Menu

Latest articles

Email blackmailer threatens to have your website blocked forever

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for atomic-openshift-web-console is now available for Red Hat Openshift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The GoldBrute botnet is trying to crack open 1.5 million RDP servers
BlueKeep – everyone agrees, you should patch PCs running legacy versions of Windows

An update that fixes one vulnerability is now available.

An update that fixes 17 vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Cryptocurrency attack thwarted by npm team
Laptops used in 2016 NC poll to be examined by feds – after 2.5 years
Online shops fear 2FA at checkout will increase abandoned carts
Firefox fires blockers at trackers, Exim tackles command exec flaw, and RDP pops up yet again
Idle Computer Science skills are the Devil’s playthings
Protip: No, the CIA will not call off a pedophilia probe into your life in exchange for Bitcoin
National Censorship: Pros and Cons

A flaw was discovered in the CalDAV feature in httpd of the Cyrus IMAP server, leading to denial of service or potentially the execution of arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

security update

Critical Flaws in Amcrest HDSeries Camera Allow Complete Takeover

An update that solves one vulnerability and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

MetaTrader 4 vs MetaTrader 5 iPhone app
Forget BlueKeep: Beware the GoldBrute
Security Basics for the Novice Online Traders
SandboxEscaper Debuts ByeBear Windows Patch Bypass
Umm.. that’s not a movies password update. That’s a downgrade

Reading Time: ~ 2 min. Quest Diagnostics Customers Affected by Third-Party Breach The medical testing organization Quest Diagnostics has fallen victim to a third-party data breach that could affect nearly 12 million of their patients. AMCA, a collections agency that works with Quest Diagnostics, noticed unauthorized access to their systems over an eight-month period from […]

Cryptocurrency wallet GateHub hacked, nearly $10 million worth of Ripple (XRP) stolen
News Wrap: Infosecurity Europe Highlights and BlueKeep Anxiety

An update that solves two vulnerabilities and has 13 fixes is now available.

An update that fixes four vulnerabilities is now available.

Threatlist: Targeted Espionage-as-a-Service Takes Hold on the Dark Web
Troy Hunt: ‘Messy’ Password Problem Isn’t Getting Better
Praise the lard! Police hook up with Microsoft to school us on National Phish and Chip Day

Update to version 3.0.10, which fixes a security issue (a buffer overrun vulnerability in the httpd daemon, CVE-2019-11356).

Action required! Exim mail servers need urgent patching
What’s the best approach to patching vulnerabilities?
Researchers eavesdrop on smartphone finger taps
There’s a reason why my cat doesn’t need two-factor authentication
The FBI is sitting on more than 641m photos of people’s faces

An update that fixes one vulnerability is now available.

Someone slipped a vuln into crypto-wallets via an NPM package. Then someone else siphoned off $13m in coins to protect it from thieves

Hanno Bck discovered that Evolution was vulnerable to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted HTML email. This issue was mitigated by moving the security bar with encryption and signature information above the message

security update

You. Quest and LabCorp. Explain these medical database super-hacks, say US senators as 425,000 more people hit

Reading Time: ~ 3 min. The main focus of Webroot’s Senior Director of Development Operations is collaboration with engineers to advance the architecture of cloud services, and that’s no easy task.   In this spotlight, we dive into Robert Scott’s #LifeatWebroot. From working with Google and Amazon cloud devices to savings initiatives, Robert’s days are […]

Update to version 2.8 from upstream, Security fix for [CVE-2019-11555]

Update to version 3.0.10, which fixes a security issue (a buffer overrun vulnerability in the httpd daemon, CVE-2019-11356).

security update

An update that fixes four vulnerabilities is now available.

An update that solves 24 vulnerabilities and has two fixes is now available.

AMCA Healthcare Hack Widens Again, Reaching 20.1M Victims
High-Severity Bug in Cisco Industrial Enterprise Tool Allows RCE
NSA joins chorus urging Windows users to patch ‘BlueKeep’

The alert comes on the heels of Microsoft’s second advisory calling on people to take action before it’s too late The post NSA joins chorus urging Windows users to patch ‘BlueKeep’ appeared first on WeLiveSecurity

A vulnerability in Exim could allow a remote attacker to execute arbitrary commands.

Radisson Rewards may have leaked your data… again
Streaming Video Fans Open to TV Hijacking

An update that fixes one vulnerability is now available.

Infosecurity Europe: Easing the Clash Between IT and OT
IoT Security Regulation is on the Horizon
Firefox aims at Google with Enhanced Tracking Prevention
To members of Pizza Hut’s loyalty scheme: You really knead to stop reusing your passwords

An update for qpid-proton is now available for Red Hat OpenStack Platform 14 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Microsoft dismisses new Windows RDP ‘bug’ as a feature

An update for qpid-proton is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for qpid-proton is now available for Red Hat OpenStack Platform 14 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Understanding random number generators, and their limitations, in Linux
YouTube bans kids’ live-streaming without an adult present
Gang charged with $19 million iPhone scam

Vincent Tondellier reported that the qemu update issued as DSA 4454-1 did not correctly backport the support to define the md-clear bit to allow mitigation of the MDS vulnerabilities. Updated qemu packages are now available to correct this issue.

The Growing Importance of Cyber Security Skills

Several vulnerabilities have been found in the poppler PDF rendering library, which could result in denial of service or possibly other unspecified impact when processing malformed or maliciously crafted files.

Worried ransomware will screw your network? You could consider swallowing your pride, opening your wallet
Smashing Security #131: Zap yourself from the net, and patch now against BlueKeep
It’s that time again: Android kicks off June’s patch parade with fixes for five hijack holes
Buggy Phishing Kits Allow Criminals to Cannibalize Their Own
440 Million Android Users Plagued By Extremely Obnoxious Pop-Ups
Mozilla and Google Browsers Get Security, Anti-Tracking Boosts

Risk Level: Very Low. Type: Trojan.

BlueKeep ‘Mega-Worm’ Looms as Fresh PoC Shows Full System Takeover
Why Election Trust is Dwindling in a Post-Cambridge Analytica World
Crime doesn’t pay? Crime doesn’t do secure coding, either: Akamai bug-hunters find hijack hole in bank phishing kit

The Qualys Research Labs reported a flaw in Exim, a mail transport agent. Improper validation of the recipient address in the deliver_message() function may result in the execution of arbitrary commands.

Patch Android! June 2019 update fixes eight critical flaws
Podcast: Behind-the-Scenes Look at Scattered Canary BEC Cybergang
Newly-Identified BEC Cybergang Targets U.S. Enterprise Victims
Apple bans ads, third-party tracking in apps meant for kids
Smashing Security named the Best Security Podcast

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

ATM skimming crook behind bars after draining bank accounts for 2 years
Apple battles Facebook and Google with rival sign in service

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Wajam: From start-up to massively-spread adware

How a Montreal-made “social search engine” application has managed to become a widely-spread adware, while escaping consequences The post Wajam: From start-up to massively-spread adware appeared first on WeLiveSecurity