Menu

Latest articles

Survey Finds People are Privacy Hypocrites
Woman ordered to type in iPhone passcode so police can search device

An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 and Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that solves one vulnerability and has 21 fixes is now available.

An update that fixes one vulnerability is now available.

Google chief warns visitors about smart speakers in his home

OpenJDK: Incorrect handling of nested jar: URLs in Jar URL handler (Networking, 8223892) (CVE-2019-2978) * OpenJDK: Incorrect handling of HTTP proxy responses in HttpURLConnection (Networking, 8225298) (CVE-2019-2989) * OpenJDK: Missing restrictions on use of custom SocketImpl (Networking, 8218573) (CVE-2019-2945) * OpenJDK: NULL pointer dereferen [More…]

An update is now available for Red Hat Satellite 6.6 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

OpenJDK: Incorrect handling of nested jar: URLs in Jar URL handler (Networking, 8223892) (CVE-2019-2978) * OpenJDK: Incorrect handling of HTTP proxy responses in HttpURLConnection (Networking, 8225298) (CVE-2019-2989) * OpenJDK: Missing restrictions on use of custom SocketImpl (Networking, 8218573) (CVE-2019-2945) * OpenJDK: NULL pointer dereference in DrawGlyphList (2D, 8222690) (CVE-2019- [More…]

Just say the ‘magic password’: Boffins turn up potential backdoor in SQL Server 2012, 2014

An update for python is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

An update for wget is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Just a friendly reminder there were no at-the-time classified secrets on Clinton’s email server. Yes, the one everyone lost their minds over
ATTK of the Pwns: Trend Micro’s antivirus tools ‘will run malware – if its filename is cmd.exe’
Action Fraud? Inaction Fraud
Row erupts over who to blame after NordVPN says: One of our servers was hacked via remote management tool
Gustuff Android Banker Switches Up Technical Approach

security update

U.S. Government, Military Personnel Data Leaked By Autoclerk

Type: Vulnerability. Cisco Expressway Series and Telepresence VCS are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Cisco TelePresence Collaboration Endpoint Software is prone to multiple local arbitrary file-overwrite vulnerabilities; fixes are available.

Type: Vulnerability. Apache Thrift is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco TelePresence Collaboration Endpoint Software is prone to a local arbitrary file-write vulnerability; fixes are available.

Type: Vulnerability. Cisco TelePresence Collaboration Endpoint Software is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Cisco Wireless LAN Controller Software is prone to a local directory-traversal vulnerability; fixes are available.

Type: Vulnerability. AVEVA IEC870IP Driver for Vijeo Citect and Citect SCADA is prone to a stack-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Apache Thrift is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco TelePresence Collaboration Endpoint Software is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks GlobalProtect Agent is prone to a local privilege-escalation vulnerability; fixes are available.

Avast lobs intruders into the ‘Abiss’: Miscreants tried to tamper with CCleaner after sneaking into network via VPN
Turla Compromises, Infiltrates Iranian APT Infrastructure
Assange fails to delay extradition hearing as date set for February
No one would be so scummy as to scam a charity, right? UK orgs find out the hard way
Avast Network Breached As Hackers Target CCleaner Again
Train to be a certified cyber security professional for just $39
Alexa and Google Home devices can be exploited to eavesdrop on users, phish passwords
Trend Micro would like you to fall in line and become a victim of Cloud Conformity
Avast fends off hacker who breached its internal network in copycat CCleaner attack
If there were almost a million computer misuse crimes last year, Action Fraud is only passing 2% of cases to cops
Don’t look now, but Pixel 4’s Face Unlock works with eyes closed
Samsung Galaxy S10 fingerprint reader beaten by $3 gel protector
New Way Found to Use Alexa, Google to ‘Voice Phish’ and Eavesdrop on Users
Mind your own business! CEOs who misuse data could end up in jail
Iran? More like Ivan: Brit and US spies say they can see through Turla hacking group’s facade
Winnti Group’s skip‑2.0: A Microsoft SQL Server backdoor

Notorious cyberespionage group debases MSSQL The post Winnti Group’s skip‑2.0: A Microsoft SQL Server backdoor appeared first on WeLiveSecurity

Malware hides as iOS jailbreak, Sucuri is insecuri, and China is about to get even worse

It was discovered that Aspell, the GNU spell checker, incorrectly handled certain inputs which leads to a stack-based buffer over-read. An attacker could potentially access sensitive information.

