Menu

Category Archives: Security

Articles about security

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Several security vulnerabilities were discovered in Zabbix, a server/client network monitoring solution. CVE-2016-10742

The package pacman before version 5.1.3-1 is vulnerable to arbitrary code execution.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0462

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

The Handmaid’s Tale or Man-made Fail? Exposed DB of ‘BreedReady’ women probably not as bad as it sounds
Researcher Claims Iranian APT Behind 6TB Data Heist at Citrix
Google Patches Critical Bluetooth RCE Bug
Forrester: Ransomware Set to Resurge As Firms Pay Off Attacks
Citrix hackers may have stolen six terabytes worth of files
NASA’s crap infosec could be ‘significant threat’ to space ops
Hapless engineers leave UK cable landing station gate open, couple of journos waltz right in
Over 2 billion records exposed by email marketing firm

The repository of email addresses and other records would offer a gold mine of data for scammers The post Over 2 billion records exposed by email marketing firm appeared first on WeLiveSecurity

Facebook Alleges Two Ukrainians Scraped Data From 63K Profiles
Facebook sues quiz app developers who allegedly stole users’ private data through browser plugins
Just a reminder: We’re still bad at securing industrial controllers

poppler could be made to crash if it opened a specially craftedfile.

Why Your Email Security Solution May Not Be Enough
Gaming industry still in the scope of attackers in Asia

Asian game developers again targeted in supply-chain attacks distributing malware in legitimately signed software The post Gaming industry still in the scope of attackers in Asia appeared first on WeLiveSecurity

Freelance devs: Oh, you wanted the app to be secure? The job spec didn’t mention that
Verifications.io breach: Database with 2 billion records leaked

A vulnerability in GNU Wget which could allow an attacker to obtain sensitive information.

Multiple vulnerabilities have been found in systemd, the worst of which may allow execution of arbitrary code.

Multiple vulnerabilities have been discovered in rdesktop, the worst of which could result in the remote execution of arbitrary code.

security update

A vulnerability in Tar could led to a Denial of Service condition.

Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.

Multiple vulnerabilities have been found in cURL, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec, that could be leveraged to cause a denial of service or possibly remote code execution.

Clement Lecigne discovered a use-after-free issue in chromium’s file reader implementation. A maliciously crafted file could be used to remotely execute arbitrary code because of this problem.

Input validation errors in Zsh could result in arbitrary code execution.

Multiple vulnerabilities have been found in Keepalived, the worst of which could allow an attacker to cause Denial of Service condition.

Several security vulnerabilities have been discovered in symfony, a PHP web application framework. Numerous symfony components are affected: Security, bundle readers, session handling, SecurityBundle,

Applicants data of 3 elite US colleges hacked for ransom

security update

An update that fixes one vulnerability is now available.

Hackers steal 6TB of data from enterprise software developer Citrix
RSA Conference 2019: The Expanding Automation Platform Attack Surface
FBI warns of SIM-swap scams, IBM finds holes in visitor software, 13-year-old girl charged over JavaScript prank…
Vulnerable smart alarms allowed hackers to track & turn off car engine

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: The EXIF extension had multiple cases of invalid memory access and rename() was implemented insecurely.

That marketing email database that exposed 809 million contact records? Maybe make that two-BILLION-plus

Security fix for CVE-2018-15587

RSA Conference 2019: Operational Technology Widens Supply Chain Attack Surfaces

An update that solves one vulnerability and has 5 fixes is now available.

An update that fixes two vulnerabilities is now available.

Citrix Falls Prey to Password-Spraying Attack

New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Iranian hackers ransack Citrix, make off with 6TB+ of emails, biz docs, internal secrets

An update that solves 5 vulnerabilities and has 6 fixes is now available.

