Menu

Latest articles

Boots yanks loyalty card payouts after 150K accounts get stuffed
Like a Virgin, hacked for the very first time… UK broadband ISP spills 900,000 punters’ records into wrong hands from insecure database
Android users, if you could pause your COVID-19 panic buying for one minute to install these critical security fixes, that would be great
Man hacks Indian tech support scam call center; leaks CCTV footage
Let’s Encrypt: OK, maybe nuking three million HTTPS certs at once was a tad ambitious. Let’s take time out
Zynga Faces Lawsuit Over Massive Words with Friends Breach
Chris Eng: Patch Management Challenges Drive ‘Security Debt’
Staffer emails compromised and customer details exposed in T-Mobile US’s third security whoopsie in as many years
Hackers dropping info-stealer malware with fake security certificate alerts
High-Severity Cisco Webex Flaws Fixed
‘Unfixable’ boot ROM security flaw in millions of Intel chips could spell ‘utter chaos’ for DRM, file encryption, etc
Coronavirus warning spreads computer virus
Facebook: No, we are not killing Libra

An update that fixes two vulnerabilities is now available.

It was discovered that there was an out-of-bounds write vulnerability in pdfresurrect, a tool for extracting or scrubbing versioning data from PDF documents.

Ethical hackers swarm Pentagon websites

xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs (CVE-2018-1311) SL7 x86_64 xerces-c-3.1.1-10.el7_7.i686.rpm xerces-c-3.1.1-10.el7_7.x86_64.rpm xerces-c-debuginfo-3.1.1-10.el7_7.i686.rpm xerces-c-debuginfo-3.1.1-10.el7_7.x86_64.rpm xerces-c-devel-3.1.1-10.el7_7.i686.rpm xerces-c-devel-3.1.1-10.el7_7.x86_64.rpm noar [More…]

nodejs: HTTP request smuggling using malformed Transfer-Encoding header (CVE-2019-15605) SL7 x86_64 http-parser-2.7.1-8.el7_7.2.i686.rpm http-parser-2.7.1-8.el7_7.2.x86_64.rpm http-parser-debuginfo-2.7.1-8.el7_7.2.i686.rpm http-parser-debuginfo-2.7.1-8.el7_7.2.x86_64.rpm http-parser-devel-2.7.1-8.el7_7.2.i686.rpm http-parser-devel-2.7.1-8.el7_7.2.x86_64.rpm – Scient [More…]

Google launches FuzzBench service to benchmark fuzzing tools
Trump, Sanders Are the Top Brands for Cybercriminals
Enable that MF-ing MFA: 1.2 million Azure Active Directory accounts compromised every month, reckons Microsoft
Let’s Encrypt Pushes Back Deadline to Revoke Some TLS Certificates
Zynga faces class action suit over massive Words With Friends hack

An update for the virt:8.1 and virt-devel:8.1 modules is now available for Advanced Virtualization for RHEL 8.1.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Guildma: The Devil drives electric

The fourth installment of our occasional series demystifying Latin American banking trojans The post Guildma: The Devil drives electric appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

Sadly, the web has brought a whole new meaning to the phrase ‘nothing is true; everything is permitted’
Time to limber up in the battle against cybercriminals
Alleged Vault 7 leaker trial finale: Want to know the CIA’s password for its top-secret hacking tools? 123ABCdef
Smashing Security #168: The Bitcoin fraud factory
Fake reviews & third-party apps cause 50% of threats against Android
Download this update from mybrowser.microsoft.com. Oh, sorry, that was malware on a hijacked sub-domain. Oops
Critical Netgear Bug Impacts Flagship Nighthawk Router
Microsoft OneNote Used To Sidestep Phishing Detection
CIA’s 11-year old hacking campaign against China exposed
If Tesco was hacked, your data could be being flogged for just £2.70 – research
Fraud Prevention Month: How to protect yourself from scams

ESET Chief Security Evangelist Tony Anscombe sat down with us to share his insights on how to avoid falling prey to online fraud The post Fraud Prevention Month: How to protect yourself from scams appeared first on WeLiveSecurity

Loyalty Cards Targeted in Tesco Clubcard Attack
Why 3 million Let’s Encrypt certificates are being killed off today
Voice assistants can be hacked with ultrasonic waves

