Menu

Category Archives: Security

Articles about security

Facebook stored 600m user passwords in plain text exposed to 20k employees
Panic after hackers take control of emergency tornado alarms in Texas
Flaw in NSA’s GHIDRA leads to remote code execution attacks

This update addresses various overflow conditions that could result in possible memory read/write out of bounds errors or zero byte allocations when connected to a malicious server.

Backport a security fix from PuTTY 0.71 affecting SFTP connections: Fix an integer overflow in the RSA key exchange preceeding host key verification

**Version 1.38.2** (2019-03-12) * added TemplateWrapper::getTemplateName() —- **Version 1.38.1** (2019-03-12) * fixed class aliases —- **Version 1.38.0** (2019-03-12) * fixed sandbox security issue (under some circumstances, calling the __toString() method on an object was possible even if not allowed by the security policy) * fixed batch filter clobbers array

**Version 2.7.2** (2019-03-12) * added TemplateWrapper::getTemplateName() —- **Version 2.7.1** (2019-03-12) * fixed class aliases —- **Version 2.7.0** (2019-03-12) * fixed sandbox security issue (under some circumstances, calling the __toString() method on an object was possible even if not allowed by the security policy) * fixed batch filter clobbers array keys when fill

Uncle Sam’s disaster agency FEMA creates disaster of its own: 2.3 million survivors’ personal records spilled
Security storm brewing for Oracle Java-powered smart cards: More than a dirty dozen flaws found, fixes… er, any fixes?
PewDiePie ransomware forcing users to subscribe him on YouTube
Spycams Secretly Live-Streamed 1,600 Motel Guests
Firefox and Edge Fall to Hackers on Day Two of Pwn2Own

security update

Google Play Touts Certs in Quest For Enterprise Security
Critical DoS Bug Bubbles Up in Facebook Fizz TLS 1.3 Project
Analysis: Drone Tech Creates New Type of Blended Threat

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Medtronic defibrillators vulnerable to life threatening cyber attacks

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

A heap-based buffer overflow was discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of this flaw for local root privilege escalation.

Reading Time: ~2 min. Gnosticplayers Adds 26 Million More Records for Sale After the first 3 major data dumps, which totaled over 600 million records, the hacker known as Gnosticplayers has released his latest cache of data, which contains at least 26 million personal user records. These data caches hold customer information for 32 companies […]

Medtronic Defibrillators Have Critical Flaws, Warns DHS

Libzip could be made to crash if it received specially crafted input.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0622

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0623

Hey, what’s Mandarin for ‘WTF is going on?’ Nokia phones caught spewing device IDs to China, software blunder blamed
Don’t have a heart attack but your implanted defibrillator can be hacked over the air (by someone who really wants you dead)

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes three vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

‘Sharing of user data is routine, yet far from transparent’ is not what you want to hear about medical apps. But 2019 is gonna 2019

Update tcpflow to 1.5.2 tag at github, fixing a security issue.

WordPress Plugin Patched After Zero Day Discovered

security update

security update

security update

Press Release: Guardian Digital Leverages the Power of Open Source to Combat Evolving Email Security Threats
Let’s spin Facebook’s Wheel of Misfortune! Clack-clack-clack… clack… You’ve won ‘100s of millions of passwords stored in plaintext’
Hackers Take Down Safari, VMware and Oracle at Pwn2Own

Proxy Auto-Configuration file can define localhost access to be proxied (CVE-2018-18506). Memory safety bugs fixed in Firefox 66 and Firefox ESR 60.6 (CVE-2019-9788).

In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c. (CVE-2019-7397) References: – https://bugs.mageia.org/show_bug.cgi?id=24396

The user module leaked parameters passed to ssh-keygen to the process environment (CVE-2018-16837). The fetch module was susceptible to path traversal (CVE-2019-3828).

Some 2000 Facebook staff had access to millions of Facebook users’ passwords… stored in plaintext
Kaspersky Lab takes bite out of Apple in Russia over borked parental controls app

Several security issues were fixed in Ghostscript.