RSA Conference 2019: Emotet Takes Aim at Latin America

Reading Time: ~2 min. Ransomware as-a-Service Offers Tiered Membership Benefits Jokeroo is the latest ransomware-as-a-service (RaaS) to begin spreading through hacker forums, though it’s differentiating itself by requiring a membership fee with various package offerings. For just $90, a buyer obtains access to a ransomware variant that they can fully customize in exchange for a […]

New backdoor malware hits Slack and Github platforms

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0230

Flaws in smart car alarms exposed 3 million cars to hijack

The vulnerabilities, which resided in associated smartphone apps, were both easy to find and easy to fix The post Flaws in smart car alarms exposed 3 million cars to hijack appeared first on WeLiveSecurity

RSAC 2019: The Dark Side of Machine Learning

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes 15 vulnerabilities is now available.

Nah, National Cyber Security Centre doesn’t need its own minister, UK.gov tells Parliament

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

RSA Conference 2019 Recap
Saudi caller ID app Dalil leaked data of over 5 Million users
Download NSA’s reverse engineering tool GHIDRA
WordPress security: Steps to assess an employee before granting admin access to WordPress
PlayStation serial number leads Feds to bust a massive drug ring
Dark web hacker selling admin access to a Chinese railway company
The Pirate Bay’s preferred cryptominer Coinhive shutting down next week
Hackable car alarms leave three million cars at risk of hijack
RSA conference, USA 2019: Keynotes and key words

A bright tomorrow of technical delight, or a dismal future of digital dysfunction? The post RSA conference, USA 2019: Keynotes and key words appeared first on WeLiveSecurity

No guns or lockpicks needed to nick modern cars if they’re fitted with hackable ‘smart’ alarms
RSA 2019: Protecting your privacy in a NIST and GDPR world

Protecting your privacy is no longer just an option but a legal requirement in many parts of the world The post RSA 2019: Protecting your privacy in a NIST and GDPR world appeared first on WeLiveSecurity

Facebook Messenger bug made it possible for hackers to see who you have been chatting with
Buffer overflow flaw in British Airways in-flight entertainment systems will affect other airlines, but why try it in the air?
What happens when security devices are insecure? Choose the nuclear option
Tech security at Equifax was so diabolical, senators want to pass US laws making its incompetence illegal
IT guy at US govt fraud watchdog stole 16 computers from… US govt fraud watchdog

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Risk Level: Very Low. Type: Trojan.

RSA Conference 2019: Firms Continue to Fail at IoT Security

## drupal8 Upstream: – https://www.drupal.org/project/drupal/releases/8.6.10 – https://www.drupal.org/SA-CORE-2019-003 – https://www.drupal.org/project/drupal/releases/8.6.9 – https://www.drupal.org/project/drupal/releases/8.6.8 – https://www.drupal.org/project/drupal/releases/8.6.7 –

RSA Conference 2019: Ultrasound Hacked in Two Clicks

## drupal8 Upstream: – https://www.drupal.org/project/drupal/releases/8.6.10 – https://www.drupal.org/SA-CORE-2019-003 – https://www.drupal.org/project/drupal/releases/8.6.9 – https://www.drupal.org/project/drupal/releases/8.6.8 – https://www.drupal.org/project/drupal/releases/8.6.7 –

Put down the cat, coffee, beer pint, martini, whatever you’re holding, and make sure you’ve updated Chrome (unless you enjoy being hacked)

A flaw was found in Nagios Core version 4.4.1 and earlier. The qh_help function is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket (CVE-2018-13441).

If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. […]

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a […]

When symmetric encryption is used, data can be injected through the passphrase property of the gnupg.GPG.encrypt() and gnupg.GPG.decrypt() methods. The supplied passphrase is not validated for newlines, and the library passes –passphrase-fd=0 to the gpg executable, which expects the passphrase on the first line of stdin, and the ciphertext to be decrypted

RSAC 2019: For Domestic Abuse, IoT Devices Pose New Threat

NVIDIA graphics drivers could be made to expose sensitive information.

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which