Menu

Category Archives: Security

Articles about security

An update that fixes two vulnerabilities is now available.

Privacy in 2019: 6 Basic Steps to Keep Yourself Protected

Updated pdns packages fix security vulnerability: An issue has been found in PowerDNS Authoritative Server when the HTTP remote backend is used in RESTful mode (without post=1 set), allowing a remote user to cause the HTTP backend to connect to an attacker-specified

The updated live, mplayer, vlc packages fix security vulnerabilities: liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation

This kernel update is based on the upstream 4.14.106 and fixes atleast the following security issue: In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers

Updated openjpeg2 packages fix security vulnerability: Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service

The updated file packages fix security vulnerabilities: do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360. (CVE-2019-8905)

The updated poppler packages fix security vulnerabilities: In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in

Microsoft seizes 99 websites used by Iranian hackers for phishing attacks
How to eliminate the security risk of redundant data
Gimme, gimme, gimme a SANS after midnight: Brush up on your cybersecurity skills in Sweden this May
Leaky Martin will be livin’ la vida lockdown: Ex-NSA bod cops to taking home ‘up to 50TB’ of hush-hush dossiers
Someone’s spreading an MBR-trashing copy of the Christchurch killer’s ‘manifesto’ – and we’re OK with this, maybe?
TP-Link ‘smart’ router proves to be anything but smart – just like its maker: Zero-day vuln dropped after silence

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Lazarus Group Widens Tactics in Cryptocurrency Attacks
Gamers Urged to Patch Critical Bugs in GOG Galaxy

The package dovecot before version 2.3.5.1-1 is vulnerable to privilege escalation.

The package imagemagick before version 7.0.8.35-1 is vulnerable to arbitrary code execution.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes 18 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

Office Depot fined millions for tricking customers into believing their PCs were infected with malware
Huawei savaged by Brit code review board over pisspoor dev practices
Huawei’s half-arsed router patching left kit open to botnets: Chinese giant was warned years ago – then bungled it
Smashing Security #121: Hijacked motel rooms, ASUS PCs, and leaky apps
Office Depot, OfficeMax, Support.com cough up $35m after charging folks millions in ‘fake’ malware cleanup fees
Cisco Releases Flood of Patches for IOS XE, But Leaves Some Routers Open to Attack
FTC Demands Broadband Providers Reveal Data Handling Practices
Grindr Poses National Security Risk, U.S. Gov Says
Gamers Beware: Nvidia Fixes High-Severity GeForce Experience Bug
Cybercriminals Have a Heyday with WinRAR Bug in Fresh Campaigns
Asus pushes out urgent security update after its own automatic Live Update tool was hacked
Global police arrest dozens of people in dark web sting

More trouble in dark markets? A notorious black-market bazaar announces plans to close up shop on the same day as police announce the arrests of 61 people The post Global police arrest dozens of people in dark web sting appeared first on WeLiveSecurity

Ransomware Behind Norsk Hydro Attack Takes On Wiper-Like Capabilities
A PSA for twits on Twitter
Yeah, you better, you… you better tell us how you’re misusing people’s data, privacy, watchdog suggests to US telcos
ShadowHammer: ASUS software updates exploited to distribute malware

security update

Asus: Yo dawg, we hear a million of you got pwned by a software update. So we got you an update for the update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

ASUS Patches Live Update Bug That Allowed APT to Infect Thousands of PCs

An update that fixes two vulnerabilities is now available.

An update that solves 8 vulnerabilities and has one errata is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

Apple iOS 12.2 Patches 51 Serious Flaws

xmltooling could be made to crash if it opened a specially crafted file.

Red Hat Ansible Tower 3.3.5 2. Description: For a list of changes included in this release, please read the Ansible Tower Release Notes:

Red Hat Ansible Tower 3.4.3 2. Description: For a list of changes included in this release, please read the Ansible Tower Release Notes:

Reading Time: ~3 min. The last decade has been one of digital revolution, leading to the rapid adoption of new technology standards, often without the consideration of privacy ramifications. This has left many of us with a less-than-secure trail of digital breadcrumbs—something cybercriminals are more than aware of. Identity theft is by no means a […]

Several vulnerabilities have recently been discovered in libssh2, a client-side C library implementing the SSH2 protocol

An update that fixes one vulnerability is now available.

