Menu

Category Archives: Security

Articles about security

Man fried over 50 college computers with weaponized USB stick

OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936) (CVE-2019-2602) * OpenJDK: Incorrect skeleton selection in RMI registry server-side dispatch handling (RMI, 8218453) (CVE-2019-2684) SL7 x86_64 java-11-openjdk-11.0.3.7-0.el7_6.i686.rpm java-11-openjdk-11.0.3.7-0.el7_6.x86_64.rpm java-11-openjdk-debuginfo-11.0.3.7-0.el7_6.i686.rpm java-11-openjdk-debuginfo- [More…]

Cisco Patches Critical Flaw In ASR 9000 Routers
Facebook: Yeah, we hoovered up 1.5 million email address books without permission. But it was an accident!
Embracing creativity to improve cyber-readiness

How approaching cybersecurity with creativity in mind can lead to better protection from digital threats The post Embracing creativity to improve cyber-readiness appeared first on WeLiveSecurity

OpenJDK: Font layout engine out of bounds access setCurrGlyphID() (2D, 8219022) (CVE-2019-2698) * OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936) (CVE-2019-2602) * OpenJDK: Incorrect skeleton selection in RMI registry server-side dispatch handling (RMI, 8218453) (CVE-2019-2684) Bug Fix(es): * assert failure in coalesce.cpp: attempted to spill a non-spillable item SL6 [More…]

An update that fixes one vulnerability is now available.

Smashing Security #124: Poisoned porn ads, the A word, and why why why Wipro?
Never Forget That You Are Being Watched
Google hits brand slam stamping AMP with more crypto glam

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Insane in the domain: Sea Turtle hackers pwn DNS orgs to dash web surfers on the rocks of phishing pages
Ubiquitous Bug Allows HIPAA-Protected Malware to Hide Behind Medical Images

security update

security update

An update that fixes one vulnerability is now available.

Researchers: Facebook’s Data-Leveraging Scandal Puts Users on Notice
Enough about me, why do you hate Kaspersky so much? Revealed: Insp Clouseau-esque bid to smear critics as shills
State-Sponsored DNS Hijacking Infiltrates 40 Firms Globally
Bug in EA’s Origin client left gamers open to attacks

The gaming company has rolled out a fix for the remote code execution vulnerability, so make sure you run the platform’s latest version The post Bug in EA’s Origin client left gamers open to attacks appeared first on WeLiveSecurity

ThreatList: Bad Bots Account for a Fifth of All Web Traffic, FinServ Hit the Worst
Oracle Squashes 53 Critical Bugs in April Security Update
A third-party patch for Microsoft’s Internet Explorer zero-day vulnerability
Extortion emails a go-go
It doesn’t matter if you don’t use Internet Explorer, you could still be at risk from this IE zero-day vulnerability
Hackers exploiting unpatched Chrome bug to target 500M iPhone users
Cyber-sec biz Fortinet coughs up $545,000 after ‘flogging’ rebadged Chinese kit to Uncle Sam – but why so low? We may be able to explain
Oracle splats 300 vulns in MySQL, Database, Fusion, etc, pours fresh brew of Java SE terms
The curious case of Spamhaus, a port scanning scandal, and an apparent U-turn
RatVermin Spyware Targets Ukraine Gov Agencies
Wipro Confirms Hack and Supply Chain Attacks on Customers
Crooks are selling “Digital Doppelgangers” to bypass anti-fraud protection
Microsoft reveals breach affecting webmail users

Some users of Microsoft’s web-based email services such as Outlook.com had their account information exposed in an incident that, as it later emerged, also impacted email contents The post Microsoft reveals breach affecting webmail users appeared first on WeLiveSecurity

Windows Zero-Day Emerges in Active Exploits
Your Android phone can now double as a security key

An extra layer of security never hurt anybody, doubly so now that you can turn your phone into a physical security key The post Your Android phone can now double as a security key appeared first on WeLiveSecurity

Malspam Campaigns Distribute HawkEye Keylogger, Post Ownership Change
Kaspersky updates its cybercrook look book: Smashing Office is hot, browser vulns are not
Hackers bragged that pretty vanilla breach included FBI watchlist? Well, colour us shocked
Indian outsourcing giant Wipro confirms flushing phishers from systems

