Menu

Latest articles

An update that solves four vulnerabilities and has two fixes is now available.

Seven ‘no log’ VPN providers accused of leaking – yup, you guessed it – 1.2TB of user logs onto the internet
Thousands of Vulnerable F5 BIG-IP Users Still Open to Takeover
Judge green-lights Facebook, WhatsApp hacking lawsuit against spyware biz NSO, unleashing Zuck’s lawyers
40GB of leaked videos expose how Iranian hackers hijack email accounts
Cloud biz Blackbaud caved to ransomware gang’s demands – then neglected to inform customers for two months

An update for .NET Core is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Twitter Hack Update: What We Know (and What We Don’t)
High‑profile Twitter accounts hacked to promote Bitcoin scam

Tech titans and prominent politicians among victims of a sprawling hack that Twitter says leveraged its internal tools The post High‑profile Twitter accounts hacked to promote Bitcoin scam appeared first on WeLiveSecurity

Mac cryptocurrency trading application rebranded, bundled with malware

ESET researchers lure GMERA malware operators to remotely control their Mac honeypots The post Mac cryptocurrency trading application rebranded, bundled with malware appeared first on WeLiveSecurity

Ew, that’s unsanitary: SEO plugin for WordPress would run arbitrary JavaScript inputs instead of scrubbing them
CISA Emergency Directive Orders Immediate Fix of Windows DNS Server Bug
Apple’s latest updates are out for iPhones and Macs – get them now!
7 VPN firms with no-logs policy end up exposing 1.2 TB of user data
Insecure IoT devices could be banned and destroyed if they fail to meet UK security standards
Twitter admits 130 A-lister accounts compromised to promote Bitcoin scam after ‘social engineering’ attack

An update for .NET Core is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

The Twitter hack: Why Elon Musk, Bill Gates, Jeff Bezos and others might have reason to be worried
This week of never-ending security updates continue. Now Apple emits dozens of fixes for iOS, macOS, etc

Update to 3.9.0b4

0.9.24 release

Update to 3.9.0b4

Enterprise Data Security: It’s Time to Flip the Established Approach
Online Jewish service ‘Zoom bombed’ with hate speech & Swastikas

Reading Time: ~ 3 min. Summer is upon us. For some, summer is all about physical fitness. While exercise is essential to our overall well-being, we shouldn’t forget about our digital fitness, either. Just as our bodies serve our needs and help us go about our daily lives, so too do our computers and digital […]

FYI Russia is totally hacking the West’s labs in search of COVID-19 vaccine files, say UK, US, Canada cyber-spies
Hackers Look to Steal COVID-19 Vaccine Research
Microsoft patches critical, wormable flaw in Windows DNS Server

The company urges organizations to waste no time in installing updates to fix the vulnerability that rates a ‘perfect’ 10 on the severity scale The post Microsoft patches critical, wormable flaw in Windows DNS Server appeared first on WeLiveSecurity

Details of 142 million MGM hotel guests selling for US$2,900

It appears that the July 2019 breach at MGM Resorts affected far more people than initially thought The post Details of 142 million MGM hotel guests selling for US$2,900 appeared first on WeLiveSecurity

Mobile security threats amid COVID‑19 and beyond: A Q&A with Lukas Stefanko

ESET malware researcher Lukas Stefanko gives us a peek behind the scenes of his analysis of CryCryptor ransomware and puts the threat into a broader context The post Mobile security threats amid COVID‑19 and beyond: A Q&A with Lukas Stefanko appeared first on WeLiveSecurity

Crypto scam: Twitter’s internal tool was used in hijacking verified accounts
Zoom Addresses Vanity URL Zero-Day
Privacy Shield binned after EU court rules transatlantic data protection arrangements ‘inadequate’

An update that fixes three vulnerabilities is now available.

VPN firm that claims zero logs policy leaks 20 million user logs
Amazon-Themed Phishing Campaigns Swim Past Security Checks
Threat Actors Introduce Unique ‘Newbie’ Hacker Forum

Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate trust rules as software updates (CVE-2020-12421) SL6 x86_64 thunderbird-68.10.0-1.el6_10.x86_64 [More…]

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The Twitter mega-hack. What you need to know
Finally done with all those Patch Tuesday updates? Think again! Here’s 33 Cisco bug fixes, with five criticals
Smashing Security podcast #187: Huawei ban, MGM hack, and a contact-tracing cock-up

Damian Poddebniak and Fabian Ising discovered a response injection vulnerability in Evolution data server, which could enable MITM attacks.

