Menu

Latest articles

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 19 vulnerabilities and has 162 fixes is now available.

An update that fixes one vulnerability is now available.

Smashing Security podcast #188: Dinner with Elon Musk and Kris Jenner
Twitter hack latest: Up to 36 compromised accounts had their private messages read – including a Dutch politician’s
Twitter: Hackers Accessed Private Messages for Elite Accounts
Politician amongst those who had their direct messages accessed during Twitter hack
Ubiquiti, go write on the board 100 times, ‘I must validate input data before using it’… Update silently breaks IDS/IPS
UK surveillance laws tightened up as most spying demands to be subject to warrants
Shocked I am. Shocked to find that underground bank-card-trading forums are full of liars, cheats, small-time grifters
New ‘BadPower’ attack on fast chargers can burn your smartphone
OilRig APT Drills into Malware Innovation with Unique Backdoor
Apple Security Research Device Program Draws Mixed Reactions

Reading Time: ~ 3 min. Most people are familiar with phishing attacks. After all, they’re one of the most common forms of data breach around. At their most basic, phishing attacks are attempts to steal confidential information by pretending to be an authorized person or organization. Standard phishing is not targeted. It relies on achieving […]

security update

Stick that in your named pipe and smoke it: Flaw in Citrix Workspace app could let remote attacker pwn host
UFO VPN leaks database again; gets taken over & destroyed by hackers
Argentine telecom company hit by major ransomware attack

Telecom Argentina says it has contained the attack and regained access to its systems without paying up The post Argentine telecom company hit by major ransomware attack appeared first on WeLiveSecurity

Lazarus Group Surfaces with Advanced Malware Framework
Going Down the Spyware Rabbit Hole with SilkBean Mobile Malware

Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine. CVE-2020-13934

Several security issues were fixed in FFmpeg.

Leak Exposes Private Data of Genealogy Service Users
Fake cryptocurrency trading app hits Mac users with malware

Several security issues were fixed in Python.

Capita’s bespoke British Army recruiting IT cost military 25k applicants after switch-on

Pillow could be made to crash if it opened a specially crafted file.

Evolution Data Server could be made to expose sensitive information over the network.

Several vulnerabilities have been found in librsvg, an SVG rendering library. This update corrects some denial of service issues via exponential element processing, stack exhaustion or application crash when processing specially crafted files, as well as some memory safety

Pakistan bans one Chinese app and gives TikTok a final warning to clean up its act
Twilio: Someone broke into our unsecured AWS S3 silo, added ‘non-malicious’ code to our JavaScript SDK
Emotet Returns in Malspam Attacks Dropping TrickBot, QakBot
It’s July 2020, and your PC or Mac can be pwned by a dodgy Photoshop file – Adobe emits critical patch batch
Coinbase stopped scammers from stealing an extra $280,000 during Twitter hack
Camera privacy bug found in Firefox Android in 2019 hasn’t been fixed yet
Bad: US govt says Chinese duo hacked, stole blueprints from just about everyone. Also bad: They extorted cash
Chris Vickery: AI Will Drive Tomorrow’s Data Breaches
Software firm leaks 25GB worth of subscription & Ancestry.com user data
7 VPN services leaked data of over 20 million users, says report

A report calls into question the providers’ security practices and dismisses their claims of being no-log VPN services The post 7 VPN services leaked data of over 20 million users, says report appeared first on WeLiveSecurity

Data breach reports down by one‑third in first half of 2020

The Identity Theft Resource Center doesn’t expect the trend to last, however The post Data breach reports down by one‑third in first half of 2020 appeared first on WeLiveSecurity

Stick that in your named pipe and smoke it: Flaw in Citrix Workspace could let remote attacker pwn host machine
UK intel committee on Russia: Social media firms should remove state disinformation. What was that, MI5? ████████?
Critical Adobe Photoshop Flaws Patched in Emergency Update
UK Government chose not to investigate if Russian hackers interfered in Brexit referendum, report reveals
The Art of Convenience in A World Run by The Internet of Things

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Diebold ATM Terminals Jackpotted Using Machine’s Own Software
Apple was the only Fortune 50 company to foresee COVID-19 pandemic risk and properly insure against it – Forrester

An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for cloud-init is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that fixes 10 vulnerabilities is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for the mod_auth_openidc:2.3 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Argentina’s largest telecom hacked with hackers demanding $7.5 million

security update

security update

security update

security update

Reading Time: ~ 2 min. Malware Discovered in Chinese Tax Software As part of an official Chinese tax initiative, researchers have found multiple backdoors into mandatory tax software installed on all Chinese business systems. The new malware is called GoldenHelper, in a nod to the command-and-control domain tax-helper.ltd, and has been in active development and […]

Teens arrested after paying Bitcoin to watch livestream abuse & murder
Facebook’s NSO Group Lawsuit Over WhatsApp Spying Set to Proceed
Computer misuse crimes down 9% on last year in England and Wales, says Office of National Statistics
7 VPNs that leaked their logs – the logs that “didn’t exist”
Mac Cryptocurrency Traders Targeted by Trojanized Apps
You’ve had your pandemic holiday, now Microsoft really is going to kill off TLS 1.0, 1.1
Cloud hosting firm Blackbaud pays ransom after thwarting ransomware attack

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An axe age, a sword age, Privacy Shield is riven, but what might that mean for European businesses?
Mitre, the creepy company checking your fingerprints on Facebook for the US Government
Paving the Path to Passwordless
UK.gov admits it has not performed legally required data protection checks for COVID-19 tracing system
Bill & Melinda Gates foundation impersonated in Bitcoin phishing scam

An HTTP request smuggling issue was discovered in the ngx_lua plugin for nginx, a high-performance web and reverse proxy server, as demonstrated by the ngx.location.capture API.

Multiple vulnerabilities were found in Ruby on Rails, a MVC ruby-based framework geared for web application development, which could lead to remote code execution and untrusted user input usage, depending on the application.

An update that contains security fixes can now be installed.

An update that fixes 13 vulnerabilities is now available.

Is your Office 365 locked down in lockdown?
Hey there, want to break into computers like an Iranian hacker crew? IBM finds 40GB of videos that include how-tos
Career Notes podcast – Have to be able to communicate to everybody
Twitter hackers busted 2FA to access accounts and then reset user passwords
Google Cloud adds security capabilities for sensitive workloads

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

security update

security update

security update

security update

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 10 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves 5 vulnerabilities and has one errata is now available.