Menu

Latest articles

TikTok Launches Bug Bounty Program Amid Security Snafus
News Wrap: Barnes & Noble Hack, DDoS Extortion Threats and More
British Airways fined £20m for Magecart hack that exposed 400k folks’ credit card details to crooks

CVE-2020-26116: HTTP request method CRLF injection in httplib

Critical Magento Holes Open Online Shops to Code Execution

security update

FIFA 21 Blockbuster Release Gives Fraudsters an Open Field for Theft
One alleged Dridex money-launderer set for US extradition, beams UK’s National Crime Agency

Priyank Nigam discovered that HttpComponents Client, a Java HTTP agent implementation, could misinterpret malformed authority component in a request URI and pick the wrong target host for request execution.

COVID-19 security tips: Ensure you sack your staff without leaving their IT access enabled, says Secureworks
50,000 home cameras reportedly hacked, footage posted online

Some footage has already appeared on adult sites, with cybercriminals offering lifetime access to the entire loot for US$150 The post 50,000 home cameras reportedly hacked, footage posted online appeared first on WeLiveSecurity

Zoom Rolls Out End-to-End Encryption After Setbacks
Broadvoice Leak Exposes 350M Records, Personal Voicemail Transcripts
Security much? Twitter should have had a CISO to prevent Bitcoin hack, says US state financial body
Barnes & Noble Hack: A Reading List for Phishers and Crooks
Beware COVID-19 charity fraudsters, warns the FBI
Carnival Corp. Ransomware Attack Affects Three Cruise Lines

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

Barnes & Noble warns customers it has been hacked, customer data may have been accessed

Update to 3.17.7 — https://www.claws-mail.org/news.php

Microsoft would love to hear about ‘critical bugs’ in .NET 5.0 ahead of the ‘unified’ platform’s November launch
Elite security intelligence for zero cost. Meet the Recorded Future Express browser extension
Remember when Zoom was rumbled for lousy crypto? Six months later it says end-to-end is ready
Smashing Security podcast #200: Two flipping hundred
Hackney Council’s cyber attack update is more interesting for what it doesn’t say than what it does
Travelex, Other Orgs Face DDoS Threats as Extortion Campaign Rages On
BEC Attacks: Nigeria No Longer the Epicenter as Losses Top $26B
Intel celebrates security of Ice Lake Xeon processors, so far impervious to any threat due to their unavailability
Critical SonicWall VPN Portal Bug Allows DoS, Worming RCE
The rise of fearware and how to fight back
Silent Librarian Goes Back to School with Global Research-Stealing Effort
McAfee rattles tin for $600m+ in fresh IPO filing valuing firm at $3.6bn
FIN11 Cybercrime Gang Shifts Tactics to Double-Extortion Ransomware
Intel Adds Memory Encryption, Firmware Security to Ice Lake Chips

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Brit webcam criminal snared in FBI LuminosityLink creepware sting spared prison

Several security issues were fixed in Vim.

Google, Intel Warn on ‘Zero-Click’ Kernel Bug in Linux-Based IoT Devices
Cybercriminals Steal Nearly 1TB of Data from Miami-Based International Tech Firm

The package chromium before version 86.0.4240.75-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, information disclosure and insufficient validation.

Security flaws and CVSS rescore process with NVD
‘Facebook simply would not exist today if not for Bletchley Park,’ says social network – but don’t hold that against it

Red Hat Ansible Tower 3.6 runner release (CVE-2019-18874) 2. Description: * Updated python-psutil version to 5.6.6 inside ansible-runner container (CVE-2019-18874)

