Menu

Latest articles

An update for haproxy is now available for Red Hat OpenShift Container Platform 4.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Singapore to require smartphone check-ins at all businesses and will log visitors’ national identity numbers

An update that fixes two vulnerabilities is now available.

Hackers breach Ghost blogging platform to mine cryptocurrency

An update that fixes four vulnerabilities is now available.

Ghost blogging platform suffers security breach

A vulnerability was discovered in mailman. GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against

New seamonkey packages are available for Slackware 14.2 and -current to fix security issues.

An update that fixes 5 vulnerabilities is now available.

A security flaw was found on rubygem-json prior to 2.3.0 which was now assigned as CVE-2020-10663. This new rpm contains backport fixes for this issue.

Update to latest upstream OpenVPN 2.4.9 release. It contains a security fix for CVE-2020-11810. This security issue is quite hard to abuse, requiring a fairly precise timing attack combined with guessing a just assigned peer-id reference. If successful, only a single client just initiating a new connection will experience a denial of service situation. This […]

Tokopedia hacked – Login details of 91 million users sold on dark web

security update

Hackers using famous movies to spread malware through torrents

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

A vulnerability was discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. LDAP search filters with nested boolean expressions can result in denial of service (slapd daemon

The 5.6.8 stable kernel update contains a number of important fixes across the tree.

The 5.6.8 stable kernel update contains a number of important fixes across the tree.

The 5.6.8 stable kernel update contains a number of important fixes across the tree.

Spyware slinger NSO to Facebook: Pretty funny you’re suing us in California when we have no US presence and use no American IT services…
Upgraded Cerberus Spyware Spreads Rapidly via MDM

security update

Sextortion scammers still shilling with stolen passwords

The email includes the potential victim’s password as evidence of a hack, but there is more than meets the eye The post Sextortion scammers still shilling with stolen passwords appeared first on WeLiveSecurity

News Wrap: Microsoft Sway Phish, Malicious GIF and Spyware Attacks
Microsoft Teams Impersonation Attacks Flood Inboxes
Maze Ransomware group steals 11m card data from Banco de Costa Rica
TrickBot Attack Exploits COVID-19 Fears with DocuSign-Themed Ploy
Android ransomware found extorting credit card details from users

Reading Time: ~ 3 min. Anyone who has spent late nights scrolling through their social media feed or grinding on video games knows one thing is true: Technology can be a good thing, but only in moderation. Like too much of anything, spending a lot of time on the internet or social media can lead […]

Reading Time: ~ 2 min. As Oil Prices Drop, Hackers Take Aim at Producers With the recent crash in oil prices, and supply rapidly piling up, a new spear phishing campaign has begun targeting executives at several major oil producers. A massive number of emails started being distributed in late March, without the telltale signs […]

Google fights spammy extensions with new Chrome Web Store policy
COVID-19 prompts DHS warning to review Office 365 security
Android trojan EventBot abuses accessibility services to clear out bank accounts – fortunately, it’s ‘in preview’

An update that solves two vulnerabilities and has one errata is now available.

Several vulnerabilities have been discovered in otrs2 (Open source Ticket Request System)

What’s worse than an annoying internet filter? How about one with a pre-auth remote-command execution hole and there’s no patch?

An update that fixes one vulnerability is now available.

OpenJDK 14 April CPU update

Security fix for CVE-2020-5260 and CVE-2020-11008 CVE-2020-5260 – From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.4.txt): > With a crafted URL that contains a newline in it, the credential > helper machinery can be fooled to give credential information for > a wrong host. The

Update to 2.9.10 * Fix CVE-2019-19956, CVE-2019-20388 and CVE-2020-7595

Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers
Microsoft Sway Abused in Office 365 Phishing Attack
Salt Bugs Allow Full RCE as Root on Cloud Servers

security update

security update

security update

security update

security update

Building for Billions: Addressing Security Concerns for Platforms at Scale
New nasty Android EventBot malware infects devices by evading 2FA
ESET Threat Report

A view of the Q1 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report appeared first on WeLiveSecurity

“Zero-click” mobile phone attacks – and how to avoid them
Cybercriminals are using Google reCAPTCHA to hide their phishing attacks
New Android Malware Targets PayPal, CapitalOne App Users
Nursery school teacher arrested for years-long dark web child abuse
Bumper Adobe update fixes flaws in Magento, Bridge and Illustrator
Coronavirus delays trial of alleged Russian hacker a third time

It was discovered that there was a integer signedness error in the miniupnpc UPnP client that could allow remote attackers to cause a denial of service attack.

An issue has been found in pound, A request smuggling vulnerability was discovered in pound, a everse proxy, load balancer and HTTPS front-end for Web servers, that may allow

Two issues have been found in w3m, WWW browsable pager with excellent tables/frames support.

An issue has been found in yodl, a pre-document language. Hanno Bock discovered that there was a buffer over-read vulnerability.

Newly-discovered Android malware steals banking passwords and 2FA codes
Shade Threat Actors Call It Quits, Release 750K Encryption Keys
Salt peppered with holes? Automation tool vulnerable to auth bypass: Patch now

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Critical WordPress e-Learning Plugin Bugs Open Door to Cheating
In trying times like these, it’s reassuring to know you can still get pwned five different ways by Adobe Illustrator files
Smashing Security #176: Hacking hacks and university attacks
High-Severity Cisco IOS XE Flaw Threatens SD-WAN Routers
Millions of Brute-Force Attacks Hit Remote Desktop Accounts
Android users worldwide hit by sophisticated Google Play malware
Grandoreiro: How engorged can an EXE get?

Another in our occasional series demystifying Latin American banking trojans The post Grandoreiro: How engorged can an EXE get? appeared first on WeLiveSecurity

ThreatList: Human-Mimicking Bots Spike, Targeting e-Commerce and Travel
Critical GitLab Flaw Earns Bounty Hunter $20K
Shade ransomware calls it a day, 750,000 decryption keys released

An update that solves 7 vulnerabilities and has 77 fixes is now available.

An update that solves 7 vulnerabilities and has 77 fixes is now available.

An update that solves 13 vulnerabilities and has 157 fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves 6 vulnerabilities and has 8 fixes is now available.

Academics demand answers from NHS over potential data timebomb ticking inside new UK contact-tracing app

An update that solves 13 vulnerabilities and has 157 fixes is now available.

EFF: Google, Apple’s Contact-Tracing System Open to Cyberattacks
Flaw in defunct WordPress plugin exploited to create backdoor
Twitter turns off SMS-based tweeting in most countries
ProtonMail-run website boasting ‘complete guide’ to GDPR left credential-baring .git repo exposed online
San Francisco trial of Russian bloke extradited and accused of hacking LinkedIn, Dropbox, Formspring stalls again amid pandemic lockdown
Enterprise Security Woes Explode with Home Networks in the Mix
Best legal & free online streaming sites for movies & TV shows 2020
‘Black Rose Lucy’ is Back, Now Pushing Ransomware

security update

Critical Adobe Illustrator, Bridge and Magento Flaws Patched

Reading Time: ~ 3 min. A popular military maxim speaks to the need for redundancy and it goes like this: “Two is one and one is none.” Redundancy is also a key principle when it comes to cyber-resilience. A popular rule in data protection and disaster recovery is called the 3-2-1 backup rule. IT pros […]

Hackers Leak Biopharmaceutical Firm’s Data Stolen in Ransomware Attack
iPhone “word of death” could crash your phone – what you need to know
WordPress Plugin Bug Opens 100K Websites to Compromise
Sophisticated Android Spyware Attack Spreads via Google Play
Ransomware hackers leak pharmaceutical giant’s data on dark web