Menu

Latest articles

‘Don’t be so concerned with your image’… US prosecutor lets rip on Uber for hack cover-up as pair plead guilty

security update

Insurance Pays Out a Sliver of Norsk Hydro’s Cyberattack Damages

Type: Vulnerability. WebKit is prone to cross-site scripting and multiple memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. WebKit is prone to a cross-site scripting vulnerability and multiple memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Samba is prone to an arbitrary file write vulnerability; fixes are available.

Type: Vulnerability. Samba is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Samba is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. WebKit is prone to multiple memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. D-Link DAP-1320 Wireless Range Extender is prone to an information-disclosure vulnerability.

Type: Vulnerability. IBM Security Guardium Big Data Intelligence is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. IBM Security Guardium Big Data Intelligence is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. McAfee Total Protection Windows client is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. IBM Security Guardium Big Data Intelligence is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple Trend Micro products are prone to an unspecified directory-traversal vulnerability; fixes are available.

Type: Vulnerability. Trend Micro Apex One is prone to a command-injection vulnerability; fixes are available.

Type: Vulnerability. Trend Micro OfficeScan is prone to a directory-traversal vulnerability; fixes are available.

WhatsApp Spyware Attack: Uncovering NSO Group Activity
U.S. Universities Get Failing Grades for DMARC Adoption

Risk Level: Very Low. Type: Trojan.

Facebook builds tool to confound facial recognition

However, the social network harbors no plans to deploy the technology in any of its services any time soon The post Facebook builds tool to confound facial recognition appeared first on WeLiveSecurity

While Apple fanbois rage at Catalina, iGiant quietly drops iOS and macOS security patches
Murky Details Surround Bed, Bath and Beyond Breach
Medical data is being leaked by NHS pagers, and then broadcast for the world to see…
MSPs Can Now Provide Managed Detection and Response with Cynet 360
Android Malware Plaguing 45K Devices Remains a Mystery
City of Johannesburg, on Second Hit, Refuses to Pay Ransom
Got an early iPhone or iPad? Update now or turn it into a paperweight
Sextortion scammers are hijacking blogs – and victims are paying up
Facebook launches $2m suit against alleged phishing, hacking sites
Uber sues LA in bid to protect scooter riders’ geolocation data
Europe’s digital identity system needs patching after can_we_trust_this function call ignored
Is HONK nothing sacred HONK? It’s 2019 and an evil save file can pwn much-loved HONK Untitled Goose Game
WhatsApp slaps app hacker chaps on the rack for booby-trapped chat: NSO Group accused of illegal hacking by Facebook
Q. Who’s triumphantly slamming barn door shut after horse bolted at warp 9? A. NordVPN
Australia Proposes Facial Recognition for Adult Sites

security update

security update

security update

Facebook Sues NSO Group Over Alleged WhatsApp Hack

Type: Vulnerability. Multiple IBM products are prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple IBM Products are prone to a local security vulnerability; fixes are available.

Type: Vulnerability. Atlassian JIRA is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Atlassian JIRA is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. NetApp Clustered Data ONTAP is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. IBM Security Access Manager is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Atlassian JIRA is prone to an information-disclosure vulnerability; fixes are available.

Chrome devs tell world that DNS over HTTPS won’t open the floodgates of hell
Joker’s Stash Drops Largest-Ever Credit Card Cache on Dark Web
New Adwind Variant Targets Windows, Chromium Credentials
Running on Intel? If you want security, disable hyper-threading, says Linux kernel maintainer
Fancy Bear Targets Sporting, Anti-Doping Orgs As 2020 Olympics Loom

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update for apb, containernetworking-plugins, and golang-github-prometheus-promu is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact

Huawei with you! FCC’s American Pai proposes rip-and-replace of scary Chinese comms kit

A micro version update (from 7.4 to 7.4.1) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

Country of Georgia Suffers Widespread Cyberattack
ThreatList: Most Retail Hardware Bug Bounty Flaws Are Critical

Several security issues were fixed in Samba.

An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for mediawiki is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score,

Reading Time: ~ 4 min. In my previous blog post, Why Healthcare Organizations are Easy Targets for Cybercrime, I discussed various reasons that hospitals and healthcare organizations make desirable and lucrative targets for hackers. In this second installment, I’ll go over how criminals are attacking these organizations, the methods they use, and also what needs to be done […]

Updated file packages fix security vulnerability: A buffer overflow was found in file which may result in denial of service or potentially the execution of arbitrary code if a malformed CDF (Composite Document File) file is processed (CVE-2019-18218).

Updated php and pcre2 packages fix security vulnerabilities: – FPM (#78599) env_path_info underflow in fpm_main.c can lead to RCE. (CVE-2019-11043) – MBString (#78633) Heap buffer overflow (read) in mb_eregi.

This kernel update is based on the upstream 5.3.7 and fixes several issues: * various security issues in the usb subsystem * rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow (CVE-2019-17666)

The updated packages fix a security vulnerability: The agroot() function in cgraphobj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv. (CVE-2019-11023)

Gradient “celebrity matching” photo app sparks privacy fears
PHP team fixes nasty site-owning remote execution bug
UK Ministry of Justice brags about new digital forensics unit to thwart tech-savvy jailbirds
New Facebook AI fools facial recognition
What you may be getting wrong about cybersecurity

Attention-grabbing cyberattacks that use fiendish exploits are probably not the kind of threat that should be your main concern – here’s what your organization should focus on instead The post What you may be getting wrong about cybersecurity appeared first on WeLiveSecurity

What a bunch of dopes! Fancy Bear hackers take aim at drug-testing orgs
UniCredit Suffers Third Breach Despite Investing Billions in Cybersecurity

Type: Vulnerability. IBM Cloud Orchestrator is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. QEMU is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Multiple IBM Products are prone to a directory-traversal vulnerability; fixes are available.

Type: Vulnerability. IBM Cloud Orchestrator is prone to local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple IBM Products are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. IBM API Connect is prone to an information-disclosure vulnerability; fixes are available.

How Facebook helps an abusive ex-partner find out your new identity, even after you’ve blocked them
Pwn2Own Expands Into Industrial Control Systems Hacking
City of Joburg says it knows who ransom hack attacker is, refuses to pay off criminals
Adobe database exposes 7.5 million Creative Cloud users
PHP Bug Allows Remote Code-Execution on NGINX Servers
Update your iPhone 5 before November 3 2019, or lose its internet access
Magecart Gang Targets Skin Care Site Visitors For 5+ Months

An update that fixes one vulnerability is now available.

Ransomware with a difference as hackers threaten to release city data
TikTok says no, senators, we’re not under China’s thumb
New BBC ‘dark web’ Tor mirror site aims to beat censorship
Cybercriminals Impersonate Russian APT ‘Fancy Bear’ to Launch DDoS Attacks
Crypto Capital boss arrested over money laundering

An update that fixes one vulnerability is now available.

See you at NISC, the National Information Security Conference, next week

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

Remember that competition for non-hoodie hacker pics? Here’s their best entries

The package chromium before version 78.0.3904.70-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, access restriction bypass, authentication bypass, denial of service, information disclosure, privilege escalation and cross-site scripting.