Menu

Latest articles

Researchers hide data in music – and human ears can’t detect it
Meet IRpair & Phantom; powerful anti-facial recognition glasses

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

It was totally Samsung’s fault that crims stole your personal info from a Samsung site, says Samsung-blaming Sprint
Let’s open the Mystery Data Security Blunder box, and see what’s inside today… Ah! Hotel reservations and more
LenovoEMC Storage Gear Leaks Sensitive Financial Data
Hackers used Samsung website to access Sprint’s customer data
Maybe double-check that HMRC email? UK taxman remains a fave among the phisherfolk
The Future is Female: A Key to the Cybersecurity Workforce Challenge
WhatsApp, Telegram Coding Blunders Can Expose Personal Media Files
How your Instagram account could have been hijacked

A researcher found that it was possible to subvert the platform’s password recovery mechanism and take control of user accounts The post How your Instagram account could have been hijacked appeared first on WeLiveSecurity

GandCrab ransomware revisited – is it back under a (R)evil new guise?
JetBlue Bomb Scare Set Off with Apple AirDrop

An update that solves one vulnerability and has two fixes is now available.

Several security issues were fixed in NSS.

Patch now before you get your NAS kicked: Iomega storage boxes leave millions of files open to the internet

An update is now available for Red Hat JBoss BPM Suite. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Bluetooth LE’s anti-tracking technology beaten
$5b privacy fine against Facebook seen as ‘chump change’
Ransomware attackers demand $1.8m from US college

Several security issues were fixed in Redis.

Asian consortium plans blockchain-based mobile ID system
Amadeus! Amadeus! Pwn me Amadeus! Airline check-in bug may have exposed all y’all boarding passes to spies

An update for vim is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for keepalived is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libssh2 is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for perl is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for 389-ds-base is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in NSS.

Alan Turing chosen for the UK’s new £50 note – a cracking result!

Risk Level: Very Low. Type: Trojan.

This update includes a fix for a security vulnerability, CVE-2018-20843: > Fix extraction of namespace prefixes from XML names; XML names with multiple colons could end up in the wrong namespace, and take a high amount of RAM and CPU resources while processing, opening the door to use for denial-of-service attacks For more information on […]

Rebase to radare2 3.6.0 and fixes CVE-2019-12790 and CVE-2019-12802

Privacy Experts: Facebook’s $5B Fine Unlikely to Do Much
Turla APT Returns with New Malware, Anti-Censorship Angle

security update

Symantec share price nose dives after rumored Broadcom biz gobble taken off the menu
Hacker gets $30,000 for reporting hack Instagram account flaw
Instagram bug could have allowed anyone to take over your account
Alan Turing – the face of the new £50 note
How to secure your website – InfoSec tips for newbie website owners
Researcher Bypasses Instagram 2FA to Hack Any Account

An update that fixes 5 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 20 vulnerabilities is now available.

An update that solves three vulnerabilities and has 5 fixes is now available.

This update upgrades Thunderbird to version 60.8.0. * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by […]

Bust the password for an air-gapped machine – with its keyboard LEDs
Why Cities Are a Low-Hanging Fruit For Ransomware
How any Instagram account could be hacked in less than 10 minutes

Several security issues were fixed in Squid.

A system hardening measure could be bypassed.

Apple quietly removes Zoom’s hidden web server from Macs

An update that fixes one vulnerability is now available.

FCC underwhelmed by carriers’ sluggish robocall efforts

Zipios could be made to crash or consume system resources if it received specially crafted input.

This update upgrades Thunderbird to version 60.8.0. * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by […]

Several security issues were fixed in Exiv2.

vim/neovim: ‘:source!’ command allows arbitrary command execution via modelines (CVE-2019-12735) SL6 x86_64 vim-X11-7.4.629-5.el6_10.2.x86_64.rpm vim-common-7.4.629-5.el6_10.2.x86_64.rpm vim-debuginfo-7.4.629-5.el6_10.2.x86_64.rpm vim-enhanced-7.4.629-5.el6_10.2.x86_64.rpm vim-filesystem-7.4.629-5.el6_10.2.x86_64.rpm vim-minimal-7.4.629-5.el6_10.2.x86_64.rpm i386 [More…]

Ransomware attackers, US mayors say you should go jump in a lake
Malicious code ousted from PureScript’s npm installer – but who put it there in the first place?
New old Windows bug emerges, your ‘strong’ password is anything but, plus plenty more

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Threatlist: 68% of Overwhelmed IT Managers Can’t Keep Up with Cyberattacks
Exploring the Top 15 Most Common Vulnerabilities with HackerOne and GitHub

Vulnerabilities have been identified in libspring-java, a modular Java/J2EE application framework.

An update that solves one vulnerability and has 11 fixes is now available.

An update that fixes three vulnerabilities is now available.

Firefox could be made to crash or run programs as your login if it opened a malicious website.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

In memoriam – Corby Corbató, MIT computer science pioneer, dies at 93

Harsh Jaiswal discovered a remote shell execution vulnerability in ruby-mini-magick, a Ruby library providing a wrapper around ImageMagick or GraphicsMagick, exploitable when using MiniMagick::Image.open with specially crafted URLs coming from unsanitized user input.

security update

An update that contains security fixes can now be installed.

#### Update to v1.48 * New API: – `snapd_client_get_connections_async` – `snapd_client_get_connections_finish` – `snapd_client_get_connections_sync` – `snapd_client_get_interfaces2_async` – `snapd_client_get_interfaces2_finish` – `snapd_client_get_interfaces2_sync` – `snapd_client_get_snap_conf_async`

– New upstream version (60.8.0)

#### Update to v1.48 * New API: – `snapd_client_get_connections_async` – `snapd_client_get_connections_finish` – `snapd_client_get_connections_sync` – `snapd_client_get_interfaces2_async` – `snapd_client_get_interfaces2_finish` – `snapd_client_get_interfaces2_sync` – `snapd_client_get_snap_conf_async`

– Update to 2.8 fixes rhbz#1581180 rhbz#1603993 rhbz#1674893 and rhbz#1524335 – Removed upstreamed patch – Bug 1524335 – CVE-2017-17459 fossil: Command injection via malicious ssh URLs [fedora-all] – Bug 1581180 – Update fossil version to 2.6 (currently is 2.2) – Bug 1603993 – fossil: FTBFS in Fedora rawhide – Bug 1674893 – fossil: FTBFS in […]

update to 2.1.10, security fix for CVE-2019-12781

Agent Smith Android malware has infected 25 million devices so far

security update

security update

Brilliant Boston boffins blow big borehole in Bluetooth’s ballyhooed barricades: MAC addy randomization broken
Heather Mills Gets An Apology and ‘Substantial’ Settlement in Spyware Case
Blah blah Blaha: Slovak infosec firm ESET sues politico who called them ‘outrageous fascists’
London cop illegally used police database to monitor investigation into himself

This update upgrades Firefox to version 60.8.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins […]

Multiple vulnerabilities were discovered in the HyperLogLog implementation of Redis, a persistent key-value database, which could result in denial of service or potentially the execution of arbitrary code.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, spoofing, information disclosure, denial of service or cross-site request forgery.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Unusual Linux Ransomware Targets NAS Servers

Reading Time: ~ 2 min. Magecart Attacks See Spike in Automation The latest attack in the long string of Magecart breaches has apparently affected over 900 e-commerce sites in under 24 hours. This increase over the previous attack, which affected 700 sites, suggests that its authors are working on improving the automation of these information-stealing […]

An update that fixes one vulnerability is now available.