Menu

Latest articles

Several vulnerabilities were discovered in coturn, a TURN and STUN server for VoIP. CVE-2020-4067

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Yes, Prime Minister, rewrite the Computer Misuse Act: Brit infosec outfits urge reform

Mailman could be made to inject arbitrary content in the login page if it received a specially crafted input.

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Satori IoT botnet author sentenced to 13 months in prison
Monday review – the hot 10 stories of the week
CyberX, CyberX, does whatever a CyberX does. Locks IoT, machines too, Microsoft got it, so will you
Sony Announces PlayStation Bug Bounty Program

security update

Lucifer malware infects Windows & launch DDoS attack using NSA exploits

An update that solves four vulnerabilities and has four fixes is now available.

It was discovered that there was a “roster push attack” in mcabber, a console-based Jabber (XMPP) client. This is identical to CVE-2015-8688 for gajim.

It was discovered that there was a command injection vulnerability in picocom, a minimal dumb-terminal emulation program.

Several issues have been fixed in zziplib, a library providing read access on ZIP-archives. They are basically all related to invalid memory access and resulting crash or memory leak.

It was found that pngquant, a PNG (Portable Network Graphics) image optimising utility, is susceptible to a buffer overflow write issue triggered by a maliciously crafted png image, which could lead into

It was discovered that libtiprc, a transport-independent RPC library, could be used for a denial of service or possibly unspecified other impact by a stack-based buffer overflow due to a flood of crafted ICMP and UDP

Russian hacker Aleksei Burkov jailed for 9 years in US

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

Major Magecart skimming attack hits 8 local US government sites

A vulnerability was discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in denial of service via malformed HTTP/2 headers.

An update that fixes one vulnerability is now available.

Macs, iPhones, iPads to get encrypted DNS – how’d you like them Apples?

– avoid overwriting a local file with -J (CVE-2020-8177) – fix partial password leak over DNS on HTTP redirect (CVE-2020-8169)

Let’s roll the 3d6 dice on today’s security drama: Ah, 15, that’s LG allegedly hacked, source code stolen by Maze ransomware gang
DarkCrewFriends Returns with Botnet Strategy
8 U.S. City Websites Targeted in Magecart Attacks

An update that fixes one vulnerability is now available.

‘Cardplanet’ Operator Sentenced to 9 Years for Selling Stolen Credit Cards
Mainstream European bank hit by largest ever PPS based DDoS attack
Tune in and watch live: Email encryption doesn’t have to be an all-or-nothing deal
Facial recognition technology banned in another US city

In a move lauded by privacy advocates, Boston joins the ranks of cities that have voted down the municipal use of the technology The post Facial recognition technology banned in another US city appeared first on WeLiveSecurity

Domestic violence assistance app breached placing victims at risk
Satori Botnet Creator Sentenced to 13 Months in Prison
Brit plod’s use of facial-recognition tech is lawful, no need to question us, cops’ lawyer tells Court of Appeal

An update that fixes one vulnerability is now available.

Man sentenced, two others charged, in connection with Satori IoT botnet
Fancy hacking a PlayStation? Sony announces its bug bounty program
TikTok To Stop Clipboard Snooping After Apple Privacy Feature Exposes Behavior

An update that solves two vulnerabilities and has 10 fixes is now available.

When one open-source package riddled with vulns pulls in dozens of others, what’s a dev to do?

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

REvil gang threaten to auction celebrity data from Mariah Carey, Lebron James, MTV and more
Talk about the fox guarding the hen house. Comcast to handle DNS-over-HTTPS for Firefox-using subscribers
US govt: Julian Assange tried to recruit hacker to steal hush-hush dirt and we should know – the hacker was an informant
“I think you appear in this video” phishing scam hijacks Facebook accounts
Nationwide Facial Recognition Ban Proposed By Lawmakers
Golang Worm Widens Scope to Windows, Adds Payload Capacity
Maze Ransomware operators hack LG Electronics stealing critical data
Honeypot behind sold-off IP subnet shows Cyberbunker biz hosted all kinds of filth, says SANS Institute
US indicts WikiLeaks’ Julian Assange for hiring Anonymous & LulzSec
Nvidia Warns Windows Gamers of Serious Graphics Driver Bugs
Find a Playstation 4 vulnerability and earn over $50,000

An update that fixes one vulnerability is now available.

