Menu

Latest articles

Update to upstream 17.9.0 for bug and security fixes

TurkeyBombing Puts New Twist on Zoom Abuse
FBI warns of threat actors spoofing Bureau domains, email accounts

The U.S. law enforcement agency shares a sampling of more than 90 spoofed FBI-related domains registered recently The post FBI warns of threat actors spoofing Bureau domains, email accounts appeared first on WeLiveSecurity

SIM swap scam: What it is and how to protect yourself

Here’s what to know about attacks where a fraudster has your number, literally and otherwise The post SIM swap scam: What it is and how to protect yourself appeared first on WeLiveSecurity

Manchester United email servers remain offline amid what is being called a ‘ransomware’ attack
You too can be a security intelligence expert, with these free tools from Recorded Future
UK infoseccer launches petition asking government not to backdoor encryption
Cybersecurity Predictions for 2021: Robot Overlords No, Connected Car Hacks Yes
ThreatList: Cyber Monday Looms – But Shoppers Oblivious to Top Retail Threats

An update that fixes 10 vulnerabilities, contains one feature is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Fertility patients’ sensitive personal information stolen during ransomware attack

An update that fixes 12 vulnerabilities is now available.

security update

Bzzzzzzt! How safe is that keenly priced digital doorbell?
Suspected BEC scammers arrested in Nigeria following year-long Interpol investigation
Federated Learning: A Therapeutic for what Ails Digital Health
Changing Employee Security Behavior Takes More Than Simple Awareness

An update that solves 26 vulnerabilities and has 32 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 26 vulnerabilities and has 32 fixes is now available.

Smashing Security podcast #206: Robo dogs, deepfakes and dirty deceptions with Tim Harford
Privacy campaigner flags concerns about Microsoft’s creepy Productivity Score
Sophos security breach exposes customer support records

security update

Major BEC Phishing Ring Cracked Open with 3 Arrests
Critical MobileIron RCE Flaw Under Active Attack
Up to 350,000 Spotify accounts hacked in credential stuffing attacks

This won’t be music to your ears – researchers spot an unsecured database replete with records used for an account hijacking spree The post Up to 350,000 Spotify accounts hacked in credential stuffing attacks appeared first on WeLiveSecurity

How to Update Your Remote Access Policy – And Why You Should Now
Laser-Based Hacking from Afar Goes Beyond Amazon Alexa

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has one errata is now available.

An update that solves 12 vulnerabilities and has 103 fixes is now available.

An update that fixes one vulnerability is now available.

Ticketmaster: We’re not liable for credit card badness because the hack straddled GDPR day
Google binned two apps by China’s Baidu, which says researchers got it wrong by linking it to personal info leaks
Post-Breach, Peatix Data Reportedly Found on Instagram, Telegram
‘Minecraft Mods’ Attack More Than 1 Million Android Devices

This November 28 may be the most important Small Business Saturday since the occasion was founded by American Express in 2010. As early as July, nearly half (43 percent) of small businesses had closed at least temporarily, according to a study published in the Proceedings of the National Academy of Sciences. Research also suggests that […]

VMware urges sysadmins to apply workarounds after critical Workspace command execution vuln found
Gift card hack exposed – you pay, they play
Smart Doorbells on Amazon, eBay, Harbor Serious Security Issues
Baidu Apps in Google Play Leak Sensitive Data
Blackrota Golang Backdoor Packs Heavy Obfuscation Punch

An update that solves 21 vulnerabilities and has 21 fixes is now available.

OctopusWAF: A Customizable Open-Source WAF for High Performance Applications>

An update that solves 17 vulnerabilities and has 15 fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Tesla Hacked and Stolen Again Using Key Fob
Fake Minecraft mods installed on over one million Android devices

net-snmp: Improper Privilege Management in EXTEND MIB may lead to privileged commands execution (CVE-2020-15862) SL6 x86_64 net-snmp-5.5-60.el6_10.2.x86_64.rpm net-snmp-debuginfo-5.5-60.el6_10.2.i686.rpm net-snmp-debuginfo-5.5-60.el6_10.2.x86_64.rpm net-snmp-libs-5.5-60.el6_10.2.i686.rpm net-snmp-libs-5.5-60.el6_10.2.x86_64.rpm net-snmp-devel-5.5-60.el6_10.2.i686.rpm [More…]

