Menu

Latest articles

Hack strikes Words with Friends and Draw Something, amid claims 218 million players’ details breached
Social media manipulation as a political tool is spreading
Outlook on the web bans a further 38 file types
Is the era of social media Likes over?
Microsoft changes encryption, another D-Link bug, phishing dangers, and more

An update that fixes 24 vulnerabilities is now available.

An update that fixes 24 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Two vulnerabilities were found in the WPA protocol implementation found in wpa_supplication (station) and hostapd (access point). CVE-2019-13377

Security fix for CVE-2019-14822

– double free due to subsequent call of realloc() (CVE-2019-5481) – fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)

New upstream version 1.12.8. Fixes second Denial of Service attack: https://www.redhat.com/archives/libguestfs/2019-September/msg00272.html

security update

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

New upstream version 1.14.2. Fixes second Denial of Service attack: https://www.redhat.com/archives/libguestfs/2019-September/msg00272.html

Update to latest upstream version.

An open redirect, that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control,

Hackers used fake job website to scam jobless US veterans

security update

security update

Got a pre-A12 iPhone? Love jailbreaks? Happy Friday! ‘Unpatchable tethered Boot ROM exploit’ released
Hacker publishes ‘unpatchable’ permanent jailbreak for iPhone 4s to iPhone X
What’s that smell? Perfume merchant senses the scent of a digital burglary
iOS Exploit ‘Checkm8’ Could Allow Permanent iPhone Jailbreaks
Masad Spyware Uses Telegram Bots for Command-and-Control

Risk Level: Very Low. Type: Trojan.

Dunkin’ Donuts Gets Hit with Lawsuit Over 2015 Attack
Arcane Stealer V Takes Aim at the Low End of the Dark Web
Microsoft Blacklists Dozens of New File Extensions in Outlook

An update that solves one vulnerability and has one errata is now available.

‘Fleeceware’ Play store apps quietly charging up to $250
Apple users, patch now! The ‘bug that got away’ has been fixed
Chrome cripples movie studio Mac Pros
Google made thousands of deepfakes to aid detection efforts
News Wrap: GandCrab Operators Resurface, Utilities Firms Hit By LookBack Malware

Reading Time: ~ 2 min. Copyright Phishing Campaign Hits Instagram Many Instagram accounts were recently compromised after receiving a notice that their accounts would be suspended for copyright infringement if they didn’t complete an objection form within 24 hours. By setting a timeframe, the attackers are hoping that flustered victims would quickly begin entering account […]

Thousands of PCs Affected by Nodersok/Divergent Malware

An update that solves two vulnerabilities and has two fixes is now available.

Match knowingly puts people at risk from scammers, FTC charges
Pupil mental health monitor promises app rewrite after hardcoded login creds discovered

An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS. Red Hat Product Security has rated this update as having a security impact

DoorDash doesn’t just pick up your food orders, it delivers your data to hackers, too
Accept certain inalienable truths: Prices will rise, politicians will philander… And US voting machines will be physically insecure
Tune in next month: Learn all about the hackers staring down Singapore, Australia

Security fix for CVE-2019-1010228

An update for kibana is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

DoorDash Data Breach Impacts Personal Data of Almost 5M Users

Security fix for CVE-2019-1010228

Dunkin do-nots: Deep-fried cake maker did not warn its sugar addicts that crooks raided web accounts, says NY AG

security update

An update for golang-github-openshift-oauth-proxy-container is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for logging-elasticsearch5-container is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Reading Time: ~ 3 min. You have probably seen or heard news reports about STEM education (Science, Technology, Engineering, and Math), and how important STEM jobs are for the economy; or maybe you’ve heard reports on schools that are making strides to improve their STEM programs for kids. It’s important for parents with school-aged children to fully understand what a STEM education is and why access to […]

Rash of Exploits Targets Critical vBulletin RCE Bug

Risk Level: Very Low. Type: Trojan.

5G and IoT: How to Approach the Security Implications
Cisco Patches 13 High-Severity Router and Switch Bugs
Hearing aid manufacturer hit by cyber attack slashes profits by $95 million
Phish Uses Google’s URL Decoding to Swim Past Defenses
Vimeo Slapped With Lawsuit Over Biometrics Privacy Policy

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Who is reading your CEO’s email? And how to stop it
WordPress sites hacked through defunct Rich Reviews plugin

An update for gRPC, included in sriov-network-device-plugin-container, is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

CISOs: Support Vendor Security Ops for Best Cloud Results
Four words from Cisco to strike fear into the most hardened techies: Guest account as root
Now Uncle Sam would like a word with Brit teen TalkTalk hacker about a huge crypto-coin heist
Cyber-Risk Business Cases: Using Economic Impact to Justify TIG Investment
Chrome Bug, Not Avid Software, Causes Damage to MacOS File Systems
Hackers are infecting WordPress sites via a defunct plug-in
Russian pleads guilty in massive JPMorgan hacking scheme
Update ColdFusion now! Emergency patch for critical flaws
AI Leaps into Banking: When to know You Can Trust It
Vimeo sued for storing faceprints of people without their say-so

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2836

TalkTalk still struggles to shut down legacy email addresses on request

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

A command injection vulnerability in Nokogiri allows commands to be executed in a subprocess by Ruby’s `Kernel.open` method. For Debian 8 “Jessie”, this problem has been fixed in version

US senators green-light recruitment of crack infosec teams, both public and private
Smashing Security #147: Don’t Snapchat and drive
Magecart Group Targets Routers Behind Public Wi-Fi Networks
How to Secure a Website by Monitoring DNS Records
Confused why Trump fingered CrowdStrike in that Ukraine call? You’re not the only one…

Update to current release. Python3 compatible Installable with f31+ —- Update to 2.5.0 (pre-release)

Two security vulnerabilities were found in OpenSSL, the Secure Sockets Layer toolkit. CVE-2019-1547

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Firefox could be made to hijack the mouse pointer it if opened a malicious website.

‘Narrator’ Windows Utility Trojanized to Gain Full System Control

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Unpatched Bug Under Active Attack Threatens WordPress Sites with XSS
Hacker House shoved under UK Parliament’s spotlight following Boris Johnson funding allegs
Cybercrooks Target U.S. Veterans with Fake Hiring Website

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.