Menu

Latest articles

Millions of LiveAuctioneers passwords offered for sale following data breach
Digicert revokes a raft of web security certificates
Hacker steals databases from breach monitoring site; sells them online
Sueball locked, loaded and pointed at LinkedIn over iOS privacy naughtiness

An update is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

A ‘New Age’ of Sophisticated Business Email Compromise is Coming
The Enemy Within: How Insider Threats Are Changing
How CARTA Strategies for Web Applications are Met with Indusface AppTrana Solution

An update for machine-config-daemon and openshift is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

dbus: denial of service via file descriptor leak (CVE-2020-12049) SL7 x86_64 dbus-1.10.24-14.el7_8.x86_64.rpm dbus-debuginfo-1.10.24-14.el7_8.i686.rpm dbus-debuginfo-1.10.24-14.el7_8.x86_64.rpm dbus-libs-1.10.24-14.el7_8.i686.rpm dbus-libs-1.10.24-14.el7_8.x86_64.rpm dbus-x11-1.10.24-14.el7_8.x86_64.rpm dbus-devel-1.10.24-14.el7_8.i686.rpm dbus-devel-1.10.24- [More…]

Better get Grandpa off Windows 7 because zero-day bug in Zoom allows remote code execution on vintage OS
Monday review – the hot stories of the week

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Trump reveals US cyber-attack on Russian election-misdirection troll farms

The previous update for chromium released as DSA 4714-2 contained a flaw in the service worker implementation. This problem causes the browser to crash when a connection error occurs. Updated chromium packages are now available that correct this issue.

How to make your IT security go beyond your network – and make people your perimeter
LiveAuctioneers security breach puts users at risk

Update to 2.28.3: * Fix kinetic scrolling with async scrolling. * Fix web process hangs on large GitHub pages. * Bubblewrap sandbox should not attempt to bind empty paths. * Fix threading issues in the media player. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-9802, CVE-2020-9803, CVE-2020-9805, CVE-2020-9806, CVE-2020-9807, CVE-2020-9843, CVE-2020-9850,

The 5.7.8 stable kernel update contains a number of important fixes across the tree.

Update to 2.53.3 The database format of the stored passwords and certificates in the user profile are now changed. SeaMonkey should perform the changes hiddenly at the first run, just asking for the master password (if used). To avoid a hypothetical data loss, it is recommended to backup user profile before the update, or even […]

Kasa camera flaw allows enumerating usernames for credential stuffing
An email banning our staff from using TikTok? Haha, funny story about that, we didn’t mean it – Amazon
Popular TP-Link Family of Kasa Security Cams Vulnerable to Attack
‘Zoom account suspended’ phishing scam aims at Office 365 credentials

This update applies a proposed fix for CVE-2018-12983.

This update applies a proposed fix for CVE-2018-12983.

Backport patches for CVE-2020-15306, CVE-2020-15305, CVE-2020-15304

Security fix

This update applies a proposed fix for CVE-2018-12983.

This update applies a proposed fix for CVE-2018-12983.

Google Bans Stalkerware Ads – With a Loophole
New smishing scam spreads fake TikTok App loaded with malware

Reading Time: ~ 2 min. Ragnar locker Attacks Portuguese Energy Producer It was recently confirmed that Energias de Portugal (EDP), one of the largest energy producers in the world, has fallen victim to the Ragnar Locker ransomware variant. The original attack took place in April but was only discovered in May after nearly three weeks […]

Billions of stolen passwords for sale on the dark web

While logins to music and video streaming services sell for less than ten dollars each, domain admin access is being offered for US$120,000 The post Billions of stolen passwords for sale on the dark web appeared first on WeLiveSecurity

More evil: A deep look at Evilnum and its toolset

ESET research gives a detailed picture of the operations of the Evilnum group and its toolkit deployed in attacks against carefully chosen targets in the fintech sector The post More evil: A deep look at Evilnum and its toolset appeared first on WeLiveSecurity

Smartwatch Hack Could Trick Dementia Patients into Overdosing
New variant of Joker malware found in Android apps on Play Store
Tony Blair tells Russian infosec conference that cross-border infosec policies need more gov intervention
Google’s ad ban won’t stop stalkerware apps from promoting themselves

Updated mbedtls packages fix security vulnerabilities Fix a side channel vulnerability in modular exponentiation that could reveal an RSA private key used in a secure enclave.