This update upgrades Thunderbird to version 78.4.3. * Mozilla: Write side effects in MCallGetProperty opcode not accounted for (CVE-2020-26950) SL6 x86_64 thunderbird-78.4.3-1.el6_10.x86_64.rpm thunderbird-debuginfo-78.4.3-1.el6_10.x86_64.rpm i386 thunderbird-78.4.3-1.el6_10.i686.rpm – Scientific Linux Development Team

Imagine things are bad enough that you need a payday loan. Then imagine flaws in systems of loan lead generators leave your records in the open… for years

An update that fixes 5 vulnerabilities is now available.

Marketers for an Open Web ask UK competition watchdog to block launch of Google’s anti-tracking Privacy Sandbox
Crooks social-engineer GoDaddy staff into handing over control of crypto-biz domain names
Critical VMware Zero-Day Bug Allows Command Injection; Patch Pending
Apple’s global security boss accused of bribing cops with 200 free iPads in exchange for concealed gun permits
GoDaddy Employees Tricked into Compromising Cryptocurrency Sites

REvil Ransomware Strikes Hosting Provider In recent days the web hosting provider Managed.com has been working to recover from a ransomware attack targeting many of their core systems. While the company was able to stop the spread of the attack by shutting down their systems and client websites, it remains unclear what information may have […]

Security flaws in smart doorbells may open the door to hackers

The peace of mind that comes with connected home security gadgets may be false – your smart doorbell may make an inviting target for unwanted visitors The post Security flaws in smart doorbells may open the door to hackers appeared first on WeLiveSecurity

Manchester United versus a “sophisticated” cyber attack
TA416 APT Rebounds With New PlugX Malware Variant
Spotify Users Hit with Rash of Account Takeovers
FBI warns of criminals spoofing its website domain names
Manchester United: IT Systems Disrupted in Cyberattack
Joe Biden Campaign Subdomain Down After Hacktivist Defacement
Penetration testing isn’t enough, you need to activate full offensive operations

An update that solves 15 vulnerabilities and has 75 fixes is now available.

An update for microcode_ctl is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for microcode_ctl is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact

An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.4 Advances Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

US Air Force deploys robot security dogs to guard base
No Xmas office party? Missing infosec pals and colleagues? Want to listen to DJs who also happen to be cyber warriors?
Head thumping, heart racing? Here’s how not to panic when you’re under cyber attack

security update

security update

Update to 87.0.4280.66. Fixes bugs and security holes. Yay! CVE-2020-16012 CVE-2020-16018 CVE-2020-16019 CVE-2020-16020 CVE-2020-16021 CVE-2020-16022 CVE-2020-16015 CVE-2020-16014 CVE-2020-16023 CVE-2020-16024 CVE-2020-16025 CVE-2020-16026 CVE-2020-16027 CVE-2020-16028 CVE-2020-16029 CVE-2020-16030 CVE-2020-16031 CVE-2020-16032 CVE-2020-16033 CVE-2020-16034 CVE-2020-16035

– Update to upstream 2.1-31. 20201118 – Removal of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode at revision 0x68[1]; – Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x32 up to 0x34[2]. [1] The microcode has been removed after reports of system hangs: https://github.com/intel/Intel-Linux-Processor- Microcode-Data-Files/issues/44 [2] Addresses CVE-2020-8695 for this platform.

Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.

Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.

Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.

Manchester United working with infosec experts to ‘minimize ongoing IT disruption’ caused by ‘cyber attack’

Multiple vulnerabilities were discovered in Zabbix, a network monitoring solution. An attacker may remotely execute code on the zabbix server, and redirect to external links through the zabbix web frontend.

Three issues have been found in golang-1.8, a Go programming language compiler version 1.8

Two issues have been found in golang-1.7, a Go programming language compiler version 1.7

A heap-based buffer overflow flaw was discovered in MuPDF, a lightweight PDF viewer, which may result in denial of service or the execution of arbitrary code if malformed documents are opened.

security update