Menu

Latest articles

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

WhatsApp Axes COVID-19 Mass Message Forwarding

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For the oldstable distribution (stretch), these problems have been fixed

‘Fake Fingerprints’ Bypass Scanners with 3D Printing
COVID-19 CISO Checklist for Securing a Remote Workforce
Be careful when pulling images by short name
Linux Malware: The Truth About This Growing Threat>
Update Firefox again – more RCEs and an Android “takeover” bug too
Microsoft prevents Domain of Danger from falling into miscreants’ paws by forking out cash for corp.com
Microsoft project proposed to aid Linux IoT code integrity
As if the world couldn’t get any weirder, this AI toilet scans your anus to identify you
Please, just stop downloading apps from unofficial stores: Android users hit with ‘unkillable malware’
China and Taiwan aren’t great friends. Zoom sends chats through China. So Taiwan has banned Zoom
Serious Exchange Flaw Still Plagues 350K Servers
Login details of verified Zoom accounts posted on Dark Web
Visual Studio Code extension flags NPM vulnerabilities
New year, old threats: Malware peddlers went into overdrive in Q1, says Trend Micro
Flaw hunter bags $75,000 off Apple after duping Safari into spying through iPhone, Mac cameras without permission
xHelper: The Russian Nesting Doll of Android Malware
FIN6 and TrickBot Combine Forces in ‘Anchor’ Attacks
Italian email provider Email.it hacked with data on sale
600,000 people affected in email provider breach

The users’ personal data are now up for grabs on the dark web for anywhere between US$3,500 and US$22,000 worth of Bitcoin The post 600,000 people affected in email provider breach appeared first on WeLiveSecurity

Official Government COVID-19 Mobile Apps Hide a Raft of Threats

The package firefox before version 74.0.1-1 is vulnerable to arbitrary code execution.

Twitter warns users – Firefox might hold on to private messages

telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code (CVE-2020-10188) SL6 x86_64 krb5-appl-clients-1.0.1-10.el6_10.x86_64.rpm krb5-appl-debuginfo-1.0.1-10.el6_10.x86_64.rpm krb5-appl-servers-1.0.1-10.el6_10.x86_64.rpm i386 krb5-appl-clients-1.0.1-10.el6_10.i686.rpm krb5-appl-debuginfo-1.0.1-10.el6_10.i686.rpm krb5-appl-se [More…]

Mozilla: Use-after-free while running the nsDocShell destructor (CVE-2020-6819) * Mozilla: Use-after-free when handling a ReadableStream (CVE-2020-6820) SL6 x86_64 firefox-68.6.1-1.el6_10.x86_64.rpm firefox-debuginfo-68.6.1-1.el6_10.x86_64.rpm firefox-68.6.1-1.el6_10.i686.rpm firefox-debuginfo-68.6.1-1.el6_10.i686.rpm i386 firefox-68.6.1-1.el6_10.i686.rpm firefox- [More…]

Two schoolkids sue Google for collecting biometrics

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

GnuTLS could expose sensitive information over the network.

Thousands of Android apps contain undocumented backdoors, study finds
Crazy cryptomining Cooking Mama rumours spread as game pulled from Nintendo Switch online store
Atlassian issues advice on how to keep your IT service desk secure… after hundreds of portals found facing the internet amid virus lockdown

Reading Time: ~ 2 min. Zoom Video Software Targeted by Hackers With much of the professional world now telecommuting, hackers have taken notice and are finding vulnerabilities within Zoom’s software to hijack online meetings. Over 400 new domains have been registered through Zoom in just the last month, of which many have been found to […]

A Brisk Private Trade in Zero-Days Widens Their Use
FBI Threatens ‘Zoom Bombing’ Trolls With Jail Time
Mozilla plugs two Firefox browser holes exploited in the wild by hackers to hijack victims’ computers
Maze ransomware group hacks oil giant; leaks data online
Apple Safari Flaws Enable One-Click Webcam Access
Roaring trade in zero-days means more vulns are falling into the hands of state spies, warn security researchers
Learn Morse Code in 30 minutes on your smartphone with Google
Government VPN Servers Targeted in Zero-Day Attack
Will Apple’s “microphone switch” stop your iPad getting bugged?
Staying home? Here are 5 best Java learning platforms

