Menu

Latest articles

Linux users warned to update libarchive to beat flaw
Pilot presses the wrong button, triggers airport hostage alarm
Google Enlists Help to Fight Bad Android Apps
Facebook confesses 100 devs may have accessed leaked Groups data
Warrant let police search online DNA database

An update for cri-o is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for mediawiki123 is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Mac users warned that disabling all Office macros doesn’t actually disable all Office macros

Several security issues were fixed in WebKitGTK+.

An update that fixes 9 vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that solves one vulnerability and has two fixes is now available.

An update for openstack-octavia is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

We’re almost into the third decade of the 21st century and we’re still grading security bugs out of 10 like kids. Why?
Microsoft crams Office 365 docs into Edge-style sandboxes to thwart malware infections
Ex-Twitter staff charged with spying for Saudi royals: Duo accused of leaking account records, including those of critics
Smashing Security #153: Cybercrime doesn’t pay (but Uber does)
Google’s joins Gang of Four to guard Play Store apps from malware, and maybe not fail so much
Microsegmentation and Isolation: 2 Essential Strategies in Zero-Trust Security
You’ve Been Served…with Subpoena-Themed Phishing Emails
NSA to Congress: Our spy programs don’t work, aren’t used, or have gone wrong – now can you permanently reauthorize them?
Rogue Trend Micro Employee Sold Customer Data for 68K Accounts

security update

Trend Micro: Our super-duper security software will keep you safe from everyone – except our staff who go rogue

Type: Vulnerability. Joomla! is prone to a cross-site request-forgery vulnerability; fixes are available.

Type: Vulnerability. Google Android is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Google Android is prone to multiple information-disclosure vulnerabilities; fixes are available.

Type: Vulnerability. MantisBT is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Google Android is prone to a remote code execution vulnerability; fixes are available.

Type: Vulnerability. Red Hat ‘389-ds-base’ is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Sonatype Nexus Repository Manager is prone to an OS command-injection vulnerability; fixes are available.

Facebook Privacy Breach: 100 Developers Improperly Accessed Data
DarkUniverse APT Emerges to Deliver Sophisticated, Targeted Spy Attacks
Controversies aren’t Boeing away for aircraft maker amid claims of faulty oxygen systems and wobbling wings
Emotet Resurgence Continues With New Tactics, Techniques and Procedures
Leeds IT bloke pleads guilty to hacking Jet2 CEO’s email account
Google Analytics Emerges as a Phishing Tool
Presentation Template: Build Your 2020 Security Plan
Smartphone and speaker voice assistants can be hacked using lasers
Mozilla says ISPs are lying to Congress about encrypted DNS
Ransomware attacks in Spain leave radio station in “hysteria”
Founders of ‘worthless cryptocurrency’ ATM Coin fined over $4.25m scam
Before you high-five yourselves for setting up that bug bounty, you’ve got the staff in place to actually deal with security, right?

security update

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a cross-site scripting vulnerability.

Google patches bug that let nearby hackers send malware to your phone
Office for Mac 2011 users warned about SYLK file format
Android keyboard app caught red‑handed trying to make sneaky purchases

The virtual keyboard app ai.type, which has racked up 40 million downloads, has been found to sign up users to premium services without their consent The post Android keyboard app caught red‑handed trying to make sneaky purchases appeared first on WeLiveSecurity

‘Peregrine falcon’-style drone swarms could help defend UK against Gatwick copycat attacks
Trump, Putin and Politics Name-Dropped to Peddle Malware
Concerns raised over privacy and security of UK Home Office’s £842m biometrics programme
Florida city sends $742K to fraudsters as it bites the BEC hook
Three UK does it again: Random folk on network website are still seeing others’ account data
Eye Clinic Breach Reveals Data of 20,000 Patients
Five ways to strengthen employee cybersecurity awareness

How can organizations foster a workplace environment that enables employees to acquire the skills needed to keep cyber-threats at bay? The post Five ways to strengthen employee cybersecurity awareness appeared first on WeLiveSecurity

Police interrogate Alexa for clues in fatal spear-stabbing
PSA: Turning off silent macros in Office for Mac leaves users wide open to silent macro attacks
Ransomware freezes govt IT in Canadian territory of Nunavut, drops citizens right Inuit
Magecart Groups Attack Simultaneous Sites in Card-Theft Frenzy
Alexa, Siri, Google Smart Speakers Hacked Via Laser Beam
DoHn’t believe the hype! You are being lied to by data-hungry ISPs, Mozilla warns lawmakers
Apple developers – get this update to protect the rest of us!

Type: Vulnerability. Xen is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a security vulnerability; fixes are available.

Type: Vulnerability. OpenAFS is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office for Mac is prone to a remote code-execution vulnerability.

Type: Vulnerability. Apple Xcode is prone to multiple memory corruption vulnerabilities; fixes are available.

Type: Vulnerability. Honeywell equIP and Performance Series IP Cameras and Recorders is prone to a remote authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. Multiple Honeywell Products are prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. Advantech WISE-PaaS/RMM is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Multiple IBM Products are prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. Apache Commons Beanutils is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. LibGD is prone to a heap-based buffer-overflow vulnerability; fixes are available.

In a world of infosec rockstars, shutting down sexual harassment is hard work for victims
Wizard Spider Upgrades Ryuk Ransomware to Reach Deep into LANs

Risk Level: Very Low. Type: Trojan.

Critical Remote Code Execution Flaw Found in Open Source rConfig Utility
BEC Scam Costs Media Giant Nikkei $29 Million
Please tell us why you’re not securing yourselves, UK.gov asks businesses
Russia’s sovereign internet law comes into force
Pentagon publishes AI guidelines
Undercover reporter tells all after working for a Polish troll farm
After months of worry, BlueKeep vulnerability is now being exploited in mass-hacking campaign
BlueKeep Attacks Have Arrived, Are Initially Underwhelming
Emerging Technology and Privacy: What You Need to Know
US grounds Chinese-made drones as part of security review
Chrome bug squashed, QNAP NAS nasty hits, BlueKeep malware spreads, and more

Risk Level: Very Low.

The package qt5-webengine before version 5.13.2-2 is vulnerable to arbitrary code execution.

Antimalware Day 2019: Building a culture of cybersecurity awareness

The introduction to a series of articles marking this year’s Antimalware Day and highlighting the importance of cyber-readiness The post Antimalware Day 2019: Building a culture of cybersecurity awareness appeared first on WeLiveSecurity

An update that fixes 21 vulnerabilities is now available.

An update that fixes 21 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Rebasing to 2.26.x For release info please see https://www.webkitgtk.org/2019/09/09/webkitgtk2.26.0-released.html and https://www.webkitgtk.org/2019/09/23/webkitgtk2.26.1-released.html CVE fixes: CVE-2019-8625, CVE-2019-8720, CVE-2019-8769, CVE-2019-8771