Menu

Latest articles

Telnet Backdoor Opens More Than 1M IoT Radios to Hijack
Wikipedia, World of Warcraft Downed By Weekend DDoS Attacks
Wikipedia and World of Warcraft Classic targeted by DDoS attacks

An update that fixes 8 vulnerabilities is now available.

Critical Exim Flaw Opens Millions of Servers to Takeover
What a bunch of DoSers: Wikipedia says it was walloped by ‘bad faith’ actors over weekend
Cloud security: Inside the shared responsibility model

Memcached could be made to expose sensitive information if it received a specially crafted UNIX socket.

Apple Claims Google is Spreading FUD Over Patched iPhone Bugs
Symantec shares up as private equity suitors sniff consumer tentacle

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

WordPress 5.2.3 fixes new clutch of security vulnerabilities
Brave accuses Google of sidestepping GDPR
Facebook launches $10m deepfake detection project
Hackers who hit Texas with ransomware attack demanded $2.5 million, got nothing
US city balks at paying $5.3 million ransomware demand
ESET discovered an undocumented backdoor used by the infamous Stealth Falcon group

ESET researchers discovered a backdoor linked to malware used by the Stealth Falcon group, an operator of targeted spyware attacks against journalists, activists and dissidents in the Middle East The post ESET discovered an undocumented backdoor used by the infamous Stealth Falcon group appeared first on WeLiveSecurity

Apple and Google trade barbs over bugs, digital lothario arrested and Bluekeep gets busy

An update for go-toolset-1.11 and go-toolset-1.11-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Update to 2.0.16

Update to 2.0.16

Chromium update to 76.0.3809.132.

Wikipedia suffers DDoS attack causing worldwide service disruption

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An authentication bypass was discovered in D-Bus.

Multiple vulnerabilities have been found in Simple DirectMedia Layer, the worst of which could result in the arbitrary execution of code.

Updated dovecot packages fix security vulnerability: IMAP protocol parser does not properly handle NUL byte when scanning data in quoted strings, leading to out of bounds heap memory writes.

Updated tomcat packages fix security vulnerabilities: The HTTP/2 implementation accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for

This release fixes a heap buffer over-read in BlitNtoN() function when processing an invalid BMP image. It also updates a URL in the RPM metadata.

**Version 1.3.10** – Managesieve: Fix so “Create filter” option does not show up when Filters menu is disabled (#6723) – Enigma: Fix bug where revoked users/keys were not greyed out in key info – Enigma: Fix error message when trying to encrypt with a revoked key (#6607) – Enigma: Fix “decryption oracle” bug [CVE-2019-10740] (#6638) […]

Security fix for CVE-2019-15043

Resolves: rhbz#1609774 nsd-4.2.2 is available

Fixes for CVE-2019-6472, CVE-2019-6473 and CVE-2019-6474

This release fixes a heap buffer over-read in BlitNtoN() function when processing an invalid BMP image. It also updates a URL in the RPM metadata.

Security fix for CVE-2019-15043

An update that fixes one vulnerability is now available.

It was discovered that various procedures in Ghostscript, the GPL PostScript/PDF interpreter, do not properly restrict privileged calls, which could result in bypass of file system restrictions of the dSAFER sandbox.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

It was discovered that there was a stack-based buffer over-read in memcached, the in-memory object caching system. For Debian 8 “Jessie”, this issue has been fixed in memcached version

Multiple vulnerabilities have been found in Exim, the worst of which allows remote attackers to execute arbitrary code.

Week in security

This week, we present an introduction to the MITRE ATT&CK framework, the review of the mobile threats and vulnerabilities detected for mobile during the first half of 2019, and Firefox 69 new features. The post Week in security appeared first on WeLiveSecurity

security update

ThreatList: Police Use of Facial Recognition is Just Fine, Say Most Americans

An update that fixes one vulnerability is now available.

China’s APT3 Pilfers Cyberweapons from the NSA
Back-to-School Scams Target Students with Library-Themed Emails
News Wrap: Deepfake CEO Voice Scam, Facebook Phone Data Exposed

Exim could be made to run programs as an administrator if it received specially crafted network traffic.

Hackers can break into Android devices by sending a text
Semi‑annual balance of mobile security 2019

Malware detections for iOS increased, as did the number of vulnerabilities detected in this operating system, while in the case of Android, the number of reported vulnerabilities decreased, although the number of highly critical bugs reported increased. The post Semi‑annual balance of mobile security 2019 appeared first on WeLiveSecurity

Multiple vulnerabilities have been found in WebkitGTK+, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in Apache, the worst of which could result in a Denial of Service condition.

A buffer overflow in Pango might allow an attacker to execute arbitrary code.

Multiple vulnerabilities have been found in VLC, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in Perl, the worst of which could result in the arbitrary execution of code.

Database exposed 133 million US Facebook users’ phone numbers
YouTube fined $170m for covertly tracking kids online
Facebook expands use of face recognition

Reading Time: ~ 2 min. Deepfake BEC Scam  A new variant of the well-known BEC scam has implemented a feature that has yet to be used in an email scam: voice fraud. Using an extremely accurate deepfake voice of a company’s CEO, scammers were able to successfully convince another company to wire $250,000 with the promise of a quick return. Unfortunately, that transfer was […]

Facebook, Microsoft Challenge Industry to Detect, Prevent ‘Deepfakes’

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

It was discovered that there was a heap-based buffer overread vulnerability in expat, an XML parsing library. A specially-crafted XML input could fool the parser into changing

7 Tips to Increase Your WordPress Security
Exim marks the spot… of remote code execution: Patch due out today for ‘give me root’ flaw in mail server
Twitter turns off SMS texting after @Jack hijacking
Firefox 69: Third‑Party Tracking Cookies and Cryptomining Now Blocked by Default

Firefox new Enhanced Tracking Protection (ETP) feature launched to all users of the browser to offer better privacy and protection from cryptojacjing. The post Firefox 69: Third‑Party Tracking Cookies and Cryptomining Now Blocked by Default appeared first on WeLiveSecurity

* Security fix for CVE-2019-14267 * Security fix for CVE-2019-14934

Update to 1.8.6 release which fixes a bug in 1.8.5. 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling.

Update LXC to version 3.0.4. The release announcement can be found [here](https://discuss.linuxcontainers.org/t/lxc-3-0-4-has-been-released/5080).

Massachusetts city tells ransomware scumbags to RYUK off, our IT staff will handle this easily

security update

Too bad, so sad, exploit devs: Google patches possibly several million dollars’ worth of security flaws in Android
Insights and Tips on Video Compression using VLC
Zerodium to pay up to $2.5 million for reporting 0-day Android exploits
Joker Spyware Found in 24 Google Play Apps
FunkyBot Malware Intercepts Android Texts, 2FA Codes

security update

Type: Vulnerability. Microsoft ASP.NET Core and .NET Framework are prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core and .NET Framework are prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core and .NET Framework are prone to a remote denial-of-service vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has 19 fixes is now available.

Unsecured database leaks phone numbers of 419 million Facebook users
$5.3M Ransomware Demand: Massachusetts City Says No Thanks

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, bypass of the same-origin policy, sandbox escape, information disclosure or denial of service.

Raspberry Pi blasted into space, sends back video of Earth
Scammers deepfake CEO’s voice to talk underling into $243,000 transfer
Firefox won’t follow Chrome’s anti-ad-blocker changes, says Mozilla

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.