With access to text messages and the ability to make fraudulent phone calls, attackers could wreak more damage than you’d think The post Voice assistants can be hacked with ultrasonic waves appeared first on WeLiveSecurity

It has been 15 years, and we’re still reporting homograph attacks – web domains that stealthily use non-Latin characters to appear legit
UK data watchdog slaps a £500,000 fine on Cathay Pacific for 2018 9.4m customer data leak

An update for http-parser is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Police raid tech support scam centre who had their CCTV hacked by vigilantes

An update for http-parser is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

NCSC: Secure your webcams now
Cathay Pacific slammed for security failures following hack which exposed 9.4 million people worldwide
Google fixes MediaTek bug in Android March patches

An update that solves 22 vulnerabilities and has 152 fixes is now available.

Fancy that: Hacking airliner systems doesn’t make them magically fall out of the sky

An update that solves 22 vulnerabilities and has 152 fixes is now available.

Tech support scammers hacked back by vigilante
Facebook purges hundreds of fake accounts from state actors, marketers

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Hackers are using Word documents to drop NetSupport Manager RAT
Cobalt Ulster Strikes Again With New ForeLord Malware
Let’s Encrypt to Revoke Millions of TLS Certs
Let’s Encrypt? Let’s revoke 3 million HTTPS certificates on Wednesday, more like: Check code loop blunder strikes
MediaTek Bug Actively Exploited, Affects Millions of Android Devices
Why ‘free’ Wi-Fi isn’t really free
Have I Been Pwned No Longer For Sale
Brave comes out on top in browser privacy study

By contrast, two web browsers share identifiers that are tied to the device hardware and so persist even across fresh installs The post Brave comes out on top in browser privacy study appeared first on WeLiveSecurity

GCHQ’s infosec arm has 3 simple tips to secure those insecure smart home gadgets
Apple removes Clearview AI iPhone app from App Store
Digital piggy bank sevice broken into by cybercrooks

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

Huge flaw found in how facial features are measured from images
GoodRx stops sharing personal medical data with Google, Facebook
Have I Been S0ld? No, trusted security website HIBP off the table, will remain independent

Rake could be made run arbitrary commands it received a specially crafted file.

DoppelPaymer Ransomware Used to Steal Data from Supplier to SpaceX, Tesla

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat build of Eclipse Vert.x. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each

Nvidia patches severe flaws affecting GeForce, Quadro NVS and Tesla
Maersk prepares to lay off the Maidenhead staffers who rescued it from NotPetya super-pwnage
XSS plugin vulnerabilities plague WordPress users
5 reasons to consider a career in cybersecurity

From competitive salaries to ever-evolving job descriptions, there are myriad reasons why a cybersecurity career could be right for you The post 5 reasons to consider a career in cybersecurity appeared first on WeLiveSecurity

NetSupport Manager RAT Spread via Bogus NortonLifeLock Docs
Gamer Alert: Serious Nvidia Flaw Plagues Graphics Driver
Forrester: Keeping Smart Cities Safe From Hacks
Voice assistant devices can be manipulated with ultrasonic waves
Wi-Fi kit spilling data with bad crypto – Huawei, eh? No, it’s Cisco. US giant patches Krook spy-hole bug in network gear

An update that fixes two vulnerabilities is now available.

An update that solves 10 vulnerabilities and has two fixes is now available.

An update that fixes two vulnerabilities is now available.

TrickBot Adds ActiveX Control, Hides Dropper in Images
Walgreens Mobile App Leaks Prescription Data
DoppelPaymer ransomware hits SpaceX, Tesla & Boeing’s parts manufacturer
RSA 2020 – Is your machine learning/quantum computer lying to you?

And how would you know if the algorithm was tampered with? The post RSA 2020 – Is your machine learning/quantum computer lying to you? appeared first on WeLiveSecurity

Delicious irony: Credit rating builder Loqbox lets customer details and card numbers slip after ‘sophisticated attack’
Siri and Google Assistant hacked in new ultrasonic attack
Let’s Encrypt issues one billionth free certificate
Ironpie robot vacuum can suck up your privacy
Fresh phish! Stripe scam baked and delivered in under an hour
Facebook sues data analytics firm OneAudience over malicious SDK

Several security issues were fixed in libarchive.

An update that fixes 8 vulnerabilities is now available.