Menu

Latest articles

Disgrace of Base: Scammy hordes force Keybase to end cryptocoin giveaway
Chrome now warns you if your password has been stolen

The browser’s latest version also aims to up the ante in phishing protection The post Chrome now warns you if your password has been stolen appeared first on WeLiveSecurity

It’s time you were T0RTT a lesson: Here’s how you could build a better Tor, say boffins
Retail Cyberattacks Set to Soar 20% in 2019 Holiday Season
December Patch Tuesday blunts WizardOpium attack chain
Apple iOS 13.3 is here, bringing support for keyfobby authentication
Microsoft movie tried to Azure Ignite attendees about CPU side-channel flaws, but biz wouldn’t be drawn on details
LightAnchors array: LEDs in routers, power strips, and more, can sneakily ship data to this smartphone app
You had one job, Cupertino: Apple’s Intelligent Tracking Protection actually gets tracking protection
Smashing Security #158: The man behind The Missing Cryptoqueen
Plundervolt: A new attack on Intel processors threatening SGX data
Smart Krampus-3PC Malware Targets iPhone Users

Update to Samba 4.11.3 – Security fixes for CVE-2019-14861, CVE-2019-14870 —- Restart winbindd on samba-winbind package upgrade

Serious Security Flaws Found in Children’s Connected Toys

security update

Apple Fixes ‘AirDoS’ Bug That Cripples Nearby iPhones, iPads

Type: Vulnerability. WebKit is prone to an arbitrary-code execution vulnerability; fixes are available.

Type: Vulnerability. Broadcom CA Nolio is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Apple iOS and iPadOS are prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Apple iOS and iPadOS are prone to an arbitrary code execution vulnerability; fixes are available.

Type: Vulnerability. Apple Xcode is prone to an arbitrary code-execution vulnerability; fixes are available.

Signal Tests Upgraded Cryptography for Groups Function

Risk Level: Very Low. Type: Virus.

Risk Level: Very Low. Type: Trojan.

Bad news: KeyWe Smart Lock is easily bypassed and can’t be fixed
Modern Intel CPUs Plagued By Plundervolt Attack
2.7 billion email addresses & plain-text passwords exposed online
Web-hosting firm 1&1 hit by almost €10 million GDPR fine over poor security at call centre
Google Chrome will check for breached credentials every time you sign in anywhere
Lazarus APT Collaborates with Trickbot’s Anchor Project

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4152

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4108

Several security issues were fixed in Samba.

Windows 10 Mobile receives its last security patches
DoItForState domain name thief gets 14 years for pistol-whipping plot
49% of workers, when forced to update their password, reuse the same one with just a minor change
FTC warns Christmas buyers that smart toys are a security risk
Beware of bad Santas this Xmas: Piles of insecure smart toys fill retailers’ shelves
Ad industry groups ask that the CCPA keep its mitts off their cookies

An update that fixes three vulnerabilities is now available.

nss: Out-of-bounds write when passing an output buffer smaller than the block size to NSC_EncryptUpdate (CVE-2019-11745) SL6 x86_64 nss-softokn-3.44.0-6.el6_10.i686.rpm nss-softokn-3.44.0-6.el6_10.x86_64.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.i686.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.x86_64.rpm nss-softokn-freebl-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-3 [More…]

nss: Out-of-bounds write when passing an output buffer smaller than the block size to NSC_EncryptUpdate (CVE-2019-11745) * nss: Empty or malformed p256-ECDH public keys may trigger a segmentation fault (CVE-2019-11729) SL7 x86_64 nss-3.44.0-7.el7_7.i686.rpm nss-3.44.0-7.el7_7.x86_64.rpm nss-debuginfo-3.44.0-7.el7_7.i686.rpm nss-debuginfo-3.44.0-7.el7_7.x86_64.rpm nss-so [More…]

Alleged Nigerian social engineer wins free flight to the US for business email fraud and love scams
Cyber attack cripples networks in city of Pensacola days after shooting
It’s the end of the 20-teens, and your Windows PC can still be pwned by nothing more than a simple bad font
Microsoft Zaps Actively Exploited Zero-Day Bug
Americans should have strong privacy-protecting encryption …that the Feds and cops can break, say senators

security update

Type: Vulnerability. Openssl is prone to an integer-overflow vulnerability; fixes are available.

Type: Vulnerability. Zoho Applications Manager Plugin is prone to an SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Zoho Applications Manager Plugin is prone to a remote command-execution vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.

Type: Vulnerability. Symantec Industrial Control System Protection is prone to an unauthorized access vulnerability; fixes are available.

Cyberattack Downs Pensacola’s City Systems
Intel might want to reconsider the G part of SGX – because it’s been plunderstruck
Snatch Team Steals Data and Hammers Orgs with Ransomware
Adobe Fixes 17 Critical Acrobat, Photoshop and Brackets Flaws
Don’t pay off Ryuk ransomware, warn infoseccers: Its creators borked the decryptor
Amazon’s Blink Smart Security Cameras Open to Hijack
Download: The 2020 Cybersecurity Salary Survey Results
Data leak exposes 750,000 birth certificate applications

A variety of sensitive information has been there for the taking due to an unsecured cloud storage container The post Data leak exposes 750,000 birth certificate applications appeared first on WeLiveSecurity

20 years prison for Romanian hackers who infected 400,000 computers
Snatch ransomware reboots Windows in Safe Mode to bypass anti-virus protection
DHS Rolls Back Facial-Recognition Expansion Plan

It was found that freeimage, a graphics library, was affected by the following two security issues: CVE-2019-12211

Snatch ransomware pwns security using sneaky ‘safe mode’ reboot
EU releases its 5G conclusions

An update for nss, nss-softokn, and nss-util is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

It was found that Squid, a high-performance proxy caching server for web clients, has been affected by the following security vulnerabilities.

SIEMs like a stretch: Elastic searches for cash from IT pros with security budgets
Facebook users were duped by Cambridge Analytica, FTC rules
TikTok settles class action over child privacy one day after it’s filed

An update for sudo is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Cybersecurity Trends 2020: Technology is getting smarter – are we?

With 2019 ending, ESET experts offer their insights into how new innovations will impact our privacy, security and lives in the not so distant future The post Cybersecurity Trends 2020: Technology is getting smarter – are we? appeared first on WeLiveSecurity

An update that solves three vulnerabilities and has one errata is now available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Remote Desktop Protocol is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple information-disclosure vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple arbitrary code-execution vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple arbitrary code-execution vulnerabilities; fixes are available.

Type: Vulnerability. Adobe ColdFusion is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to a heap-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Adobe Photoshop CC is prone to multiple unspecified memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Samba is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. SAP Adaptive Server Enterprise is prone to an unspecified information-disclosure vulnerability; fixes are available.

Type: Vulnerability. SAP BusinessObjects Business Intelligence Platform is prone to an cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. SAP Portfolio and Project Management is prone to an information-disclosure vulnerability; fixes are available.