Menu

Latest articles

An update that fixes one vulnerability is now available.

April Patch Tuesday: Microsoft Battles 4 Bugs Under Active Exploit
Over half a million Zoom accounts being sold on hacker forum
Adobe Fixes ‘Important’ Flaws in ColdFusion, After Effects and Digital Editions
TA505 Crime Gang Deploys SDBbot for Corporate Network Takeover
Cyberattacks Target Healthcare Orgs on Coronavirus Frontlines
Americans report US$13 million in losses from coronavirus scams

The median loss to fraudulent schemes that exploit the global health crisis is almost US$600 The post Americans report US$13 million in losses from coronavirus scams appeared first on WeLiveSecurity

Watch: Flaw exploited to post fake COVID-19 clips from TikTok accounts
Exclusive: Personal data of 1.41m US doctors sold on hacker forum
Safe Remote Access to Critical Infrastructure Networks in a Time of Global Crisis
4 million Quidd user accounts dumped on hacker forum for download
TikTok Flaw Allows Threat Actors to Plant Forged Videos in User Feeds

Reading Time: ~ 3 min. Despite the intent of ensuring safe transit of information to and from a trusted website, encrypted protocols (usually HTTPS) do little to validate that the content of certified websites is safe. With the widespread usage of HTTPS protocols on major websites, network and security devices relying on interception of user […]

An update for podman is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Let’s authenticate: Beyond Identity pitches app-wrapped certificate authority

An update that fixes one vulnerability is now available.

Malware Risks Triple on WFH Networks: Experts Offer Advice

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

TikTok users beware: Hackers could swap your videos with their own

An update is now available for Red Hat Satellite 6.7 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Is “global privacy” an oxymoron?

While in France, a citizen of Brazil who resides in California books a bungee jump in New Zealand. Is it a leap of faith into the unknown, for both the operator and the thrill-seeker? The post Is “global privacy” an oxymoron? appeared first on WeLiveSecurity

Red Hat AMQ Broker 7.4.3 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

ICANN asks registrars to crack down on scam coronavirus websites
Microsoft and Google delay online authentication change
Zoom adds Choose Your Own Routing Adventure to keep chats out of China
So how do the coronavirus smartphone tracking apps actually work and should you download one to help?
Oracle Tackles a Massive 405 Bugs for Its April Quarterly Patch Update
Gaming controllers manufacturer exposed 1.1M customer records
Overlay Malware Leverages Chrome Browser, Targets Banks and Heads to Spain
How to make a stranger’s insecure 3D printer halt-and-catch-fire – plus more alerts from infosec world

New upstream version, fix CVEs

## 1.4.3 (12, Nov 2019) ### Security Improvements: – Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465).

– https://www.drupal.org/project/ckeditor/releases/7.x-1.19 – https://www.drupal.org/sa-contrib-2020-007

New upstream version, fix CVEs

## 1.4.3 (12, Nov 2019) ### Security Improvements: – Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465).

– https://www.drupal.org/project/ckeditor/releases/7.x-1.19 – https://www.drupal.org/sa-contrib-2020-007

Security fix for CVE-2020-11100)

An update that contains security fixes can now be installed.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

2 San Francisco Int. airport websites hacked with info-stealer code
Dutch Police takes down 15 DDoS-for-hire services in one week

An update that solves one vulnerability and has three fixes is now available.

An update that fixes 5 vulnerabilities is now available.

SFO Websites Hacked: Airport Discloses Data Breach
Apple, Google Team on Coronavirus Tracking – Sparking Privacy Fears
Sextortion emails and porn scams are back – don’t let them scare you!
WooCommerce Falls to Fresh Card-Skimmer Malware

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More…]

A vulnerability in libssh could allow a remote attacker to cause a Denial of Service condition.

3D printed fingerprints can unlock your device with 80% success rate
Critical VMware Bug Opens Up Corporate Treasure to Hackers
Apple App Store Riddled With Money-Sucking Fleeceware Apps
The pains – and pleasures? – of network security: Tell us exactly what you think about this corner of business IT
Travelex Pays $2.3M in Bitcoin to Hackers Who Hijacked Network in January

Reading Time: ~ 2 min. Malicious COVID-19 Websites Surge In recent months, more than 136 thousand new domains have been registered that reference the current COVID-19 outbreak, many of which have yet to be flagged. A large portion of these sites are distributing phishing campaigns with fake bank login forms and inaccurate URLs, including any […]

An update that fixes two vulnerabilities is now available.

The package libssh before version 0.9.4-1 is vulnerable to denial of service.

The package wireshark-cli before version 3.2.3-1 is vulnerable to arbitrary code execution.

The package chromium before version 81.0.4044.92-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure, access restriction bypass and insufficient validation.

The package firefox before version 75.0-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and access restriction bypass.

The package haproxy before version 2.1.4-1 is vulnerable to arbitrary code execution.

Compromised Zoom Credentials Swapped in Underground Forums
Ransomware scumbags leak Boeing, Lockheed Martin, SpaceX documents after contractor refuses to pay
Cloudflare Axes Google reCAPTCHA Due to Privacy, Price
Unique P2P Architecture Gives DDG Botnet ‘Unstoppable’ Status

security update

security update

Signal sends smoke, er, signal: If Congress cripples anonymous speech with EARN IT Act, we’ll shut US ops
Copycat Site Serves Up Raccoon Stealer
A billion-dollar US firm caught exposing highly sensitive database online
Report: Travelex paid hackers $2.3 million worth of Bitcoin after ransomware attack
Zoom takes action after meeting IDs leak in careless screenshots
Fleeceware on your iPhone? Don’t get caught out while penned up at home

An update that fixes 5 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Consumer reviewer Which? finds CAN bus ports on Ford and VW, starts yelling ‘Security! We have a problem…’

An update that fixes 5 vulnerabilities is now available.

Zoom Taps Ex-Facebook CISO Amid Security Snafus, Lawsuit

Security fix for CVE-2020-5247, CVE-2020-5249

This update incorporates fixes from the upstream glibc 2.29 stable release branch, including 3 fixes for medium severity security vulnerabilities. (CVE-2020-10029, CVE-2020-1752, CVE-2020-1751)

Cisco ‘Critical Update’ Phishing Attack Steals Webex Credentials
‘Unbreakable’ Smart Lock Draws FTC Ire for Deceptive Security Claims
Smashing Security #173: 5G fiascos, Zoom gloom, and butt biometrics
52k Iranian ID cards with selfies sold on dark web & hacking forum
Google removes Android VPN with ‘critical vulnerability’ from Play Store
Low-orbit internet banking fraud claim alleged to be a load of space junk
Cloudflare dumps Google’s reCAPTCHA, moves to hCaptcha as free ride ends (and something about privacy)
PowerPoint ‘Weakness’ Opens Door to Malicious Mouse-Over Attack
Dark_Nexus Botnet Compromises Thousands of ASUS, D-Link Routers
Fake Coronavirus vaccine, patients’ blood & saliva sold on dark web
ThreatList: Skype-Themed Apps Hide a Raft of Malware
Slack in the security spotlight – lessons for collaboration servers

Updated firefox packages fix security vulnerabilities: When reading from areas partially or fully outside the source resource with WebGL’s copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized,

Bisq Bitcoin exchange halts trade due to critical vulnerability
Top tips for videoconferencing security

ESET Chief Security Evangelist Tony Anscombe shares advice on how to keep your virtual meet-ups private and safe while you’re holed up at home during the pandemic The post Top tips for videoconferencing security appeared first on WeLiveSecurity