crew targeted scores of firms, big and small – researchers
7 Easy-to-Use Java Performance Tuning Tips

Mozilla: Type confusion in Array.pop (CVE-2019-11707) * Mozilla: Sandbox escape using Prompt:Open (CVE-2019-11708) SL6 x86_64 firefox-60.7.2-1.el6_10.x86_64.rpm firefox-debuginfo-60.7.2-1.el6_10.x86_64.rpm firefox-60.7.2-1.el6_10.i686.rpm firefox-debuginfo-60.7.2-1.el6_10.i686.rpm i386 firefox-60.7.2-1.el6_10.i686.rpm firefox-debuginfo-60.7.2-1.el6_10.i686.rpm – [More…]

How Phishing Has Evolved in 2019

Several security issues were fixed in bzip2.

Several security issues were fixed in bzip2.

Bought a second-hand Nest Cam? It might have been spying on you
Stop us if you’ve heard this one: US government staff wildly oblivious to basic computer, info security safeguards

Risk Level: Very Low. Type: Trojan.

SEMrush Plugs Remote Code Execution Bug in Its SaaS Platform

security update

Newly-Discovered Malware Targets Unpatched MacOS Flaw
Cellular networks worldwide hit by hackers in espionage attempt
Malspam Emails Blanket LokiBot, NanoCore Malware With ISO Files

An update that solves one vulnerability and has 24 fixes is now available.

Researchers exploit LTE flaws to send 50,000 fake presidential alerts
McAfee sues ship-jumping sales staff over trade secret theft allegations
9 risky apps that you need to monitor on your kids’ smartphone

Reading Time: ~ 2 min. It’s been more than a decade since Netflix launched its on-demand online streaming service, drastically changing the way we consume media. In 2019, streaming accounts for an astonishing 58 percent of all internet traffic, with Netflix alone claiming a 15 percent share of that use. But as streaming has become […]

Open-heart nerdery: Boffins suggest identifying and logging in people using ECGs

An update that contains security fixes can now be installed.

An update that fixes three vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

The update issued as DLA-1835-1 caused a regression in the http.client library in Python 3.4 which was broken by the patch intended to fix CVE-2019-9740 and CVE-2019-9947.

A security improvement has been made to policykit-desktop-privileges.

A system hardening measure could be bypassed.

Several security issues were fixed in Ceph.

Several security issues were fixed in ImageMagick.

Several security vulnerabilities were discovered in the rdesktop RDP client, which could result in buffer overflows and execution of arbitrary code.

Stopping stalkerware: What needs to change?

What technology makers and others can – and should – do to counter the kind of surveillance that starts at home The post Stopping stalkerware: What needs to change? appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

Please stop regulating the dumb tubes, says Internet Society boss

Multiple security issues have been found in Thunderbird which may lead to the execution of arbitrary code if malformed email messages are read. For Debian 8 “Jessie”, these problems have been fixed in version

Two brothers arrested for Bitfinex hack and multi-year cryptocurrency phishing campaign
What the cell…? Telcos around the world were so severely pwned, they didn’t notice the hackers setting up VPN points
Biz tells ransomware victims it can decrypt their files… by secretly paying off the crooks and banking a fat margin

security update

Hackers breach NASA, steal Mars mission data

The infiltration was only spotted and stopped after the hackers roamed the network undetected for almost a year The post Hackers breach NASA, steal Mars mission data appeared first on WeLiveSecurity

Iran is doing to our networks what it did to our spy drone, claims Uncle Sam: Now they’re bombing our hard drives
Facebook Faces Lawsuit Over Massive 2018 Data Breach
New cryptomining botnet malware hits Android devices
WeTransfer security failure results in file transfer emails being sent to the wrong people

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Iran Targeting U.S. With Destructive Wipers, Warns DHS

A sandbox escape was discovered in Firefox.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1587

The Modern-Day Heist: IP Theft Techniques That Enable Attackers

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has four fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves two vulnerabilities and has four fixes is now available.