Menu

Category Archives: Security

Articles about security

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

Hackers using hacked WordPress & Joomla sites to drop malware

It was discovered that missing input sanitising in the file module of Drupal, a fully-featured content management framework, could result in cross-site scripting.

How to Respond to a Cyber Attack on Your Business

An update that fixes two vulnerabilities is now available.

An update that solves 14 vulnerabilities and has 5 fixes is now available.

An update that solves 15 vulnerabilities and has 10 fixes is now available.

An update that solves two vulnerabilities and has 10 fixes is now available.

An update that solves 6 vulnerabilities and has 21 fixes is now available.

Don’t be foolish when it comes to data security

Dovecot could be made to crash or run programs as an administrator if it opened a specially crafted file.

This update includes the changes in tzdata 2019a for the Perl bindings. For the list of changes, see DLA-1744-1. For Debian 8 “Jessie”, this problem has been fixed in version

VMware emits security alerts, Planet Hollywood chain hacked, SWAT death caller gets 20 years in clink, and more

security update

Several vulnerabilities have been found in php5, a server-side, HTML-embedded scripting language.

security update

Brit founder of Windows leaks website BuildFeed, infosec bod spared jail over Microsoft hack
​Brush up your cybersecurity credentials at SANS Stockholm 2019

Update to 3.0. License has changed to ASL 2.0 + exception. See https://github.com/michaelrsweet/mxml/releases/tag/v3.0 for more info.

Security fix for CVE-2018-19872

Medical Weed Dispensary Exposes Health Data for Thousands

A security vulnerability was discovered in gpsd, the Global Positioning System daemon. A stack-based buffer overflow may allow remote attackers to execute arbitrary code via traffic on port 2947/TCP or crafted JSON inputs.

Multiple security issues have been found in the Thunderbird mail client, which could lead to the execution of arbitrary code or denial of service. For the stable distribution (stretch), these problems have been fixed in

The impact of the GDPR – privacy matters

An update that contains security fixes can now be installed.

An update that fixes three vulnerabilities is now available.

An update that solves two vulnerabilities and has 53 fixes is now available.

Undocumented Intel VISA Tech Can Be Abused, Researchers Allege

security update

An update that solves four vulnerabilities and has 7 fixes is now available.

An update that fixes 11 vulnerabilities is now available.

An update that solves 9 vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Family locator app leaked real-time location data of 238,000 individuals
Critical RCE Bug in Cisco WebEx Browser Extensions Faces ‘Ongoing Exploitation’
Brit founder of Windows leaks website Buildfeed and infosec bod spared jail for hacking Microsoft
New Gustuff Android malware targets cryptocurrency & messaging apps
Magento Patches Critical SQL Injection and RCE Vulnerabilities
Zero-Day Bug Lays Open TP-Link Smart Home Router

Reading Time: ~2 min. First GDPR Fine Issued in Poland The first fine issued from the Polish privacy regulator has been issued to an unnamed firm for quietly gathering personal data for over 6 million Polish citizens and using it for commercial gains without consent. The fine of £187,000 was generated after officials learned that only […]

Terrorist’s mainfesto used to spread disk-wiping malware

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that fixes four vulnerabilities is now available.

Critical Rockwell Automation Bug in Drive Component Puts IIoT Plants at Risk

An update that solves one vulnerability and has four fixes is now available.

An update that fixes two vulnerabilities is now available.

Privacy in 2019: 6 Basic Steps to Keep Yourself Protected

Updated pdns packages fix security vulnerability: An issue has been found in PowerDNS Authoritative Server when the HTTP remote backend is used in RESTful mode (without post=1 set), allowing a remote user to cause the HTTP backend to connect to an attacker-specified

The updated live, mplayer, vlc packages fix security vulnerabilities: liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation

This kernel update is based on the upstream 4.14.106 and fixes atleast the following security issue: In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers

Updated openjpeg2 packages fix security vulnerability: Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service

The updated file packages fix security vulnerabilities: do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360. (CVE-2019-8905)

The updated poppler packages fix security vulnerabilities: In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in

Microsoft seizes 99 websites used by Iranian hackers for phishing attacks
How to eliminate the security risk of redundant data
Gimme, gimme, gimme a SANS after midnight: Brush up on your cybersecurity skills in Sweden this May
Leaky Martin will be livin’ la vida lockdown: Ex-NSA bod cops to taking home ‘up to 50TB’ of hush-hush dossiers
Someone’s spreading an MBR-trashing copy of the Christchurch killer’s ‘manifesto’ – and we’re OK with this, maybe?
TP-Link ‘smart’ router proves to be anything but smart – just like its maker: Zero-day vuln dropped after silence

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Lazarus Group Widens Tactics in Cryptocurrency Attacks
Gamers Urged to Patch Critical Bugs in GOG Galaxy

The package dovecot before version 2.3.5.1-1 is vulnerable to privilege escalation.

The package imagemagick before version 7.0.8.35-1 is vulnerable to arbitrary code execution.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes 18 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

Office Depot fined millions for tricking customers into believing their PCs were infected with malware
Huawei savaged by Brit code review board over pisspoor dev practices
Huawei’s half-arsed router patching left kit open to botnets: Chinese giant was warned years ago – then bungled it
Smashing Security #121: Hijacked motel rooms, ASUS PCs, and leaky apps
Office Depot, OfficeMax, Support.com cough up $35m after charging folks millions in ‘fake’ malware cleanup fees
Cisco Releases Flood of Patches for IOS XE, But Leaves Some Routers Open to Attack
FTC Demands Broadband Providers Reveal Data Handling Practices
Grindr Poses National Security Risk, U.S. Gov Says
Gamers Beware: Nvidia Fixes High-Severity GeForce Experience Bug
Cybercriminals Have a Heyday with WinRAR Bug in Fresh Campaigns
Asus pushes out urgent security update after its own automatic Live Update tool was hacked
Global police arrest dozens of people in dark web sting

More trouble in dark markets? A notorious black-market bazaar announces plans to close up shop on the same day as police announce the arrests of 61 people The post Global police arrest dozens of people in dark web sting appeared first on WeLiveSecurity

Ransomware Behind Norsk Hydro Attack Takes On Wiper-Like Capabilities
A PSA for twits on Twitter
Yeah, you better, you… you better tell us how you’re misusing people’s data, privacy, watchdog suggests to US telcos
ShadowHammer: ASUS software updates exploited to distribute malware

security update

Asus: Yo dawg, we hear a million of you got pwned by a software update. So we got you an update for the update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

ASUS Patches Live Update Bug That Allowed APT to Infect Thousands of PCs

An update that fixes two vulnerabilities is now available.