Menu

Category Archives: Security

Articles about security

An update that fixes three vulnerabilities is now available.

Soaring Cryptocurrency Prices Draw Malicious New Onslaught of Apps, Malware

Security fix for CVE-2019-11328

We’ll hack back at Russians, declare UK ministers in cyber-Blitz blitz
Phisher folk reel in Computacenter security vetting mailbox packed with sensitive staff data
Fake cryptocurrency apps crop up on Google Play as bitcoin price rises

ESET researchers have analyzed fake cryptocurrency wallets emerging on Google Play at the time of bitcoin’s renewed growth The post Fake cryptocurrency apps crop up on Google Play as bitcoin price rises appeared first on WeLiveSecurity

WannaCry-Infested Laptop Starts at $1.13M in Art Auction
Fingerprinting iPhones with the built-in gyroscope
Critical Flaws in Khan Academy Opened Door to Account Takeovers
Patch now! Why the BlueKeep vulnerability is a big deal

What you need to know about the critical security hole that could enable the next WannaCryptor The post Patch now! Why the BlueKeep vulnerability is a big deal appeared first on WeLiveSecurity

Google says it stored some G Suite passwords in plain text for 14 years
US Air Force probes targeted malware attack, blames… er, the US Navy? What?
Windows Zero-Day Drops on Twitter, Developer Promises 4 More

An update that fixes four vulnerabilities is now available.

Google Stored G Suite Passwords in Plaintext Since 2005
Google stored business customers’ passwords in plaintext on its servers… for 14 years
Data on millions of Instagram accounts spills onto the internet

An update that fixes one vulnerability is now available.

6 keys to MongoDB database security
A journey to Zebrocy land

ESET sheds light on commands used by the favorite backdoor of the Sednit group The post A journey to Zebrocy land appeared first on WeLiveSecurity

An update for python27-python and python27-python-jinja2 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dotnet is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Bug-hunter reveals another ‘make me admin’ Windows 10 zero-day – and vows: ‘There’s more where that came from’
G Suite’n’sour: Google resets passwords after storing some unhashed creds for months, years

An update that fixes 5 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Database with millions of Instagram influencers’ info leaked online

– New upstream version (67.0) – Release notes are available at https://www.mozilla.org/en-US/firefox/67.0/releasenotes/

Updates the nss package to upstream NSS 3.44. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.44_release_notes

Mozilla Tackles Two Critical Flaws with Firefox 67 Release
Intel Fixes Critical, High-Severity Flaws Across Several Products
Data Security in the Cloud: How to Lock Down the Next-Gen Perimeter

An update that fixes 5 vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Hackers hacked: Account hijacking forum OGUsers pwned
What the ban on facial recognition tech will – and will not – do

As San Francisco moves to regulate the use of facial recognition systems, we reflect on some of the many ‘faces’ of the fast-growing technology The post What the ban on facial recognition tech will – and will not – do appeared first on WeLiveSecurity

Cisco Starts Patching Firmware Bug; Millions of Devices Still Vulnerable
Cybersecurity training and awareness: helpful resources for educators

Free resources for cybersecurity awareness and training are out there – links to many of them are provided here The post Cybersecurity training and awareness: helpful resources for educators appeared first on WeLiveSecurity

HCL Exposes Customer, Personnel Info in Wide-Ranging Data Leak
Millions of Golfers Land in Privacy Hazard After Cloud Misconfig
Mining cryptocurrency at work lands Australian civil servant in court

Reading Time: ~3 min. Technology has unlocked a new type of worker, unlike any we have seen before—the digital nomad. Digital nomads are people who use technologies like WiFi, smart devices, and cloud-based applications to work from wherever they please. For some digital nomads, this means their favorite coffee shop or co-working space. For others, it means an idyllic […]

iPhone gyroscopes, of all things, can uniquely ID handsets on anything earlier than iOS 12.2

An update that fixes two vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Gmail wittingly storing your online purchase data for years

Fixes possible man-in-the-middle security vulnerability – CVE-2019-11065

This update fixes security vulnerability – Checkstyle loads external DTDs by default. Upstream issue: https://github.com/checkstyle/checkstyle/issues/6474 https://github.com/checkstyle/checkstyle/issues/6478 References: https://checkstyle.org/releasenotes.html#Release_8.18

Sharing Threat Intelligence: Time for an Overhaul
Windows 10 Update Bricks PCs, Microsoft Offers Workarounds
Salesforce Woes Linger as Admins Clean Up After Service Outage
Sophos tells users to roll back Microsoft’s Patch Tuesday run if they want PC to boot
Behind the Naming of ZombieLoad and Other Intel Spectre-Like Flaws
Google bans Huawei from accessing Android & its licensed apps
Boeing admits 737 Max sims didn’t accurately reproduce what flying without MCAS was like
Slack Bug Allows Remote File Hijacking, Malware Injection
ZombieLoad: How Intel’s Latest Side Channel Bug Was Discovered and Disclosed

Multiple vulnerabilities have been discovered in jruby, Java implementation of the Ruby programming language.

