Menu

Latest articles

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Palo Alto gateway security alert, FSB hack, scourge of data-stealing web plugins, and more

Vulnerabilities have been discovered in nss, the Mozilla Network Security Service library.

Jann Horn discovered that the ptrace subsystem in the Linux kernel mishandles the management of the credentials of a process that wants to create a ptrace relationship, allowing a local user to obtain root privileges under certain scenarios.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has four fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes four vulnerabilities is now available.

In the cooler for the next three years: Hacker of iCloud accounts used by athletes and rappers

Update to Samba 4.9.11 —- Update to Samba 4.9.9 Security fixes for CVE-2019-12435

Update to Samba 4.9.11 —- Update to Samba 4.9.9 Security fixes for CVE-2019-12435

Iran-Linked APT34 Invites Victims to LinkedIn for Fresh Malware Infections
When Harry met celly: NSA hoarder thrown in the clink for 9 years – after taking classified work home for decades
Adult Sites Lack Privacy, Open the Door for Harassment and Tracking
All very MoD-ern: RAF test pilot headed into space with Virgin, £30m small sat demo project
Bug in NVIDIA’s Tegra Chipset Opens Door to Malicious Code Execution
Israel’s NSO Group: Our malware? Slurp your cloud backups plus phone data? They’ve misunderstood

Reading Time: ~ 2 min. Over 100 Million Accounts Exposed in Evite Breach More than 100 million users of Evite were exposed after the company’s servers were compromised earlier this year. While the company doesn’t store financial information, plenty of other personally identifiable information was found in the leaked database dump. The initial figures for […]

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Your biz won’t be hacked by a super-leet exploit. It’ll be Bob in sales opening a dodgy email
Slack response. Passwords reset four years after data breach
Excluding Huawei from UK’s 5G will harm security, MPs warn
Firefox to pile on more native privacy features
Shapeshifting Morpheus chip aims to baffle hackers
FaceApp privacy panic sets internet alight

It was discovered that there was an integer overflow vulnerability in exiv2, a tool to manipulate images containing (eg.) EXIF metadata. This could have resulted in a denial of service via a specially-

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

2015 database hack is the terrible gift that keeps giving for Slack: Tens of thousands of passwords now reset

Update to v5.1.18 —- Update to v5.1.17

Update to v5.1.18 —- Update to v5.1.17

– fixes security issues CVE-2019-10190 and CVE-2019-10191 – https://lists.nic.cz/pipermail/knot-resolver-announce/2019/000009.html

Slack data breach: Company resets thousands of passwords
Security Watch: Elon Musk’s NeuraLink Links Brains to iPhones via Bluetooth

– fixes security issues CVE-2019-10190 and CVE-2019-10191 – https://lists.nic.cz/pipermail/knot-resolver-announce/2019/000009.html

It’s never good when ‘Magecart’ and ‘bulletproof’ appear in the same sentence, but here we are
Mirai Botnet Sees Big 2019 Growth, Shifts Focus to Enterprises
Slack Initiates Mass Password Reset

Several security issues were fixed in LibreOffice.

Google Triples Some Bug Bounty Payouts
Ke3chang APT Linked to Previously Undocumented Backdoor
Bulgaria hack: 20-year-old infosec whizz cuffed after ‘adult population’s’ finance deets nicked
EvilGnomes Linux malware record activities & spy on users

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Those facial recognition trials in the UK? They should be banned, warns Parliamentary committee
Thousands of NHS computers are still running Windows XP from beyond the grave
Hacked Bluetooth hair straighteners are too hot to handle
Google Chrome is ditching its XSS detection tool
Microsoft demos end-to-end voting verification system ElectionGuard, code will be on GitHub
Still not using HTTPS? Firefox is about to shame you

An update that solves two vulnerabilities and has three fixes is now available.

‘Member Ke3chang? They’re still at it, you know. Euro diplomats targeted by ‘China-based’ hacker crew
Okrum: Ke3chang group targets diplomatic missions

Tracking the malicious activities of the elusive Ke3chang APT group, ESET researchers have discovered new versions of malware families linked to the group, and a previously unreported backdoor The post Okrum: Ke3chang group targets diplomatic missions appeared first on WeLiveSecurity

Security researcher arrested after data on every adult in Bulgaria hacked from government site
Dutch cops collar fella accused of crafting and flogging Office macro nasties to cyber-crooks
Fresh stalkerware crop pops up on Google’s Android Play Store, swiftly yanked offline
Don’t give it away, give it away, give it away now, bot busting biz tells reCAPTCHA data serfs
Smashing Security #137: Porn trolling lawyers, Insta hacking, and Ctrl-Alt-LED
Wormable BlueKeep Bug Still Threatens Legions of Windows Systems

security update

Several security issues were fixed in Thunderbird.

BlueKeep patching isn’t progressing fast enough

Keeping up with BlueKeep; or how many internet-facing systems, and in which countries and industries, remain ripe for exploitation? The post BlueKeep patching isn’t progressing fast enough appeared first on WeLiveSecurity

For pity’s sake, groans Mimecast, teach your workforce not to open obviously dodgy emails
Firmware Bugs Plague Server Supply Chain, 7 Vendors Impacted
Bluetooth Flaws Could Allow Global Tracking of Apple, Windows 10 Devices

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Massive Malvertising Campaign Reaches 100M Ads, Manipulates Supply Chain

An update that fixes three vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Email scammers extract over $300m a month from American suits’ pockets

An update that fixes 10 vulnerabilities is now available.

An update that solves 7 vulnerabilities and has three fixes is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1775

The package chromium before version 75.0.3770.142-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

The package squid before version 4.8-1 is vulnerable to arbitrary code execution.

The package firefox before version 68.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, cross-site request forgery, sandbox escape, arbitrary filesystem access, content spoofing, cross-site scripting, denial of service, information disclosure, insufficient validation and silent downgrade.

StrongPity APT Returns with Retooled Spyware
RDP exposed: the wolves already at your door

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1774

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1777

A use-after-free in onig_new_deluxe() in regext.c allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker

Microsoft, Google and Apple clouds banned in Germany’s schools
Facebook rolls out anti-scam reporting tool in UK
Apple pushes out another silent update to address flaws in RingCentral and other video conferencing apps
Researchers hide data in music – and human ears can’t detect it
Meet IRpair & Phantom; powerful anti-facial recognition glasses

Risk Level: Very Low. Type: Trojan.