Menu

Latest articles

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code.

Thousands of websites at risk from critical WordPress commenting plugin vulnerability
Facial-Recognition Flop: Face Masks Thwart Virus, Stump Security Systems

An update of the Red Hat OpenShift Container Platform 3.11 and 4.4/4.5 container images is now available for Red Hat AMQ Online. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Top 8 File and Disk Encryption Tools for Linux>

An update that fixes one vulnerability is now available.

The Case Against Full-Disk Encryption>
Hacker plays cat-and-mouse with the EBRD’s Twitter account
OkCupid Security Flaw Threatens Intimate Dater Details
No wonder Brit universities report hacks so often: Half of staff have had zero infosec training, apparently
Japan starts work on global quantum crypto network
Reply-All storm flares as email announcing privacy policy puts 500 addresses in the ‘To’ field, not ‘BCC’

security update

Lazarus Group Brings APT Tactics to Ransomware

security update

We’re suing Google for harvesting our personal info even though we opted out of Chrome sync – netizens
Almost 4,000 databases now wiped in ‘Meow’ attacks

The attackers and their motivations remain unknown; however, the incidents yet again highlight the risks of careless data security The post Almost 4,000 databases now wiped in ‘Meow’ attacks appeared first on WeLiveSecurity

Firefox 79 is out – it’s a double-update month so patch now!
Business anti-virus products put to the test – which received the highest score?

An update that fixes 5 vulnerabilities is now available.

Bank of Ireland fined €1.66 million after being tricked by fraudster
Google blames algorithm for adding porn titles to train station search results
The Ultimate Guide to Using Data Encryption on Linux>
Podcast: Security Lessons Learned In Times of Uncertainty
Researchers Warn of High-Severity Dell PowerEdge Server Flaw
MI6 tried to intervene in independent court by stopping judge seeing legal papers – but they said sorry, so it’s OK

A minor version update (from 7.6 to 7.7) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

Linux malware could soon be a thing of the past>

Several security issues were fixed in MySQL.

# July 2020 OpenJDK security update for OpenJDK 11 Full release notes: https://bitly.com/openjdk1108 ## Security fixes – JDK-8230613: Better ASCII conversions – JDK-8231800: Better listing of arrays – JDK-8232014: Expand DTD support – JDK-8233234: Better Zip Naming – JDK-8233239, CVE-2020-14562: Enhance TIFF support – JDK-8233255: Better Swing Buttons –

# July 2020 OpenJDK security update for OpenJDK 8. Full release notes: https://bitly.com/oj8u262 ## New features * [JDK-8223147](https://bugs.openjdk.java.net/browse/JDK-8223147): JFR Backport ## Security fixes – JDK-8028431, CVE-2020-14579: NullPointerException in DerValue.equals(DerValue) – JDK-8028591, CVE-2020-14578:

ClamAV 0.102.4 is a bug patch release to address the following issues: CVE-2020-3350 Fixed a vulnerability a malicious user could exploit to replace a scan target’s directory with a symlink to another path to trick clamscan, clamdscan, or clamonacc into removing or moving a different file (such as a critical system

Find out this week: How to build a cyber threat intelligence program while cutting through the noise
Tune in this week to learn all about an identity-centric approach to zero-trust security
Data-stealing, password-harvesting, backdoor-opening QNAP NAS malware cruises along at 62,000 infections
Microsoft Revamps Windows Insider Preview Bug Bounty Program
Source code of over 50 high profile organizations leaked online
Garmin staggers back online after ransomware attack
Attackers Exploiting High-Severity Network Security Flaw, Cisco Warns
Cloudflare suffered data leak; exposing 3 million IP addresses: Ukraine
Encryption Under ‘Full-Frontal Nuclear Assault’ By U.S. Bills
Garmin staggers back to its feet: Aviation systems seem to be lagging, though. Here’s why

An update that solves two vulnerabilities and has three fixes is now available.

