Menu

Latest articles

Use of open-source libraries leave web apps vulnerable to cyber attacks
Has your Roblox account been hacked to support Donald Trump?
E.U. Authorities Crack Encryption of Massive Criminal and Murder Network
Facebook hoaxes back in the spotlight – what to tell your friends
Fitness firm V Shred exposes 606 GB worth of sensitive customer data

An update that fixes 19 vulnerabilities is now available.

Ring Doorbell’s Police Partnerships Questioned Over Racial Bias

An update that contains security fixes can now be installed.

An update that solves three vulnerabilities and has three fixes is now available.

Google buys AR smart-glasses company North
Fighting BEC and EAC: Why whack-a-mole won’t work
F5 emits fixes for critical flaws in BIG-IP gear: Hopefully yours aren’t internet-facing while you ready a patch
Holy Guacamole! Researchers find Apache remote desktop software was silently pwnable for snooping on sessions

2.23 fixes CVE-2020-14929 (#1850048,#1850047) and new version (#1848786)

Update to latest upstream version

Fix CVE-2020-12695 (UPnP SUBSCRIBE misbehavior in hostapd WPS AP)

Euro police forces infiltrated encrypted phone biz – and now ‘criminal’ EncroChat users are being rounded up

security update

security update

Hold off that rush into the July 4 weekend – you may need this: Microsoft patches pwn-by-picture pitfalls in Win 10

Reading Time: ~ 2 min. WastedLocker Shuts Down US News Sites Over 30 news sites were compromised in the latest WastedLocker attack that affected many sites under a single parent company. Of the more than 30 companies targeted, eight belong to the Fortune 500 group and were in the early stages of a experiencing a […]

Facebook exposed user data to thousands of app developers
Users who don’t understand how to encrypt their emails won’t do it
Trojans, Backdoors and Droppers: The Most-Analyzed Malware
Microsoft releases emergency update to fix two serious Windows flaws

The out-of-band update plugs two remote code execution bugs in the Windows Codecs library, including one rated as critical The post Microsoft releases emergency update to fix two serious Windows flaws appeared first on WeLiveSecurity

Apache Guacamole Opens Door for Total Control of Remote Footprint
Facebook Privacy Glitch Gave 5K Developers Access to ‘Expired’ Data
47% of online MongoDB databases hacked demanding ransom
MongoDB ransom threats step up from blackmail to full-on wiping
FakeSpy Android Malware Spread Via ‘Postal-Service’ Apps
Cisco SMB kit harbors cross-site scripting bug: One wrong link click… and that’s your router pwned remotely
Smashing Security podcast #185: Bieber fever, Roblox, and ransomware

An update for rh-nginx116-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that solves one vulnerability and has 9 fixes is now available.

Several security issues were fixed in Samba.

Firefox could be made to crash or run programs as your login if it opened a malicious website.

A security update is now available for Red Hat Single Sign-On 7.4.1 adapters for Red Hat JBoss Enterprise Application Platform 6 Red Hat Product Security has rated this update as having a security impact of

133m records for sale as fruits of data breach spree keep raining down

Reading Time: ~ 4 min. After surveying more than 10,000 people in 50 states about their cybersecurity habits, we wound up with some pretty surprising results. Like the fact that tech experts demonstrate riskier behaviors than average Americans. But the most significant result of all was the fact that most Americans are more confident than […]

A security update is now available for Red Hat Single Sign-On 7.4.1 adapters for Red Hat JBoss Enterprise Application Platform 7.3 Red Hat Product Security has rated this update as having a security impact of

Reading Time: ~ 3 min. While the proliferation of encrypted DNS is being driven by consumer privacy, businesses will want to take notice. Encrypted DNS – also known as DNS over HTTPS, or DoH – obscures internet traffic from bad actors. But it also has the potential to decrease visibility for IT admins whose responsibility […]

New EvilQuest ransomware hits Mac devices through pirated software
Cisco Warns of High-Severity Bug in Small Business Switch Lineup
Alina Point-of-Sale Malware Spotted in Ongoing Campaign

security update

China’s insidious surveillance against Uyghurs with Android malware
EvilQuest: Inside A ‘New Class’ of Mac Malware
COVID‑19 contact tracing – technology panacea or privacy nightmare?