An update that solves one vulnerability and has two fixes is now available.

An update that solves one vulnerability and has two fixes is now available.

security update

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update for logging-elasticsearch5-container is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

It was discovered that the Special:Redirect functionality of MediaWiki, a website engine for collaborative work, could expose suppressed user names, resulting in an information leak.

New build after fixing BuildRequires —- – Rebase to upstream version 3.9.0 – fix CVE-2019-14745

In the nfs-utils package, providing support files for Network File System (NFS) including the rpc.statd daemon, the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files

* Rebase to 1.8.28 * Fixed CVE-2019-14287

Deus ex hackina: It took just 10 minutes to find data-divulging demons corrupting Pope’s Click to Pray eRosary app
Microsoft Tackles Election Security with Bug Bounties

Type: Vulnerability. Horner Automation Cscape is prone to multiple arbitrary code-execution vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Aironet Access Points is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco Wireless LAN Controller is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. ISC Kea is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks GlobalProtect Agent is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. ISC Kea is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. ISC Kea is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco Aironet Access Points is prone to an unauthorized access vulnerability; fixes are available.

Type: Vulnerability. Jenkins is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Pulse Connect Secure and Policy Secure are prone to an access-bypass vulnerability; fixes are available.

Type: Vulnerability. Pulse Connect Secure and Pulse Policy Secure are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapter is prone to multiple arbitrary code-execution vulnerabilities; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a cross-site request-forgery vulnerability; fixes are available.

Type: Vulnerability. VMware SD-WAN by VeloCloud is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Npmjs ‘csv-parse’ module is prone to a denial-of-service vulnerability; fixes are available.

Execs Could Face Jail Time For Privacy Violations
Major Airport Malware Attack Shines a Light on OT Security
Four-Year-Old Critical Linux Wi-Fi Bug Allows System Compromise
Phishy text message tries to steal your cellphone account
Podcast: Insider Attacks May Soon Cost Less Than Malware-based Equivalent

The fix for CVE-2019-10871 broke xpdf. This change has been reverted until a better fix can be developed.

The 5.3.6 update contains a number of important fixes across the tree.

The 5.3.6 update contains a number of important fixes across the tree.

The 5.3.6 update contains a number of important fixes across the tree.

== Security fixes == * (T230402, CVE-2019-16738) SECURITY: Add permission check for suppressed account to Special:Redirect. == Links to all mentioned tasks == * https://phabricator.wikimedia.org/T230402 * https://phabricator.wikimedia.org/T227662

Zappos Offers Users 10% Discount in 2012 Breach Settlement

Reading Time: ~ 2 min. Cryptominers Found in Audio Files Researchers have recently found that both cryptominers and backdoors are being deployed within WAV audio files on targeted systems. Using steganography, attackers can include components for both loading and executing malicious scripts, while still allowing some audio files to play normally. Along with the malicious […]

Some Android adware apps hide icons to make it hard to remove them
Bitcoin money trail leads cops to ‘world’s largest’ child abuse site
How does £36m sound, mon CHERI? UK.gov pumps cash into Arm security research
Much-attacked Baltimore uses ‘mind-bogglingly’ bad data storage

kernel: Use-after-free in __blk_drain_queue() function in block/blk-core.c (CVE-2018-20856) * kernel: Heap overflow in mwifiex_update_bss_desc_with_ie function in marvell/mwifiex/scan.c (CVE-2019-3846) * hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB) (CVE-2019-9506) * kernel: Heap overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ [More…]

Google slings websites into Chrome’s solitary confinement on Android to thwart Spectre-style data snooping

Two buffer allocation issues were identified in poppler. CVE-2019-9959

An update for jenkins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for mediawiki is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Phorpiex Botnet Shifts Gears From Ransomware to Sextortion