Over 1000 Twitter staff and contractors had access to internal tools that helped hackers hijack accounts
ProLock ransomware – new report reveals the evolution of a threat

Several vulnerabilities were fixed in MilkyTracker, a music tracker for composing music in the MOD and XM module file formats. CVE-2019-14464

Several security issues were fixed in ClamAV.

SQLite could be made to crash or run programs if it processed a specially crafted query.

libslirp could be made to crash if it received specially crafted network traffic.

librsvg could be made to crash if it opened a specially crafted file.

Monday review – our recent stories revisited
UKIP blackmail, data breach sueball allegations were groundless, rules High Court
iOS14 shows Instagram opens camera even when users scroll photo feed

An update that fixes 8 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has 55 fixes is now available.

An update that solves four vulnerabilities and has 7 fixes is now available.

The following CVE(s) were reported against src:qemu: CVE-2017-9503

Apple co-founder Steve Wozniak sues YouTube over Bitcoin scams on his name

security update

Hackers leak 7m Dave.com accounts; 17m Couchsurfing accounts for sale
Psst.. You may want to patch this under-attack data-leaking Cisco bug – and these Ripple20 hijack flaws
It’s a Meow-nixed system, I know this: Purr-fect storm of 3,000+ insecure databases – and a data-wiping bot

0.9.24 release

Forex Trading and Online Security: Things to Look Out For
DJI drone app can transfer sensitive data and install malicious apps
DJI Drone App Riddled With Privacy Issues, Researchers Allege

Reading Time: ~ 2 min. ATM Jackpotting Attacks on the Rise ATM manufacturer Diebold Nixdorf has identified a malicious campaign that uses proprietary software to “jackpot” the machines. The attack requires malicious actors to breach the ATM manually and then use the software to force the machine to dispense cash at a rapid rate, known […]

Google adds security enhancements to Gmail, Meet and Chat

The tech giant introduces its own version of verified accounts in Gmail, rolls out increased moderation controls in Meet, and enhances phishing protection in Chat The post Google adds security enhancements to Gmail, Meet and Chat appeared first on WeLiveSecurity

NSA Urgently Warns on Industrial Cyberattacks, Triconex Critical Bug
News Wrap: Twitter Hack, Apple Under Fire and Global Privacy Finger Wags
Ransomware attack on fitness devices maker Garmin cripples operation
Cabinet Office takes over control of UK government data: Mundane machinery or Machiavellian manoeuvrings?
ASUS routers could be reflashed with malware – patch now!

An update that fixes two vulnerabilities is now available.

An update that fixes 10 vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has four fixes is now available.

Brit unis hit in Blackbaud hack inform students that their data was nicked, which has gone as well as you might expect
Malicious ‘Blur’ Photo App Campaign Discovered on Google Play
UK’s NCSC reveals Premier League footie clubs to be ripe pickings for cybercrooks: One almost lost £1m to BEC attack
Garmin knocked out by ransomware attack
Raytheon techie who took home radar secrets gets 18 months in the clink in surprise time fraud probe twist
Congrats, First American Title Insurance, you’ve made technology history. For all the wrong reasons
Cryptojacking botnet Prometei uses NSA exploit to steal data, mine Monero
Cisco Network Security Flaw Leaks Sensitive Data
UPDATED: Garmin Suffers Reported Ransomware Attack
Bridgecrew: Our mission is to set cloud security free
Privacy watchdogs urge videoconferencing services to boost privacy protections

The open letter highlights five security and privacy principles that require heightened attention from videoconferencing services The post Privacy watchdogs urge videoconferencing services to boost privacy protections appeared first on WeLiveSecurity

Sharp Spike in Ransomware in U.S. as Pandemic Inspires Attackers
A free iPhone from Apple? It’s possible, but there are some catches
Sports team nearly paid a $1.25m transfer fee… to cybercrooks
ASUS Home Router Bugs Open Consumers to Snooping Attacks
Cisco, Zoom and Others Must Bolster Security, Say Privacy Chiefs
New privacy tool ‘Fawkes’ blocks your images from facial recognition