Menu

Latest articles

Microsoft rushes out patch for Internet Explorer zero‑day

There is no word on which threat actor is abusing the severe vulnerability for attacks The post Microsoft rushes out patch for Internet Explorer zero‑day appeared first on WeLiveSecurity

What You Need to Know About Next Gen EDR
Microsoft rushes out fix for Internet Explorer zero-day
Teenage TalkTalk hacker accused of $800,000 cryptocurrency theft in the United States
Apple to Patch Bug Granting Full Access to 3rd-Party Keyboards

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

Google wins landmark case: Right to be forgotten only applies in EU
Patch released for Windows-pwning VPN bug
Twitter’s new policy bans financial scams

File Roller could be made to overwrite sensitive files if it received a specially crafted TAR file.

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that solves 7 vulnerabilities and has one errata is now available.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Hot patches for ColdFusion: Adobe drops trio of fixes for three serious flaws
Google takes sole stand on privacy, rejects new rules for fear of ‘authoritarian’ review

It was discovered that SPIP, a website engine for publishing, would allow unauthenticated users to modify published content and write to the database, perform cross-site request forgeries, and enumerate registered users.

We finally got one! Russian ‘fesses up to cracking bank servers, netting big bucks

security update

security update

This vBulletin vBug is vBad: Zero-day exploit lets miscreants hijack vulnerable web forums
GandCrab Operators Resurface with REvile Malware
An illegal prostitution ring took Kazakhstan offline
Adobe Unscheduled Update Fixes Critical ColdFusion Flaws
DoH! Mozilla assures UK minister that DNS-over-HTTPS won’t be default in Firefox for Britons
CafePress finally warns customers that it was hacked
Can you code a way to foil online terrorist vids? The Home Office might just have £600K for you
Dtrack RAT is Behind Virulent ATM-Espionage Campaign
Zebrocy Retools for New Political Attacks
Instagram phish poses as copyright infringement warning – don’t click!
YouTube ‘influencers’ get 2FA tokens phished
Do companies take cybersecurity seriously enough?

Many companies are ranking cybersecurity as a top 5 priority but their actions do not measure up to the claim, a survey finds The post Do companies take cybersecurity seriously enough? appeared first on WeLiveSecurity

Malicious Ad Blockers for Chrome Caught in Ad Fraud Scheme
Why do cloud leaks keep happening? Because no one has a clue how their instances are configured
Facebook has booted tens of thousands of data-grabbing apps
Apple restricts old adblocking tech
Jira development and ticketing software hit by critical flaws
No summer vacations for Zebrocy

ESET researchers describe the latest components used in a recent Sednit campaign The post No summer vacations for Zebrocy appeared first on WeLiveSecurity

World of Warcraft’s suspected DDoS attacker has been arrested
How to Protect Your Online Store from Cyber Threats
Nine words to ruin your Monday: Emergency Internet Explorer patch amid in-the-wild attacks
4 Helpful Tips to Make Your WiFi Fast and Efficient
How to Increase Your Business’s Online Brand Awareness
Microsoft Internet Explorer Zero-Day Flaw Addressed in Out-of-Band Security Update

Type: Vulnerability. Microsoft .NET Core is prone to a remote denial-of-service vulnerability; fixes are available.

The Benefits of Using a VPN at Home
More U.S. Utility Firms Targeted in Evolving LookBack Spearphishing Campaign
Several months after the fact, CafePress finally acknowledges huge data theft to its customers
I’m keynoting about cybercrime at the CRN MSP conference in London next week
Google Assistant Audio Privacy Controls Updated After Outcry

An update that solves 8 vulnerabilities and has one errata is now available.

USN 4134-1 introduced a regression in IBus.

HMRC’s HTTPS howler: Childcare payments site cert expired at 1am on Sunday, down for hours
200K Sign Petition Against Equifax Data Breach Settlement
Google pulls more fake adblockers from Chrome Web Store

Reading Time: ~ 3 min. When you’re running a business, it’s important to stay connected, whether you’re in the office or not. Modern technology has made this easier than ever, ensuring you can answer emails and stay on top of tasks in hotels, coffee shops, wherever. Social media influencer and serial entrepreneur Gary Vaynerchuk has even […]

Investors accuse FedEx of lying, stock dumping after NotPetya attack

An update that fixes 24 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Could EarEcho change the way we authenticate our phones?

A buffer overflow flaw was found in the way Linux kernel’s vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host. (CVE-2019-14835) […]

Two charged with tech-support scamming the elderly for $10m
Pizza prankster’s prisoner plea plot perturbs police, Norks invading and Uber woes
WannaCry – and why it never went away

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dbus is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dbus is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kpatch-patch is now available for RHEL-7.6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

It was discovered that Expat, an XML parsing C library, did not properly handled internal entities closing the doctype, potentially resulting in denial of service or information disclosure if a malformed XML file is processed.

security update

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

Bug fixes and security fixes. Better threading compile time option set. See: https://src.fedoraproject.org/rpms/ImageMagick/pull-request/2 Additional formats enabled.

Bug fixes and security fixes. Better threading compile time option set. See: https://src.fedoraproject.org/rpms/ImageMagick/pull-request/2 Additional formats enabled.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– rebase to latest upstream version 9.27 – security fixes added for: – CVE-2019-14811 (bug #1747908) – CVE-2019-14812 (bug #1747907) – CVE-2019-14813 (bug #1747906) – CVE-2019-14817 (bug #1747909)

This kernel update is based on the upstream 5.2.16 and fixes atleast the following security issues: There is heap-based buffer overflow in the marvell wifi chip driver that allows local users to cause a denial of service(system crash) or possibly

This kernel update is based on the upstream 4.14.145 and fixes atleast the following security issues: There is heap-based buffer overflow in the marvell wifi chip driver that allows local users to cause a denial of service(system crash) or possibly

Updated samba packages fix security vulnerabilities: A combination of parameters and permissions in smb.conf can allow user to escape from the share path definition (CVE-2019-10197).

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The updated thunderbird packages fix security issues: Covert Content Attack on S/MIME encryption using a crafted multipart/ alternative message. (CVE-2019-11739)

It was discovered that any unprivileged user could monitor and send method calls to the ibus bus of another user, due to a misconfiguration during the setup of the DBus server. When ibus is in use, a local attacker, who discovers the UNIX socket used by another user connected on a graphical environment, could use […]

Multiple flaws were found in the way Chromium 73.0.3683.103 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information. (CVE-2019-5805, CVE-2019-5806, CVE-2019-5807, CVE-2019-5808, CVE-2019-5809, CVE-2019-5810,

Disgraced ex-Kaspersky guy made me do it, says bloke in Russian court on hacking charges
Poor security: 15,000 private webcams exposed to creeps

security update

security update

security update

An update that fixes one vulnerability is now available.