An update for ksh is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c (CVE-2020-5208) SL6 x86_64 ipmitool-1.8.15-3.el6_10.x86_64.rpm ipmitool-debuginfo-1.8.15-3.el6_10.x86_64.rpm i386 ipmitool-1.8.15-3.el6_10.i686.rpm ipmitool-debuginfo-1.8.15-3.el6_10.i686.rpm – Scientific Linux Development Team

An update for ipmitool is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for ksh is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code (CVE-2020-10188) SL6 x86_64 telnet-0.17-49.el6_10.x86_64.rpm telnet-debuginfo-0.17-49.el6_10.x86_64.rpm telnet-server-0.17-49.el6_10.x86_64.rpm i386 telnet-0.17-49.el6_10.i686.rpm telnet-debuginfo-0.17-49.el6_10.i686.rpm telnet-server-0.17-49.el6_10.i686.rpm – Scientif [More…]

Rights groups appeal to governments over COVID-19 surveillance

An update for telnet is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Kaspersky cleans up poisoned watering hole, Google presses pause on cookie crackdown
Hackers’ forum hacked, OGUsers database dumped (again)
Beyond Zoom: How Safe Are Slack and Other Collaboration Apps?
What to do you if your phone is lost or stolen

Losing your smartphone can be expensive, but the cost of the device may not be the final price you’ll be paying The post What to do you if your phone is lost or stolen appeared first on WeLiveSecurity

British Airways and Marriott UK data protection fines deferred again as coronavirus shutdown hits business
Pan-European group plans cross-border contact-tracing app – and promises GDPR compliance

security update

Firefox zero day in the wild: patch now!
Digital wallet app leaks millions of users’ credit cards & Govt IDs

This update is based on upstream 5.5.15 and fixes some security related issues related to use after free and null pointer dereferences and also some other bugfixes. Other fixes in this update:

Updated firefox packages fix security vulnerabilities: Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free (CVE-2020-6819).

Updated python-ntlk package fixes security vulnerability: A vulnerability was found in NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ in an NLTK package (ZIP archive) that is mishandled during extraction

The updated packages fix a security vulnerability: In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number

libmtp is a library for communicating with MTP aware devices. The Media Transfer Protocol (commonly referred to as MTP) is a devised set of custom extensions to support the transfer of music files on USB digital audio players

– New upstream version (74.0.1), fixed 0day vulnerability

Hacker defaces Escrow.com by hacking GoDaddy employee’s account
Bugs allowed hackers to hijack & activate Mac, iPhone cameras
Firefox Zero-Day Flaws Exploited in the Wild Get Patched

Two security issues have been found in the Mozilla Firefox web browser, which could result in the execution of arbitrary code. For the oldstable distribution (stretch), these problems have been fixed

An update that fixes one vulnerability is now available.

A flaw was reported in the DTLS protocol implementation in GnuTLS, a library implementing the TLS and SSL protocols. The DTLS client would not contribute any randomness to the DTLS negotiation, breaking the security guarantees of the DTLS protocol.

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code.

Watch: Rare Second World War footage of Bletchley Park-linked MI6 intelligence heroes emerges, shared online

Security fix for CVE-2020-10188

security update

Not only is Zoom’s strong end-to-end encryption not actually end-to-end, its encryption isn’t even that strong
NSO Group: Facebook tried to license our spyware to snoop on its own addicts – the same spyware it’s suing us over

security update

security update

Reading Time: ~ 2 min. For the past several years, Webroot and its partners have conducted a series of studies aimed at better understanding the attitudes, perspectives, and behaviors related to cyber hygiene in United States. This helps users determine which behaviors put them most at risk and which behavioral changes could help increase their […]

Self-Propagating Malware Targets Thousands of Docker Ports Per Day
Cloud Providers, CDNs Team Up to Battle Internet Routing Attacks
Hacking the iOS/macOS webcam – Apple pays out $75,000 to bug hunter
OGUsers hacking forum hacked; entire database dumped on rival forum
5 things you can do today to make Zooming safer

An update that fixes one vulnerability is now available.

Spearphishing Campaign Exploits COVID-19 To Spread Lokibot Infostealer

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

‘Zombie’ Windows win32k bug reanimated by researcher
Watch out for the new wave of COVID-19 scams, warns IRS

An update that fixes 6 vulnerabilities is now available.

Zoom vows to spend next 90 days thinking hard about its security and privacy after rough week, meeting ID war-dialing tool emerges