Menu

Category Archives: Security

Articles about security

MacOS Zero-Day Allows Trusted Apps to Run Malicious Code
Legacy app whitelist can be abused to bypass latest macOS security features, expert warns
Facebook lawyer argues you should have ‘no expectation of privacy’

An update that fixes four vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Pharma-testing biz Eurofins Scientific says it fell victim to ‘new version’ of malware

An update that fixes 8 vulnerabilities is now available.

An update that solves 5 vulnerabilities and has 6 fixes is now available.

An update that fixes three vulnerabilities is now available.

Data protection authority reports itself to itself after data breach
5G Security Challenges: A Vendor’s POV

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Nginx nJS will need patches, hotels exposed via security systems, Docker containers dinged, and more
5 Best VPN Apps for Android 2019

An update that fixes 16 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

– https://www.drupal.org/project/views/releases/7.x-3.23 – https://www.drupal.org/project/views/releases/7.x-3.22 – https://www.drupal.org/project/views/releases/7.x-3.21 – [Less critical – Cross site scripting – SA-CONTRIB-2019-036](https://www.drupal.org/sa- contrib-2019-036) – [Moderately critical – Information disclosure – SA-

– https://www.drupal.org/project/module_filter/releases/7.x-2.2 – [Moderately critical – Cross site scripting – SA- CONTRIB-2019-042](https://www.drupal.org/sa-contrib-2019-042)

– https://www.drupal.org/project/path_breadcrumbs/releases/7.x-3.4 – [Less critical – Cross site scripting – SA- CONTRIB-2019-027](https://www.drupal.org/sa-contrib-2019-027)

– https://www.drupal.org/project/context/releases/7.x-3.10 – [Moderately critical – Cross site scripting – SA- CONTRIB-2019-028](https://www.drupal.org/sa-contrib-2019-028) – https://www.drupal.org/project/context/releases/7.x-3.9 – https://www.drupal.org/project/context/releases/7.x-3.8

– https://www.drupal.org/project/xmlsitemap/releases/7.x-2.6 – https://www.drupal.org/project/xmlsitemap/releases/7.x-2.5 – https://www.drupal.org/project/xmlsitemap/releases/7.x-2.4 – [Moderately critical – Information Disclosure – SA- CONTRIB-2018-053](https://www.drupal.org/sa-contrib-2018-053) –

– https://www.drupal.org/project/uuid/releases/7.x-1.2 – https://www.drupal.org/project/uuid/releases/7.x-1.1 – [Moderately critical – Arbitrary file upload – SA-CONTRIB-2018-045](https://www.drupal.org/sa- contrib-2018-045)

– https://www.drupal.org/project/ds/releases/7.x-2.16 – https://www.drupal.org/project/ds/releases/7.x-2.15 – [Critical – Cross site scripting (XSS) – SA-CONTRIB-2018-019](https://www.drupal.org/sa- contrib-2018-019)

Update to 4.6.6 Various bugfixes on the 4.6 branch

– https://www.drupal.org/project/ds/releases/7.x-2.16 – https://www.drupal.org/project/ds/releases/7.x-2.15 – [Critical – Cross site scripting (XSS) – SA-CONTRIB-2018-019](https://www.drupal.org/sa- contrib-2018-019)

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

Gen Z Interns and Social Media: A Perfect Security Storm

Insufficient sanitization of the query parameter in search_opensearch.php could lead to reflected cross-site scripting or iframe injection.

Update to 8.2.0.

Researcher Exploits Microsoft’s Notepad to ‘Pop a Shell’

security update

5G Networks Spark Concerns For Enterprise Risks
How to become a better writer with Wordeep using artificial intelligence

Reading Time: ~ 3 min. I’ve been in this business a long time, and I can honestly say that many MSPs lack a concrete sales process structure. That’s pretty worrisome because, let’s face it, you have to have a plan in order to succeed at just about anything. Imagine you’re an engineer working on server […]

Best Cyber Security Certifications 2019

Reading Time: ~ 2 min. News Site Suffers Data Breach Flipboard, a news aggregation site, recently revealed that it’s been the victim of a data breach that could affect many of their more than 100 million active users. Digital tokens were among the compromised data, which could give the attackers further access to other sites, […]

2.3 billion files exposed online

Millions of the files that are sitting out in the open across various file storage technologies are actually encrypted by ransomware The post 2.3 billion files exposed online appeared first on WeLiveSecurity

Nvidia Fixes High-Severity Flaws in GeForce Experience for Gamers

The package live-media before version 2019.05.12-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

The package curl before version 7.65.0-1 is vulnerable to arbitrary code execution.

