Menu

Latest articles

Should governments track your location to fight COVID-19?
Google sent ~40K warnings to targets of state-backed attackers in 2019
You know all those stories of leaky cloud buckets taken offline? Well, some may still be there, just badly hidden
First-ever SANS Women in Cybersecurity survey reveals significant mentorship gaps

An update that solves two vulnerabilities and has one errata is now available.

Fix CVE-2018-19655

Fix CVE-2018-19655

Hackers sending malware infected USBs with Best Buy Gift Cards

Fix CVE-2018-19655

* New upstream release 5.3.1 (rhbz#1814882) * Fixes CVE-2020-1747 (rhbz#1807367,1809011)

An update that fixes 7 vulnerabilities is now available.

“Operation Poisoned News” infecting iPhones with LightSpy spyware
How To Keep Your Router And WiFi Safe From Hackers
Yeah, that Zoom app you’re trusting with work chatter? It lives with ‘vampires feeding on the blood of human data’

security update

Reading Time: ~ 2 min. World Health Organization Sees Rise in Cyberattacks Officials for the World Health Organization (WHO) have announced that many of their sites and servers have been under attack by unsuccessful hackers trying to capitalize on the latest health scare. The attack stemmed from the use of several malicious domains that attempted […]

Dark web hosting firm quits after hackers delete its database
Apple Unpatched VPN Bypass Bug Impacts iOS 13, Warn Researchers

An update that fixes one vulnerability is now available.

Cybersecurity insurance firm Chubb investigates its own ransomware attack
Cyber crime marketplace DEER.IO seized, admin arrested from JFK airport
Android apps are snooping on your installed software
Firefox 76 will have option to enforce HTTPS-only connections

ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c (CVE-2020-5208) SL7 x86_64 ipmitool-1.8.18-9.el7_7.x86_64.rpm ipmitool-debuginfo-1.8.18-9.el7_7.x86_64.rpm noarch bmc-snmp-proxy-1.8.18-9.el7_7.noarch.rpm exchange-bmc-os-info-1.8.18-9.el7_7.noarch.rpm – Scientific Linux Development Team

Thousands of Dark Web sites deleted in attack on free hosting service
FBI takes down hacker platform Deer.io
Zeek and Jitsi: 2 open source projects we need now

The 5.5.11 stable kernel update contains a number of important fixes across the tree.

* New upstream release 5.3.1 (rhbz#1814882) * Fixes CVE-2020-1747 (rhbz#1807367,1809011)

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has 37 fixes is now available.

Hackers exploiting vulnerable routers to drop malicious “WHO” COVID-19 app

security update

Critical CODESYS Bug Allows Remote Code Execution
AMD dials 911, emits DMCA takedowns after miscreant steals a load of GPU hardware blueprints, leaks on GitHub
Tupperware Cyberattack Stores Away Customer Payment Cards
Hacker Steals & Leaks Xbox Series X GPU Source Code
Emerging APT Mounts Mass iPhone Surveillance Campaign
As Zoom Booms, Incidents of ‘ZoomBombing’ Become a Growing Nuisance
Watch out! Scummy scammers target home deliveries
Hackers Hijack Routers to Spread Malware Via Coronavirus Apps
Critical vulnerabilities found in popular Password Managers
Apple Safari now blocks all third-party cookies by default
Hey, China. Maybe you should have held your hackers off for a bit while COVID-19 ravaged the planet. Just a suggestion
Third-party data breach exposes GE employees’ personal information
Responding to the New Normal: How to Prevent Added Risk in Your Business
HPE issues fix to stop some SSDs from self‑destructing

If left unpatched, a firmware flaw in some enterprise-class solid-state drives could make data on them unrecoverable as early as this fall The post HPE issues fix to stop some SSDs from self‑destructing appeared first on WeLiveSecurity

Adobe issues emergency fix for file-munching bug

A minor version update (from 7.5 to 7.6) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

Hijacked Twitter accounts used to advertise face masks
Smashing Security #171: WhatsApp hoaxes, Zoombombs, and 8-bit love

An update for ipmitool is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Multiple vulnerabilities have been found in PHP, the worst of which could result in the execution of arbitrary shell commands.

