Menu

Latest articles

Microsoft Addresses Active Attacks, Air-Gap Danger with 99 Patches
Intel Patches High-Severity Flaw in Security Engine
Estée Lauder Exposes 440M Records, with Email Addresses, Network Info
B-but it doesn’t get viruses! Not so, Apple fanbois: Mac malware is growing faster than nasties going for Windows
U.S. FDA: No link between smartphone radiation & cancer
Crypto AG backdooring rumours were true, say German and Swiss news orgs after explosive docs leaked
Adobe Addresses Critical Flash, Framemaker Flaws
China denies it was behind the Equifax hack, as four men charged for data breach
Tens of millions of biz Dell PCs smacked by privilege-escalation bug in bundled troubleshooting tool
5 tips for you and your family on Safer Internet Day
5 tips for businesses on Safer Internet Day
Prison inmates’ sensitive data left exposed on leaky cloud bucket
Graham Cluley on Tripwire’s Talking Cybersecurity Podcast
Dell Patches SupportAssist Flaw That Allows Arbitrary Code Execution
Freedom Hosting owner pleads guilty to distributing child abuse images
Officials raise alarm about Chinese hacking
Facebook’s Twitter and Instagram accounts hijacked
Dashlane password manager’s Chrome extension has disappeared

Yubico PIV Tool could be made to crash or run programs as an administrator if it received specially crafted input.

Competing in esports: 3 things to watch out for

If you’re looking to become a pro gamer, there are risks you shouldn’t play down The post Competing in esports: 3 things to watch out for appeared first on WeLiveSecurity

spice-client: Insufficient encoding checks for LZ can cause different integer/buffer overflows (CVE-2018-10893) SL6 x86_64 spice-glib-0.26-8.el6_10.2.i686.rpm spice-glib-0.26-8.el6_10.2.x86_64.rpm spice-gtk-0.26-8.el6_10.2.i686.rpm spice-gtk-0.26-8.el6_10.2.x86_64.rpm spice-gtk-debuginfo-0.26-8.el6_10.2.i686.rpm spice-gtk-debuginfo-0.26-8.el6_10.2.x86_64.rpm spic [More…]

An update for spice-gtk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for nss-softokn is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Forgotten motherboard driver turns out to be perfect for slipping Windows ransomware past antivirus checks
US charges 4 Chinese military hackers over 2017 Equifax breach
Five Open-Source Projects AI Enthusiasts Might Want to Know About>
Game over, LAN, game over! Windows software nasty Emotet spotted spreading via brute-forced Wi-Fi networks
BYO-Bug Tactic Attacks Windows Kernel with Outdated Driver
Active PayPal Phishing Scam Targets SSNs, Passport Photos
These truly are the end times for TLS 1.0, 1.1: Firefox hopes to ‘eradicate’ weak HTTPS standard by blocking it
Hackers caught using CNET website to spread nasty malware
US govt accuses four Chinese army soldiers of hacking Equifax and siphoning 145m Americans’ personal info

The updated packages fix a security vulnerability: In Sudo before 1.8.31, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however,

Equifax Breach: Four Members of Chinese Military Charged with Hacking
Docker Registries Expose Hundreds of Orgs to Malware, Data Theft
Emotet Now Hacks Nearby Wi-Fi Networks to Spread Like a Worm
Owner of dark web Freedom hosting pleads guilty to host child abuse content
Coronavirus phishing attack disguises as a message from the Center for Disease Control
Google Chrome to start blocking downloads served via HTTP

Security researchers from Snyk discovered that the fix for CVE-2019-9658 was incomplete. Checkstyle, a development tool to help programmers write Java code that adheres to a coding standard, was still vulnerable to XML External Entity (XXE) injection.

Facebook encrypted messaging will ‘create hiding places for child abuse’
FBI director warns of sustained Russian disinformation threat
Frustrated author cybersquats novelist’s website
How to bring security into agile development and CI/CD
Home anti-virus products put to the test by AV-Comparatives – which received the highest score?

an out-of-bounds write vulnerability due to an integer overflow was reported in libexif, a library to parse exif files. This flaw might be leveraged by remote attackers to cause denial of service, or potentially execute arbitrary code via crafted image files.

Several security issues were fixed in libxml2.

Several security issues were fixed in Qt.

Facebook loses control of its own Twitter account in hacker attack – and more news

Add patch for CVE-2020-6750 and related issues.

Emergency call service in Australia to use AI to detect signs of heart attack

An update that fixes 38 vulnerabilities is now available.

Update to Node.js 12.15.0

Update to Node.js 12.15.0

Update to Node.js 12.15.0

libasr-1.0.4, opensmtpd-6.6.2p1 update

libasr-1.0.4, opensmtpd-6.6.2p1 update

Facebook’s Twitter account is hijacked by notorious OurMine hacking group
Dark web hackers selling payment card data of half a million Indians
Wacom Tablet Data Exfiltration Raises Security Concerns

Resolve buffer overflow in TexOpen() function, CVE-2019-19601

Resolves: #1796107, #1796109 – Security fix for CVE-2019-19921

Update to upstream 2.0.1 release for CVE-2019-10747

Update to upstream 1.3.2 release for CVE-2019-10746

MinGW cross compiled SDL 2.0.10, fixing a number of CVE issues.

Update to 2.40.0. —- MinGW cross compiled gdk-pixbuf 2.36.12 release, fixing various CVE’s.

Google Chrome to block file downloads – from .exe to .txt – over HTTP by default this year. And we’re OK with this
Critical Android Bluetooth Bug Enables RCE, No User Interaction Needed

security update

security update

The Oscar nominated movie you just downloaded could be a malware

Reading Time: ~ 2 min. Tax Season Brings Emotet to the Front As Americans prepare for tax season, Emotet authors have started a new campaign that imitates a W-9 tax form requested by the target. As with most malicious phishing, an attached document asks users to enable macros when viewing the files. This campaign can […]

Google Chrome To Bar HTTP File Downloads
RobbinHood – the ransomware that brings its own bug
Uncle Sam tells F-35B allies they’ll have to fly the things a lot more if they want to help out around South China Sea
Dutch university paid $220,000 ransom to hackers after Christmas attack
Critical Citrix RCE Flaw Still Threatens 1,000s of Corporate LANs
Day 4 of outage: UK’s Manchester police deploy exciting new carbon-based method to record crime
Phishing Campaign Targets 250 Android Apps with Anubis Malware
Apple fined €25 million for deliberately slowing down old iPhones
The RSAC 2020 Trend Report

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that fixes four vulnerabilities is now available.

Researchers transmit data covertly by altering screen brightness
Android users at risk from Bluetooth hijack attack, and are warned of “short distance worm” threat
Facebook, Google, YouTube order Clearview to stop scraping faceprints
Wacom driver caught monitoring third-party software use
Cybercrooks busted for multimillion-dollar identity fraud
Magecart Gang Attacks Olympic Ticket Reseller and Survival Food Sites

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

Android owners – you’ll want to get these latest security patches, especially for this nasty Bluetooth hijack flaw
How Technology Has Altered the Education Landscape
Good: IT admins scrambled to patch 80 per cent of public-facing Citrix boxes to close nightmare hijack hole
Hackers can steal data from air-gapped PC using screen brightness
Metamorfo Returns with Keylogger Trick to Target Financial Firms