Menu

Category Archives: Security

Articles about security

ProtonMail filters this into its junk folder: New claim it goes out of its way to help cops spy

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

5G IoT: Literally a Matter of Life or Death

Risk Level: Very Low. Type: Trojan.

IEEE tells contributors with links to Chinese corp: Don’t let the door hit you on Huawei out
News aggregator app Flipboard hacked; user data stolen
WordPress Plugin Has Unpatched Privilege Escalation Flaw, Warn Researchers
Top UK Official: Huawei Is ‘Bad Security’

An update that fixes two vulnerabilities is now available.

Teen hacked Apple twice hoping for a job
50k Servers Infected with Cryptomining Malware in Nansh0u Campaign

Reading Time: ~ 4 min. Cities are expanding their technological reach. Many of their efforts work to increase public protections, such as using GPS tracking to help first responders quickly locate the site of a car accident. But, in the rush for a more secure and technologically advanced city, privacy can fall by the wayside. We’ve reviewed the top cities around the […]

News aggregator app Flipboard hacked: All passwords reset after hackers pinch user data
What Red Hat learns at our Security Symposium events: a product manager’s point of view
Infosec bloke claims: Pornhub owner shafted me after I exposed gaping holes in its cartoon smut platform
Hackers stole Flipboard users’ email addresses and hashed passwords
A dive into Turla PowerShell usage

ESET researchers analyze new TTPs attributed to the Turla group that leverage PowerShell to run malware in-memory only The post A dive into Turla PowerShell usage appeared first on WeLiveSecurity

An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Guilty of hacking in the UK? Worry not: Stats show prison is unlikely

Two more security issues have been corrected in multiple demuxers and decoders of the libav multimedia library.

Contain yourself, Docker: Race-condition bug puts host machines at risk… sometimes, ish
Online graphic-design tool Canva hacked; 139 million accounts stolen

Update to version 0.9.5.4. Resolves CVE-2018-20433 and CVE-2019-5427.

Two weeks after Microsoft warned of Windows RDP worms, a million internet-facing boxes still vulnerable

Update to version 0.9.5.4. Resolves CVE-2018-20433 and CVE-2019-5427.

**MySQL 8.0.16** **Release notes:** https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-16.html **Devel Blog:** https://mysqlserverteam.com/the-mysql-8-0-16-maintenance-release- is-generally-available/ **Bugs fixed:** A lot of tests fixed **CVEs fixed:** Unfortunatelly, I don’t have the list of truly CVEs affecting

Germany mulls giving end-to-end chat app encryption das boot: Law requiring decrypted plain-text is in the works
200k Personal Records Exposed by Events Planning Firm
Gatekeeper Bug in MacOS Mojave Allows Malware to Execute
Equifax stripped of ‘stable’ outlook over 2017 breach

Add that to the US$1.4 billion that the massive incident has cost the company so far The post Equifax stripped of ‘stable’ outlook over 2017 breach appeared first on WeLiveSecurity

One Million Devices Open to Wormable Microsoft BlueKeep Flaw

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The package webkit2gtk before version 2.24.2-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

pacemaker: Insufficient local IPC client-server authentication on the client’s side can lead to local privesc (CVE-2018-16877) * pacemaker: Insufficient verification inflicted preference of uncontrolled processes can lead to DoS (CVE-2018-16878) * pacemaker: Information disclosure through use-after-free (CVE-2019-3885) SL7 x86_64 pacemaker-1.1.19-8.el7_6.5.x86_64.rpm pacemaker-cl [More…]

World’s most dangerous laptop has been sold for $1.3 million

The package firefox before version 67.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, same-origin policy bypass, content spoofing, information disclosure, cross-site scripting and denial of service.

The package thunderbird before version 60.7.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, same-origin policy bypass, information disclosure and denial of service.

An update that solves four vulnerabilities and has 9 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes four vulnerabilities is now available.

Seize the chance to boost your IT security skills: SANS London has plenty of courses for you
What to do if your email is found on the Dark Web

Risk Level: Very Low. Type: Trojan.

