Menu

Latest articles

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Hacked Hair Straighteners Can Threaten Homes
UK Home Secretary doubles down on cops’ deeply flawed facial recognition trials

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1763

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1765

An update that fixes one vulnerability is now available.

IT pros: we’re understaffed, under-resourced and under pressure
Hey, Google, why are your contractors listening to me?
Windows 7 users upset by unwanted Patch Tuesday telemetry
Apple Watch’s Walkie-Talkie app goes radio silent due to vulnerability

An update that solves 11 vulnerabilities and has two fixes is now available.

Train maker’s coder goes loco, choo-choo-chooses to flee to China with top-secret code – allegedly

An update that contains security fixes can now be installed.

Oh, lovely, a bipartisan election hack alert law bill for Mitch McConnell to feed into the shredder

security update

Intel patches SSD firmware and microprocessor diagnostic tool
Google Home Silently Captures Recordings of Domestic Violence and More
Twitter is down – Twitter’s website & app suffering outage (Updated)

This update provides ffmpeg version 4.1.4, which fixes several security vulnerabilities and other bugs which were corrected upstream References: – https://bugs.mageia.org/show_bug.cgi?id=25109

10 ways to keep yourself secure online against cyber attacks

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Two vulnerabilities were discovered in the DOSBox emulator, which could result in the execution of arbitrary code on the host running DOSBox when running a malicious executable in the emulator.

Two security vulnerabilities were discovered in openjpeg2, a JPEG 2000 image library. CVE-2016-9112

The urllib library in Python ships support for a second, not well known URL scheme for accessing local files (“local_file://”). This scheme can be used to circumvent protections that try to block local file access

IBM Closes its $34 Billion Acquisition of Red Hat: A Monumental Moment for Open Source
Apple pushes out silent update to remove sketchy Zoom code from Macs
Apple Issues Silent Update Removing Zoom’s Hidden Server
Unprotected MongoDB leaks 188m users’ data from sensitive search engine

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Apple Disables Walkie-Talkie App Due to Eavesdropping Flaw

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Facial recognition surveillance must be banned, says Fight for the Future

An update for the virt:8.0.0 module is now available for Red Hat Enterprise Linux 8 Advanced Virtualization. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1726

Apple says its Walkie-Talkie app could be exploited to spy on iPhones
Implementing Bug Bounty Programs: The Right and Wrong Approaches
Cyberattack lands ship in hot water
Wondering how to whack Zoom’s dodgy hidden web server on your Mac? No worries, Apple’s done it for you
GDPR superpowers lead to whopper ICO fines for BA, Marriott
Why CVSS does not equal risk: How to think about risk in your environment

An update that solves one vulnerability and has one errata is now available.

Scots NHS symptom checker pings Facebook, Google and other ad peddlers
Buhtrap group uses zero‑day in latest espionage campaigns

ESET research reveals notorious crime group also conducting espionage campaigns for the past five years The post Buhtrap group uses zero‑day in latest espionage campaigns appeared first on WeLiveSecurity

Dodgy-govt fave FinSpy snoopware is back and badder than ever for Android and iOS kit
Sea Turtle hackers head to the Mediterranean, snag Greece’s TLD registrar as a souvenir
“Mozilla aren’t villains after all” – ISPs back down after public outcry
AMD’s SEV tech that protects cloud VMs from rogue servers may as well stand for… Still Extremely Vulnerable
Bug in Anesthesia Respirators Allows Cyber-Tampering
Remember Stuxnet? You’ll endure its hated-by-critics sequel if you don’t patch your holey Siemens industrial kit

New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure Automation is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server and Team Foundation Server are prone to an remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Visual Studio is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Visual Studio is prone to a local privilege-escalation vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Zoom Pushes Emergency Patch for Webcam Hijack Flaw
Latest FinSpy Modules Lift Data from Secure Messaging Apps
UK watchdog fined firms £3m for data breaches last year – before its GDPR balls dropped

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Agent Smith Malware Infects 25M Android Phones to Push Rogue Ads

dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass (CVE-2019-12749) SL6 x86_64 dbus-1.2.24-11.el6_10.x86_64.rpm dbus-debuginfo-1.2.24-11.el6_10.i686.rpm dbus-debuginfo-1.2.24-11.el6_10.x86_64.rpm dbus-libs-1.2.24-11.el6_10.i686.rpm dbus-libs-1.2.24-11.el6_10.x86_64.rpm dbus-x11-1.2.24-11.el6_10.x86_64.rpm dbus-devel-1.2.24-11.el6_10.i686.rpm dbus-devel-1 [More…]

Marriott faces £99.2 million fine after hack exposed 393 million hotel guest records

An update that solves one vulnerability and has 8 fixes is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that solves 21 vulnerabilities and has two fixes is now available.

An update that solves one vulnerability and has two fixes is now available.

Two zero days and 15 critical flaws fixed in July’s Patch Tuesday
Rogue Android apps ignore your permissions
Did a hacked smart TV upload footage of couple having sofa sex to a porn website?
Instagram asks bullies, ‘Are you sure you want to say that?’

It was discovered that there were two heap buffer overflows in the Hyperloglog functionality provided by the Redis in-memory key-value database.

Windows zero‑day CVE‑2019‑1132 exploited in targeted attacks

ESET research discovers a zero-day exploit that takes advantage of a local privilege escalation vulnerability in Windows The post Windows zero‑day CVE‑2019‑1132 exploited in targeted attacks appeared first on WeLiveSecurity

An update for openstack-ironic-inspector is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for openstack-tripleo-common is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which