Softly-as-a-service: IBM whispers plan for security SaaS based on a Cloud Pak
Windows “Ping of Death” bug revealed – patch now!
October Patch Tuesday: Microsoft Patches Critical, Wormable RCE Bug
Lemon Duck Cryptocurrency-Mining Botnet Activity Spikes
It’s 2020 and a rogue ICMPv6 network packet can pwn your Microsoft Windows machine
Software AG Data Released After Clop Ransomware Strike – Report
Critical Flash Player Flaw Opens Adobe Users to RCE
For Foxit’s sake: Windows and Mac users alike urged to patch PhantomPDF over use-after-free vulns
Attackers chain Windows, VPN flaws to target US government agencies

Bad actors have accessed US elections support systems, although there’s no evidence to suggest that election data has been compromised, say FBI and CISA The post Attackers chain Windows, VPN flaws to target US government agencies appeared first on WeLiveSecurity

ESET takes part in global operation to disrupt Trickbot

Throughout its monitoring, ESET analyzed thousands of malicious samples every month to help this effort The post ESET takes part in global operation to disrupt Trickbot appeared first on WeLiveSecurity

Creepy covert camera “feature” found in popular smartwatch for kids
Election Systems Under Attack via Microsoft Zerologon Exploits
Authentication Bug Opens Android Smart-TV Box to Data Theft
You can ditch the printer and go entirely paperless, but does that really make your work comms any more secure?
TrickBot Takedown Disrupts Major Crimeware Apparatus
Hackney hacked. Council hit by “serious cyber attack”, data breached

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Office 365: A Favorite for Cyberattack Persistence

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Hackers hack Hackney: Local government cries ‘cyberattack’ while UK infosec officials rush to figure out what happened
The seven deadly sins letting hackers hijack America’s govt networks: These unpatched bugs leave systems open
Microsoft on the counter­attack! Trickbot malware network takes a hit
Microsoft and chums use US trademark law to trash Trickbot malware network

An update that contains security fixes can now be installed.

An update that solves 12 vulnerabilities and has 59 fixes is now available.

Home security cams hacked in Singapore, and stolen footage sold on adult websites
‘You’ve got the old cheeky Corona’: Ireland’s pandemic advice SMS service can be spoofed, warns researcher
Android ransomware learns new tricks to lock devices
Ransomware Attackers Buy Network Access in Cyberattack Shortcut

An update that solves two vulnerabilities and has one errata is now available.

Beware, drone fliers, of Scotland’s black-headed gulls. For they will tear your craft from Mother Nature’s skies
One year after server hackers left NordVPN red-faced, firm’s first colocated setup is online
Britannia should rule the (cyber) waves, minister tells Singapore event in bid to drum up Commonwealth support
Five Eyes nations plus Japan and India call for Big Tech to bake backdoors into everything
Securing A Linux Web Server: Preventing Information Leakage>

An update that fixes one vulnerability is now available.

Frediano Ziglio discovered multiple buffer overflow vulnerabilities in the QUIC image decoding process of spice, a SPICE protocol client and server library, which could result in denial of service, or possibly, execution of arbitrary code.

security update

An update that fixes 5 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

A potential Cross-Site Scripting (XSS) vulnerability was found in rails, a ruby based MVC framework. Views that allow the user to control the default (not found) value of the `t` and `translate` helpers could be susceptible to XSS attacks. When an HTML-unsafe string is passed as the

Oleg Kalnichevski discovered that httpcomponents-client, a Java library for building HTTP-aware applications, can misinterpret a malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Taking a screwdriver to unlock your IoT sex toy is nuts

An update that solves one vulnerability and has one errata is now available.

Global Privacy Control emerges as latest attempt to let netizens choose whether they want to be tracked online
Five bag $300,000 in bug bounties after finding 55 security holes in Apple’s web apps, IT infrastructure

In Eclipse Web Tools Platform, a component of the Eclipse IDE, XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user

Reading Time: ~ 2 min. New Jersey Hospital Pays Massive Ransom Officials have decided to pay roughly $670,000 in ransom following a ransomware attack on the University Hospital in New Jersey. The hospital was likely forced into this decision after being unable to restore from backups the 240GB of data stolen in the attack on […]