LinuxSecurity.com: The package logstash before version 6.6.1-1 is vulnerable to information disclosure.
LinuxSecurity.com: The package elasticsearch before version 6.6.1-1 is vulnerable to privilege escalation.
LinuxSecurity.com: An update for polkit is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: GNOME Keyring could be made to expose sensitive information.
LinuxSecurity.com: USN-3866-2 introduced a regression in Ghostscript.
LinuxSecurity.com: LDB could be made to crash if it received specially crafted network traffic.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
With FIDO2 certification for Android, Google is setting the stage for password-less app and website sign-ins on a billion devices The post Google aims for password-free app and site logins on Android appeared first on WeLiveSecurity
LinuxSecurity.com: ultiple vulnerabilities have been discovered in liblivemedia, the LIVE555 RTSP server library: CVE-2019-6256
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 7 vulnerabilities is now available.
LinuxSecurity.com: The package kibana before version 6.6.1-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.
LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.
LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
The keeper of the internet’s ‘phone book’ is urging a speedy adoption of security-enhancing DNS specifications The post Escalating DNS attacks have domain name steward worried appeared first on WeLiveSecurity
LinuxSecurity.com: Several security issues were fixed in Bind.
LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: A newer version of waagent is needed for several features of the Azure platform. For Debian 8 “Jessie”, this problem has been fixed in version
LinuxSecurity.com: The package msmtp before version 1.8.3-1 is vulnerable to certificate verification bypass.
LinuxSecurity.com: The package python-mysql-connector before version 8.0.15-1 is vulnerable to authentication bypass.
Reading Time: ~2 min. Email Phishers Find New Filter Bypass Since email filters have gained popularity over the last decade, scammers have been forced to adapt their attacks. To bypass a normal URL filter that would check for malicious links, these scammers have found a way to alter the “document relationship” file (xml.rels) and continue […]
A new report shines some light on multiple aspects of the growing threat of cyber-extortion The post Cyber-extortionists take aim at lucrative targets appeared first on WeLiveSecurity
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft .NET Framework and Visual Studio are prone to an security vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.
Reading Time: ~3 min. “Internet of things” (IoT) is a term that’s becoming increasingly commonplace in our daily lives. Internet-connected devices are being designed and implemented at a rapid clip, especially in our own homes. The internet is not just at our fingertips anymore, but also at our beck and call with smart speakers and […]
And that’s on top of the heartache experienced by the tens of thousands of people who fall for romance scams each year The post How costly are sweetheart swindles? appeared first on WeLiveSecurity
security update
Siegeware is what you get when cybercriminals mix the concept of ransomware with building automation systems: abuse of equipment control software to threaten access to physical facilities The post Siegeware: When criminals take over your smart building appeared first on WeLiveSecurity
security update
security update
