Menu

Latest articles

The girl with the dragnet tattoo: How a TV news clip, Insta snaps, a glimpse of a tat and a T-shirt sold on Etsy led FBI to alleged cop car arsonist
AcidBox Malware Uncovered Using Repurposed VirtualBox Exploit
Premier League’s Return: A Hat Trick of Cyberthreats?
Zoom will offer proper end-to-end encryption to free vid-chat accounts – not just paid-up bods – once you verify your phone number…

security update

CIA failed to protect its sophisticated hacking tools from hackers
Ripple20 bugs expose hundreds of millions of devices to attacks

Devices used in the energy, transportation and communications sectors are also affected by the flaws in the TCP/IP software library The post Ripple20 bugs expose hundreds of millions of devices to attacks appeared first on WeLiveSecurity

Hackers posing as LinkedIn recruiters to scam military, aerospace firms
Shlayer Mac Malware Returns with Extra Sneakiness
Tune in online this week – and discover how to secure all of your attack surfaces
Avon cosmetics suffers “cyber incident” – but was it ransomware?
Survey shows rise in robocalls amid COVID‑19 fears

The unsolicited phone calls tout everything from miracle cures to financial relief – here’s how you can stay safe The post Survey shows rise in robocalls amid COVID‑19 fears appeared first on WeLiveSecurity

New Mac malware spreads disguised as Flash Player installer via Google search results
NHS Test & Trace sends text to wrong person, telling them they tested negative for Coronavirus

An update is now available for Red Hat build of Eclipse Vert.x. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For

Coronavirus-Themed Cyberattacks Drop, Microsoft
D-Link home routers plagued with critical & multiple vulnerabilities

An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For

NSS could be made to expose sensitive information over the network.

From the crew behind the Sony Pictures hack comes Operation Interception: An aerospace cyber-attack thriller
More ad fraud apps found hiding on Google Play Store
eBay staff charged with cyberstalking, sending fetal pig and spiders
LinkedIn ‘Job Offers’ Targeted Aerospace, Military Firms With Malware

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 6 vulnerabilities is now available.

Boffins find that over nine out of ten ‘ethical’ hackers are being a bit naughty when it comes to cloud services
Business email compromise: What can be learned from the Norfund attack
If you’re despairing at staff sharing admin passwords, look on the bright side. That’s CIA-grade security
You. Yeah you, in the beret. Drop that media file right now unless you’ve patched Illustrator or After Effects
Qbot Trojan Reappears to Go After U.S. Banking Customers
Adobe Patches 18 Critical Flaws in Out-Of-Band Update
LinuxSecurity Celebrates 24 Years of Serving as the Linux Community’s Central Security Resource >
Intel announces “exploit busting” features in its next processor chips
Warning issued over hackable security cameras

The owners of the vulnerable indoor cameras are advised to unplug the devices immediately The post Warning issued over hackable security cameras appeared first on WeLiveSecurity

Theft of CIA’s ‘Vault 7’ Secrets Tied to ‘Woefully Lax” Security
‘Ripple20’ Bugs Impact Hundreds of Millions of Connected Devices
Aqua-Fi – New optical networks can deliver Internet underwater
No Wiggle room: Two weeks after angry bike shop customers report mystery orders on their accounts, firm confirms payment cards delinked

The package intel-ucode before version 20200609-1 is vulnerable to information disclosure.

The package dbus before version 1.12.18-1 is vulnerable to denial of service.

