Menu

Latest articles

Mozilla boots alleged snoop troupe from its root cert coop: UAE-based DarkMatter thrown onto CA blocklist
It’s 2019 and SQL Server can be pwned by an SQL query, DHCP failover server failed by a packet, Edge, IE by webpages…

Risk Level: Very Low. Type: Trojan.

Intel Patches High-Severity Flaw in Processor Diagnostic Tool
Cyber ​​attacks cost $45 billion in 2018 with Ransomware at top

security update

Microsoft Patches A Pair of Zero-Days Under Active Attack
Huawei website ████ ██████ security flaws ██████ customer info and biz operations at risk: ███████ patched
Marriott’s got 99 million problems and the ICO’s one: Starwood hack mega-fine looms over
Vulnerability in Zoom video conference app lets Mac’s camera hijacking
UK’s data watchdog hands out two mega‑fines for breaches

The times they have a-changed since the ICO could only slap fines worth a fraction of the current amounts The post UK’s data watchdog hands out two mega‑fines for breaches appeared first on WeLiveSecurity

1,300 Popular Android Apps Access Data Without Proper Permissions
‘This repository is private’ – so what’s it doing on the public internet, GE Aviation?
Zoom flaw could force you into a meeting, expose your video feed
Marriott Hit With $123M Fine For Massive 2018 Data Breach
Zoom Zero-Day Bug Opens Mac Users to Webcam Hijacking
Backdoor discovered in Ruby strong_password library
Rapid Incident Response Now Available through Cynet’s Free IR Service Providers Offering
Boffins ready to go live with system that will track creatures great and small from space
Anyone for unintended Chat Roulette? Zoom installs hidden Mac web server to allow auto-join video conferencing

Apport could be made to expose sensitive information in crash reports.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Two pentesters, one glitch: Firefox browser menaced by ancient file-snaffling bug, er, feature
Zoom Mac flaw allows webcams to be hijacked – because they wanted to save you a click
Google suspends Trends emails after revealing murder suspect’s name

An update is now available for Red Hat JBoss Web Server 3.1. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Firefox to include tracker blocking report feature
Apple aims privacy billboard at Google’s controversial smart-city

An update is now available for Red Hat JBoss Web Server 3.1 for RHEL 6 and Red Hat JBoss Web Server 3.1 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in GVfs.

The package python2-django before version 1.11.22-1 is vulnerable to silent downgrade.

The package python-django before version 2.2.3-1 is vulnerable to silent downgrade.

The package irssi before version 1.2.1-1 is vulnerable to arbitrary code execution.

Spring Security support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user

Whoopsie could be made to crash or expose sensitive information if it processed a specially crafted crash report.

Apport could be made to expose sensitive information in crash reports.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft SQL Server is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to a spoofing vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows DNS Server is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a spoofing vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Meet the Great Duke of… DLL: Microsoft shines light on Astaroth, a devilishly sneaky strain of fileless malware
GE Aviation Passwords, Source Code Exposed in Open Jenkins Server
Rules-Based Policy Approaches Need to Go
Dear El Reg, Will Windows 10 break my VPN? I read it on the web so it must be true
GoBotKR Targets Pirate Torrents to Build a DDoS Botnet

Risk Level: Very Low. Type: Trojan.

Apple Patches iMessage Bug That Bricks iPhones with Out-of-Date Software

Fang-Pen Lin discovered a stack-based buffer-overflow flaw in ZeroMQ, a lightweight messaging kernel library. A remote, unauthenticated client connecting to an application using the libzmq library, running with a

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.