Menu

Latest articles

New upstream release with security fixes for CVE-2019-15945, CVE-2019-15946, CVE-2019-19479, CVE-2019-19480, CVE-2019-19481

Protestors petition equity firm over .org buyout
9th Methbot suspect arrested in massive clickfraud ring

An update that solves three vulnerabilities and has one errata is now available.

Privacy watchdog throws wider net to protect children online
Russian super-crook behind $20m internet fraud den Cardplanet and malware-exchange forum pleads guilty

Reading Time: ~ 2 min. Point-of-Sale Breach Targets U.S. Cannabis Industry Late last month, researchers discovered a database owned by the company THSuite that appeared to contain information belonging to roughly 30,000 cannabis customers in the U.S. With no authentication, the researchers were able to find contact information as well as cannabis purchase receipts, including […]

Study shows prominent apps are selling your data to 3rd parties
Critical, Unpatched ‘MDhex’ Bugs Threaten Hospital Devices
U.S. Gov Agency Targeted With Malware-Laced Emails
Shlayer, No. 1 Threat for Mac, Targets YouTube, Wikipedia
Did Saudi Crown Prince use Israeli spyware to hack Jeff Bezos’s iPhone?
Ransomware: The average ransom payment has doubled in just three months
Cisco Warns of Critical Network Security Tool Flaw
Traffic jams could be worse than normal, because of the Shitrix vulnerability
We need to make it even easier for UK terror cops to rummage about in folks’ phones, says govt lawyer
Looking for silver linings in the CVE-2020-0601 crypto vulnerability
Ooh, watch out Google. You’ve got competition. Verizon has a new ‘privacy-focused’ search engine

USN-4233-1 marked SHA1 as untrusted in GnuTLS with no workaround.

Microsoft exposed 250 million customer support records

Databases containing 14 years’ worth of customer support logs were publicly accessible with no password protection The post Microsoft exposed 250 million customer support records appeared first on WeLiveSecurity

Google: Flaws in Apple’s Private-Browsing Technology Allow for Third-Party Tracking

An update for ansible is now available for Ansible Engine 2 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.9 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.8 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.7 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

A free tool for detecting Shitrix-related compromises on your business network
UN report alleges that Saudi crown prince hacked Jeff Bezos’s phone

Several security issues were fixed in python-apt.

Apple allegedly made nice with FBI by dropping iCloud encryption plan
Sonos’s tone-deaf legacy product policy angers customers
FBI issues warning about lucrative fake job scams
Smashing Security #162: Robocalls, health hacks, and facial recognition fears
Still losing sleep over that awful Citrix bug? This scanner is here to help… you realize you’ve already been pwned
Pwn2Own Miami Contestants Haul in $180K for Hacking ICS Equipment
Who honestly has a crown prince in their threat model? UN report officially fingers Saudi royal as Bezos hacker
Vivin Nets Thousands of Dollars Using Cryptomining Malware
Safari’s Intelligent Tracking Protection is misspelled, says Google: It should be Dumb Browser Stalking Enabler
Owner of DDoS mitigation firm launched DDoS attacks on others

security update

Big Microsoft data breach – 250 million records exposed
Academics call for UK’s Computer Misuse Act 1990 to be reformed
sLoad Malware Revamped as Powerful ‘StarsLord’ Loader
Dating apps share personal data with advertisers, study says

Some of the most popular dating services may be violating GDPR or other privacy laws The post Dating apps share personal data with advertisers, study says appeared first on WeLiveSecurity

Plastic surgery patients at risk after ransomware attack
Microsoft Leaves 250M Customer Service Records Open to the Web
WindiLeaks: Microsoft exposes 250 million customer support records dating back to 2005 (Not on purpose though)
Teenager charged over $50 million SIM-swap cryptocurrency theft
Microsoft data breach exposes 250 million customer service and support records
250 million Microsoft customer support records leaked in plain text

An update that fixes three vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

New Muhstik Botnet Attacks Target Tomato Routers
Ubisoft sues DDoS-for-hire operators for ruining game play
PoC Exploits Do More Good Than Harm: Threatpost Poll
NIST’s new privacy rules – what you need to know
Regus spills data of 900 staff on Trello board set to ‘public’

apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086) SL7 noarch apache-commons-beanutils-1.8.3-15.el7_7.noarch.rpm apache-commons-beanutils-javadoc-1.8.3-15.el7_7.noarch.rpm – Scientific Linux Development Team

Jeff Bezos, WhatsApp, and Mohammed bin Salman – what you need to know
Nobody boogies quite like you
Capita Education Services accidentally spaffs email addresses in Helpdesk snafu

An update that solves 5 vulnerabilities and has one errata is now available.

python-reportlab: code injection in colors.py allows attacker to execute code (CVE-2019-17626) SL6 x86_64 python-reportlab-2.3-3.el6_10.1.x86_64.rpm python-reportlab-debuginfo-2.3-3.el6_10.1.x86_64.rpm i386 python-reportlab-2.3-3.el6_10.1.i686.rpm python-reportlab-debuginfo-2.3-3.el6_10.1.i686.rpm noarch python-reportlab-docs-2.3-3.el6_10.1.noarch.rpm – Scientific L [More…]

Crown Prince of Saudi Arabia accused of hacking Jeff Bezos’ phone with malware-laden WhatsApp message
16Shop Phishing Gang Goes After PayPal Users

security update

security update

No backdoors needed: Apple ditched plans to fully encrypt iCloud backups after heavy pressure from FBI – claim
Citrix Accelerates Patch Rollout For Critical RCE Flaw
Clearview app lets police find your information with just a photo
FTCODE Ransomware Now Steals Chrome, Firefox Credentials
Microsoft Zero-Day Actively Exploited, Patch Forthcoming
WTF, EFS? Experts warn Windows encryption could spawn nasty new ransomware
Citrix ships patches as vulnerable servers come under attack

A security update is now available for Open Liberty 20.0.0.1 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Hacker Leaks More Than 500K Telnet Credentials for IoT Devices
China and US top user data requests in Apple transparency report
Exams cancelled? University closing due to Brexit? A mischievous email from Southampton’s Vice-Chancellor

An update for openvswitch2.12 is now available for Fast Datapath for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

What do online file sharers want with 70,000 Tinder images?

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

3 ways to browse the web anonymously

Are you looking to hide in plain sight? Here’s a rundown of three options for becoming invisible online The post 3 ways to browse the web anonymously appeared first on WeLiveSecurity

Internet-enabled dash cams that allow anyone to track your GPS location in real-time

An update that fixes one vulnerability is now available.

Leave your admin interface’s TLS cert and private key in your router firmware in 2020? Just Netgear things

security update

security update

New sextortion scam claims to record you with hacked Google Nest cam
Citrix emits patches to stop RCE-holes fiddling with Gateway and ADC
Ubisoft sues handful of gamers for DDoSing Rainbow Six: Siege
New Internet Explorer zero‑day remains unpatched

You may want to implement a workaround or stop using the browser altogether, at least until Microsoft issues a a fix The post New Internet Explorer zero‑day remains unpatched appeared first on WeLiveSecurity

Sextortion scam leverages Nest video footage to fool victims into believing they are being spied upon everywhere
LastPass stores passwords so securely, not even its users can access them

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.