Patch time! NVIDIA fixes kernel driver holes on Windows and Linux
Office 365 Users Targeted By ‘Coronavirus Employee Training’ Phish

An update for nghttp2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The inside story of the Maersk NotPetya ransomware attack, from someone who was there

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 9 fixes is now available.

Reading Time: ~ 3 min. It didn’t take long for COVID-19 to completely alter the way we work. Businesses that succeed in this rapidly changing environment will be the ones that adapt with the same velocity. In our second installment from The Future of Work series, you’ll hear from Webroot Product Marketing Director George Anderson, […]

Twitter apologizes for leaking businesses’ financial data

Red Hat AMQ Broker 7.7 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

There are DDoS attacks, then there’s this 809 million packet-per-second tsunami Akamai says it just caught
Smashing Security podcast #184: Vanity Bitcoin wallets, BlueLeaks, and a Coronavirus app conspiracy
After huffing and puffing for years, US senators unveil law to blow the encryption house down with police backdoors
‘Safe Documents’ tool in Office 365 will automatically detect malware
Emerging Ransomware Targets Photos, Videos on Android Devices
Self-Propagating Lucifer Malware Targets Windows Systems
Ransomware crims to sell off ‘scandalous’ files swiped from Mariah Carey, Nicki Minaj, Puff Daddy’s legal eagles

**horde 5.2.23** * [mjr] SECURITY: Fix javascript injection vulnerability in mobile login page. * [mjr] Fix broken cloud search in portal block.

security update

Fake govt COVID-19 contact tracking app spreads Android ransomware
DDoSecrets thrown off Twitter after distributing 269GB BlueLeaks data dump
Laws on police facial recognition aren’t tough enough, UK data watchdog barrister tells Court of Appeal
Glupteba – the malware that gets secret messages from the Bitcoin blockchain
HEY pulls feature which could expose email threads without participants’ knowledge
Clop ransomware operators leak 4.75 GB data on Indiabulls conglomerate
Former UK Labour deputy leader wants to know how the NHS’s contact-tracing app will ensure user privacy
New Bill Targeting ‘Warrant-Proof’ Encryption Draws Ire
Experts Denounce Racial Bias of Crime-Predictive Facial-Recognition AI
Maze ransomware gang threatens to publish sensitive stolen data after US aerospace biz sensibly refuses to pay
EncroChat encrypted communication provider quits after malware attack

An update that fixes three vulnerabilities is now available.

An update for candlepin and satellite is now available for Red Hat Satellite 6.5 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Carbon-based vuln hunters will always be better at infosec than AI, insist puny humans

An update that fixes one vulnerability is now available.

iOS 14, macOS Big Sur, Safari to give us ‘No, thanks!’ option for ad tracking

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Three words you do not want to hear regarding a ‘secure browser’ called SafePay… Remote. Code. Execution
Verizon FiOS Router and Security Issues
The state of OpenPGP key servers: Kristian, can you renew my certificate? A month later: Kristian? Ten days later: Too late, it’s expired
Here’s a headline we never thought we’d write 20 years ago: Microsoft readies antivirus for Linux, Android
New ransomware posing as COVID‑19 tracing app targets Canada; ESET offers decryptor

ESET researchers dissect an Android app that masquerades as an official COVID-19 contact-tracing app and encrypts files on the victim’s device The post New ransomware posing as COVID‑19 tracing app targets Canada; ESET offers decryptor appeared first on WeLiveSecurity