Menu

Latest articles

Type: Vulnerability. Google Android is prone to a local privilege-escalation vulnerability.

Type: Vulnerability. Apache MINA is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Cisco Firepower Threat Defense Software is prone to a local command-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco Firepower Management Center Software is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Apache Hadoop is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Android-gif-drawable is prone to a remote code execution vulnerability; fixes are available.

Type: Vulnerability. Cisco Email Security Appliance is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Cisco IC3000 Industrial Compute Gateway is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco Unified Communications Manager is prone to an SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Cisco Identity Services Engine is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Cisco Unified Communications Manager is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Cisco Security Manager is prone to a command-execution vulnerability; fixes are available.

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
That was some of the best flying I’ve seen to date, right up to the part where you got hacked
Signal app flaw allowed incoming calls to be connected without user interaction
Alabama Hospitals Pay Up in Ransomware Attack

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

All You Need To Know For External Hard Drive Recovery

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

In lib/mini_magick/image.rb in ruby-mini-magick, a fetched remote image filename could cause remote command execution because Image.open input is directly passed to Kernel#open, which accepts a ‘|’ character

Iran-linked Hackers Target Trump 2020 Campaign, Microsoft says
Android devices hit by zero-day exploit Google thought it had patched
Facebook urged by governments to halt end-to-end encryption plans
Social media platforms can be forced to delete illegal content worldwide
Wi-Fi signals let researchers ID people through walls from their gait

Several security issues were fixed in OpenEXR.

CVE-2019-16993 In phpBB, includes/acp/acp_bbcodes.php had improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An

An update that solves two vulnerabilities and has one errata is now available.

Can ordinary companies keep up with data compliance regulations?

– Update to 2.16.3 – Side channel attack on deterministic ECDSA (CVE-2019-16910) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.16.3-and-2.7.12-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2019-10

– Update to 2.16.3 – Side channel attack on deterministic ECDSA (CVE-2019-16910) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.16.3-and-2.7.12-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2019-10

This is an update fixing CVE-2019-16928.

Update to 1.7.5 —- Fixes CVE-2019-12816

security update

security update

1.6.7 Fix potential crash when reloading config. Client library: * Don’t use / in autogenerated client ids, to avoid confusing with topics. * Fix mosquitto_max_inflight_messages_set() and mosquitto_int_option(…, MOSQ_OPT_*_MAX, …) behaviour. * Fix regression on use of

Max Kellermann reported a NULL pointer dereference flaw in libapreq2, a generic Apache request library, allowing a remote attacker to cause a denial of service against an application using the library (application crash) if an invalid nested “multipart” body is processed.

1.6.7 Fix potential crash when reloading config. Client library: * Don’t use / in autogenerated client ids, to avoid confusing with topics. * Fix mosquitto_max_inflight_messages_set() and mosquitto_int_option(…, MOSQ_OPT_*_MAX, …) behaviour. * Fix regression on use of

1.6.7 Fix potential crash when reloading config. Client library: * Don’t use / in autogenerated client ids, to avoid confusing with topics. * Fix mosquitto_max_inflight_messages_set() and mosquitto_int_option(…, MOSQ_OPT_*_MAX, …) behaviour. * Fix regression on use of

An XSS vulnerability was discovered in noVNC in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

A Nord VPN bug, a(nother) bad Microsoft patch, Zynga data farmed out, and more

An update that fixes 29 vulnerabilities is now available.

Google sounds the alarm over Android flaw being exploited in the wild, possibly by NSO

Type: Vulnerability. Linux Kernel is prone to multiple local privilege-escalation vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Unified Communications Manager is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco Unified Communications Manager is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco Unified Contact Center Express is prone to an HTTP response-splitting vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco Adaptive Security Appliance is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Moxa EDR 810 Series is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Prime Infrastructure is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Cisco Prime Infrastructure is prone to a cross-site scripting vulnerability; fixes are available.

GPS cyberstalking of girlfriend brings surveillance and indictment for alleged American mobster
Here we go again: US govt tells Facebook to kill end-to-end encryption for the sake of the children
Iran tried to hack hundreds of politicians, journalists email accounts last month, warns Microsoft

The package ruby2.5 before version 2.5.7-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, cross-site scripting, denial of service and insufficient validation.

The package ruby-rdoc before version 6.1.2-1 is vulnerable to cross- site scripting.

New malware mimics Windows scanner to infect PCs with ransomware
Google Warns of Android Zero-Day Bug Under Active Attack
Dead simple: Plenty of Magecart miscreants still looking to skim off your credit card deets
Virus Bulletin 2019: VoIP Espionage Campaign Hits U.S. Utilities Supplier
Buying a new laptop? Here’s how to secure it

An update that fixes 27 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 27 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

Former Yahoo employee admits he hacked 6000 users’ accounts, stole nude photos and videos
TalkTalk says WalkWalk if you’ve got a mouldy Tiscali email address, or pay £50 a year to keep it
WhatsApp vulnerability could compromise Android smartphones

Reading Time: ~ 2 min. DoorDash Data Breach Nearly five months after a breach, DoorDash has just now discovered that unauthorized access to sensitive customer information has taken place. Among the stolen data were customer names, payment history, and contact info, as well as the last four digits of both customer payment cards and employee […]

Several security issues were fixed in the Linux kernel.

£3 billion Safari iPhone privacy lawsuit given go-ahead
Implementing corporate laptop encryption using LUKS
AG Barr, Officials to Facebook: Don’t Encrypt Messaging
Hacker’s parents sentenced for selling his cryptocurrency
Google brings Incognito mode to Maps
Virus Bulletin 2019: Magecart Infestations Saturate the Web
Egyptian government caught tracking opponents and activists through phone apps
Life’s certainties: Death, taxes, and Cisco patching more serious vulnerabilities
FBI softens stance on ransomware: it’s (sort of) okay to pay off crims to get your data back
Kaspersky warns of encryption-busting Reductor malware
New Reductor Malware Hijacks HTTPS Traffic

A vulnerability was discovered by Lukas Kupczyk of the Advanced Research Team at CrowdStrike Intelligence in OpenConnect, an open client for Cisco AnyConnect, Pulse, GlobalProtect VPN. A malicious HTTP server

An update that fixes one vulnerability is now available.

Type: Vulnerability. Cisco Firepower Management Center is prone to multiple remote code-execution vulnerabilities; fixes are available.

Type: Vulnerability. Cisco FXOS and Firepower Threat Defense Software are prone to multiple local command-injection vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Firepower Threat Defense Software is prone to multiple security-bypass vulnerabilities; fixes are available.

Type: Vulnerability. Multiple Cisco Unified Communications Products are prone to a cross-site request-forgery vulnerability.

Type: Vulnerability. Cisco Firepower Management Center is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Cisco Firepower Management Center is prone to multiple SQL-injection vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Firepower Management Center is prone to a command-injection vulnerability; fixes are available

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to an information-disclosure vulnerability; fixes are available.