Menu

Latest articles

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Post-Data Breach, British Airways Slapped With Record $230M Fine
Researchers hack VR worlds

GLib did not properly restrict directory and file permissions.

Docker could be made to overwrite files as the administrator.

Fang-Pen Lin discovered a stack-based buffer-overflow flaw in ZeroMQ, a lightweight messaging kernel library. A remote, unauthenticated client connecting to an application using the libzmq library, running with a socket listening with CURVE encryption/authentication enabled, can take

Privacy and security risks as Sign In with Apple tweaks Open ID protocol
ISPs call Mozilla ‘Internet Villain’ for promoting DNS privacy

An update for python27-python is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

British Airways faces record £183 million GDPR fine after data breach
New Year’s eve gaming DDoSer lulz himself into a 27-month sentence
Medway Council reforms eforms to stop blurting out residents’ details
Malicious campaign targets South Korean users with backdoor-laced torrents

ESET researchers have discovered a malicious campaign distributing a backdoor via torrents, with Korean TV content used as a lure The post Malicious campaign targets South Korean users with backdoor-laced torrents appeared first on WeLiveSecurity

Several security issues were fixed in libvirt.

UK privacy watchdog threatens British Airways with 747-sized fine for massive personal data blurt

An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

Fibaro flummoxed, Georgia courts held for ransom, and more

Bugfixes, and a security fix: Fixed vulnerabilities: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

Bugfixes, and a security fix: Fixed vulnerabilities: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

Bugfixes, and a security fix: Fixed vulnerabilities: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

Bugfixes, and a security fix: Fixed vulnerabilities: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

Fix vfs_fruit, vfs_glusterfs and smbspool —- Update to Samba 4.10.5 Security fixes for CVE-2019-12435 and CVE-2019-12436

Data Breach Lessons from the Trenches

An update that fixes one vulnerability is now available.

WordPress Plugin WP Statistics Patches XSS Flaw
Cisco delivers Patch Tuesday warmup with bundle of 18 bug fixes

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Several security issues were fixed in Irssi.

PGP Ecosystem Targeted in ‘Poisoning’ Attacks
Wide of the net: Football Association of Ireland says player, manager data safe after breach
5 tips to stay secure on social media

An update that solves two vulnerabilities and has one errata is now available.

The Logic of a Classic Advanced Persistent Threat Attack
OpenPGP experts targeted by long-feared ‘poisoning’ attack
Bitcoin eats as much energy as Switzerland
Mannequin Challenge videos teach computers to see
Deepfake revenge porn now a crime in Virginia
Worried about hackers? Catch a lifeline with this month’s Sophos SOS cybersecurity podcasts
Get rekt: Two years in clink for game-busting DDoS brat DerpTrolling
Why are they “smart” locks if more money buys you less security?
Derp! DDoS attacker who brought down EA, Sony, and Steam jailed for 27 months

An update that contains security fixes can now be installed.

An update that solves three vulnerabilities and has two fixes is now available.

St John Ambulance service hit by ransomware attack
Reports of cyber attacks fall, says UK.gov survey: GDPR? Fewer nasties? More targeted attacks? We just don’t know

USN-4038-1 introduced a regression in bzip2.

USN-4038-1 introduced a regression in bzip2.

An update that solves three vulnerabilities and has 26 fixes is now available.

An update that solves three vulnerabilities and has 26 fixes is now available.

An update that fixes three vulnerabilities is now available.

Open Sesame! Zipato’s smart hub hacked to open front doors
Facebook’s down-ranking those ‘miracle cure’ health posts we all hate
Facebook should put a stop to Libra for now, says Congress
TikTok investigated (again) over how it handles children’s data and safety

It was discovered that there was a XML external entity vulnerability in the lemonldap-ng single-sign on system. This may have led to the disclosure of confidential data, denial of service, server side request forgery, port scanning, etc.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

US Cyber Command warns that the Outlook is not so good – Iranians hitting email flaw
Smashing Security #135: Zombie grannies and unintended leaks

This update includes a rebase from 9.0.13 up to 9.0.21 which resolves two CVEs along with various other bugs/features: * rhbz#1673856 tomcat-9.0.21 is available * rhbz#1713279 CVE-2019-0221 tomcat: XSS in SSI printenv * rhbz#1693326 CVE-2019-0199 tomcat: Apache Tomcat HTTP/2 DoS

How do we stop facial recognition from becoming the next Facebook: ubiquitous and useful yet dangerous, impervious and misunderstood?
YouTube mystery ban on hacking videos has content creators puzzled
Facebook and Instagram suffer massive outage
D-Link must suffer indignity of security audits to settle with the Federal Trade Commission
Apple Transparency Report Now Includes App Store Takedown Requests
NHS warned to act now to keep hackers at bay

A trifecta of issues impact the organization’s cyber-resilience and conspire to put it in the firing line of cyberattacks The post NHS warned to act now to keep hackers at bay appeared first on WeLiveSecurity

Serious Security: Beware eBay scrapers promising to help you
Amazon Admits Alexa Voice Recordings Saved Indefinitely

An update that fixes 15 vulnerabilities is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1650

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1652

You lost US Customs Border data? You’re losing your government contracts…
US Cyber Command warns nation-state hackers are exploiting old Microsoft Outlook bug. Make sure you’re patched!
IoT vendor Orvibo gives away treasure trove of user and device data
Georgia’s court system hit by ransomware

Two vulnerabilities have been discovered in pdns, an authoritative DNS server which may result in denial of service via malformed zone records and excessive NOTIFY packets in a master/slave setup.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Russian ‘Silence’ hacking crew turns up the volume – with $3m-plus cyber-raid on bank’s cash machines
Miami police body cam videos up for sale on the darkweb
Patch Android! July 2019 update fixes 9 critical flaws

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Here’s a great idea: Why don’t we hardcode the same private key into all our smart home hubs?
$30/month email upstart Superhuman brought low with a blast of privacy Kryptonite
Cloudflare’s recent 502 Bad Gateway outage blamed on bad software

Update to v5.1.15 —- Update to v5.1.14

Update to v5.1.15 —- Update to v5.1.14

Security Camera Firm Arlo Zaps High-Severity Bugs

security update

security update

IBM Patches Critical, High-Severity Flaws in Spectrum Protect