Menu

Category Archives: Security

Articles about security

FYI: Yeah, the cops can force your finger onto a suspect’s iPhone to see if it unlocks, says judge
Facebook May Face $5 Billion FTC Fine for Data Misuse
Sophos antivirus tools. Working Windows box. Latest Patch Tuesday fixes. Pick two: ‘Puters knackered by bad combo

Reading Time: ~4 min. These are the places your digital tracks can be dug up. With a little sleuthing. Experts have warned for years of the risks of using public computers such as those found in libraries, hotels, and airline lounges.  Many warnings focused on the potential for hackers to plant keystroke loggers, or intercept […]

Hackers using Google Sites to spread banking malware
Adware-Ridden Apps in Google Play Infect 30 Million Android Users
WiFi finder app exposes millions of WiFi network passwords
‘We’re not omnipotent,’ trills National Cyber Security Centre in open-armed pitch to UK biz
Point Blank Gamers Targeted with Backdoor Malware
Poll: Are You Creeped Out by Facial Recognition?
Brit spy chief: We need trust or we won’t have a ‘licence to operate in cyberspace’

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 24 fixes is now available.

An update that fixes three vulnerabilities is now available.

Latest Qbot Variant Evades Detection, Infects Thousands
Facial Recognition is Here: But Are We Ready?

An update that solves one vulnerability and has 23 fixes is now available.

The package dovecot before version 2.3.5.2-1 is vulnerable to denial of service.

The package flashplugin before version 32.0.0.171-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

The package jenkins before version 2.172-1 is vulnerable to multiple issues including access restriction bypass and cross-site scripting.

The package ghostscript before version 9.27-1 is vulnerable to sandbox escape.

Bodybuilding.com suffers data breach; issues password reset for all users
WannaCryptor ‘accidental hero’ pleads guilty to malware charges

Marcus Hutchins, who is best known for his inadvertent role in blunting the WannaCryptor outbreak two years ago, may now face a stretch behind bars The post WannaCryptor ‘accidental hero’ pleads guilty to malware charges appeared first on WeLiveSecurity

Carbanak Source Code Unveils a Startlingly Complex Malware
Exploits for Social Warfare WordPress Plugin Reach Critical Mass
Wall Street market exit scam? Admins steal $30 million worth of crypto
FBI: BEC Scam Losses Almost Double To Reach $1.2 Billion

AdvanceCOMP could be made to run arbitrary code if it opened a specially crafted file.

A security update is now available for Red Hat Single Sign-On 7.2 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Security updates for Red Hat Single Sign-On 7.2.7 packages are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Security updates for Red Hat Single Sign-On 7.2.7 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 6 vulnerabilities is now available.

Building a VPN for Mobile Devices at the Network Level

Reading Time: ~5 min. From Landline Hacking to Cryptojacking By its very nature, cybercrime must evolve to survive. Not only are cybersecurity experts constantly working to close hacking loopholes and prevent zero-day events, but technology itself is always evolving. This means cybercriminals are constantly creating new attacks to fit new trends, while tweaking existing attacks to avoid detection. To understand how cybercrime might evolve […]

Several security issues were fixed in PHP.

An update for ovmf is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Cedric Buissart discovered two vulnerabilities in Ghostscript, the GPL PostScript/PDF interpreter, which could result in bypass of file system restrictions of the dSAFER sandbox.

Several security issues were fixed in Pacemaker.

Several security issues were fixed in PHP.

Like that other bloke who rose from the grave, the El Reg security desk is back this week…
Wi-Fi Hotspot Finder Spills 2 Million Passwords
Is Privacy Really iPhone? Researchers Weigh in on Apple’s Targeted Ad Tracking
Evil TeamViewer Attacks Under the Guise of the U.S. State Department
France’s ‘Secure’ Telegram Replacement Hacked in an Hour
WannaCry Hero Pleads Guilty to Kronos Malware Charges
Millions of Medical Documents for Addiction and Recovery Patients Leaked

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Out-of-bounds read and write conditions have been fixed in clamav. CVE-2019-1787

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

The Weather Channel goes offline after ransomware attack

debian-security-support, the Debian security support coverage checker, has been updated in jessie. The jessie relevant changes are: * Mark spice-xpi as end-of-life for Jessie.

An update that solves one vulnerability and has two fixes is now available.

A cross-site scripting vulnerability has been found in Drupal, a fully-featured content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2019-006 .

security update

WannaCry hero MalwareTech pleads guilty to writing banking malware
Wannacry-slayer Marcus Hutchins pleads guilty to two counts of banking malware creation
Microsoft’s Latest Patch Hoses Some Antivirus Software
Defense against the Darknet, or how to accessorize to defeat video surveillance
Not one of the 12 steps: Rehab patients’ details exposed in publicly visible database
Three-Fourths of Consumers Don’t Trust Facebook, Threatpost Poll Finds

An update that solves two vulnerabilities and has two fixes is now available.

ZNC could be made to crash or run programs if it received speciallycrafted network traffic.

Insecure Ride App Database Leaks Data of 300K Iranian Drivers

Reading Time: ~2 min. Major IT Outsourcer Suffers After Phishing Attack Global IT services provider Wipro announced they are in the process of investigating a data possibly affecting some of their clients. These types of companies are popular for hackers because, by breaching a single IT service company, they gain access to a far larger […]

An update that contains security fixes can now be installed.

Old-school cruel: Dodgy PDF email attachments enjoying a renaissance
Facebook: Storing Instagram passwords in plain text & harvesting your emails
We’ve read the Mueller report. Here’s what you need to know: ██ ██ ███ ███████ █████ ███ ██ █████ ████████ █████
Weather Channel Knocked Off-Air in Dangerous Precedent
Shopify Flaw Exposed Thousands of Merchants’ Revenue, Traffic Numbers
Who’s using Mueller Report Day to bury bad news? If you guessed Facebook, you’re right: Millions more passwords stored in plaintext

Fixes for https://bugzilla.redhat.com/show_bug.cgi?id=1694523

Fixes for https://bugzilla.redhat.com/show_bug.cgi?id=1697217

Poll: Facebook Harvests Email Contacts for 1.5M Users – Is Enough, Enough?

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes 11 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Facebook hoovered up 1.5 million users’ email contacts without permission… “unintentionally”
Facebook’s role in Brexit – and the threat to democracy
Easter Attack Affects Half a Billion Apple iOS Users via Chrome Bug

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.