Several security vulnerabilities have been discovered in drupal7, a PHP web site platform. The vulnerabilities affect the embedded versions of the jQuery JavaScript library and the Typo3 Phar Stream Wrapper library.

TeamViewer was Targeted by Chinese Hackers in 2016

An update that fixes one vulnerability is now available.

An update that solves 14 vulnerabilities and has 90 fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update is now available for Red Hat Quay 3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Firms, stop sending out automated emails that look suspicious as hell!
Let adware be treated as malware, Canuck boffins declare after breaking open Wajam ad injector

gnome-desktop 3.30.2.3 release, fixing thumbnailer sandbox escape, CVE-2019-11460

Multiple vulnerabilities have been discovered in graphicsmagick, the image processing toolkit: CVE-2019-11473

A vulnerability was discovered in libspring-security-2.0-java, a modular Java/J2EE application security framework, when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance,

The update for ghostscript released as DLA-1792-1 uncovered an issue in cups-filters which was using the undocumented Ghostscript internal “pdfdict” now hidden in the ghostscript update. Updated cups-filters

* Fix rendering of emojis copy-pasted from GTK emoji chooser. * Fix space characters not being rendered with some CJK fonts. * Fix adaptive streaming playback with older GStreamer versions. * Set a maximum zoom level for pinch zooming gesture. * Fix navigation gesture to not interfere with scrolling. * Fix SSE2 detection at compile […]

CIA traitor spy thrown in the clink for selling secrets to China. Stack Overflow, TeamViewer admit: We were hacked…
Giga-hurts radio: Terrorists build Wi-Fi bombs to dodge cops’ cellphone jammers
WordPress WP Live Chat Support Plugin Fixes XSS Flaw
It’s not chicken feed: Million-dollar meal deal for livestock sabotaged by hackers… and, er, exchange rates
Ransomware ‘Remediation’ Firm Exposed: Researchers Weigh in on Paying
How Decoding Network Traffic Can Save Your Data Bacon

Reading Time: ~2 min. WhatsApp Exploited to Install Spyware through Calls A serious flaw has been discovered in the messaging app WhatsApp that would allow an attacker to install spyware on a victim’s device by manipulating the packets being sent during the call. Further disguising the attack, the malicious software could be installed without the […]

Get out of Huawei, it’s an avalanche of news from everyone’s favourite Chinese bogeyman

An update that fixes 6 vulnerabilities is now available.

The minified jquery library was broken in version 1.7.2+dfsg-3.2+deb8u6 due to an error during the build. This problem has now been fixed in version 1.7.2+dfsg-3.2+deb8u7

News Wrap: WhatsApp, Microsoft, Intel and Cisco Flaws

An update that fixes 8 vulnerabilities is now available.

Good heavens, is it time to patch Cisco kit again? Prime Infrastructure root privileges hole plugged
Freed whistleblower Chelsea Manning back in jail for refusing to testify before secret grand jury
Bank-account-raiding Goznym malware bust: Five suspects collared, five still on the run. $100m feared stolen

– [3.1.1](https://github.com/TYPO3/phar-stream-wrapper/releases/tag/v3.1.1) – [TYPO3-PSA-2019-007](https://typo3.org/security/advisory/typo3-psa-2019-007/) / [CVE-2019-11831](https://nvd.nist.gov/vuln/detail/CVE-2019-11831) – [TYPO3-PSA-2019-008](https://typo3.org/security/advisory/typo3-psa-2019-008/) / [CVE-2019-11830](https://nvd.nist.gov/vuln/detail/CVE-2019-11830) –

The plane, it’s ‘splained, falls mainly without the brain: We chat to boffins who’ve found a way to disrupt landings using off-the-shelf radio kit
The Future of Wi-Fi Security: Assessing Vulnerabilities in WPA3
Mobile Risks Boom in a Post-Perimeter World
Forbes Becomes Latest Victim of Magecart Payment Card Skimmer
Office 365 user security practices are woeful, yet it’s still ‘Microsoft’s fault’ when an org is breached