YouTuber hacks fingerprint scanner of OnePlus 7 Pro using hot glue
Baltimore city ransomware attack is powered by stolen NSA hacking tool

Risk Level: Very Low. Type: Trojan.

An update that fixes one vulnerability is now available.

Chinese Spy Group Mixes Up Its Malware Arsenal with Brand-New Loaders

An update that fixes four vulnerabilities is now available.

ThreatList: Top 8 Threat Actors Targeting Canada in 2019

An update for pacemaker is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for pacemaker is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that solves 5 vulnerabilities and has 6 fixes is now available.

Risk Level: Very Low. Type: Trojan.

Why So Many Businesses Can Never Recover After Cyber Attacks
Xbox Two vs PlayStation 5: Which console is winning the race of anticipation?

It was discovered that there was a use after free vulnerability in minissdpd, a network device discovery daemon. A remote attacker could abuse this to crash the process.

Code cleanups and Simplifications: * in stream instance and main connection output handling for a common strategy in h2/h2c versions of the protocol. Stream instances are kept in one place which will make future optimizations in state handling easier. * Discarding idea of re-using bucket beams and let them live for one request only. Removing […]

security update

security update

security update

cURL, an URL transfer library, contains a heap buffer overflow in the function tftp_receive_packet() that receives data from a TFTP server. It calls recvfrom() with the default size for the buffer rather than with the size that was used to allocate it. Thus, the content that

Reading Time: ~4 min. In a constantly evolving cyber landscape, it’s no simple task to keep up with every new threat that could potentially harm customers. Webroot Senior Threat Research Analyst Kelvin Murray highlighted the volume of threats he and his peers are faced with in our latest conversation. From finding new threats to answering questions from the press, Kelvin has become a trusted voice in the cybersecurity industry. What is your favorite part of working […]

A read past allocated buffer vulnerability and two heap-buffer overflow vulnerabilites were discovered in the PHP5 programming language within the Exif image module.

Millions of personal files exposed by insurance biz, serial web hacker strikes again, and more from infosec land

Several vulnerabilities have been found in wireshark, a network traffic analyzer. CVE-2019-10894

Security fix for CVE-2019-12083

Snapchat Privacy Blunder Piques Concerns About Insider Threats
Joomla and WordPress Found Harboring Malicious Redirect Code
Crypto tumbler BestMixer.io seized for large-scale money laundering
Microsoft Beefs Up Wi-Fi Protection

Reading Time: ~2 min. Banking Trojan Shuts Down Ohio School District After the discovery of the banking Trojan known as Trickbot, an Ohio school district was forced to cancel school since they were unable to fully disinfect the networks before classes resumed the following Monday. Preliminary reports have concluded that no students were responsible for […]

London Underground passengers told to turn off their Wi-Fi if they don’t want to be tracked

An update that fixes 5 vulnerabilities is now available.

News Wrap: Which Companies Are Doing Privacy Right and Which Aren’t?
Snapchat workers snooped on users with internal tool

A vulnerability was found in the WPA protocol implementation found in wpa_supplication (station) and hostapd (access point). The EAP-pwd implementation in hostapd (EAP server) and wpa_supplicant (EAP

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Maker of US border’s license-plate scanning tech ransacked by hacker, blueprints and files dumped online
WikiLeaks boss Assange acted as a foreign spy, Uncle Sam exclaims in fresh rap sheet
Goodbye Passwords: Hello Identity Management

security update

security update

Why telcos ‘handed over’ people’s GPS coords to a bounty hunter: He just had to ask nicely
Shade Ransomware Expands to U.S. Targets
Calibration Attack Drills Down on iPhone, Pixel Users
World’s most dangerous laptop ‘Persistence of Chaos’ is up for auction
Smashing Security #129: Too Long; Didn’t Listen
British Army cyber ‘n’ psyops unit 77 Brigade can’t even brainwash civvies into helping it meet recruitment targets
SandboxEscaper Drops Three More Windows Exploits, IE Zero-Day
Download official version of Tor browser on Android devices