Menu

Category Archives: Security

Articles about security

Several vulnerabilities have been found in the poppler PDF rendering library, which could result in denial of service or possibly other unspecified impact when processing malformed or maliciously crafted files.

Worried ransomware will screw your network? You could consider swallowing your pride, opening your wallet
Smashing Security #131: Zap yourself from the net, and patch now against BlueKeep
It’s that time again: Android kicks off June’s patch parade with fixes for five hijack holes
Buggy Phishing Kits Allow Criminals to Cannibalize Their Own
440 Million Android Users Plagued By Extremely Obnoxious Pop-Ups
Mozilla and Google Browsers Get Security, Anti-Tracking Boosts

Risk Level: Very Low. Type: Trojan.

BlueKeep ‘Mega-Worm’ Looms as Fresh PoC Shows Full System Takeover
Why Election Trust is Dwindling in a Post-Cambridge Analytica World
Crime doesn’t pay? Crime doesn’t do secure coding, either: Akamai bug-hunters find hijack hole in bank phishing kit

The Qualys Research Labs reported a flaw in Exim, a mail transport agent. Improper validation of the recipient address in the deliver_message() function may result in the execution of arbitrary commands.

Podcast: Behind-the-Scenes Look at Scattered Canary BEC Cybergang
Newly-Identified BEC Cybergang Targets U.S. Enterprise Victims
Smashing Security named the Best Security Podcast

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Wajam: From start-up to massively-spread adware

How a Montreal-made “social search engine” application has managed to become a widely-spread adware, while escaping consequences The post Wajam: From start-up to massively-spread adware appeared first on WeLiveSecurity

Labs are for nerds, it’s simply Kaspersky now – just hold still while we cyber-immunise you

It was discovered that there was a cross-site scripting (XSS) vulnerability in the Django web development framework. For Debian 8 “Jessie”, this issue has been fixed in python-django version

Bloody awful: Hell-thcare hackers break into databases of 20m medical test biz patients
Quest Diagnostics data breach affects 12 million customers
Is ‘Sign in with Apple’ Marketing Spin or Privacy Magic? Experts Weigh In

security update

Zero-Day No More: Windows Bug Gets a Fix
Zebrocy: A Russian APT Specializing in Victim Profiling, Access
Malware spotted doing unspeakable, filthy things to infected Macs – injecting Bing results into Google searches
AI Isn’t Good Enough When Lives Are on the Line, Experts Warn
A New Approach for Combating Insider Threats
Guardian Digital Celebrates 20 Years of Revolutionizing Digital Security, Securing Email with Open Source
Hackers steal 19 years’ worth of data from Australia’s top university

It is the second major breach that the Australian National University suffered in 2018 The post Hackers steal 19 years’ worth of data from Australia’s top university appeared first on WeLiveSecurity

Strewth: Hackers slurp 19 years of Oz student data in uni’s second breach within a year

An update for systemd is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Infosecurity Europe: Cryptojacking is Making a Comeback

An update for java-1.8.0-ibm is now available for Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The package python-django before version 2.2.2-1 is vulnerable to cross-site scripting.

The package python2-django before version 1.11.21-1 is vulnerable to cross-site scripting.

An update that contains security fixes can now be installed.

Supra smart TVs aren’t so super smart: Hole lets hackers go all Max Headroom on e-tellies
Devs slam Microsoft for injecting tech-support scam ads into their Windows Store apps

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Tap ‘n Ghost Attack Creatively Targets Android Devices
WWDC 2019: Apple Takes Aim at Facebook on Privacy
Smart-TV Bug Allows Rogue Broadcasts
Google may limit ad blockers for Chrome users
GandCrab Ransomware Shutters Its Operations

An update that solves 5 vulnerabilities and has 6 fixes is now available.

IEEE says it may have gone about things the wrong Huawei, lifts ban after US govt clearance
MacOS Zero-Day Allows Trusted Apps to Run Malicious Code
Legacy app whitelist can be abused to bypass latest macOS security features, expert warns
Facebook lawyer argues you should have ‘no expectation of privacy’

An update that fixes four vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Pharma-testing biz Eurofins Scientific says it fell victim to ‘new version’ of malware

An update that fixes 8 vulnerabilities is now available.

An update that solves 5 vulnerabilities and has 6 fixes is now available.

An update that fixes three vulnerabilities is now available.