Tokyo Olympics Postponed, But 5G Security Lessons Shine
Apple iOS 13.4 offers fixes for 30 vulnerabilities

An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

SANS is offering fully certified cybersecurity training – without leaving your bunker

**PHP version 7.3.16** (19 Mar 2020) **Core:** * Fixed bug php#63206 (restore_error_handler does not restore previous errors mask). (Mark Plomer) **DOM:** * Fixed bug php#77569: (Write Access Violation in DomImplementation). (Nikita, cmb) * Fixed bug php#79271 (DOMDocumentType::$childNodes is NULL). (cmb) **Enchant:** * Fixed bug php#79311 (enchant_dict_suggest() fails on big

Security and performance fixes.

If there’s something strange in Symantec’s neighborhood, who you gonna call? Not Broadcom, it seems: Systems go down, cut off customers
Apple Update Fixes WebKit Flaws in iOS, Safari
Public health vs. personal privacy: Choose only one?

As the world turns to technology to track and contain the COVID-19 pandemic, could this spell the end of digital privacy rights? The post Public health vs. personal privacy: Choose only one? appeared first on WeLiveSecurity

Chinese Hackers Exploit Cisco, Citrix Flaws in Massive Espionage Campaign
Tupperware-dot-com has a live credit card skimmer on its payment page, warns Malwarebytes
GE Employees Lit Up with Sensitive Doc Breach
Hackers are actively targeting WHO amid Coronavirus pandemic

An exploitable heap overflow vulnerability exists in the Psych::Emitter startdocument function of Ruby. In Psych::Emitter startdocument function heap buffer “head” allocation is made based on

An update that solves one vulnerability and has 6 fixes is now available.

An update that solves one vulnerability and has 6 fixes is now available.

Multiple vulnerabilities have been found in Samba, the worst of which could lead to remote code execution.

TrickBot App Bypasses Non-SMS Banking 2FA

Multiple vulnerabilities have been found in WeeChat, the worst of which could allow remote attackers to cause a Denial of Service condition.

Windows has a zero-day that won’t be patched for weeks

Multiple vulnerabilities were found in Tor, the worst of which could allow remote attackers to cause a Denial of Service condition.

Apple Safari Blocks Ad-Targeting Cookie Support
Your unused computer could help find a COVID-19 cure
Hackers target WHO in phishing attack
Battling the global COVID-19 scammers and fake news hawkers
Brit housing association blabs 3,500 folks’ sexual orientation, ethnicity in email blunder
Stuck inside with nothing to do? Apple fires out security fixes for iOS, macOS, wrist-puters… and something weird called iTunes for Windows

Reading Time: ~ 3 min. Have you ever watched a movie and seen a character doing something you know how to do, and thought to yourself, “jeez, that’s totally wrong. Couldn’t they have done a little research?” That’s exactly what hackers think when they watch movies, too. For most of us, the image that comes […]

Unknown ‘WildPressure’ Malware Campaign Lets Off Steam in Middle East
Covid-19 Privacy Poll: Phone Tracking, Public Health and Surveillance
Adobe debuts disk-cleaning tool cleverly disguised as an arbitrary file deletion bug in Creative Cloud on Windows
WHO Targeted in Espionage Attempt, COVID-19 Cyberattacks Spike
Hackers are exploiting a critical, unpatched flaw in Windows

IBus could allow local users to capture key strokes of other locally logged in users.

Critical Adobe Flaw Fixed in Out-of-Band Security Update
Watch live online this week: Why you need managed detection and response

Tomcat8 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle

Android malware caught infecting Play Store apps for kids
Free Netflix pass because of Coronavirus? It’s a scam
Microsoft warns of two Windows zero‑day flaws

Updates for the critical-rated vulnerabilities, which are being actively exploited in the wild, are still weeks away The post Microsoft warns of two Windows zero‑day flaws appeared first on WeLiveSecurity

Domain Name Security: Important Measures You Need to Know
Tekya Malware Threatens Millions of Android Users via Google Play
Got your number? Maybe. 118 118 Money shutters website after spotting an intruder
Facebook Messenger may ban mass-forwarding of messages
Russia’s FSB wanted its own IoT botnet
Memcached has a crash-me bug, but hey, only about 83,000 public-facing servers appear to be running it

An update for openshift-enterprise-template-service-broker-operator-container is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact