Menu

Latest articles

Type: Vulnerability. SAP Portfolio and Project Management is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. SAP Enable Now is prone to multiple unspecified security vulnerabilities; fixes are available.

Type: Vulnerability. SAP BusinessObjects Business Intelligence Platform is prone to an unspecified cross-site request-forgery vulnerability; fixes are available.

Advertisers want exemption from web privacy rules that, you know, enforce privacy
Birth Certificate Data Laid Bare on the Web in Multiple States
Serious Security: Understanding how computers count
Romanian Duo Receives Jailtime For Infecting 400,000 With Malware

Type: Vulnerability. Palo Alto Networks PAN-OS is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Dell Command Configure is prone to an arbitrary file-overwrite vulnerability; fixes are available.

Type: Vulnerability. Adobe Stock is prone to remote code-execution vulnerability.

Type: Vulnerability. Multiple QNAP products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Multiple QNAP products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. OpenSLP is prone to a heap-memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Docker is prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Facebook Mcrouter is prone to multiple denial of service vulnerabilities; fixes are available.

Type: Vulnerability. Atlassian Companion is prone to a security-bypass vulnerability.

FBI uses PlayStation to bust large scale drug deal
Elder Scrolls Online Targeted by Cybercrooks Hunting In-Game Loot
Will the new iPhone 11 track you even if you tell it not to?
Fake VPN website delivering password-stealing malware
Ad network ransomware crook to flog £5k Rolex after court confiscates £270k in ill-gotten gains
Hackers steal credit card details from Sweaty Betty customers
GE, Dunkin’, Forever 21 Caught Up in Broad Internal Document Leak
Reddit Says Influence Campaign is Behind Leaked U.S.-U.K. Trade Documents
Metasploit for drones? Best of luck with that, muses veteran tinkerer

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

Networking attack gives hijackers VPN access
HackerOne pays $20,000 bounty after breach of own systems
Facebook suing ILikeAd for hijacking users’ ad accounts
$5m bounty set on the alleged head of Evil Corp banking Trojan group
5 scam prevention tips for seniors

How can people who didn’t grow up with technology protect themselves against some of the most common types of online fraud? The post 5 scam prevention tips for seniors appeared first on WeLiveSecurity

A security update is now available for Open Liberty 19.0.0.12 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

NSS could be made to crash if it received a specially crafted certificate.

An update for nss is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

security update

Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, information disclosure or the execution of arbitrary code.

The OpenSLP package had two open security issues: CVE-2017-17833

phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/display_git_revision.lib.php and libraries/Footer.class.php.

This update addresses a number of bugs affecting processing of CRLs in mod_tls, including possible null pointer dereferences and missing some checks. Thanks to Lionel Debroux for reporting them.

This update addresses a number of bugs affecting processing of CRLs in mod_tls, including possible null pointer dereferences and missing some checks. Thanks to Lionel Debroux for reporting them.

Address CVE-2019-19204 CVE-2019-19203 CVE-2019-19012. Fixes are backported.

Amazon battles leaky S3 buckets with a new security tool
OpenBSD bugs, Microsoft’s bad update, a new Nork hacking crew, and more
New privacy tool exposes which website leaves your data unprotected
Email Voted a Weak Link for Election Security, with DMARC Lagging
China fires up ‘Great Cannon’ denial-of-service blaster, points it toward Hong Kong
Feds Crack Down on Money Mules, Warn of BEC Scams

Type: Vulnerability. Multiple Linux Distributions are prone to a security-bypass vulnerability.

Type: Vulnerability. Xen is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. CZ.NIC Knot Resolver is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. OpenBSD is prone to multiple privilege-escalation and authentication-bypass vulnerabilities; fixes are available.

Type: Vulnerability. Redhat KeyCloak is prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. Apache Olingo is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. An AMD ATI driver is prone to denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Wireshark is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Embedthis GoAhead is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Embedthis GoAhead Web Server is prone to a remote code execution vulnerability; fixes are available.

News Wrap: Authorities Target Evil Corp., Imminent Monitor, Money Mules
New Linux vulnerability puts VPN connections at risk of hijacking
Linux Bug Opens Most VPNs to Hijacking
Facebook Alleges Company Infiltrated Thousands for Ad Fraud
Stealthy MacOS Malware Tied to Lazarus APT
Mac users targetted by Lazarus ‘fileless’ Trojan

Reading Time: ~ 2 min. ZeroCleare Malware Wiping Systems IBM researchers have been tracking the steady rise in ZeroCleare deployments throughout the last year, culminating in a significant rise in 2019. This malware is deployed on both 32 and 64-bit systems in highly targeted attacks, with the capability to completely wipe the system by exploiting […]

US parents file class action against TikTok over children’s privacy
Reasons to be fearful 2020: Smishing, public Wi-Fi, deepfakes… and all the usual suspects
Instagram trying to protect kids by getting dates of birth from new users
OpenBSD devs patch authentication bypass bug
5 things you should never do when using anonymous operating systems

The updated packages fix a security vulnerability: ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage. (CVE-2019-16709)

Updated sysstat package fixes security vulnerability: Memory corruption due to an integer overflow (CVE-2019-16167). References:

Updated python-psutil packages fix security vulnerability: Riccardo Schirone discovered that psutil incorrectly handled certain reference counting operations. An attacker could use this issue to cause psutil to crash, resulting in a denial of service, or possibly execute

Updated libvpx packages fix security vulnerabilities: It was discovered that libvpx did not properly handle certain malformed WebM media files. If an application using libvpx opened a specially crafted WebM file, a remote attacker could cause a denial of service, or possibly

Updated libvncserver packages fix security vulnerability: LibVNC contained a memory leak in VNC server code, which allowed an attacker to read stack memory and could be abused for information disclosure. Combined with another vulnerability, it could be used to

Updated tnef package fixes security vulnerability: In tnef, an attacker may be able to write to the victim’s .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based

SANS Announces 13th Holiday Hack Challenge and 2nd KringleCon infosec conference
Tricky VPN-busting bug lurks in iOS, Android, Linux distros, macOS, FreeBSD, OpenBSD, say university eggheads
VCs find exciting new way to blow $1m: Wire it directly to hackers after getting spoofed
If there’s somethin’ stored in a secure enclave, who ya gonna call? Membuster!
Ransomware Attack Hits Data Center Provider CyrusOne: Report
Israeli firm buys Private Internet Access (PIA) VPN raising privacy concerns

Type: Vulnerability. Redhat KeyCloak is prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability.

Type: Vulnerability. VMware Harbor Container Registry for PCF is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple local denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Moxa AWK-3121 Series is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple local denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. Dell Command Update is prone to multiple arbitrary-file-deletion vulnerabilities; a fix is available.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability.

Type: Vulnerability. Reliable Controls LicenseManager is prone to a local code execution vulnerability; fixes are available.

Type: Vulnerability. Dell EMC RSA Authentication Manager is prone to an HTML-injection vulnerability; fixes are available.

AT&T, Verizon Subscribers Exposed as Mobile Bills Turn Up on the Open Web