Menu

Latest articles

Type: Vulnerability. Microsoft Azure Stack is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Just-Released Checkra1n iPhone Jailbreak Stirs Security Concerns
California’s Domino Effect on U.S. Privacy Regulation
Website, Know Thyself: What Code Are You Serving?
APT33 Mounts Focused, Highly Targeted Botnet Attacks Against U.S. Victims
Threat Actor Impersonates USPS to Deliver Backdoor Malware
Download: The Comprehensive Compliance Guide
Only after running out of hard disk space did firm realise hacker had stolen one million users’ details
Microsoft issues patch for Internet Explorer zero‑day

The critical vulnerability could also be exploited via a malicious Microsoft Office document The post Microsoft issues patch for Internet Explorer zero‑day appeared first on WeLiveSecurity

Updated libapreq2 packages fix security vulnerability: Max Kellermann reported a NULL pointer dereference flaw in libapreq2, allowing a remote attacker to cause a denial of service against an application using the library (application crash) if an invalid nested

Infosec boffins pour cold water on claims Home Office Brexit app can be easily hacked

in cpio 2.11, when using the –no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive (CVE-2015-1197). Thomas Habets discovered that GNU cpio incorrectly handled certain

Updated fribidi packages fix security vulnerability: A stack buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi 1.0.0 through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary

Updated webkit2 packages fix security vulnerabilities: Processing maliciously crafted web content may lead to universal cross site scripting (CVE-2019-8625, CVE-2019-8674, CVE-2019-8719, CVE-2019-8813)

A security vulnerability has been reported in libzmq/zeromq. a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary

Updated python-numpy packages fix security vulnerability: An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call

An update for kernel is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Facebook fixes iPhone camera bug
About the “easy to hack” EU Exit: ID Document Check app
Innovative PureLocker Ransomware Emerges in Targeted Attacks
Warrantless searches of devices at US borders ruled unconstitutional
Alleged mastermind behind $20m stolen-card site extradited to US
Getting into cybersecurity: Self‑taught vs. university‑educated?

Are you considering a career in cybersecurity? What learning path(s) should you take? Does formal education matter? ESET experts share their insights. The post Getting into cybersecurity: Self‑taught vs. university‑educated? appeared first on WeLiveSecurity

An update that solves 8 vulnerabilities and has 29 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

ENFUSE 2019: Security Regulations, Insider Threats, and IoT Privacy Risks
Smashing Security #154: A buttock of biometrics

Type: Vulnerability. Symantec Endpoint Protection is prone to an local privilege escalation vulnerability; fixes are available.

Type: Vulnerability. Multiple Symantec Products are prone to an local privilege escalation vulnerability; fixes are available.

Type: Vulnerability. Symantec Endpoint Protection is prone to a local code-execution vulnerability; fixes are available.

Type: Vulnerability. Symantec Endpoint Protection is prone to an local privilege escalation vulnerability; fixes are available.

Type: Vulnerability. Symantec Endpoint Protection is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Symantec Endpoint Protection Manager is prone to a local privilege-escalation vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Consumer Data Privacy Rights: Emerging Tech Blurs Lines
Donation details “leak” from the Labour Party website

security update

security update

security update

security update

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Open Enclave SDK is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office Online is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Office Online is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Netlogon is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Google’s Plan to Crunch Health Data on Millions of Patients Draws Fire

Risk Level: Very Low. Type: Trojan.

November 2019 Patch Tuesday fixes 13 critical flaws and one zero day

Reading Time: ~ 3 min. Why do so many businesses allow unfettered access to their networks? You’d be shocked by how often it happens. The truth is: your employees don’t need unrestricted access to all parts of our business. This is why the Principle of Least Privilege (POLP) is one of the most important, if […]

Get 70% off NordVPN Virtual Private Network Service + 3 months free – Deal Alert
Facebook bug turns on iPhone camera in the background

A recent update to the Facebook’s iOS app introduced a bug that had some users worried The post Facebook bug turns on iPhone camera in the background appeared first on WeLiveSecurity

IoT Security Woes Plague Healthcare Industry

In libssh2, SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A

Apple pulls Instagram-watching app from store
US-CERT warns of critical flaws in Medtronic equipment

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in libjpeg-turbo.