Updated mediawiki packages fix security vulnerability: In MediaWiki before 1.31.8, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This

Advisory text to describe the update. Wrap lines at ~75 chars. A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool.

Updated ffmpeg packages fix security vulnerabilities: This update provides ffmpeg version 4.1.6, which fixes several security vulnerabilities and other bugs which were corrected upstream.

Report: Most Popular Home Routers Have ‘Critical’ Flaws
TomTom bill bomb: Why am I being charged for infotainment? I sold my car last year, rages Reg reader

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Digicert will shovel some 50,000 EV HTTPS certificates into the furnace this Saturday after audit bungle
Locating malicious drone operators through deep neural networks
Microsoft Warns on OAuth Attacks Against Cloud App Users
FYI: Someone’s scanning gateways, looking for those security holes Citrix told you not to worry too much about

security update

security update

Proxy or VPN for Netflix – Which is Best?
Popular home routers plagued by critical security flaws

A study paints a dim picture of router security, as none of the 127 devices tested was free of severe vulnerabilities The post Popular home routers plagued by critical security flaws appeared first on WeLiveSecurity

Zoom Zero-Day Allows RCE, Patch on the Way
Smartwatch vulnerability allowed hackers to overdose dementia patients
Joker Android Malware Dupes Its Way Back Onto Google Play
How to build a cyber threat intelligence program while cutting through the noise
15 billion credentials from 100,000 data breaches sold on dark web
BlueLeaks Server Seized By German Police: Report

Several security issues were fixed in OpenSSL.

Cosmic Lynx: The highly-professional cybercrime gang scamming businesses out of millions of dollars
‘Undeletable’ Malware Shows Up in Yet Another Android Device
Smashing Security podcast #186: This one’s for all the Karens!
If you haven’t potentially exposed 1000s of customers once again with networking vulns, step forward… Not so fast, Palo Alto Networks
Social engineering hacks weaken cybersecurity during the pandemic
240 top Microsoft Azure-hosted subdomains hacked to spread malware
Microsoft sues coronavirus phishing spammers to seize their domains amid web app attacks against Office 354.5

FIx CVE-2019-20454

This is a security fix release that includes fixes for the following local buffer overflow vulnerability. – CVE-2022-4044: Local users can perform a buffer overflow attack against the xrdp-sesman service and then impersonate it This update is recommended for all xrdp users.

Remmina 1.4.7 and FreeRDP 2.1.2 to fix many bugs and CVEs

Remmina 1.4.7 and FreeRDP 2.1.2 to fix many bugs and CVEs

Security update for CVE-2020-12695 (CallStranger)

security update

Advertising Plugin for WordPress Threatens Full Site Takeovers
Nasty Cerberus banking trojan found on Google Play Store
One surefire way to get the boss’s attention on network security is to get hacked. But there must be a better way?
Criminals auction off stolen domain admin credentials for up to £95k. Your bank account details? Barely get £50
Attackers target critical flaw in popular networking gear

The vulnerability, which received the highest possible severity score, leaves thousands of devices at risk of being taken over by remote attackers. A patch is available. The post Attackers target critical flaw in popular networking gear appeared first on WeLiveSecurity

Raising children in the social media limelight? Pause before you post

How (over)sharing your children’s triumphs and antics with the world may impact their immediate and distant future – and how to reduce the risks of ‘sharenting’ The post Raising children in the social media limelight? Pause before you post appeared first on WeLiveSecurity

German Police seize DDoSecrets server hosting BlueLeaks data dump
Notorious Hacker ‘Fxmsp’ Outed After Widespread Access-Dealing
Feds indict Fxmsp hacker who breached anti-virus firms to sell data
Microsoft Seizes Malicious Domains Used in Mass Office 365 Attacks

Several security issues were fixed in Thunderbird.

Mozilla turns off “Firefox Send” following malware abuse reports

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2824

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2827

15 Billion Credentials Currently Up for Grabs on Hacker Forums

Several vulnerabilities have been discovered in the interpreter for the Ruby language. CVE-2020-10663

Citrix tells everyone not to worry too much over its latest security patches. NSA’s former top hacker disagrees
Kinda sorta weakened version of EARN IT Act creeps closer

An update that fixes four vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

security update

Shopped recently in a small online store? Check this list to see if it was one of 570 websites infected with card-skimming Magecart
BEC Hotshot with Opulent Social Media Presence to Face U.S. Charges
Keeper Threat Group Rakes in $7M from Hundreds of Compromised E-Commerce Sites