‘Anonymous’ takes down Atlanta Police Dept. site after police shooting
Eavesdroppers can use light bulbs to listen in from afar
Shadow IT: Why It’s Still a Major Risk in Today’s Environments

Reading Time: ~ 3 min. As these times stress the bottom lines of businesses and SMBs alike, many are looking to cut costs wherever possible. The problem for business owners and MSPs is that cybercriminals are not reducing their budgets apace. On the contrary, the rise in COVID-related scams has been noticeable. It’s simply no […]

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

845GB of sensitive explicit data on niche dating apps users exposed online
845GB of racy dating app records exposed to entire internet via leaky AWS buckets
How hackers weaponized the COVID-19 virus pandemic – and how you can stop them: Tune in here tomorrow
Twitter Disrupts Wide-Ranging Political Disinformation Campaigns
Lamphone attack recovers secretive conversations via hanging light bulb
ESET rushes to defend rival Malwarebytes in legal war sparked by vendor upset at ‘unwanted program’ labeling
Intel Adds Anti-Malware Protection in Tiger Lake CPUs
WFH Alert: Critical Bug Found in Old D-Link Router Models
You’ve heard of sextortion – now there’s “breachstortion”, too
Fake version of note sharing site Privnote.com stealing users’ Bitcoin
Congress wants to know who is using spyware against the US
Claire’s Customers Targeted with Magecart Payment-Card Skimmer
‘Lamphone’ Hack Uses Lightbulb Vibrations to Eavesdrop on Homes
20 months behind bars for IT support worker who nicked £30k worth of crypto-cash
Microsoft Azure users leave front door open for cryptomining crooks

This is a security update for JBoss EAP Continuous Delivery 12.0. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

This is a security update for JBoss EAP Continuous Delivery 13.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

This is a security update for JBoss EAP Continuous Delivery 18.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

This is a security update for JBoss EAP Continuous Delivery 16.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

RIP ROP, COP, JOP? Intel to bring anti-exploit tech to market in this year’s Tiger Lake chip family
Retail giant Claire’s online store hacked after closing 3000 stores

This is a security update for JBoss EAP Continuous Delivery 14.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An error in Cyrus IMAP Server allows mailboxes to be created with administrative privileges.

Fake govt-issued COVID-19 contact tracing apps spread spyware

Update to upstream 3.6.14 release, and security fix for CVE-2020-13777.

Fixes CVE-2020-10995, CVE-2020-12244 and CVE-2020-10030

Update to upstream 3.6.14 release, and security fix for CVE-2020-13777. —- – Fix certificate chain validation involving the expired “AddTrust External Root”. – Disable RSA blinding during FIPS self-tests to avoid hanging if there is not enough entropy for `getrandom()` – Add `–waitresumption` option to `gnutls-cli` to force the client to wait for resumption data […]

Fixes CVE-2019-20479

– Update to 1.20.12 release – ifcfg-rh: handle “802-1x.{,phase2-}ca-path” (rh #1841395, CVE-2020-10754)

Update to upstream 3.6.14 release, and security fix for CVE-2020-13777.

Facebook paying for exploit to catch a predator, voting software security under the microscope…

Reading Time: ~ 2 min. Nintendo Accounts Breached Stemming from a cyber-attack back in April, Nintendo has just announced that roughly 300,000 user accounts have been compromised, though most belong to systems that are now inoperable. From the excessive unauthorized purchases, the attackers likely used credential-stuffing methods to access accounts and make digital purchases through […]

security update

security update

security update

An update that fixes three vulnerabilities is now available.

An update that fixes 10 vulnerabilities is now available.

An update that solves 25 vulnerabilities and has 132 fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Whatsapp blamed own users for failure to keep phone number repo off Google searches
Knoxville Ransomware Attack Leads to IT Network Shutdown
Wailing Wednesday follows Patch Tuesday as versions of Windows 10 stop playing nicely with plugged-in printers
How Big Tech Leveraged Agile Principles to Build Empires
Microsoft Joins Ban on Sale of Facial Recognition Tech to Police
Gamaredon group grows its game

Active APT group adds cunning remote template injectors for Word and Excel documents; unique Outlook mass-mailing macro The post Gamaredon group grows its game appeared first on WeLiveSecurity

Posh Spice’s perfume people pop up in Maze ransomware gang extortion effort
Android ‘ActionSpy’ Malware Targets Turkic Minority Group
Intel patches chip flaw that could leak your cryptographic secrets

An update that fixes four vulnerabilities is now available.