Menu

Latest articles

Feds Reveal Hidden Cobra’s Trove of Espionage Tools
Info on NHS Coronavirus app leaks out via Google Drive snafu

Reading Time: ~ 3 min. If you’ve been working in the technology space for any length of time, you’ve undoubtedly heard about the rising importance of artificial intelligence (AI) and machine learning (ML). But what can these tools really do for you? More specifically, what kinds of benefits do they offer for cybersecurity and business […]

An update for .NET Core is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that solves one vulnerability and has one errata is now available.

How SELinux separates containers using Multi-Level Security

Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category may cause kernel panic (CVE-2020-10711) SL6 x86_64 kernel-2.6.32-754.29.2.el6.x86_64.rpm kernel-debug-2.6.32-754.29.2.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-754.29.2.el6.i686.rpm kernel-debug-debuginfo-2.6.32-754.29.2.el6.x86_64.rpm kernel-debug-devel-2.6.32-754.29.2.el6.i686 [More…]

USN-3911-1 introduced a regression in file.

Several security issues were fixed in Squid.

IPRoute could be made to execute arbitrary code if it received a specially crafted input.

TikTok’s handling of child privacy gets another watchdog’s attention
Criminal forum trading stolen data suffers ironic data breach
Sadly, 111 in this story isn’t binary. It’s decimal. It’s the number of security fixes emitted by Microsoft this week
Thunderbolt flaws open millions of PCs to physical hacking

A new attack method enables bad actors to access data on a locked computer via an evil maid attack within 5 minutes The post Thunderbolt flaws open millions of PCs to physical hacking appeared first on WeLiveSecurity

REvil Ransomware Attack Hits A-List Celeb Law Firm
Microsoft Addresses 111 Bugs for May Patch Tuesday

Reading Time: ~ 2 min. Adult Website Leaks Trove of Sensitive Data An recently discovered unsecured database belonging to the adult streaming site Cam4 was found to contain nearly 11 billion unique records amounting to seven terabytes of data. For a site with billions of visitors each year, the exposed data could affect millions who […]

Researchers spot thousands of Android apps leaking user data through misconfigured Firebase databases
Over 160 million user records put up for sale on the dark web

Eleven companies, ranging from online marketplaces to news websites, have had their user databases poached The post Over 160 million user records put up for sale on the dark web appeared first on WeLiveSecurity

Breaking news? App promises news feeds, brings DDoS attacks instead

After being targeted by an Android DDoS app, ESET seized the opportunity to analyze the attack and to help put an end to it The post Breaking news? App promises news feeds, brings DDoS attacks instead appeared first on WeLiveSecurity

WordPress Page Builder Plugin Bugs Threaten 1 Million Sites with Full Takeover
Adobe Kills 16 Critical Flaws in Acrobat and Reader, Digital Negative SDK
Thunderspy – why turning your computer off is a cool idea!
Chatbooks Confirms Breach After ‘Shiny Hunters’ Sell Data
Dating app user logins found on hacking forum
Anubis Malware Upgrade Logs When Victims Look at Their Screens

An update that solves 53 vulnerabilities and has 32 fixes is now available.

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

An update for libreswan is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

India releases data-use protocols for its contact-tracing app… after five weeks and 100 million downloads

An update for libreswan is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libreswan is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Papa don’t breach: Contracts, personal info on Madonna, Lady Gaga, Elton John, others swiped in celeb law firm ‘hack’
Incredible how you can steal data via Thunderbolt once you’ve taken the PC apart, attached a flash programmer, rewritten the firmware…
Astaroth’s New Evasion Tactics Make It ‘Painful to Analyze’
Unpatched Bugs in Oracle iPlanet Open Door to Info-Disclosure, Injection
Millions of Thunderbolt-Equipped Devices Open to ‘ThunderSpy’ Attack
Sphinx Malware Returns to Riddle U.S. Targets

Multiple CVE(s) were discovered in the src:wordpress package. CVE-2020-11026

Celebrity personal data taken in ransomware attack
Hacking group puts millions of Zoosk dating profiles up for sale
Chatbooks security breach. Users told to change their passwords
Mama mia! Nintendo in need of a plumber after leak sprays N64, GameCube, Wii code

An update that fixes two vulnerabilities is now available.

Mailman could be made to inject arbitrary content in the login page if it received a specially crafted input.

The Internet of Things in 2020: More vital than ever
Clearview AI won’t sell vast faceprint collection to private companies

Open Liberty 20.0.0.5 Runtime is now available from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Microsoft opens IoT bug bounty program

An update that fixes two vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Researchers detected 400 million malware infections in April 2020

The package firefox before version 76.0-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing and insufficient validation.