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Top 10 Best Anime Movie Sites 2019
What’s long, hard, and full of seamen? The US Navy’s latest cybersecurity war gaming classes
Just a little FYI: Filtering doodad in Adblock Plus opens door to third-party malware injection
TicTocTrack Smartwatch Flaws Can Be Abused to Track Kids
Fake Instagram Apps on Google Play Harvest User Logins
Authentication Bypass Bug Hits Top Enterprise VPNs
Top VPNs found improperly securing cookies & tokens
Microsoft Outlook Breach Widens in Scope, Impacting MSN And Hotmail – Report
Brit Watchkeeper drone fell in the sea because blocked sensor made algorithms flip out
Hackers could read users’ Outlook, Hotmail, and MSN email via compromised Microsoft support account
Rogue Waves: Preparing the Internet for the Next Mega DDoS Attack
Top The Pirate Bay Alternatives – Best Torrent Download Sites (2019)
Wikileaks founder Julian Assange arrested in London
Nasty Android & iOS malware found using govt surveillance tech

Several security vulnerabilities were discovered in Graphicsmagick, a collection of image processing tools. Heap-based buffer over-reads and a memory leak may lead to a denial-of-service or information disclosure.

* Yaws ver. 2.0.6

This update backports a fix for CVE-2018-20096, CVE-2018-20097, CVE-2018-20098, CVE-2018-20099.

The update of jasper issued as DLA-1628-1 caused a regression due to the fix for CVE-2018-19542, a NULL pointer dereference in the function jp2_decode, which could lead to a denial-of-service. In some cases not only invalid jp2 files but also valid jp2 files were rejected.

This update fixes security vulnerability – Checkstyle loads external DTDs by default. Upstream issue: https://github.com/checkstyle/checkstyle/issues/6474 https://github.com/checkstyle/checkstyle/issues/6478 References: https://checkstyle.org/releasenotes.html#Release_8.18

An update that solves two vulnerabilities and has four fixes is now available.

rssh could be made to run arbitrary commands if it received specially crafted input.

This update fixes security vulnerability – Checkstyle loads external DTDs by default. Upstream issue: https://github.com/checkstyle/checkstyle/issues/6474 https://github.com/checkstyle/checkstyle/issues/6478 References: https://checkstyle.org/releasenotes.html#Release_8.18

Hackers post private data of thousands of Federal agents online
IE under fire, Triton goes under the microscope, and Norsk still reeling from ransomware attack

Reading Time: ~4 min. The process of bringing a cybersecurity product to market can be long and tedious, but Kiran Kumar, Product Director at Webroot, loves to oversee all the moving parts. It keeps him on his toes and immersed in the ever-changing world of security technology. We sat down to chat with Kumar about […]

security update

US-Cert alert! Thanks to a massive bug, VPN now stands for “Vigorously Pwned Nodes”

security update

security update

Risk Level: Very Low. Type: Trojan, Worm.

Bucharest’s Bayrob boys blasted based on bogus buys, Bitcoin banditry, bound to be behind bars
Romanian Duo Convicted of Malware Scheme Infecting 400,000 Computers

Reading Time: ~2 min. Tax Extortion Emails Bring Major Threats A new email campaign has been spotted threatening ransomware and DDoS attacks over fake tax documents allegedly held by the attackers if a Bitcoin ransom isn’t paid. The campaign authors also threaten to send fake tax documents to the IRS through a poorly-worded ransom email […]

North Korea’s Hidden Cobra Strikes U.S. Targets with HOPLIGHT

An update that fixes one vulnerability is now available.

WordPress Yellow Pencil Plugin Flaws Actively Exploited

An update that solves one vulnerability and has 13 fixes is now available.

An update that fixes one vulnerability is now available.

ThreatList: Tax Scammers Launch a Raft of Fake Mobile Apps
Bayrob malware gang convicted of infecting over 400,000 computers worldwide, stealing millions through online auction fraud
Hackers crack university defenses in just two hours

More than 50 universities in the United Kingdom had their cyber-defenses tested by ethical hackers, and the ‘grades’ aren’t pretty The post Hackers crack university defenses in just two hours appeared first on WeLiveSecurity

Hear me speak about how to make a billion dollars through cybercrime

An update that fixes one vulnerability is now available.

US: We’ll pull security co-operation if you lot buy from Huawei

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0710

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0697

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0717

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0711

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 15 fixes is now available.

An update that fixes three vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan, Worm.

Bug-hunters punch huge holes in WPA3 standard for Wi-Fi security
Client-attorney privilege? Not when you’re accused of leaking Vault 7 CIA code
Juniper slips out update after hardcoded credentials left in switches
As Alexa’s secret human army is revealed, we ask: Who else has been listening in on you?