Menu

Latest articles

Mozilla Private Network VPN gives Firefox another privacy boost

Samuel R Lovejoy discovered a security vulnerability in dnsmasq. Carefully crafted packets by DNS servers might result in out of bounds read operations, potentially leading to a crash and denial

Fin7 sysadmin pleads guilty to running IT for billion-dollar crime syndicate
From PowerShell to auditing: Expand your cybersecurity know-how at SANS London 2019
From pen-test to penitentiary: Infosec duo cuffed after physically breaking into courthouse during IT security assessment
Snoops can bypass iOS 13 lock screen to eyeball your address book. Apple hasn’t fix it yet. Valid flaw? You decide

An update that fixes one vulnerability is now available.

Those fake spying cell towers in Washington DC? Ex-intel staffers claim they’re Israeli
Eco-activists arrested by Brit cops after threatening to close Heathrow with drones

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Simjacker vulnerability lets attackers track your location with an SMS
Library-Themed University Phishing Attack Expands to Massive Scale
California Passes Bill to Ban Police Use of Facial Recognition
1B Mobile Users Vulnerable to Ongoing ‘SimJacker’ Surveillance Attack
UNICEF Leaks Personal Data of 8,000 Users via Email Blunder

Reading Time: ~ 3 min. According to a report from hired.com, the demand for security engineers is up 132%. Additionally, the need for engineers who specialize in data analytics and machine learning has increased by 38% and 27%, respectively. Given recent trends in cybersecurity, it’s no wonder, and demand at Webroot is no exception. To […]

September 2019’s Patch Tuesday: 2 zero-days, 17 critical bugs
Massive email fraud bust snares 281 suspects
Google experiments with DNS-over-HTTPS in Chrome
Error-laden phone location data suspended from use in Danish courts
How to download online video & audio files with new tool from SaveFrom.net
Mystery database left open turns out to be massive Groupon fraud ticket fraud ring
Watch live today: How to make your voice heard – and keep your staff safe from hackers

Risk Level: Very Low. Type: Trojan.

Smashing Security #145: Apple and Google willy wave while home assistants spy – DoH!
ThreatList: Apple Adware, Phishing, APT Attacks Threaten macOS Users
Major Groupon, Ticketmaster Fraud Scheme Exposed By Insecure Database
100s of Flashlight apps on Play Store ask for dangerous permissions

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Several security issues were fixed in curl.

Infosec prophet Bruce Schneier (peace be upon him) is only as famous as half of Salt-N-Pepa
198 Million Car-Buyer Records Exposed Online for All to See
Intel CPUs Vulnerable to Sensitive Data Leakage in NetCAT Attack
Toyota parts supplier loses $37 million in email scam
Lemonade is changing the way we insure our homes
Operation reWired: 281 suspected email scammers arrested around the world
CISO/CIO: Get an iPad and Apple Watch with an App Monitoring your Security 24/7
Strangest Phishing Lures of 2019: From Divorce Papers to Real Estate Decoys
Feds Indict 281 People for Involvement in Massive E-Mail Fraud Scheme
Wikipedia fights off huge DDoS attack
LinkedIn can’t block public profile data scraping, court rules
Telegram fixes ‘unsend message’ bug that held on to your pictures
Facebook says location data in iOS 13, Android 10 may be confusing
How Can SEO Help Increase Website Security?
Selfies for kids – A guide for parents

Are you – and especially your children – aware of the risks that may come with sharing selfies? The post Selfies for kids – A guide for parents appeared first on WeLiveSecurity

D-Link, Comba network gear leave passwords open for potentially whole world to see

An update for rh-dotnet21-dotnet and rh-dotnet22-dotnet is now available for .NET Core on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for dotnet is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that solves three vulnerabilities and has 9 fixes is now available.

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the pki-deps:10.6 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for poppler is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for libwmf is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

USN 4115-1 introduced a regression in the Linux kernel.

An update for the openshift and atomic-enterprise-service-catalog packages is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Required: Massive email fraud bust. Tired: Cops who did the paperwork. Expired: 281 suspected con men’s freedom
It’s 2019, and Windows PCs can be pwned via a shortcut file, a webpage, an evil RDP server…

security update

security update

security update

security update

Insider Threats Are Rising – But They Shouldn’t Be
Rolling in DoH: Chrome 78 to experiment with DNS-over-HTTPS – hot on the heels of Firefox
Microsoft Addresses Two Zero-Days Under Active Attack
ThreatList: Amidst Data Breaches, Account Creation Fraud Soars in 2019
Adobe Fixes Critical Flash Player Code Execution Flaws
The NetCAT is out of the bag: Intel chipset exploited to sniff SSH passwords as they’re typed over the network
600,000 GPS child trackers found vulnerable to location tracking

An update that fixes 24 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

U.S. Manufacturer Most Recent Target of LokiBot Malspam Campaign

An update is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Vulnerabilities in D-Link, Comba Routers Can Leak Credentials

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Mozilla increases browser privacy with encrypted DNS
Google & Apple pushed to reveal gun scope app users’ names to feds
Chrome bumps ineffective EV certificates off the omnibar
Critical TLS flaw opens Exim servers to remote compromise

Several security issues were fixed in Python.

An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for polkit is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Mozilla Firefox to begin slow rollout of DNS-over-HTTPS by default at the end of the month
Equifax is going to make you work for that 125 bucks it owes each of you: Biz sneaks out Friday night rule change
That Telegram feature that let you delete your private messages on recipients’ phones? It didn’t work properly
PsiXBot Adds PornModule, Google DNS Service to Its Arsenal
Stealth Falcon Targets Middle East with Windows BITS Feature

It was discovered that the code fixes for LibreOffice to address CVE-2019-9852 were not complete. Additional information can be found at https://www.libreoffice.org/about-us/security/advisories/CVE-2019-9854/