Menu

Latest articles

Undercover reporter tells all after working for a Polish troll farm
After months of worry, BlueKeep vulnerability is now being exploited in mass-hacking campaign
BlueKeep Attacks Have Arrived, Are Initially Underwhelming
Emerging Technology and Privacy: What You Need to Know
US grounds Chinese-made drones as part of security review
Chrome bug squashed, QNAP NAS nasty hits, BlueKeep malware spreads, and more

Risk Level: Very Low.

The package qt5-webengine before version 5.13.2-2 is vulnerable to arbitrary code execution.

Antimalware Day 2019: Building a culture of cybersecurity awareness

The introduction to a series of articles marking this year’s Antimalware Day and highlighting the importance of cyber-readiness The post Antimalware Day 2019: Building a culture of cybersecurity awareness appeared first on WeLiveSecurity

An update that fixes 21 vulnerabilities is now available.

An update that fixes 21 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Rebasing to 2.26.x For release info please see https://www.webkitgtk.org/2019/09/09/webkitgtk2.26.0-released.html and https://www.webkitgtk.org/2019/09/23/webkitgtk2.26.1-released.html CVE fixes: CVE-2019-8625, CVE-2019-8720, CVE-2019-8769, CVE-2019-8771

– fix heap-based buffer overflow in cdf_read_property_info() (CVE-2019-18218)

Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes

Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes

**PHP version 7.3.11** (24 Oct 2019) **Core:** * Fixed bug php#78535 (auto_detect_line_endings value not parsed as bool). (bugreportuser) * Fixed bug php#78620 (Out of memory error). (cmb, Nikita) **Exif :** * Fixed bug php#78442 (‘Illegal component’ on exif_read_data since PHP7) (Kalle) **FPM:** * Fixed bug php#78599 (env_path_info underflow in fpm_main.c can lead to RCE).

Updated libxslt package fixes security vulnerabilities: * In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains

Updated libsoup package fixes security vulnerability: It was discovered that libsoup incorrectly handled parsing certain NTLM messages. If a user or automated system were tricked into connecting to a malicious server, a remote attacker could possibly use this issue to

Updated aspell packages fix security vulnerability: libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated character (CVE-2019-17544).

Updated golang packages fix security vulnerability: Daniel Mandragona discovered that invalid DSA public keys can cause a panic in dsa.Verify(), resulting in denial of service (CVE-2019-17596).

Updated ansible package fixes security vulnerabilities: ansible-playbook -k and ansible cli tools prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them

An update that fixes 21 vulnerabilities is now available.

Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes

Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes

Office for Mac Users Warned of Malicious SYLK Files

**PHP version 7.2.24** (24 Oct 2019) **Core:** * Fixed bug php#78535 (auto_detect_line_endings value not parsed as bool). (bugreportuser) * Fixed bug php#78620 (Out of memory error). (cmb, Nikita) **Exif:** * Fixed bug php#78442 (‘Illegal component’ on exif_read_data since PHP7) (Kalle) **FPM:** * Fixed bug php#78599 (env_path_info underflow in fpm_main.c can lead to RCE).

Solar, Wind Power Utility Disrupted in Rare Cyberattack

security update

security update

Type: Vulnerability. Xen is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Honeywell equIP Series IP Cameras is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Foxit PhantomPDF is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Elasticsearch Logstash is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Magento CMS is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Google Chrome is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Multiple IBM Products are prone to an HTTP response-splitting vulnerability; fixes are available.

Type: Vulnerability. Cisco Video Communications Server is prone to a remote command-execution vulnerability; fixes are available.

News Wrap: APTs, Office 365 Voicemail Phish and Bed Bath & Beyond Breach

Upstream details at : https://access.redhat.com/errata/RHSA-2019:3287

Upstream details at : https://access.redhat.com/errata/RHSA-2019:3281

Upstream details at : https://access.redhat.com/errata/RHSA-2019:3286

Global Crime Ring Bilks U.S. Military Members, Vets Out of Millions
Stubborn Malware Targets QNAP NAS Hardware Specifically
S2 Ep15: City under attack! VPN hacked, floppies nixed
Google Discloses Chrome Flaw Exploited in the Wild
A guest appearance on the IT Pro podcast…
Are you as handy with privacy certs as you are with a screwdriver? Ikea has the perfect vacancy
Apple props up macOS Catalina with 10.15.1 update
Happy Birthday, CVE!
Move along, nothing to see here: Auditors say £100k grant to Hacker House was ‘appropriate’
Android Keyboard App Could Swindle 40M Users Out of Millions