Hackers poison Asus software updates, may have infected one million PCs

openwsman: Disclosure of arbitrary files outside of the registered URIs (CVE-2019-3816) SL7 x86_64 libwsman1-2.6.3-6.git4391e5c.el7_6.i686.rpm libwsman1-2.6.3-6.git4391e5c.el7_6.x86_64.rpm openwsman-client-2.6.3-6.git4391e5c.el7_6.i686.rpm openwsman-client-2.6.3-6.git4391e5c.el7_6.x86_64.rpm openwsman-debuginfo-2.6.3-6.git4391e5c.el7_6.i686.rpm openwsman-debuginfo-2. [More…]

DXC Security exec: Yes, I’d have thought we’d spend more on certs and laptop kit for staff, too

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Huge news from Apple: No, not mags, games or TV – more than 50 security bugs to patch

Risk Level: Very Low. Type: Trojan, Virus.

Risk Level: Very Low. Type: Trojan, Virus.

Risk Level: Very Low. Type: Trojan, Virus.

ThreatList: Remote Workers Threaten 1 in 3 Organizations

security update

Spyware sneaks into ‘million-ish’ Asus PCs via poisoned software updates, says Kaspersky
Malware Payloads Hide in Images: Steganography Gets a Reboot
Bugs in Grandstream Gear Lay Open SMBs to Range of Attacks

An update that fixes four vulnerabilities is now available.

Some ASUS Updates Drop Backdoors on PCs in ‘Operation ShadowHammer’
Two white hats hack a Tesla, get to keep it

The electric automaker is working to release a fix for the underlying vulnerability in a matter of days The post Two white hats hack a Tesla, get to keep it appeared first on WeLiveSecurity

Get trained to turn the tables on your computer adversaries at SANS Bucharest

Multiple scp client vulnerabilities have been discovered in OpenSSH, the premier connectivity tool for secure remote shell login and secure file transfer.

Firefox, Edge, Safari, Tesla & VMware pwned at Pwn2Own
FEMA leaks sensitive details of 2.3 million disaster survivors

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

FEMA Exposes PII for Millions of Hurricane, Wildfire Survivors

Two issues have been fixed in bash, the GNU Bourne-Again Shell: CVE-2016-9401

CVE-2018-19364: 9pfs: use-after-free (bz #1651359) CVE-2018-19489: 9pfs: use- after-free renaming files (bz #1653157) CVE-2018-16867: usb-mtp: path traversal issue (bz #1656746) CVE-2018-16872: usb-mtp: path traversal issue (bz #1659150) CVE-2018-20191: pvrdma: uar_read leads to NULL deref (bz #1660315) CVE-2019-6778: slirp: heap buffer overflow (bz #1669072) CVE-2019-3812: Out-of-

Security fix for [CVE-2018-1000877 CVE-2018-1000878 CVE-2018-1000879 CVE-2018-1000880] —- Applied various flaws from upsteam

Geiger counters are so last summer. Lasers can detect radioactive material too, y’know

Update to 3.0. License has changed to ASL 2.0 + exception. See https://github.com/michaelrsweet/mxml/releases/tag/v3.0 for more info.

Trail of Bits used the automated vulnerability discovery tools developed for the DARPA Cyber Grand Challenge to audit zlib. As rsync, a fast, versatile, remote (and local) file-copying tool, uses an embedded copy of

security update

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

It was discovered that Wireshark, a network traffic analyzer, contained several vulnerabilities in the dissectors for 6LoWPAN, P_MUL, RTSE, ISAKMP, TCAP, ASN.1 BER and RPCAP, which could result in denial of service.

An arbitrary file read vulnerability was discovered in passenger, a web application server. A local user allowed to deploy an application to passenger, can take advantage of this flaw by creating a symlink from the REVISION file to an arbitrary file on the system and have its

Slack slings crypto-keys at big biz, union gets worked over, VPN owners probed, trolls trouble vets, and more

The package firefox before version 66.0.1-1 is vulnerable to arbitrary code execution.

security update

Several issues have been discovered in Apache module auth_mellon, which provides SAML 2.0 authentication. CVE-2019-3877

Facebook stored 600m user passwords in plain text exposed to 20k employees
Panic after hackers take control of emergency tornado alarms in Texas
Flaw in NSA’s GHIDRA leads to remote code execution attacks