An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

NTFS-3G could be made to crash or potentially run programs as anadministrator if executed with specially crafted arguments.

Facebook Stored Passwords in Plain Text For Years
Live Regcast: Ex-CISO and coal-face engineer Scott King shares his advice on becoming a pragmatic security leader
Brit Police Federation cops to ransomware attack on HQ systems
MyPillow and Amerisleep Targeted in Magecart Group Attacks
Most second-hand thumb drives contain data from past owners

Our penchant for plugging in random memory sticks isn’t the only trouble with our USB hygiene, a study shows The post Most second-hand thumb drives contain data from past owners appeared first on WeLiveSecurity

New phisherman’s friends and a few old favourites slither out of WatchGuard’s Security Report
Cisco Patches High-Severity Flaws in IP Phones
I Still Didn’t See What You Did

More advice for detecting and avoiding sextortion scams The post I Still Didn’t See What You Did appeared first on WeLiveSecurity

Smashing Security #120: Silk Road with Deliveroo
Windows Defender ATP is dead. Long live Microsoft Defender ATP
Don’t become another expensive statistic: Learn how to tackle cyber-criminals, at SANS London next month
Carolina coward fesses up: I was a tech support scambag, and I made millions out of defrauding the elderly
Mac-Focused Malvertising Campaign Abuses Google Firebase DBs

Reading Time: ~4 min. Since the dawn of IT, there’s been a very consistent theme among admins: end users are the weakest link in your network, organization, security strategy, fill-in-the-blank. We’ve all heard the stories, and even experienced them first-hand. An employee falls for a phishing scam and the whole network is down. Another colleague […]

Post-Perimeter Security: Addressing Evolving Mobile Enterprise Threats
Renegade Android apps can siphon off your web logins, browser history. So make sure Chrome or OS is patched, friends
Years-Long Phishing Campaign Targets Saudi Gov Agencies

An update that fixes three vulnerabilities is now available.

Risk Level: Very Low. Type: Trojan.

Fin7 Ramps Up Campaigns With Two Fresh Malware Samples

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that fixes two vulnerabilities is now available.

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that solves 9 vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

Uber Deployed ‘Surfcam Spyware’ in Australia to Crush the Competition – Report
Google hit with €1.49 billion antitrust fine by EU

The third penalty that Europe has levied on the tech giant in less than two years brings the total to €8.25 billion The post Google hit with €1.49 billion antitrust fine by EU appeared first on WeLiveSecurity

The package wordpress before version 5.1-1 is vulnerable to directory traversal.

The package libelf before version 0.176-1 is vulnerable to denial of service.

MySpace loses 12 years worth of photos, songs & video files

Multiple vulnerabilities have been found in OpenSSH, the worst of which could allow a remote attacker to gain unauthorized access.

Hydro working hard to recover following ransomware attack
Fake or Fake: Keeping up with OceanLotus decoys

ESET researchers detail the latest tricks and techniques OceanLotus uses to deliver its backdoor while staying under the radar The post Fake or Fake: Keeping up with OceanLotus decoys appeared first on WeLiveSecurity

Israeli fintech firms hit by Cardinal RAT malware

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0597

Silence of the WANs: FBI DDoS-for-hire greaseball takedowns slash web flood attacks ‘by 11%’

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Cardinal RAT Resurrected to Target FinTech Firms
Host of Flaws Found in CUJO Smart Firewall

security update

Podcast: The High-Risk Threats Behind the Norsk Hydro Cyberattack
Ransomware drops the Lillehammer on Norsk Hydro: Aluminium giant forced into manual mode after systems scrambled
Old Tech Spills Digital Dirt on Past Owners
Youve Been Pwned! Best Practices to Prevent Your Email Account from Being Compromised in a Data Breach

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

cloud-init: extra ssh keys added to authorized_keys on the Azure platform (CVE-2019-0816) SL7 x86_64 cloud-init-18.2-1.el7_6.2.x86_64.rpm – Scientific Linux Development Team