Reading Time: ~ 2 min. Bed, Bath, & Beyond Data Breach An official announcement made earlier this week acknowledged illicit access to customer data used in online accounts for Bed, Bath, & Beyond. While the breach didn’t affect payment card information, the retailer quickly began contacting affected customers and took steps to safeguard against future […]

Twitter bans political ads
Hackers plead guilty to breach that Uber covered up
US Air Force inks deal with Raytheon on Windows 10 (and other) support for ARSE
Hunt or be hunted: Get top advice and training from SANS on how to track’n’thwart hackers
40 million emoji-addicted keyboard app users left with $18m bill – after malware sneaks into Play Store yet again

Type: Vulnerability. Symantec Endpoint Protection is prone to a security-bypass vulnerability; fixes are available.

Men who were paid $100,000 by Uber to hush-up hack plead guilty to extortion scheme
A stranger’s TV went on spending spree with my Amazon account – and web giant did nothing about it for months

Type: Vulnerability. Apple iOS and macOS are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Apple iTunes and macOS are prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Apple tvOS and macOS are prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Apple iOS, iPadOS, tvOS, watchOS and macOS are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Apple macOS, TV OS, and iOS are prone to multiple memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Philips IntelliSpace Perinatal is prone to a local security-bypass vulnerability.

Type: Vulnerability. Foxit PhantomPDF is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Foxit Studio Photo is prone to a information disclosure vulnerability; fixes are available.

Cyber-security super-brain Rudy Giuliani forgets password, bricks iPhone, begs Apple Store staff for help

Type: Vulnerability. Apple iOS is prone to an address bar spoofing vulnerability; fixes are available.

Type: Vulnerability. Apple macOS, watchOS and iCloud for Windows are prone to a memory corruption vulnerability; fixes are available.

Calypso APT Emerges from the Shadows to Target Governments
From Instagram to insta-banned: Facebook wipes NSO Group workers’ personal profiles amid WhatsApp hack rap
China-Linked Hackers Spy on Texts With MessageTap Malware
ProtonMail shoves its iOS app’s source code on GitHub for world+dog to rummage around in
Radio ham who sipped NHS pager messages then streamed them via webcam may have committed a crime
Untitled Goose Game security hole could have allowed hackers to wreak havoc
ICS Attackers Set To Inflict More Damage With Evolving Tactics
Linux maintainer: Patching side-channel flaws is killing performance
Fake Voicemail/Office 365 Attack Targets Enterprise Execs
Valve Source Engine, Fortnite Servers Crippled By Gafgyt Variant
Judge lambasts porn company for spewing copyright lawsuits
Researchers find hole in EU-wide identity system
WhatsApp sues spyware maker for allegedly hacking phones worldwide

Reading Time: ~ 5 min. “Phishing” may have been a relatively obscure term, but pretty much everyone has heard of it by now. In fact, recent statistics indicate a high likelihood that you—or someone you know—have been the victim of a phishing attack at least once. Now, if you remember the classic Nigerian Prince scams from back in […]

Belgian city slurps mobile data to track visitors – report
Deepfakes: When seeing isn’t believing

Is the world as we know it ready for the real impact of deepfakes? The post Deepfakes: When seeing isn’t believing appeared first on WeLiveSecurity

Smashing Security #152: Cats, hoodies, and rent

Type: Vulnerability. Apple iOS, iPad and macOS are prone to multiple information-disclosure vulnerabilities; fixes are available.

‘Don’t be so concerned with your image’… US prosecutor lets rip on Uber for hack cover-up as pair plead guilty

security update

Insurance Pays Out a Sliver of Norsk Hydro’s Cyberattack Damages

Type: Vulnerability. WebKit is prone to cross-site scripting and multiple memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. WebKit is prone to a cross-site scripting vulnerability and multiple memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Samba is prone to an arbitrary file write vulnerability; fixes are available.

Type: Vulnerability. Samba is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Samba is prone to a remote denial-of-service vulnerability; fixes are available.