LokiBot Redux Attacks Massive List of Common Android Apps
Twitter says hack of key staff led to celebrity, politician, biz account hijack mega-spree

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Report: CIA runs secret cyberwar with little oversight after Trump gave the OK, say US government officials
Twitter limits tweeting as prominent accounts spam out cryptocoin scams
Twitter Confirms it was Hacked in an Unprecedented Cryptocurrency Scam
Twitter mass hacking: Bill Gates, Elon Musk, Jeff Bezos, Mike Bloomberg, Biden, Obama, more hijacked to peddle Bitcoin scam
Prominent & verified Twitter accounts hacked to run crypto scam
If Microsoft 365 security is so great, why do its customers keep getting hacked?
Is it Patch Blues-day for Outlook? Microsoft’s email client breaks worldwide, leaves everyone stumped
17-year-old “wormable” SigRed vulnerability found in Windows servers
Brazil’s Banking Trojans Go Global
Patch now! SIGRED – the wormable hole in your Windows servers
Welcome Chat as a secure messaging app? Nothing could be further from the truth

ESET research uncovers a malicious operation that both spies on victims and leaks their data The post Welcome Chat as a secure messaging app? Nothing could be further from the truth appeared first on WeLiveSecurity

Database of Indonesian store Bhinneka dumped with 1 million+ accounts
Database with 271 million Wattpad accounts leaked on hacker forum

An update that solves 5 vulnerabilities and has one errata is now available.

An update that fixes 5 vulnerabilities is now available.

Several security issues were fixed in libvpx.

The TLS 1.2 Deadline is Looming, Do You Have Your Act Together?

kernel: powerpc: incomplete Spectre-RSB mitigation leads to information exposure (CVE-2019-18660) SL6 x86_64 kernel-2.6.32-754.31.1.el6.x86_64.rpm kernel-debug-2.6.32-754.31.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-754.31.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-754.31.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-754.31.1.el6.i686.rpm kernel-debug-devel-2.6.3 [More…]

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

“Secure in your thoughts” – malware memories and brain passwords in the Stroke of Genius podcast
Cambridge student rebuilds Polish Enigma-code-breaking box that paved the way for Turing … and Victory!

Multiple security issues were discovered in Python, an interactive high-level object-oriented language. CVE-2018-20406

Citrix denies dark web claim of network compromise and ransomware attack
Old-school security hole perfect for worms and remote hijackings found lurking in Windows Server DNS code
Microsoft Tackles 123 Fixes for July Patch Tuesday
So kind of SAP NetWeaver to hand out admin accounts to anyone who can reach it. You’ll want to patch this
Critical DNS Bug Opens Windows Servers to Infrastructure Hijacking
Citrix allegedly hacked exposing database with 2000,000 users
Adobe Discloses Critical Code-Execution Bugs in July Update
142 million MGM customers’ data sold on dark web marketplace
DMARC Adoption Spikes, Higher Ed Remains Behind
Leaked Details of 142 Million MGM Hotel Guests Found for Sale Online
RATicate malware gang goes commercial
Most Companies Are Ignoring Your Most Vulnerable Endpoint…and It’s Not the Laptop
Burn baby burn, infosec inferno: Just 21% of security pros haven’t considered quitting their current job
Leaked Details of 142 Million MGM Hotel Guests Found for Sale on Dark Web
Critical SAP Bug Allows Full Enterprise System Takeover

Several security issues were fixed in WebKitGTK.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Collabera hacked: IT staffing’n’services giant hit by ransomware, employee personal data stolen
Guilty: Russian miscreant who hacked LinkedIn, Dropbox, Formspring, stole 200-million-plus account records

security update

Man convicted for identity theft & fraud against US Military, veterans

Reading Time: ~ 4 min. Prior to the outbreak of the novel coronavirus, Webroot’s annual Threat Report highlighted a 640% increase in active phishing sites on the web. However difficult it may be to believe (or easy, depending on your outlook), things have gotten even worse since.   From fake anti-malware sites named for the […]

Zoom patches zero‑day flaw in Windows client

The vulnerability exposed Zoom users running Windows 7 or earlier OS versions to remote attacks The post Zoom patches zero‑day flaw in Windows client appeared first on WeLiveSecurity

TrickBot Sample Accidentally Warns Victims They’re Infected
Secret Service Creates Cyber Fraud Task Forces
Man who lived luxury lifestyle after hacking LinkedIn and Dropbox is found guilty