The package lib32-curl before version 7.65.0-1 is vulnerable to arbitrary code execution.

The package lib32-libcurl-compat before version 7.65.0-1 is vulnerable to arbitrary code execution.

The package lib32-libcurl-gnutls before version 7.65.0-1 is vulnerable to arbitrary code execution.

The package libcurl-gnutls before version 7.65.0-1 is vulnerable to arbitrary code execution.

The package libcurl-compat before version 7.65.0-1 is vulnerable to arbitrary code execution.

An update that solves two vulnerabilities and has one errata is now available.

You go that way, we’ll go Huawei: China Computer Federation kicks back at IEEE in tit-for-tat spat

An update that fixes 13 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

Own goal for Leicester City FC after fan credit card details snatched in merch store hack
New Linux Malware ‘HiddenWasp’ Borrows from Mirai, Azazel
Mozilla returns crypto-signed website packaging spec to sender – yes, it’s Google

security update

Senator: US govt staff may be sending their smartphone web traffic ‘wrapped in a bow’ to Russia, China via VPNs

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

AI, the Mandatory Element of 5G Mobile Security
ProtonMail denies that it offers real-time surveillance assistance

Ben Barnea and colleagues from VDOO discovered several vulnerabilities in miniupnpd, a small daemon that provides UPnP Internet Gateway Device and Port Mapping Protocol services.

POS Malware Found at 102 Checkers Restaurant Locations
New Zealand budget details leaked due to website sloppiness, not hackers
HiddenWasp malware seizes control of Linux systems

– https://www.drupal.org/project/entity/releases/7.x-1.9 – https://www.drupal.org/sa-contrib-2018-013

Microarchitectural Data Sampling speculative side channel [XSA-297, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091] additional patches so above applies cleanly work around grub2 issues in dom0

2.3B Files Exposed in a Year: A New Record for Misconfigs
We ain’t afraid of no ‘ghost user’: Infosec world tells GCHQ to GTFO over privacy-busting proposals

Reading Time: ~ 4 min. As technology continues to evolve, several trends are staying consistent. First, the volume of data is growing exponentially. Second, human analysts can’t hope to keep up—there just aren’t enough of them and they can’t work fast enough. Third, adversarial attacks that target data are also on the rise. Given these […]

Smashing Security #130: Doctored videos, Bcc blunders, and a diva

This is the 6 month notification for the retirement of Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions (E4S) and Telecommunications Update Service (TUS). This notification applies only to those customers subscribed to the Update Services for SAP Solutions (E4S) and

An update for go-toolset-1.11 and go-toolset-1.11-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for JBoss Core Services on RHEL 6 and RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Red Hat JBoss Core Services Pack Apache Server 2.4.29 Service Pack 2 zip release for RHEL 6 and RHEL 7 is available. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Nightwatch Cybersecurity Research team identified a XSS vulnerability in tomcat7. The SSI printenv command echoes user provided data without escaping. SSI is disabled by default. The printenv command is intended

The aftermath of a data breach: A personal story

Criminals used my account to launder credit card transactions into cash, at least where the company transacted with was willing to refund The post The aftermath of a data breach: A personal story appeared first on WeLiveSecurity

Chinese software nasty enslaves stadium-load of servers, puts them to work digging up digital dosh in crypto-mines

– https://www.drupal.org/project/entity/releases/7.x-1.9 – https://www.drupal.org/sa-contrib-2018-013

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Git your patches here! GitHub offers to brew automatic pull requests loaded with vuln fixes
‘5G is Coming,’ But Can the Security Industry Keep Up?
ProtonMail filters this into its junk folder: New claim it goes out of its way to help cops spy

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.