Menu

Latest articles

Metamorfo Returns with Keylogger Trick to Target Financial Firms
U.S. Finance Sector Hit with Targeted Backdoor Campaign
Shoe with GPS embedded insole tracks ‘lost’ alzheimer’s & dementia patients
Update now – WhatsApp flaw gave attackers access to local files
How your network could be hacked through a Philips Hue smart bulb
Wacom drawing tablets are spying on every app you open, and sending the data back to Wacom
Twitter bans deepfakes, but only those ‘likely to cause harm’
Researchers reckon 500k PCs infested with malware after dodgy downloads install even more nasties from Bitbucket

This package allowed ../ directory traversal to access private resources because resource matching did not ensure that pathnames were in a canonical format.

How your screen’s brightness could be leaking data from your air-gapped computer

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in Pillow.

Google’s Chrome 80 clamps down on cookies and notification spam
Charming Kitten Uses Fake Interview Requests to Target Public Figures
Dropbox Passes $1M Milestone for Bug-Bounty Payouts
Android pulls 24 ‘dangerous’ malware-filled apps from Play Store
Smashing Security #164: A bitter pill to swallow
LCD pwn System: How to modulate screen brightness to covertly transmit data from an air-gapped computer… slowly
Yahoo! hack! payout! nearly! approved! and! the! question! is! how! to! spend! 60! cents!?
WhatsApp flaw gave hackers access to files from Windows and Macs
Terrifying bug in WhatsApp allows hackers to steal files. So get patching all nine of you using it on the desktop
Sketchy behavior? Wacom tablet drivers phone home with names, times of every app opened on your computer
CamuBot Banking Trojan Returns In Targeted Attacks
Time to patch your lightbulb? Researchers demonstrate Philips Hue exploit
Hackers can use flaw in Philips smart light bulbs to spread malware
New Lemon Duck Malware Campaign Targets IoT, Large Manufacturers
RIP FTP? File Transfer Protocol switched off by default in Chrome 80
Oh ****… Sudo has a ‘make anyone root’ bug that needs to be patched – if you’re unlucky enough to enable pwfeedback
Man pleads guilty to hacking Nintendo & possession of child pornography
Coronavirus “safety measures” email is a phishing scam
PayPal SMS scams – don’t fall for them!
WhatsApp Bug Allows Malicious Code-Injection, One-Click RCE
They can’t collect your bins or fix your roads. They let Google stalk visitors to their websites. Yes, it’s UK local government
Critical Cisco ‘CDPwn’ Protocol Flaws Explained: Podcast
Critical Cisco ‘CDPwn’ Flaws Break Network Segmentation

An update that solves two vulnerabilities and has one errata is now available.

Several security issues were fixed in systemd.

Someone else may have your videos, Google tells users
Critical Android flaws patched in February bulletin
Twitter admits to raid on users’ phone numbers
Gamaredon APT Improves Toolset to Target Ukraine Government, Military
How to catch a cybercriminal: Tales from the digital forensics lab

What is it like to defeat cybercrime? A peek into how computer forensics professionals help bring cybercriminals to justice. The post How to catch a cybercriminal: Tales from the digital forensics lab appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

OpenSMTPD could be made to run programs as root if it received specially crafted input over the network.

ipa: Denial of service in IPA server due to wrong use of ber_scanf() (CVE-2019-14867) * ipa: Batch API logging user passwords to /var/log/httpd/error_log (CVE-2019-10195) SL7 x86_64 ipa-client-4.6.5-11.el7_7.4.x86_64.rpm ipa-debuginfo-4.6.5-11.el7_7.4.x86_64.rpm ipa-server-4.6.5-11.el7_7.4.x86_64.rpm ipa-server-trust-ad-4.6.5-11.el7_7.4.x86_64.rpm noarch ipa-client-co [More…]

hw: TSX Transaction Asynchronous Abort (TAA) (CVE-2019-11135) * QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378) SL7 x86_64 qemu-img-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-common-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-debuginfo-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-tools-1.5.3-167.el7_7.4.x86_64.rpm – Scien [More…]

Google Takeout a bit too true to its name after potentially 1000s of private videos shared with complete strangers
Is Chrome really secretly stalking you across Google sites using per-install ID numbers? We reveal the truth
Welp – Google sent your photos & videos to strangers
Community Housing Nonprofit Hit with $1.2M Loss in BEC Scam
This is not Huawei to reassure people about Beijing’s spying eyes: Trivial backdoor found in HiSilicon’s firmware for net-connected cams, recorders
Ransomware Attack Hinders Toll Group Operations
Malware infection attempts appear to be shrinking… possibly because miscreants are less spammy and more focused on specific targets

security update

7 best practices for managing a multi-cloud environment
Two Critical Android Bugs Get Patched in February Update
Medtronic Patches Implanted Device, CareLink Programmer Bugs
Oh buoy. Rich yacht bods’ job agency leaves 17,000 sailors’ details exposed in AWS bucket
Israeli government’s Gov.il DNS server found vulnerable
Open-Source Security Projects: Choosing a Brandable .com Domain>
Electric scooters vulnerable to remote hacks

A helmet may not be enough to keep you safe(r) while riding an e-scooter The post Electric scooters vulnerable to remote hacks appeared first on WeLiveSecurity

Twitter API Abused to Uncover User Identities
School’s out as ransomware attack downs IT systems at Scotland’s Dundee and Angus College

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

NIST tests methods of recovering data from smashed smartphones
Twitter security hole allowed state-sponsored hackers to match phone numbers to usernames
Use Off-Facebook tool to stop Facebook from tracking your activities
Man admits hacking Nintendo, leaking details of Switch games console
Twitter hands over student’s account to his college

Several security issues were fixed in SpamAssassin.

Google’s Super Bowl ad will make you cry. Or wince.
Facebook privacy settings: Protect your data with these tips

As Facebook turns 16, we look at how to keep your personal information safe from prying eyes The post Facebook privacy settings: Protect your data with these tips appeared first on WeLiveSecurity

Google’s OpenSK lets you BYOSK – burn your own security key

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Twitter says a certain someone tried to discover the phone numbers used by potentially millions of twits
Your mobile network broke the law by selling location data and may be fined millions… or maybe not, shrugs FCC
AZORult Campaign Adopts Novel Triple-Encryption Technique

security update

Tesla Autopilot Duped By ‘Phantom’ Images
Hackers exploiting vulnerability in smart doors to launch DDoS attacks
Ashley Madison Breach Extortion Scam Targets Hundreds
‘Cyber security incident’ takes its Toll on Aussie delivery giant as box-tracking boxen yanked offline
Man uses 99 smartphones to cause traffic jam on Google Maps
Would you get hooked by a phishing scam? Test yourself

As the tide of phishing attacks rises, improving your scam-spotting skills is never a bad idea The post Would you get hooked by a phishing scam? Test yourself appeared first on WeLiveSecurity

iCloud hacker perv cops nearly 3 years in jail for stealing and sharing people’s private, intimate pics

An update that solves 10 vulnerabilities and has 11 fixes is now available.

Apple proposes simple security upgrade for SMS 2FA codes
Coronavirus – hackers exploit fear of infection to spread malware
FTC warns VoIP providers that help robocallers: we can and will sue
TrickBot Switches to a New Windows 10 UAC Bypass to Evade Detection
Fraudsters posed as art dealer, bilked museum for millions
Cover for ‘cyber’ attacks is risky, complex and people don’t trust us, moan insurers
Google launches open-source security key project, OpenSK

Sudo could allow unintended access to the administrator account.