Menu

Category Archives: Security

Articles about security

WordPress Urges Users to Uninstall Yuzo Plugin After Flaw Exploited
SAS 2019: Fake News Peddlers Adopt Clever New Trick to Fool Facebook, Twitter
WPA3 flaws may let attackers steal Wi-Fi passwords

The new wireless security protocol contains multiple design flaws that hackers could exploit for attacks on Wi-Fi passwords The post WPA3 flaws may let attackers steal Wi-Fi passwords appeared first on WeLiveSecurity

Uncle Sam charges Julian Assange with conspiracy to commit computer intrusion
High-rolling hacker jailed after launching malware attacks via porn websites
Patch blues-day: Microsoft yanks code after some PCs are rendered super secure (and unbootable) following update
Amazon Auditors Listen to Echo Recordings, Report Says

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Several security issues were fixed in Ruby.

An update for ceph and grafana is now available for Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

As you wrap up this month’s patch installs, don’t forget these four Intel fixes

An update for httpd24-httpd and httpd24-mod_auth_mellon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Mathy Vanhoef (NYUAD) and Eyal Ronen (Tel Aviv University & KU Leuven) found multiple vulnerabilities in the WPA implementation found in wpa_supplication (station) and hostapd (access point). These vulnerability are also collectively known as “Dragonblood”.

The package thunderbird before version 60.6.1-1 is vulnerable to arbitrary code execution.

The package apache before version 2.4.39-1 is vulnerable to multiple issues including privilege escalation, access restriction bypass and denial of service.

The package gnutls before version 3.6.7-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

The package evolution before version 3.32.0-1 is vulnerable to content spoofing.

Lazarus Group rises again from the digital grave with Hoplight malware for all
Smashing Security #123: Backups – a necessary evil?
The Samsung Galaxy S10’s ultrasonic fingerprint scanner is hacked

Backport more patches: – shared/install: Preserve escape characters for escaped unit names (https://github.com/coreos/bugs/issues/2569) – timedate: fix emitted value when ntp client is enabled/disabled (#1696586) – udev: run programs in the specified order (#1696784) – core: add Manager::honor_device_enumeration flag (https://pagure.io/fedora-

The scourge of stalkerware

Multiple vulnerabilities have been found in Git, the worst of which could result in the arbitrary execution of code.

SAS 2019: Joe FitzPatrick Warns of the ‘$5 Supply Chain Attack’
Taj Mahal and SneakyPastes: Kaspersky reveals pair of attacks menacing Asia, Middle East
You Can Now Get This Award-Winning VPN For Just $1/month

Type: Vulnerability. Microsoft Azure DevOps Server and Team Foundation Server are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server and Team Foundation Server are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server is prone to a spoofing vulnerability; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Open Enclave SDK is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge and Internet Explorer are prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows VBScript Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

An update that fixes 11 vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Yahoo Offers $117.5M Settlement in Data Breach Lawsuit
Hackers claims to steal 6 million Israeli voters data
Samsung Galaxy S10’ biometric sensor hackable with copy of owner’s fingerprint
Cynet is Launching a Free Threat Assessment for Businesses
How to identify & protect yourself from online dating scams

Several security issues were fixed in wpa_supplicant and hostapd.

Credential-stuffing attacks behind 30 billion login attempts in 2018

Streaming media feature among services that take the spotlight in a report on credential-stuffing attacks in 2018 The post Credential-stuffing attacks behind 30 billion login attempts in 2018 appeared first on WeLiveSecurity

Reading Time: ~5 min. Not that long ago, before data breaches dominated daily headlines, we felt secure with our social media apps. Conveniently, every website seemed to allow logging in with Facebook or Twitter instead of creating a whole new password, and families of apps quickly became their own industry. Third-party apps and games on social media platforms (remember […]

An update that solves three vulnerabilities and has 9 fixes is now available.

An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

King’s College London internal memo cops to account ‘compromise’ as uni resets passwords

Several security issues were fixed in Apache.

It was discovered that SPIP, a website engine for publishing, did not properly sanitize its user input. This would allow an authenticated user to perform arbitrary command execution.

SAS 2019: Triton ICS Malware Hits A Second Victim

An update that solves one vulnerability and has 5 fixes is now available.

SAS 2019: Gaza Cybergang Blends Sophistication Levels in Highly Effective Spy Effort
SAS 2019: Meet ‘TajMahal,’ A New and Highly Advanced APT Framework
Shock revelation as massive American presidential election hack confirmed

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

New upstream release 0.14.2 which also fixes CVE-2019-3878 and CVE-2019-3877

update to the bugfix release 3.9.0

update to the bugfix release 3.9.0

It’s raining patches, Hallelujah! Microsoft and Adobe put out their latest major fixes

security update

Intel Patches High-Severity Flaws in Media SDK, Mini PC

An update that fixes one vulnerability is now available.

Best password managers for 2019
Yahoo! tries! again! with! 3 billion! email! account! theft! payout!

Various vulnerabilities were discovered in Samba, SMB/CIFS file, print, and login server/client for Unix

Adobe Fixes 24 Critical Flaws in Acrobat Reader, Flash, Shockwave Player

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Brit hacker jailed for strapping ransomware to smut site ad networks
Samsung Galaxy S10 Fingerprint Sensor Duped With 3D Print
Sharpen your security skills at SANS Dublin 2019
Shadow App Development: Insider Threat or Opportunity?
2 students arrested for disrupting school WiFi to skip exam

An update that fixes three vulnerabilities is now available.

An update for katello-installer-base which configures qpid-dispatch-router is now available for Red Hat Satellite 6.2 for RHEL 6 and Red Hat Satellite 6.2 for RHEL 7. Red Hat Product Security has rated this update as having a security impact

An update for katello-installer-base which configures qpid-dispatch-router is now available for Red Hat Satellite 6.3 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for katello-installer-base which configures qpid-dispatch-router is now available for Red Hat Satellite 6.4 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Verizon Router Command Injection Flaw Impacts Millions
SAS 2019: 4 Stuxnet-Related APTs Form Gossip Girl, an ‘Apex Threat Actor’

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

OceanLotus: macOS malware update

Latest ESET research describes the inner workings of a recently found addition to OceanLotus’s toolset for targeting Mac users The post OceanLotus: macOS malware update appeared first on WeLiveSecurity