Menu

Latest articles

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Google Chrome OS is prone to a remote integer-overflow vulnerability; fixes are available.

Type: Vulnerability. WhatsApp is prone to an integer overflow vulnerability.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a remote command-injection vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a command-injection vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a hard-coded credentials vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a security vulnerability; fixes are available.

Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to an SQL-injection vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.

New Android banking botnet ‘Geost’ hits thousands of devices

Updated thunderbird packages fix security vulnerability: Spoofing a message author via a crafted S/MIME message (CVE-2019-11755) It also fixes various other bugs, as listed in the releasenotes.

Foxit PDF Reader Vulnerable to 8 High-Severity Flaws
Hospitals in US, Australia hobbled by ransomware

The incidents send medical staff back to the days of pen and paper The post Hospitals in US, Australia hobbled by ransomware appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

A short history of hacked billboards and road signs
FBI: Don’t pay ransomware demands, stop encouraging cybercriminals to target others
WhatsApp Flaw Opens Android Devices to Remote Code Execution
No federal privacy law will make it in the US this year, sources say
PDF encryption standard weaknesses uncovered
Google’s Password Manager now checks for breached credentials

patch: do_ed_script in pch.c does not block strings beginning with a ! character (CVE-2018-20969) * patch: OS shell command injection when processing crafted patch files (CVE-2019-13638) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. SL7 […]

Red Hat expands coverage of CVE fixes
Generate SELinux policies for containers with Udica

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in ClamAV.

Ransomware attacks paralyze, and sometimes crush, hospitals

An update for patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Casbaneiro: Dangerous cooking with a secret ingredient

Número dois in our series demystifying Latin American banking trojans The post Casbaneiro: Dangerous cooking with a secret ingredient appeared first on WeLiveSecurity

It was discovered that there was a remotely-exploitable null pointer dereference in libapreq2, a library for manipulating HTTP requests. For Debian 8 “Jessie”, this issue has been fixed in libapreq2 version

Huygens if true: Dutch police break up bulletproof hosting outfit and kill Mirai botnet

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. EMC RSA BSAFE Crypto-C Micro and Micro Edition Suite are prone to multiple security vulnerabilities; fixes are available.

FBI called in to investigate 2018 Mountain State mobile voting system hacking
Smashing Security #148: Billboard boobs, face forensics, and Alexa gets way too personal
Reason Security opens beta for business edition & cuts yearly subscription price
Android users installed 172 malicious apps 335m times last month
Google Maps gets Incognito fig leaf: We’ll give you vague peace of mind if you hold off those privacy laws

Security fix for CVE-2019-15026

Security fix for CVE-2019-13132

**GLPI version 9.4.4** This is a **security release**, upgrading is highly recommended Non exhaustive list of changes: * [security] Prevent account takeover vulnerability , * [security] Prevent execution of XSS on rich text, * fix cache key lenght issues, * fix user picture removal at login, * several fixes on recurring tickets, * fix some […]

Zendesk Exposes 10,000 Accounts to Unknown Third Party

security update

security update

Why This New Cybergang is Heralding a New Age For BEC
Most SMB cybersecurity defence fail short to thwart malware & file-based attacks
Medic! Uncle Sam warns hospitals not to use outdated IPnet freely on their networks

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Jenkins is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Pivotal Application Service is prone to an access-bypass vulnerability; fixes are available.

Type: Vulnerability. Foxit Reader is prone to a remote code-execution vulnerability.

Former! Yahoo! engineer! admits! to! hacking! user! emails! for! smutty! snaps!
Gaming giant Zynga data breach: 218 million records stolen
Virus Bulletin 2019: Geost Android Botnet Goes After Millions of Euros
Virus Bulletin 2019: Japanese Attacks Highlight Savvy APT Strategy
Zendesk clocks 10,000 accounts accessed by miscreants before November 2016
If you really can’t let go of Windows 7, Microsoft will keep things secure for another three years
Google Adds Password Checkup Feature to Chrome Browser
Exim suffers another ‘critical’ remote code execution flaw
O.MG! Evil Lightning cable about to hit mass distribution
218 million Words With Friends players lose data to hackers
A pervert Yahoo employee hacked 6,000 accounts using internal system
Have you been Thomas Crooked? Watch out for cybercrims slinging holiday-themed fakes
Ex-Yahoo engineer pleads guilty to hacking 6,000 accounts
Hack Breaks PDF Encryption, Opens Content to Attackers
The benefits of security behavior analytics for devops
Do apps need all the permissions?

Why you should ensure that all those apps on your smartphone only run with the permissions they reasonably need to do their job The post Do apps need all the permissions? appeared first on WeLiveSecurity

Jamf emits mystery security fix for Pro macOS, iOS wrangler, keeps admins in dark by censoring chatter

Type: Vulnerability. Xpdf is prone to a buffer-underflow vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability; fixes are available.

Type: Vulnerability. OnApp is prone to a remote command-execution vulnerability; fixes are available.

Type: Vulnerability. Dell EMC ECS is prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. Google Android is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Ghidra is prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Python is prone to multiple cross-site scripting vulnerabilities; fixes are available.

Ransomware Attacks Leave U.S. Hospitals Turning Away Patients
Hackers Turn to OpenDocument Format to Avoid AV Detection

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

vBulletin zero-day KOs Comodo user forums – that’s 245,000 accounts at risk of compromise
Leaky database exposes tax records of 20 million Russians
Google Play Malicious Apps Racked Up 335M+ Installs in September

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that solves 5 vulnerabilities and has three fixes is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

If your org hasn’t had a security incident in the last year: Good for you, you’re in the minority

An update that fixes 6 vulnerabilities is now available.

Cyber Security Awareness Month starts today!

October is upon us, reminding us to make choices every day that will scare cybersecurity threats away The post Cyber Security Awareness Month starts today! appeared first on WeLiveSecurity

Cloudflare adds VPN features to 1.1.1.1 privacy app
HMRC ‘disciplined’ almost 100 employees for computer misuse over 24 months

Reading Time: ~ 3 min. “Antivirus programs use techniques to stop viruses that are very “virus-like” in and of themselves, and in most cases if you try to run two antivirus programs, or full security suites, each believes the other is malicious and they then engage in a battle to the death (of system usability, […]

Hacking 2020 voting systems is a ‘piece of cake’