Menu

Category Archives: Security

Articles about security

You should pick your Android security app wisely, test shows

It’s prudent to get a security solution for your device, but a test by AV-Comparatives shows why you need to choose judiciously The post You should pick your Android security app wisely, test shows appeared first on WeLiveSecurity

Researcher Says NSA’s Ghidra Tool Can Be Used for RCE
Sorry, Linux. We know you want to be popular, but cyber-crooks are all about Microsoft for now

An update that fixes 9 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Norsk Hydro Calls Ransomware Attack ‘Severe’

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0482

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0485

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0483

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0512

It has been discovered that OTRS (Open source Ticket Request System) is susceptible to code injection vulnerability. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully

ThreatList: DDoS Attack Sizes Drop 85 Percent Post FBI Crackdown
I didn’t see what you did, redux

Cyberblackmail/sextortion again raises its not-so-pretty little head The post I didn’t see what you did, redux appeared first on WeLiveSecurity

PuTTY in your hands: SSH client gets patched after RSA key exchange memory vuln spotted

An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Bandersnatch to gander snatched: Black Mirror choices can be snooped on, thanks to privacy-leaking Netflix streams

security update

Bad cup of Java leaves nasty taste in IBM Watson’s ‘AI’ mouth: Five security bugs to splat in analytics gear

The CLI tools in python-rdflib-tools can load python modules found in the current directory. This happens because “python -m” appends the current directory in the python path.

The ikiwiki maintainers discovered that the aggregate plugin did not use LWPx::ParanoidAgent. On sites where the aggregate plugin is enabled, authorized wiki editors could tell ikiwiki to fetch potentially undesired URIs even if LWPx::ParanoidAgent was installed:

Fourth Major Credential Spill in a Month Hits DreamMarket
Mirai Variant Goes After Enterprise Systems
Google Gives Users More Choice with Location-Tracking Apps
This headline is proudly brought to you by wired keyboards: Wireless Fujitsu model hacked
Privacy Regulations Needed for Next-Gen Cars

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

Two vulnerabilities were discovered in SQLALchemy, a Python SQL Toolkit and Object Relational Mapper.

An update that solves four vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has four fixes is now available.

An update that fixes one vulnerability is now available.

LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.

Counter-Strike 1.6 game client 0-day exploited to spread Belonard trojan
Hackers are using 19-year-old WinRAR bug to install nasty malware
SimBad malware on Play Store infected millions of Android devices

Several security issues were fixed in file.

Lone staffer killed our shields, claims etailer Gearbest after infosec bods peep at user deets

An update for openstack-octavia is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for ansible is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

53% of Britain’s most frequent porn watchers aren’t aware that they’re about to be blocked
MySpace has lost all the music users uploaded between 2003 and 2015
Karpeles walks, Google and Microsoft board up Windows hole, and Android AV still sucks
UK code breakers drop Bombe, Enigma and Typex simulators onto the web for all to try

An update that fixes 18 vulnerabilities is now available.

Security fix CVE-2019-9210

Q&A: Crypto-guru Bruce Schneier on teaching tech to lawmakers, plus privacy failures – and a call to techies to act

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that fixes three vulnerabilities is now available.

What was that P word? Ah. Privacy. Yes, we’ll think about privacy, says FCC mulling cellphone location data overhaul

Reading Time: ~2 min. In late February, the notorious cryptojacking script engine called Coinhive abruptly announced the impending end to its service. The stated reason: it was no longer economically viable to run. Coinhive became infamous quickly following its debut as an innovative javascript-based cryptomining script in 2018. While Coinhive maintained that its service was […]

Welcome. You’re now in a timeline in which US presidential hopeful Beto was a member of a legendary hacker crew
Zillow sued for $60 million after mansion listing hijacked
Lenovo Patches High-Severity Arbitrary Code Execution Flaws

An update that fixes four vulnerabilities is now available.

An update that solves 8 vulnerabilities and has 73 fixes is now available.

Several security issues identified in ikiwiki fixed by updating to version 3.20190228. See references for details References: – https://bugs.mageia.org/show_bug.cgi?id=24453

Reading Time: ~2 min. Georgia County Pays Six Figure Ransom to Restore IT Systems Following a ransomware attack earlier this month, officials in Jackson County, Georgia decided to pay a $400,000 ransom in order to obtain a decryption key and return their systems to normal operations. While it’s not normally recommended to pay ransoms, but […]

Unpatched Fujitsu Wireless Keyboard Bug Allows Keystroke Injection
Public spending watchdog snipes at UK.gov’s £1.3bn infosec plan – but broadly nods it through
So you need an IT security center. Fret not: Let an automated solution take the strain
Threatlist: IMAP-Based Attacks Compromising Accounts at ‘Unprecedented Scale’
Zero-Days in Counter-Strike Client Used to Build Major Botnet
Open-source 64-ish-bit serial number gen snafu sparks TLS security cert revoke runaround
Don’t be a WordPress RCE-hole and patch up this XSS vuln, pronto

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Cisco Patches Critical ‘Default Password’ Bug
GlitchPOS Malware Appears to Steal Credit-Card Numbers
Online training site says it is spamming insecure printers with adverts

An update that fixes two vulnerabilities is now available.

Protip: If you’d rather cyber-scoundrels didn’t know the contents of your comp, don’t apply for a Pakistani passport
“BreedReady” database of 1.8m Chinese women surfaced online
More than Half of Android apps ask for dangerous permissions. Is yours among?
Hackers cop a FILA thousands of UK card deets after slinking onto clothing brand’s servers

An update is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openstack-octavia is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openstack-ceilometer is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Pakistani Govt’s passport application tracking site hacked with Scanbox framework
US Senators say it shouldn’t be a secret when they’ve been hacked
Insider Threats Get Mean, Nasty and Very Personal
Facebook suffer most severe outage ever

Facebook owned Instagram and WhatsApp also affected by unexplained interruption The post Facebook suffer most severe outage ever appeared first on WeLiveSecurity

An update for haproxy is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for haproxy is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

What do sexy selfies, search warrants, tax files have in common? They’ve all been found on resold USB sticks

Multiple vulnerabilities have been found in Oracles JDK and JRE software suites.

Multiple vulnerabilities have been found in BIND, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been found in WebkitGTK+, the worst of which could result in the arbitrary execution of code.

A vulnerability was discovered in XRootD which could lead to the remote execution of code.

Multiple Information Disclosure vulnerabilities in OpenSSL allow attackers to obtain sensitive information.

A vulnerability in the GNU C Library could result in a Denial of Service condition.

Thought you were done patching this week? Not if you’re using an Intel-powered PC or server
Smashing Security #119: Hijacked homes, porn passports, and ransomware regret
New Samsung Galaxy S10 review and features

security update

security update

Purveyor of Cracked Netflix, Hulu, Spotify Accounts Arrested
Just Android things: 150m phones, gadgets installed ‘adware-ridden’ mobe simulator games