Chromium-browser 81.0.4044.138 fixes security issues: Multiple flaws were found in the way Chromium 81.0.4044.129 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code,

**MySQL 8.0.20** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-20.html CVEs fixed: CVE-2020-2759 CVE-2020-2761 CVE-2020-2762 CVE-2020-2763 CVE-2020-2765 CVE-2020-2770 CVE-2020-2774 CVE-2020-2779 CVE-2020-2780 CVE-2020-2804 CVE-2020-2812 CVE-2020-2814 CVE-2020-2853 CVE-2020-2892 CVE-2020-2893

**MySQL 8.0.20** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-20.html CVEs fixed: CVE-2020-2759 CVE-2020-2761 CVE-2020-2762 CVE-2020-2763 CVE-2020-2765 CVE-2020-2770 CVE-2020-2774 CVE-2020-2779 CVE-2020-2780 CVE-2020-2804 CVE-2020-2812 CVE-2020-2814 CVE-2020-2853 CVE-2020-2892 CVE-2020-2893

Are you ready, kids? I said, are you ready? Whoooooo has another update for you to see? Google Chromium! For browsing and tweeting (but not FTP) Google Chromium! If improved security be something you wish Google Chromium! Then run dnf while you flop like a fish! Google Chromium! Google Chromium! Google Chromium! Google Chromium! Ahem. […]

**MySQL 8.0.20** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-20.html CVEs fixed: CVE-2020-2759 CVE-2020-2761 CVE-2020-2762 CVE-2020-2763 CVE-2020-2765 CVE-2020-2770 CVE-2020-2774 CVE-2020-2779 CVE-2020-2780 CVE-2020-2804 CVE-2020-2812 CVE-2020-2814 CVE-2020-2853 CVE-2020-2892 CVE-2020-2893

Hackers infect authentic 2FA app to infect Mac devices with malware
Top celebrities data at risk after REvil ransomware hits famous law firm

security update

security update

Multiple security issues have been found in Thunderbird which could result in spoofing the displayed sender email address, denial of service or potentially the execution of arbitrary code.

DigitalOcean suffers data breach after leaving internal document online

– Release 0.24.1

**Version 1.4.4** This is a **service and security update** to the stable version 1.4 of Roundcube Webmail. It contains four fixes for recently reported security vulnerabilities as well a number of general improvements from our issue tracker. – Fix bug where attachments with Content-Id were attached to the message on reply (#7122) – Fix identity […]

**Version 1.4.4** This is a **service and security update** to the stable version 1.4 of Roundcube Webmail. It contains four fixes for recently reported security vulnerabilities as well a number of general improvements from our issue tracker. – Fix bug where attachments with Content-Id were attached to the message on reply (#7122) – Fix identity […]

One malicious MMS is all it takes to pwn a Samsung smartphone: Bug squashed amid Android patch batch

– Release 0.24.1

**Version 1.4.4** This is a **service and security update** to the stable version 1.4 of Roundcube Webmail. It contains four fixes for recently reported security vulnerabilities as well a number of general improvements from our issue tracker. – Fix bug where attachments with Content-Id were attached to the message on reply (#7122) – Fix identity […]

security update

DEF CON is canceled… No, for real. The in-person event is canceled. We’re not joking. It’s canceled. We mean it
Black Hat USA, DEF CON 28 Go Virtual
DDoS-for-hire service SuperiorStresser operator gets suspended sentence
Could this be the world’s most harmless IoT botnet?
Digital transformation could be accelerated by COVID‑19

The pandemic has highlighted the need for businesses to act with alacrity and prepare for the long haul – and to do so with cybersecurity in mind The post Digital transformation could be accelerated by COVID‑19 appeared first on WeLiveSecurity

5 common password mistakes you should avoid

Password recycling or using easy-to-guess passwords are just two common mistakes you may be making when protecting your digital accounts The post 5 common password mistakes you should avoid appeared first on WeLiveSecurity

Hackers Breach 3.5 Million MobiFriends Dating App Credentials
Report: Microsoft’s GitHub Account Gets Hacked
Flaws in 2 famous WordPress plugins put millions of sites at risk
E-commerce firm StorEnvy hacked; 1.5m plain-text accounts leaked
You won’t believe who’s heading up the UK’s Coronavirus tracing app…
Hackers hit Europe’s largest healthcare provider with Snake ransomware
Podcast: Shifting Cloud Security Left With Infrastructure-as-Code
If you miss the happier times of the 2000s, just look up today’s SCADA gear which still have Stuxnet-style holes
More crypto-stealing Chrome extensions swatted by Google

Updated libvncserver packages fix security vulnerability: libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value (CVE-2019-20788).

Updated roundcubemail packages fix security vulnerabilities: – Cross-Site Scripting (XSS) via malicious HTML content (CVE-2020-12625) – CSRF attack can cause an authenticated user to be logged out

Updated samba packages fix security vulnerabilities: A client combining the ‘ASQ’ and ‘Paged Results’ LDAP controls can cause a use-after-free in Samba’s AD DC LDAP server (CVE-2020-10700).

Updated qt4 packages fix security vulnerabilities: A double-free or corruption during parsing of a specially crafted illegal XML document (CVE-2018-15518).

Multiple security issues were discovered in the microdns plugin of the VLC media player, which could result in denial of service or potentially the execution of arbitrary code via malicious mDNS packets (CVE-2020-6071, CVE-2020-6072, CVE-2020-6073, CVE-2020-6077, CVE-2020-6078, CVE-2020-6079, CVE-2020-6080).

Updated matio packages fix a security vulnerability: Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c (CVE-2019-13107).

Bored at home? Cisco has just the thing: A shed-load of security fixes to install, from a Kerberos bypass to crashes
World’s Largest Private Torrent Site Filelist.ro Seized
FYI: Your browser can pick up ultrasonic signals you can’t hear, and that sounds like a privacy nightmare to some
Blue Mockingbird Monero-Mining Campaign Exploits Web Apps

security update

security update

security update