Menu

Latest articles

– Update jackson-parent to version 2.10. – Update jackson-bom to version 2.10.0. – Update jackson-annotations to version 2.10.0. – Update jackson-core to version 2.10.0. – Update jackson-databind to version 2.10.0. Resolves CVE-2019-14540, CVE-2019-16335, CVE-2019-16942, CVE-2019-16943.

– Update jackson-parent to version 2.10. – Update jackson-bom to version 2.10.0. – Update jackson-annotations to version 2.10.0. – Update jackson-core to version 2.10.0. – Update jackson-databind to version 2.10.0. Resolves CVE-2019-14540, CVE-2019-16335, CVE-2019-16942, CVE-2019-16943.

– Update jackson-parent to version 2.10. – Update jackson-bom to version 2.10.0. – Update jackson-annotations to version 2.10.0. – Update jackson-core to version 2.10.0. – Update jackson-databind to version 2.10.0. Resolves CVE-2019-14540, CVE-2019-16335, CVE-2019-16942, CVE-2019-16943.

The update for openssl released as DSA 4539-1 introduced a regression where AES-CBC-HMAC-SHA ciphers were not enabled. Updated openssl packages are now available to correct this issue.

Update to latest upstream version.

Stalker zoomed in on Japanese idol’s eyes to find out where she lived
Software, Supply-Chain Dangers Top List of 5G Cyber Risks

Type: Vulnerability. Intel Active System Console is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Intel Smart Connect Technology is prone to a local privilege-escalation vulnerability.

Type: Vulnerability. Multiple Intel NUC Products are prone to multiple unspecified local security vulnerabilities; fixes are available

Type: Vulnerability. Juniper SBR Carrier is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Imperva: Data Breach Caused by Cloud Misconfiguration

A security vulnerability was discovered in lucene-solr, an enterprise search server. The DataImportHandler, an optional but popular module to pull in data

An update that fixes one vulnerability is now available.

Fin7 Cybergang Retools With New Malicious Code

Reading Time: ~ 2 min. E-Scooter Security Vulnerability A security researcher recently found an API vulnerability within the software of Voi e-scooters that allowed him to add over $100,000 in ride credits to his account. The vulnerability stems from a lack of authentication after creating an account which allows users to enter an unlimited number […]

Iran-Linked ‘Charming Kitten’ Touts New Spearphishing Tactics

ruby-openid performed discovery first, and then verification. This allowed an attacker to change the URL used for discovery and trick the server into connecting to the URL. This server in turn could be a private server not publicly accessible.

Most Americans don’t have a clue what https:// means
Hackers bypassing some types of 2FA security FBI warns
Facebook flags thousands of kids as interested in gambling, booze
Apple removes app that tracks Hong Kong police and protestors

Type: Vulnerability. Oracle has released an advance notification regarding the October 2019 Critical Patch Update that addresses 240 new vulnerabilities.

vBulletin Flaw Exploited in Dutch Sex-Work Forum Breach
Stalker attacks Japanese pop singer – after tracking her down using reflection in her eyes
Cryptomining Crook Steals Game Developer’s Identity to Carry Out Dirty Work

Reading Time: ~ 4 min. Online games aren’t new. Consumers have been playing them since as early as 1960. However, the market is evolving—games that used to require the computing power of dedicated desktops can now be powered by smartphones, and online gaming participation has skyrocketed. This unfortunately means that the dangers of online gaming […]

Risk Level: Very Low.

Finfisher malware authors fire off legal threats to silence German journos
Sophisticated Spy Kit Targets Russians with Rare GSM Plugin
Some fokken arse has bared the privates of 250,000 users’ from Dutch brothel forum
China’s Sway Over Tech Companies Tested with Apple, Blizzard
Just let us have Huawei and get on with 5G, UK mobe networks tell MPs
Apple iTunes Bug Actively Exploited in BitPaymer/iEncrypt Campaign
HP Touchpoint Analytics Opens PCs to Code Execution Attack

Fix KDC crash when logging PKINIT enctypes (CVE-2019-14844) This is a purely denial-of-service issue, though it is unauthenticated, and is unlikely to trigger by accident.

