Menu

Latest articles

MSP or System Integrator? Add Incident Response to Your Portfolio at No Cost
Android gets September update as price of flaws soars
Author of record-setting IoT botnets pleads guilty
Hundreds of millions of Facebook users’ phone numbers found lying around on the internet
Leaky Server Exposes 419M Phone Numbers of Facebook Users

An update that fixes two vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Today’s data whoopsie is brought to you by CircleCI: Source safe, but look out for phishers

An update that fixes 12 vulnerabilities is now available.

An update that solves three vulnerabilities and has one errata is now available.

Smashing Security #144: Google helps the FBI, Twitter Jack’s hijack, and car data woes

npm/fstream could be made to overwrite files.

An update that solves 12 vulnerabilities and has 19 fixes is now available.

Newb admits he ran Satori botnet that turned thousands of hacked devices into a 100Gbps+ DDoS-for-hire cannon
Twitter disables tweeting via SMS (temporarily at least), in wake of Jack Dorsey account hijack
Android Zero-Day Bug Opens Door to Privilege Escalation Attack, Researchers Warn
Brave accuses Google of trampling Europe’s GDPR with stealthy netizen-stalking adverts

security update

Let’s recap reCAPTCHA gotcha: Our cunning AI can defeat Google’s anti-bot tech, say uni boffins
Critical Bugs Open Food-Safety Systems to Remote Attacks
Facebook allows users to opt out of facial recognition in photos
Facebook loses control of key used to sign Android app
Blindly accepting network update texts could have pwned your mobe, say researchers
BRATA Android RAT Steals Banking Info in Real Time
Half of Android Handsets Susceptible to Clever SMS Phishing Attack
CEO ‘Deep Fake’ Swindles Company Out of $243K
Android Zero-Days Now Worth More Than iPhone Exploits
CEO voice deepfake blamed for scam that stole $243,000
Chinese tech firm Huawei says it was hacked by the United States

The package jenkins before version 2.192-1 is vulnerable to multiple issues including cross-site request forgery and cross-site scripting.

The package grafana before version 6.3.4-1 is vulnerable to denial of service.

Red flag: Home Office inks £45m border tech extension with IBM

An update that solves three vulnerabilities and has two fixes is now available.

Several newly-referenced issues have been fixed in the FreeType 2 font engine.

QR codes need security revamp, says creator
YouTube reportedly to be fined up to $200m over COPPA investigation
Earn $2.5 million if you find a remote zero-day exploit for Android
EFF and Mozilla scold Venmo over app’s privacy failings

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Bus pass or bus ass? Hackers peeved about public transport claim to have reverse engineered ticket app for free rides

An update for openstack-nova is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Alf-Andre Walla discovered a remotely triggerable assert in the Varnish web accelerator; sending a malformed HTTP request could result in denial of service.

Fancy buying a compact and bijou cardboard box home in a San Francisco alley? This $2.5m Android bounty will get you nearly there

The 5.2.11 stable kernel update contains a number of important fixes across the tree. —- The 5.2.10 stable kernel update contains a number of important fixes across the tree. —- The 5.2.9 stable kernel update contains a number of important fixes across the tree. —- The 5.2.8 stable kernel update contains a number of important […]

The 5.2.11 stable kernel update contains a number of important fixes across the tree. —- The 5.2.10 stable kernel update contains a number of important fixes across the tree. —- The 5.2.9 stable kernel update contains a number of important fixes across the tree. —- The 5.2.8 stable kernel update contains a number of important […]

The 5.2.11 stable kernel update contains a number of important fixes across the tree. —- The 5.2.10 stable kernel update contains a number of important fixes across the tree. —- The 5.2.9 stable kernel update contains a number of important fixes across the tree. —- The 5.2.8 stable kernel update contains a number of important […]

security update

Facebook Drops Default Facial Recognition Tag Suggestions
Hackers steal 560,000 user accounts in XKCD forum breach

security update

IoT Security Challenges in a 5G Era: Expert Advice
Firefox 69 Release Kills Default Tracking Cookies, Flash Support
How to Get a Handle on Patch Management
How to have your favorite playlist with you using iMusic
Effective Way to Download Youtube Playlist
WordPress Plugins Anchor Widespread Malvertising, Rogue Backdoor Campaign
Data Leak Impacts Millions of Yves Rocher Cosmetics Company Customers
iPhone attack may have targeted Android and Windows too
What is MITRE ATT&CK and how is it useful?

An introduction to the MITRE ATT&CK framework and how it can help organize and classify various types of threats and adversarial behaviors. The post What is MITRE ATT&CK and how is it useful? appeared first on WeLiveSecurity

An update that solves one vulnerability and has three fixes is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kdelibs and kde-setting is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openstack-nova is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for redis is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Join me for a webinar about making cybersecurity relevant in modern day culture

An update for openstack-nova is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for redis is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Irssi could be made to crash or execute arbitrary code if it received a specially crafted CAP request.

China’s new face-swapping app Zao gets whiplash-fast privacy backlash
FBI asks Google for help finding criminals
XKCD forums breached
‘USBAnywhere’ Bugs Open Supermicro Servers to Remote Attackers
Enjoy the holiday weekend, America? Well-rested? Good. Supermicro server boards can be remotely hijacked
NATO sharpens its cyber-lances, prepares for war games with virtual jousting tournament
Website used by Hong Kong protesters suffers DDoS attack

security update

Meet Retadup botnet that was infected by another malware

Risk Level: Very Low. Type: Trojan.

Teletext Holidays a) exists and b) left 200k customer call recordings exposed in S3 bucket
WordPress sites are being backdoored with rogue admin users

An update that solves two vulnerabilities and has 7 fixes is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has two fixes is now available.

Why are Google and Facebook banned in China?

Multiple security issues were discovered in QEMU, a fast processor emulator, which could result in denial of service, the execution of arbitrary code or bypass of ACLs.

Oh there it is, Facebook shrugs as Free Basics private key found to be signing unrelated apps
Gamification Can Transform Company Cybersecurity Culture

It was discovered that there was an arbitrary code execution vulnerability in the pump BOOTP and DHCP client. When copying the body of the server response, the ethernet packet

Google throws bug bounty bucks at mega-popular third-party apps
Capital One cryptojacking suspect indicted

PolicyKit could allow unintended access.

An update that solves three vulnerabilities and has 13 fixes is now available.