Menu

Category Archives: Security

Articles about security

Survey: What should companies do to restore trust post-breach?

The ESET survey among thousands of people in Asia-Pacific (APAC) provides valuable insight into their perceptions of cyber-threats and various common aspects of online security The post Survey: What should companies do to restore trust post-breach? appeared first on WeLiveSecurity

$100 million GozNym cybercrime network dismantled as suspects charged
Forbes subscribers warned of Magecart threat skimming credit card details

An update that fixes 6 vulnerabilities is now available.

An update that solves 11 vulnerabilities and has 20 fixes is now available.

Cisco Service Provider, WebEx Bugs Offer Up Remote Code Execution
Cybercrime Gang Behind GozNym Banking Malware Dismantled
Oh, the irony… Malware spread via Best of the Web security seals

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has 6 fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that solves three vulnerabilities and has 8 fixes is now available.

An update that solves four vulnerabilities and has three fixes is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Smashing Security #128: Shackled ankles, photo scrapes, and SIM card swaps

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for rh-python35-python-jinja2 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This update provides the Intel 20190514 microcode release that adds the microcode side mitigations for the Microarchitectural Data Sampling (MDS, also called ZombieLoad attack) vulnerabilities in Intel processors that can allow attackers to retrieve data being processed inside a CPU.

Breaking news: Bank-card-slurping malware sneaks into Forbes’ mag subscription website
Amazon, Apple, Google & Microsoft issue patches to fix ZombieLoad bug

security update

security update

security update

security update

Google Titan Security Key Recalled After Bluetooth Pairing Bug
Titan-ic disaster: Bluetooth blunder sinks Google’s 2FA keys, free replacements offered

Type: Vulnerability. Microsoft Internet Explorer is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure Active Directory Connect is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office Access Connectivity Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

We like transparency and we’re a CA, hackers hack all night and we log all day
Intel ZombieLoad Side-Channel Attack: 10 Takeaways
Hackers interrupt Eurovision webcast in Israel with missile attack alert

Reading Time: ~3 min. It’s a familiar story in tech: new technologies and shifting preferences raise new security challenges. One of the most pressing challenges today involves monitoring and securing all of the applications and data currently undergoing a mass migration to public and private cloud platforms. Malicious actors are motivated to compromise and control […]

Billions of Malicious Bot Attacks Take to Cipher-Stunting to Hide
Supreme Court says secret UK spy court’s judgments can be overruled after all

An update for ruby is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Ice Hockey World Championship: The risks of free live streaming

You think you’re watching the games for free, but are you sure that’s the case? Let’s review some of the risks that may come with free live streaming websites The post Ice Hockey World Championship: The risks of free live streaming appeared first on WeLiveSecurity

MI5 slapped on the wrist for ‘serious’ surveillance data breach
Israeli TV’s Eurovision webcast hijacked by hackers. Hamas blamed
A deeper look at the MDS vulnerability
Modern IT security: Sometimes caring is NOT sharing
Understanding the MDS vulnerability: What it is, why it works and how to mitigate it
Microsoft worm warning: Windows users urged to patch now
Microsoft emits free remote-desktop security patches for WinXP to Server 2008 to avoid another WannaCry

security update

Microsoft Patches Zero-Day Bug Under Active Attack
Apple Patches Intel Side-Channel Bugs; Updates iOS, macOS and More
Trend Micro is one of the anti-virus firms hacked by Fxsmsp

The update for ghostscript released as DSA 4442-1 uncovered an issue in cups-filters which was using the undocumented Ghostscript internal “pdfdict” now hidden in the ghostscript update. Updated cups-filters packages are now available to correct this issue.

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

VCFTools could be made to crash if it received specially crafted input.

Intel CPUs Impacted By New Class of Spectre-Like Attacks
Buffer the Intel flayer: Chipzilla, Microsoft, Linux world, etc emit fixes for yet more data-leaking processor flaws
Adobe Addresses Critical Adobe Flash Player, Acrobat Reader Flaws
WhatsApp flaw lets hackers install spyware on iOS & Android devices
Linux Kernel Flaw Allows Remote Code-Execution
WhatsApp Zero-Day Exploited in Targeted Spyware Attacks
Cynet: An Autonomous Security Platform for Any Size Organization

An update for wget is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Plead malware distributed via MitM attacks at router level, misusing ASUS WebStorage

ESET researchers have discovered that the attackers have been distributing the Plead malware via compromised routers and man-in-the-middle attacks against the legitimate ASUS WebStorage software The post Plead malware distributed via MitM attacks at router level, misusing ASUS WebStorage appeared first on WeLiveSecurity

An update is now available for Satellite Tools 6.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Seize the chance to boost your IT security skills: Trio of training events to choose from

Red Hat Satellite 6.5 for RHEL 7 is now available containing security fixes, bug fixes, and enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Urgent! Update WhatsApp NOW to add new sticker support

Isaac Boukris and Andrew Bartlett discovered that the S4U2Self Kerberos extension used in Samba’s Active Directory support was susceptible to man-in-the-middle attacks caused by incomplete checksum validation.

Multiple issues have been addressed in Qt4. CVE-2018-15518

It’s 2019 and a WhatsApp call can hack a phone: Zero-day exploit infects mobes with spyware

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Pair of Cisco Bugs, One Unpatched, Affect Millions of Devices
Twitter Leaks Apple iOS Users’ Location Data to Ad Partner