Menu

Latest articles

Tekya Malware Threatens Millions of Android Users via Google Play
Got your number? Maybe. 118 118 Money shutters website after spotting an intruder
Facebook Messenger may ban mass-forwarding of messages
Russia’s FSB wanted its own IoT botnet
Memcached has a crash-me bug, but hey, only about 83,000 public-facing servers appear to be running it

An update for openshift-enterprise-template-service-broker-operator-container is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact

An update for openshift-enterprise-builder-container, openshift-enterprise-cli-container, and ose-cli-artifacts-container is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact

Feds shut down bogus COVID-19 vaccine site

An update for openshift-clients is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Have you patched your IoT devices against the KrØØk Wi-Fi chip flaw?
The Shield: the open source Israeli Government app which warns of Coronavirus exposure
Apache Tomcat Exploit Poised to Pounce, Stealing Files
Hackers Actively Exploit 0-Day in CCTV Camera Hardware

security update

It’s 2020 and hackers are still hijacking Windows PCs by exploiting font parser security holes. No patch, either
Microsoft Warns of Critical Windows Zero-Day Flaws
WhatsApp “Martinelli” hoax is back, warning about “Dance of the Pope”
Fake Coronavirus ‘Vaccine’ Website Busted in DoJ Takedown
Coronavirus extortion scam threatens to infect victim’s family
The good, the bad and the plain ugly

A prolific ransomware gang vows to dial back its campaigns and spare healthcare organizations altogether during the COVID-19 crisis. It’s no cause for celebration. The post The good, the bad and the plain ugly appeared first on WeLiveSecurity

Cisco issues urgent fixes for SD-WAN router flaws
Tour guide/Chinese spy gets four years for SD card dead drops
Stolen data of company that refused REvil ransom payment now on sale
Firefox is dropping FTP support

Several security issues were fixed in Vim.

An update for samba is now available for Red Hat Gluster Storage 3.5 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for runc is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Red Hat AMQ Streams 1.4.0 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

It’s time to track people’s smartphones to ensure they self-isolate during this global pandemic, says WHO boffin
No, the head of the World Health Organization has not emailed you – it’s a message laced with malware

An update for devtoolset-8-gcc is now available for Red Hat Developer Toolset 8 for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The following packages CVE(s) were reported against phpmyadmin. CVE-2020-10802

The Dance of the Pope virus hoax

An update that fixes 7 vulnerabilities is now available.

The following CVE(s) were reported against jackson-databind. CVE-2020-10672

5 Best Internet Service Locators

An update that fixes 9 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

Russian Intel Agency FSB’s contractor hacked; sensitive data leaked online

security update

security update

A vulnerability was discovered in graphicsmagick, a collection of image processing tools, that allows allows an attacker to read arbitrary files via a crafted image because of TranslateTextEx for SVG.

It was discovered that systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local

A denial of service vulnerability (by triggering high CPU consumption) was found in Tor, a connection-based low-latency anonymous communication system.

Multiple vulnerabilities have been found in Node.js, worst of which could allow remote attackers to write arbitrary files.

It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when strip=False and ‘math’ or ‘svg’ tags and one or more of the RCDATA tags were whitelisted.

A vulnerability in Exim could allow a remote attacker to execute arbitrary code.

German army’s sensitive data found on laptop bought from eBay
Bored during lockdown? Why not try out these data-spilling KrØØk Wi-Fi bug exploits against your nearby devices

security update

Revamped HawkEye Keylogger Swoops in on Coronavirus Fears
Defying Covid-19’s Pall: Pwn2Own Goes Virtual
Online face mask sales scams, 400% uptick of coronavirus phishing reports: Brit cops’ workload shifts online along with the nation’s
News Wrap, Coronavirus Edition: WFH Security Woes, Pwn2Own
Security firm leaves more than five billion records exposed on unsecured database
Trolls ZoomBomb work-from-home videocall with filth
Cyber Security firm exposes 5 billion+ login credentials
Keep calm and carry on working (remotely)

How can employees stay motivated and productive while teleworking during the COVID-19 crisis? The post Keep calm and carry on working (remotely) appeared first on WeLiveSecurity

Exchange rate service’s customer details hacked via AWS

An update that fixes 7 vulnerabilities is now available.