Can a technological intervention stem the pandemic while avoiding the privacy pitfalls of location tracking? The post COVID‑19 contact tracing – technology panacea or privacy nightmare? appeared first on WeLiveSecurity

Everything You Must Know About Common Venmo Scams
New Android Spyware Tools Emerge in Widespread Surveillance Campaign
Verified Instagram account running copyright infringement phishing scam
Microsoft issues critical fixes for booby-trapped images – update now!
Email Sender Identity is Key to Solving the Phishing Crisis
Microsoft Releases Emergency Security Updates for Windows 10, Server
Google stops pushing scam ads on Americans searching for how to vote

An update for ose-machine-config-operator-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

An update for containernetworking-plugins is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openshift is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenShift Container Platform release 4.2.36 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

An update for python-psutil is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Details of Beijing’s new Hong Kong security law revealed: Signals end to more than two decades of autonomy
Firefox 78 is out – with a mysteriously empty list of security fixes

An update for httpd24-nghttp2 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Tune in and watch live right here this week – it’s your email encryption wake-up call
Things that happen every four years: Olympic Games, Presidential elections, and now new Mac ransomware
After six months of stonewalling by Apple, app dev goes public with macOS privacy protection bypass
It’s happened again: AT&T sued for allegedly transferring victim’s number to thieves in $1.9m cryptocoin heist
Verizon Media, PayPal, Twitter Top Bug-Bounty Rankings
EvilQuest Mac Ransomware Has Keylogger, Crypto Wallet-Stealing Abilities

security update

Living on a prayer? Netgear not quite halfway there with patches for 28 out of 79 vulnerable router models
StrongPity APT Back with Kurdish-Aimed Watering Hole Attacks
Remote access at risk: Pandemic pulls more cyber‑crooks into the brute‑forcing game

Poorly secured remote access attracts mostly ransomware gangs, but can provide access to coin miners and backdoors too The post Remote access at risk: Pandemic pulls more cyber‑crooks into the brute‑forcing game appeared first on WeLiveSecurity

Google joins Apple in limiting web certificates to one year
UCSF Pays $1.14M After NetWalker Ransomware Attack
Hackers deface Roblox accounts with pro-Trump messages
NEC insists its face-recog training dataset isn’t biased, but refuses to share details of Neoface system with UK court
DDoS and dingoes: Australia to bolster cyber-defences with 500 hackers amid China spat
CISA: Nation-State Attackers Likely to Exploit Palo Alto Networks Bug
How to Safeguard Data When the Majority of Your Workforce is Remote
7 Best Linux Distros for Security and Privacy in 2020>

An update that fixes two vulnerabilities is now available.

iOS 14 flags TikTok, 53 other apps spying on iPhone clipboards

An update for the virt:rhel module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the virt:rhel module is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Remember when we warned in February Apple will crack down on long-life HTTPS certs? It’s happening: Chrome, Firefox ready to join in, too
REvil Ransomware Gang Adds Auction Feature for Stolen Data
Tuesday’s Magento 1 EOL Leaves Clock Ticking on 100K Online Stores
Microsoft’s Windows File Recovery tool recovers your lost data
AWS Facial Recognition Platform Misidentified Over 100 Politicians As Criminals
Unpatched Wi-Fi Extender Opens Home Networks to Remote Control
University of California San Francisco pays ransomware gang $1.14m as BBC publishes ‘dark web negotiations’
Watching a $1.14 million ransomware negotiation between hackers and scientists searching for COVID-19 treatments
Beware “secure DNS” scam targeting website owners and bloggers

An update that fixes three vulnerabilities is now available.

Voice recordings from domestic violence alerting app exposed on the internet

An update that fixes one vulnerability is now available.