Data protection authority reports itself to itself after data breach
5G Security Challenges: A Vendor’s POV

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Nginx nJS will need patches, hotels exposed via security systems, Docker containers dinged, and more
5 Best VPN Apps for Android 2019

An update that fixes 16 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

– https://www.drupal.org/project/views/releases/7.x-3.23 – https://www.drupal.org/project/views/releases/7.x-3.22 – https://www.drupal.org/project/views/releases/7.x-3.21 – [Less critical – Cross site scripting – SA-CONTRIB-2019-036](https://www.drupal.org/sa- contrib-2019-036) – [Moderately critical – Information disclosure – SA-

– https://www.drupal.org/project/module_filter/releases/7.x-2.2 – [Moderately critical – Cross site scripting – SA- CONTRIB-2019-042](https://www.drupal.org/sa-contrib-2019-042)

– https://www.drupal.org/project/path_breadcrumbs/releases/7.x-3.4 – [Less critical – Cross site scripting – SA- CONTRIB-2019-027](https://www.drupal.org/sa-contrib-2019-027)

– https://www.drupal.org/project/context/releases/7.x-3.10 – [Moderately critical – Cross site scripting – SA- CONTRIB-2019-028](https://www.drupal.org/sa-contrib-2019-028) – https://www.drupal.org/project/context/releases/7.x-3.9 – https://www.drupal.org/project/context/releases/7.x-3.8

– https://www.drupal.org/project/xmlsitemap/releases/7.x-2.6 – https://www.drupal.org/project/xmlsitemap/releases/7.x-2.5 – https://www.drupal.org/project/xmlsitemap/releases/7.x-2.4 – [Moderately critical – Information Disclosure – SA- CONTRIB-2018-053](https://www.drupal.org/sa-contrib-2018-053) –

– https://www.drupal.org/project/uuid/releases/7.x-1.2 – https://www.drupal.org/project/uuid/releases/7.x-1.1 – [Moderately critical – Arbitrary file upload – SA-CONTRIB-2018-045](https://www.drupal.org/sa- contrib-2018-045)

– https://www.drupal.org/project/ds/releases/7.x-2.16 – https://www.drupal.org/project/ds/releases/7.x-2.15 – [Critical – Cross site scripting (XSS) – SA-CONTRIB-2018-019](https://www.drupal.org/sa- contrib-2018-019)

Update to 4.6.6 Various bugfixes on the 4.6 branch

– https://www.drupal.org/project/ds/releases/7.x-2.16 – https://www.drupal.org/project/ds/releases/7.x-2.15 – [Critical – Cross site scripting (XSS) – SA-CONTRIB-2018-019](https://www.drupal.org/sa- contrib-2018-019)

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

Gen Z Interns and Social Media: A Perfect Security Storm

Insufficient sanitization of the query parameter in search_opensearch.php could lead to reflected cross-site scripting or iframe injection.

Update to 8.2.0.

Researcher Exploits Microsoft’s Notepad to ‘Pop a Shell’

security update

5G Networks Spark Concerns For Enterprise Risks
How to become a better writer with Wordeep using artificial intelligence

Reading Time: ~ 3 min. I’ve been in this business a long time, and I can honestly say that many MSPs lack a concrete sales process structure. That’s pretty worrisome because, let’s face it, you have to have a plan in order to succeed at just about anything. Imagine you’re an engineer working on server […]

Best Cyber Security Certifications 2019

Reading Time: ~ 2 min. News Site Suffers Data Breach Flipboard, a news aggregation site, recently revealed that it’s been the victim of a data breach that could affect many of their more than 100 million active users. Digital tokens were among the compromised data, which could give the attackers further access to other sites, […]

2.3 billion files exposed online

Millions of the files that are sitting out in the open across various file storage technologies are actually encrypted by ransomware The post 2.3 billion files exposed online appeared first on WeLiveSecurity

Nvidia Fixes High-Severity Flaws in GeForce Experience for Gamers

The package live-media before version 2019.05.12-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

The package curl before version 7.65.0-1 is vulnerable to arbitrary code execution.

The package lib32-curl before version 7.65.0-1 is vulnerable to arbitrary code execution.

The package lib32-libcurl-compat before version 7.65.0-1 is vulnerable to arbitrary code execution.

The package lib32-libcurl-gnutls before version 7.65.0-1 is vulnerable to arbitrary code execution.