Menu

Latest articles

Anatomy of a “free” gift – how online surveys can harm your digital health
Only 6 ransomware attacks on the UK’s NHS since WannaCry worm hit in 2017 – report
Cynet Empowers IT Resellers and Service Providers to Become Fully Qualified MSSPs
Let’s make ransomware MORE illegal, says Maryland

Several vulnerabilities have been discovered in the otrs2 package that may lead to unauthorized access, remote code execution and spoofing.

Fraud spike prompts Chrome developer lock-out

Apache Solr could be made to run programs if it received specially crafted network traffic.

Win $1.5 million hacking an Android phone
Wawa Breach May Have Affected More Than 30 Million Customers
Time to celebrate Data Privacy Day!
15 NFL teams’ Twitter hijacked in lead-up to the Super Bowl
How AI will improve API security

The following vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2019-8835

It was discovered that there were a large number of NULL pointer dereferences due to unchecked return values from malloc and friends in hiredis, a minimalistic C client library.

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes two vulnerabilities is now available.

Dear friends in DevSecOps: Don’t forget, security is your responsibility, too – now learn how to do it right
New ‘CacheOut’ Attack Targets Intel CPUs
Cache flow problems continue for Intel: Yet more data-leaking processor design blunders discovered, patches due soon
Trolls-For-Hire Pave Way For Sophisticated Social Media Hacks
Coronavirus claims new victim: ‘DEF CON cancelled’ joke cancelled after DEF CON China actually cancelled
Ring Doorbell App for Android Caught Sharing User Data with Facebook, Data-Miners
New report suggests anti-virus firm Avast is selling user data to 3rd parties
5 ways to be a bit safer this Data Privacy Day
IoT security? We’ve heard of it, says UK.gov waving new regs
Hackers blitz social media accounts of 15 NFL teams

The league and scores of teams were caught off-guard by the re-emergence of an infamous hacking group The post Hackers blitz social media accounts of 15 NFL teams appeared first on WeLiveSecurity

MTTD and MTTR: Two Metrics to Improve Your Cybersecurity
1 in 10 Macs hit by crude malware that poses as Flash Player update, reports Kaspersky

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Libgcrypt could be made to expose sensitive information.

The duke of URL: Zoom meetups’ info leaked out through eavesdrop hole
LoRaWAN Encryption Keys Easy to Crack, Jeopardizing Security of IoT Networks

OpenJPEG had a heap-based buffer overflow in opj_t1_clbl_decode_processor in libopenjp2.so.

Windows 7 definitely won’t ever receive any more bug fixes (errm… apart from this one for its wallpaper)
States sue over rules that allow release of 3D-printed gun blueprints
Zoom Fixes Flaw Opening Meetings to Hackers
Facial recognition firm sued for scraping 3 billion faceprints
Cisco patches bugs in security admin center and Webex
Mozilla bans Firefox extensions for executing remote code
How to take charge of your Google privacy settings

Have you had a Google Privacy Checkup lately? If not, when better than Data Privacy Day to audit the privacy of your Google account? The post How to take charge of your Google privacy settings appeared first on WeLiveSecurity

An update that fixes three vulnerabilities is now available.

16 NFL teams have their social media accounts hijacked by OurMine hacking gang

An update for openjpeg2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

NetWars! Let the SANS Tournaments commence: Compete and learn all about forensics, incident response, red teaming – and much more
Remember the Clipper chip? NSA’s botched backdoor-for-Feds from 1993 still influences today’s encryption debates
Google, Mozilla Ban Hundreds of Browser Extensions in Chrome, Firefox
Google halts paid-for Chrome extension updates amid fraud surge: Web Store in lockdown ‘due to the scale of abuse’
As Necurs Botnet Falls from Grace, Emotet Rises
Maryland: Make malware possession a crime! Yes, yes, researchers get a free pass
N.Y. Could Ban Cities from Paying Ransomware Attackers
Job hunting? Beware hiring scams using spoofed company websites

Cybercriminals are putting a new twist on an old trick The post Job hunting? Beware hiring scams using spoofed company websites appeared first on WeLiveSecurity

Nasty old Android malware with new capabilities gets difficult to remove
A Magecart hacking gang may have been caught by police for the first ever time
Cisco Webex bug allowed anyone to join a password-protected meeting
Cardplanet mastermind pleads guilty to credit card fraud
Mandatory IoT Security in the Offing with U.K. Proposal
Tinder to get panic button, catfish-fighting facial recognition
Microsoft’s Internet Explorer zero-day workaround is breaking printers
Instagram CEO’s homes were targetted by SWATters
Rent out the best properties online in India with these tips

Several security issues were fixed in tcpdump.

Several security issues were fixed in Tomcat.

Several security issues were fixed in MySQL.

New York wants to ban taxpayer-funded ransomware payments

An update for nss is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This update fixes CVE-2019-20093.

This update fixes CVE-2019-20093.

Trend Micro anti-virus zero-day exploited in attack on Mitsubishi Electric
Webex flaw allowed anyone to join private online meetings – no password required
Watch out for Shlayer malware targeting Mac devices

An update that fixes 5 vulnerabilities is now available.

This update fixes CVE-2019-20093.

This update fixes CVE-2019-20093.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Teenagers today. Can’t take them anywhere, eh? 18-year-old kid accused of $50m SIM-swap cryptocurrency heist

– Security fix for CVE-2019-19746, CVE-2019-19797 – New upstream release 3.2.7b – Add patch fixing CVE-2019-19746 (rhbz#1787040) – Add patch fixing CVE-2019-19797 (rhbz#1786726)

– Security fix for CVE-2019-19746, CVE-2019-19797 – New upstream release 3.2.7b – Add patch fixing CVE-2019-19746 (rhbz#1787040) – Add patch fixing CVE-2019-19797 (rhbz#1786726)

** MySQL 8.0.19 ** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-19.html

Security fix for CVE-2020-5395:out-of-bounds write in sfd.c

ThreatList: Ransomware Costs Double in Q4, Sodinokibi Dominates
Netgear vulnerability exposed TLS certificates to public

security update

The importance of protecting your devices from cyber attack
Cisco Webex Flaw Lets Unauthenticated Users Join Private Online Meetings
New Bill Proposes NSA Surveillance Reforms
2015-member database floats off through breach in Royal Yachting Association’s hull
Google finds privacy holes in Safari’s ITP anti-tracking system
We’re dung for! Hackers hit firms with ransomware by exploiting Shitrix flaw
Want your photo removed from our facial recognition database? Just send us your photo and government-issued ID…
Fake Smart Factory Honeypot Highlights New Attack Threats
Sonos backtracks (a little) over its software updates fustercluck

An update that fixes 7 vulnerabilities is now available.

Whoops! LastPass accidentally deleted its browser extension from the Chrome store. But it’s back now

update to enigmail 2.1.5 Includes a security fix for “Unsigned MIME parts displayed as signed”

Update to 12.14.1 Add new subpackage `nodejs-full-i18n` to provide non-English locale and Unicode support.

Update to 12.14.1 Add new subpackage `nodejs-full-i18n` to provide non-English locale and Unicode support.

New upstream release with security fixes for CVE-2019-15945, CVE-2019-15946, CVE-2019-19479, CVE-2019-19480, CVE-2019-19481

Protestors petition equity firm over .org buyout