5 Best Android Emulators for PC
Covid-19 Spurs Facial Recognition Tracking, Privacy Fears
New Mirai Variant ‘Mukashi’ Targets Zyxel NAS Devices

Reading Time: ~ 2 min. DDoS Attack Strikes U.S. Health Department Amidst the panic caused by the novel coronavirus, millions of people began navigating to the U.S. Department of Health’s website to find more information on the illness, but instead found the site to be offline after a DDoS attack overwhelmed its servers. This comes […]

COVID-19 disruption delays release of Chrome version 81
Location-tracking wristbands required on all incoming travelers to Hong Kong
What to do if your Twitter account has been hacked

Losing access to your account can be stressful, but there are steps you can take to get it back – and to avoid getting hacked again The post What to do if your Twitter account has been hacked appeared first on WeLiveSecurity

Firefox to burn FTP out of its browser, starting slowly in version 77 due in April

The package bluez before version 5.54-1 is vulnerable to access restriction bypass.

The package chromium before version 80.0.3987.149-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution and information disclosure.

In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView’s JavaScript literal escape helpers.

‘Dirty little secret’ extortion email threatens to give your family coronavirus

Update to 80.0.3987.132. Lots of security fixes here. VAAPI re-enabled by default except on NVIDIA. List of CVEs fixed (since last update): * CVE-2019-20446 * CVE-2020-6381 * CVE-2020-6382 * CVE-2020-6383 * CVE-2020-6384 * CVE-2020-6385 * CVE-2020-6386 * CVE-2020-6387 * CVE-2020-6388 * CVE-2020-6389 * CVE-2020-6390 * CVE-2020-6391 * CVE-2020-6392 *

Coronavirus Poll Results: Cyberattacks Ramp Up, WFH Prep Uneven

Update to WebKitGTK 2.28.0. * Add API to enable Process Swap on (Cross-site) Navigation. * Add user messages API for the communication with the web extension. * Add support for same-site cookies. * Service workers are enabled by default. * Add support for Pointer Lock API. * Add flatpak sandbox support. * Make ondemand hardware […]

What do you not want right now? A bunch of Cisco SD-WAN, Webex vulnerabilities? Here are a bunch of them
Security flaws found in popular password managers

Not all they’re cracked up to be? Several password vaults contain vulnerabilities, both new and previously disclosed but never patched, a study says The post Security flaws found in popular password managers appeared first on WeLiveSecurity

Russian state-sponsored hackers have been sniffing Middle East defence firms, warns Trend Micro
Dark Web: Hackers launch Coronavirus sale to sell hacking tools
Whatever happened to cryptojacking?
Cisco Warns of High-Severity SD-WAN Flaws
NIST shared dataset of tattoos that’s been used to identify prisoners
Work from home: Improve your security with MFA

Remote work can be much safer with the right cyber‑hygiene practices in place – multi‑factor authentication is one of them The post Work from home: Improve your security with MFA appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

Multiple vulnerabilities have been found in Apache Tomcat, the worst of which could lead to arbitrary code execution.

Cloud Misconfig Mistakes Show Need For DevSecOps
What is the Best Defense Against Phishing Attacks?

Multiple vulnerabilities have been found in libgit2, the worst of which could result in the arbitrary execution of code.

A heap-based buffer overflow in GNU FriBidi might allow remote attackers to execute arbitrary code.

Multiple vulnerabilities have been found in Cacti, the worst of which could lead to the remote execution of arbitrary code.

An SQL injection vulnerability in phpMyAdmin may allow attackers to execute arbitrary SQL statements.

Cryptojacking is almost conquered – crushed along with coinhive.com

Reading Time: ~ 3 min. We’re all thinking about it, so let’s call it out by name right away. The novel coronavirus, COVID-19, is a big deal. For many of us, the structure of our lives is changing daily; and those of us who are capable of doing our work remotely are likely doing so […]

Oh-so-generous ransomware crooks vow to hold back from health organisations during COVID-19 crisis
Smashing Security #170: PornHub, Coronavirus apps, and remote working
Delayed Adobe patches fix long list of critical flaws
More business websites hit by credit-card skimming malware
Facebook accidentally blocks genuine COVID-19 news