Update to 2.0.10 to fix security issues.

Twitter used 2FA phone numbers for targeted advertising
California outlaws facial recognition in police bodycams

An update for ovirt-web-ui is now available for Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for ovirt-engine-ui-extensions is now available for Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Job seekers are scrubbing clean their social media accounts

Several security issues were fixed in Python.

Octavia could allow unintended access to network services.

ESET discovers Attor, a spy platform with curious GSM fingerprinting

ESET researchers discover a previously unreported cyberespionage platform used in targeted attacks against diplomatic missions and governmental institutions, and privacy-concerned users The post ESET discovers Attor, a spy platform with curious GSM fingerprinting appeared first on WeLiveSecurity

Former BAE Systems contractor charged with ‘damaging disclosure’ of UK defence secrets

It was discovered that clamav, the open source antivirus engine, is affected by the following security vulnerabilities: CVE-2019-12625

An update is now available for Red Hat Fuse Integration Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Smashing Security #149: Falling in love with fraudsters
American intelligence follows British lead in warning of serious VPN vulnerabilities

An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

iTerm2 issues emergency update after MOSS finds a fatal flaw in its terminal code

Red Hat A-MQ Broker 7.5 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Risk Level: Very Low.

US charges Singapore coin miner with conning cloud firms out of compute time

It was discovered that there were two vulnerabilities in the rsyslog system/kernel logging daemon in the parsers for AIX and Cisco log messages respectfully.

Type: Vulnerability. TIBCO MDM is prone to multiple unspecified cross-site scripting vulnerabilities; fixes are available.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Citrix Application Delivery Management is prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. CA Network Flow Analysis is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. GE Mark VIe Controller is prone to an authorization-bypass vulnerability.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Update Assistant is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Bootstrap 3 Typeahead is prone to a cross-site scripting vulnerability.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. SMA Solar Technology AG Sunny WebBox is prone to a cross-site request-forgery vulnerability.

Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.

Gamers Warned of High-Severity Intel, Nvidia Flaws
Most Americans Fail Cybersecurity Quiz
Privacy Groups: Ring’s Police Partnerships Can Lead to Sinister Ends
How concerned are you about the privacy challenges of your IoT devices?

An ESET survey of thousands of people in North America provides a peek into how they perceive the privacy and security of their smart home connected devices The post How concerned are you about the privacy challenges of your IoT devices? appeared first on WeLiveSecurity

Ransomware victim hacks attacker, turning the tables by stealing decryption keys
October Patch Tuesday: Microsoft fixes critical remote desktop bug

Reading Time: ~ 3 min. First and foremost, endpoint protection must be effective. Short of that, MSPs won’t succeed in protecting their clients and, more than likely, won’t remain in business for very long. But beyond the general ability to stop threats and protect users, which characteristics of an endpoint solution best set its administrators […]

Twitter Uses Phone Numbers, Emails to Sell Ads
Deepfakes have doubled, overwhelmingly targeting women
New and Improved CVE Pages
MasterMana botnet hits users by evading detection with URL shorteners
Copy-and-paste sharing on Stack Overflow spreads insecure code
TOMS hacker tells people to log off and enjoy a screenless day
Internet pioneer Dr. Paul Vixie on global internet security

We sat down with internet pioneer and Farsight Security CEO Dr. Paul Vixie, who co-invented some of the services that are central to the ‘Net’s fabric, to discuss a range of issues affecting security and privacy The post Internet pioneer Dr. Paul Vixie on global internet security appeared first on WeLiveSecurity

Twitter: No, really, we’re very sorry we sold your security info for a boatload of cash
You know the deal: October 2019. Pwned by a spreadsheet. Patch your Microsoft stuff
Tune in today: Learn lessons from Australia and Singapore – find out how to thwart cyber-crooks probing your IT
A trio of boffins scoop the Nobel Prize in physics for the first exoplanet discovery and big bang model
Hackers found tracking web traffic of Chrome and Firefox browsers
Intimate Details on Healthcare Workers Exposed as Cloud Security Lags