Menu

Latest articles

Type: Vulnerability. Eclipse Jetty is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple arbitrary code-execution vulnerabilities; fixes are available.

Type: Vulnerability. Apache Axis is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple arbitrary code-execution vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Adobe Download Manager is prone to an insecure file-permission vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Eclipse Jetty is prone to a security vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to a cross-site scripting vulnerability; fixes are available.

Help! I bought a domain and ended up with a stranger’s PayPal! And I can’t give it back

Several cross-site scripting (XSS) vulnerabilities were discovered in WordPress, a popular content management framework. An attacker can use these flaws to send malicious scripts to an unsuspecting user.

In sudo, a program that provides limited super user privileges to specific users, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can

Reading Time: ~ 3 min. In May of 2018, the General Data Protection Regulation (GDPR) came into effect in the EU. Seemingly overnight, websites everywhere started throwing pop-ups to inform us about their use of cookies and our privacy rights. While the presence of the pop-ups may be reassuring to some (and annoying to others), […]

Hacking Back? BriansClub Dark Web Attack a Boon for Banks
A cautionary, Thames Watery tale on how not to look phishy: ‘Click here to re-register!’
Trump Campaign Website Left Open to Email Server Hijack
About that “Any fingerprint can unlock your Samsung Galaxy S10” report
Cisco Aironet Access Points Plagued By Critical, High-Severity Flaws
Dangerous Kubernetes Bugs Allow Authentication Bypass, DoS
Podcast: Departing Employees Could Mean Departing Data
New Presentation Template: Incident Response Reporting for Management
Cybercrime Tool Prices Bump Up in Dark Web Markets
Galaxy S10 Fingerprint Sensor Thwarted With Screen Protector: Report
Unencrypted Mobile Traffic on Tor Network Leaks PII
On-Board ‘Mystery Boxes’ Threaten Global Shipping Vessels
Remember the Democratic National Committee email leak? Same hackers now targeting EU countries, say malware boffins

OpenJDK: Improper handling of Kerberos proxy credentials (Kerberos, 8220302) (CVE-2019-2949) * OpenJDK: Unexpected exception thrown during regular expression processing in Nashorn (Scripting, 8223518) (CVE-2019-2975) * OpenJDK: Out of bounds access in optimized String indexof implementation (Hotspot, 8224062) (CVE-2019-2977) * OpenJDK: Incorrect handling of nested jar: URLs in Jar URL handl [More…]

OpenJDK: Improper handling of Kerberos proxy credentials (Kerberos, 8220302) (CVE-2019-2949) * OpenJDK: Unexpected exception thrown during regular expression processing in Nashorn (Scripting, 8223518) (CVE-2019-2975) * OpenJDK: Incorrect handling of nested jar: URLs in Jar URL handler (Networking, 8223892) (CVE-2019-2978) * OpenJDK: Incorrect handling of HTTP proxy responses in HttpURLConne [More…]

An update that fixes one vulnerability is now available.

An update is now available for Red Hat JBoss Data Virtualization. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Pen testers find mystery black box connected to ship’s engines
Robotic hand solves Rubik’s Cube by learning how to learn about it
Hackers hack card details from BriansClub carding site
Adobe fixes 46 critical bugs in patchfest
What was wrong with Alexa? How Amazon Echo and Kindle got KRACKed

ESET Smart Home Research Team uncovers Echo, Kindle versions vulnerable to 2017 Wi-Fi vulnerabilities The post What was wrong with Alexa? How Amazon Echo and Kindle got KRACKed appeared first on WeLiveSecurity

Operation Ghost: The Dukes aren’t back – they never left

ESET researchers describe recent activity of the infamous espionage group, the Dukes, including three new malware families The post Operation Ghost: The Dukes aren’t back – they never left appeared first on WeLiveSecurity

Several security issues were fixed in LibTIFF.

The update of libsdl2 released as DLA 1714-1 led to several regressions, as reported by Avital Ostromich. These regressions are caused by libsdl1.2 patches for CVE-2019-7637, CVE-2019-7635, CVE-2019-7638 and CVE-2019-7636 being applied to libsdl2 without adaptations.

The update of libsdl1.2 released as DLA 1713-1 led to a regression, caused by an incomplete fix for CVE-2019-7637. This issue was known upstream and resulted, among others, in windows versions from libsdl1.2 failing to set video mode.

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Risk Level: Very Low.

Smashing Security #150: Liverpool WAGs, Facebook politics, and a selfie stalker

Several security issues were fixed in the Linux kernel.

Hundreds charged in internet’s biggest child-abuse swap-shop site bust: IP addy leak led cops to sys-op’s home

The updated packages fix a security vulnerability: Potential bypass of Runas user restrictions. (CVE-2019-14287) References:

10 Steps for Ransomware Protection

Type: Vulnerability. Oracle Solaris is prone to multiple local security vulnerabilities; fixes are available.

Type: Vulnerability. Oracle E-Business Suite is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle E-Business Suite is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Oracle MySQL Server is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Oracle Hospitality Reporting and Analytics is prone to multiple remote security vulnerabilities; fixes are available.

Type: Vulnerability. Oracle E-Business Suite is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Hospitality RES 3700 is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle E-Business Suite is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Banking Digital Experience is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle E-Business Suite is prone to a remote vulnerability in Oracle Advanced Outbound Telephony; fixes are available.

Type: Vulnerability. Oracle PeopleSoft Enterprise HCM Human Resources is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle PeopleSoft Enterprise SCM eProcurement is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Siebel UI Framework is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle FLEXCUBE Direct Banking is prone to multiple remote security vulnerabilities; fixes are available.

Type: Vulnerability. Oracle Primavera P6 Enterprise Project Portfolio Management is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE and Java SE Embedded are prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle PeopleSoft Enterprise PeopleTools is prone to multiple remote security vulnerabilities; fixes are available.

Type: Vulnerability. Oracle Primavera P6 Enterprise Project Portfolio Management is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Siebel Core – DB Deployment and Configuration is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Eclipse Mojarra is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. libxslt is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Oracle Database Server is prone to a local vulnerability; fixes are available.

Type: Vulnerability. Oracle Retail Xstore Point of Service is prone to a local security vulnerability; fixes are available.

Type: Vulnerability. Oracle Hyperion Enterprise Performance Management Architect is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Database Server is prone to multiple local security vulnerabilities; fixes are available.

Type: Vulnerability. Oracle Hyperion Financial Reporting is prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle Retail Customer Management and Segmentation Foundation is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE and Java SE Embedded are prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle Hyperion Data Relationship Management is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Database Server is prone to multiple remote security vulnerabilities; fixes are available.

Type: Vulnerability. Oracle Retail Xstore Office is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE and Java SE Embedded are prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE and Java SE Embedded are prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE and Java SE Embedded are prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE and Java SE Embedded are prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE and Java SE Embedded are prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE and Java SE Embedded are prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE and Java SE Embedded are prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle Hospitality Cruise Dining Room Management is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Database Server is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE and Java SE Embedded are prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE and Java SE Embedded are prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle Retail Customer Management and Segmentation Foundation is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Java SE and Java SE Embedded are prone to a remote vulnerability; fixes are available.

Type: Vulnerability. Oracle MICROS Relate CRM Software is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle Database Server is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Oracle GraalVM Enterprise Edition is prone to a remote security vulnerability; fixes are available.