Menu

Category Archives: Security

Articles about security

The package linux-zen before version 5.1.11.zen1-1 is vulnerable to denial of service.

The package linux-lts before version 4.19.52-1 is vulnerable to denial of service.

An update for gvfs is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Parliament IT bods’ fail sees server’s naked OS exposed to world+dog
Bella Thorne releases her own topless photos after hacker threats
Freaking out about fiendish IoT exploits? Maybe disable telnet, FTP and change that default password first?
Smash GandCrab: Free tools released to decrypt files scrambled by notorious ransomware
Samsung reminds rabble to scan smart TVs for viruses – then tries to make them forget
How I Discovered My First Vulnerability
Irked Researcher Discloses Facebook WordPress Plugin Flaws
5,000 Twitter Accounts Linked to Disinformation Campaigns
Sad SACK: Linux PCs, servers, gadgets may be crashed by ‘Ping of Death’ network packets
A Spate of University Breaches Highlight Email Threats in Higher Ed
Actress Bella Thorne posts her nudes to tackle threats from hackers
Microsoft Pushes Azure Users to Patch Linux Systems
Alex Jones claims malware planted child porn on InfoWars servers

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Why are fervid Googlers making ad-blocker-breaking changes to Chrome? Because they created a monster – and are fighting to secure it
Malware sidesteps Google permissions policy with new 2FA bypass technique

ESET analysis uncovers a novel technique bypassing SMS-based two-factor authentication while circumventing Google’s recent SMS permissions restrictions The post Malware sidesteps Google permissions policy with new 2FA bypass technique appeared first on WeLiveSecurity

security update

Multiple security issues have been found in Thunderbird which may lead to the execution of arbitrary code if malformed email messages are read. For the stable distribution (stretch), these problems have been fixed in

It was discovered that there was a code injection issue in PyXDG, a library used to locate “FreeDesktop.org” configuration/cache/etc. directories.

EU accuses Russia of spreading misinformation on social media

security update

An update that fixes 13 vulnerabilities is now available.

An update that fixes 13 vulnerabilities is now available.

An update that fixes 13 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Two vulnerabilities were discovered in the ZNC IRC bouncer which could result in remote code execution (CVE-2019-12816) or denial of service via invalid encoding (CVE-2019-9917).

Black Hat USA axes anti-abortion congressman as keynote speaker after outcry – and more news from infosec land

do not install /usr/libexec/crio – conflicts with crio —- Resolves: #1715668 – CVE-2019-10152

Resolves: #1715758 – CVE-2019-9946

Vulnerable infusion pumps can be remotely accessed to change dosages

https://lists.wikimedia.org/pipermail/mediawiki-announce/2019-June/000230.html

security update

Ransomware: A Persistent Scourge Requiring Corporate Action Now
ThreatList: Ransomware Trojans Picking Up Steam in 2019
No Telegram today, protestors: Chinese boxes DDoS chat app amid Hong Kong protest
News Wrap: Amazon Privacy and Telegram DDoS Attack
TRISIS Group, Known for Physical Destruction, Targets U.S. Electric Companies

Reading Time: ~ 2 min. Radiohead Refuses Ransom, Releases Stolen Tracks The band Radiohead recently fell victim to a hack in which 18 hours of previously unreleased sessions were ransomed for $150,000. Rather than pay the ludicrous fee, the band instead opted to release the tracks through Bandcamp for a donation to charity. The unreleased […]

Amazon Alexa Secretly Records Children, Lawsuits Allege

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

Millions of Linux Servers Under Worm Attack Via Exim Flaw
Student uses Snapchat’s gender filter to bust pervert cop

The package chromium before version 75.0.3770.90-1 is vulnerable to arbitrary code execution.

The package thunderbird before version 60.7.1-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Hackers Favor Weekdays for Attacks, Share Resources Often

Joe Vennix discovered an authentication bypass vulnerability in dbus, an asynchronous inter-process communication system. The implementation of the DBUS_COOKIE_SHA1 authentication mechanism was susceptible to a symbolic link attack. A local attacker could take advantage of this flaw

When virtual mittens sell for thousands, of course gamers are ripe targets for cyber shenanigans
Instagram down: Social networking site suffering service outage

Update to [3.3.8](https://github.com/vakata/jstree/compare/3.3.5…3.3.8).

Upstream announcement: Welcome to **phpMyAdmin 4.9.0.1**, a bugfix release that includes important security fixes. This release fixes two security vulnerabilities: * PMASA-2019-3 is an SQL injection flaw in the Designer feature * PMASA-2019-4 is a CSRF attack that’s possible through the ‘cookie’ login form Upgrading is highly recommended for all users. Using the ‘http’

New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

Yubico YubiKey lets you be me: Security blunder sparks recall of govt-friendly auth tokens

Security fix for CVE-2019-11459.

Update to 1.1.33 and fix CVE-2019-11068

Upstream announcement: Welcome to **phpMyAdmin 4.9.0.1**, a bugfix release that includes important security fixes. This release fixes two security vulnerabilities: * PMASA-2019-3 is an SQL injection flaw in the Designer feature * PMASA-2019-4 is a CSRF attack that’s possible through the ‘cookie’ login form Upgrading is highly recommended for all users. Using the ‘http’

dovecot updated to 2.3.6, includes several security fixes

Evernote Critical Flaw Opened Personal Data of Millions to Attack
Hacking these medical pumps is as easy as copying a booby-trapped file over the network
Max-Severity Bug in Infusion Pump Gateway Puts Lives at Risk
How to Remove Temporary Files In Windows 10?
Telegram CEO Fingers China State Actors for DDoS Attack
Train to be a top-notch cybercrime detective at SANS DFIR Europe Summit in Prague

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

High-Severity Cisco Flaw in IOS XE Enables Device Takeover

The package gvim before version 8.1.1467-1 is vulnerable to arbitrary code execution.

The package vim before version 8.1.1467-1 is vulnerable to arbitrary code execution.

The package openssl before version 1.1.1.c-1 is vulnerable to information disclosure.

The package lib32-openssl before version 1:1.1.1.c-1 is vulnerable to information disclosure.

DDoS attack that knocked Telegram secure messaging service offline linked to Hong Kong protests
UK Home Sec kick-starts US request to extradite ex-WikiLeaker Assange

An update that fixes 15 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update for python is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Telegram messaging service hit by massive DDoS attack
Smashing Security #132: CBP cyber attack, an iPhone privacy boost, and Twitter list abuse
Fishwrap Campaign Sways Social Media Users with Old News

1717503 – Security issue: patch 8.1.1365: source command doesn’t check for the sandbox

RAMBleed attack steals sensitive data from computer memory
Spain’s top soccer league fined over its app’s ‘tactics’

La Liga has taken substantial flak for tapping into microphones and geolocation services in fans‘ phones in a bid to root out piracy The post Spain’s top soccer league fined over its app’s ‘tactics’ appeared first on WeLiveSecurity

Data Breach Disclosed by Online Invitation Firm Evite
Unheard recordings of Radiohead from Ok Computer hacked; refuses to pay ransom

Type: Vulnerability. Microsoft Windows is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.