Menu

Latest articles

Own goal for Leicester City FC after fan credit card details snatched in merch store hack
New Linux Malware ‘HiddenWasp’ Borrows from Mirai, Azazel
Mozilla returns crypto-signed website packaging spec to sender – yes, it’s Google

security update

Senator: US govt staff may be sending their smartphone web traffic ‘wrapped in a bow’ to Russia, China via VPNs

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

AI, the Mandatory Element of 5G Mobile Security
ProtonMail denies that it offers real-time surveillance assistance

Ben Barnea and colleagues from VDOO discovered several vulnerabilities in miniupnpd, a small daemon that provides UPnP Internet Gateway Device and Port Mapping Protocol services.

POS Malware Found at 102 Checkers Restaurant Locations
New Zealand budget details leaked due to website sloppiness, not hackers
HiddenWasp malware seizes control of Linux systems

Microarchitectural Data Sampling speculative side channel [XSA-297, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091] additional patches so above applies cleanly work around grub2 issues in dom0

– https://www.drupal.org/project/entity/releases/7.x-1.9 – https://www.drupal.org/sa-contrib-2018-013

2.3B Files Exposed in a Year: A New Record for Misconfigs
The cryptominer that kept coming back
We ain’t afraid of no ‘ghost user’: Infosec world tells GCHQ to GTFO over privacy-busting proposals
New Zealand’s “hacked” budget was found on a website

Reading Time: ~ 4 min. As technology continues to evolve, several trends are staying consistent. First, the volume of data is growing exponentially. Second, human analysts can’t hope to keep up—there just aren’t enough of them and they can’t work fast enough. Third, adversarial attacks that target data are also on the rise. Given these […]

Smashing Security #130: Doctored videos, Bcc blunders, and a diva

This is the 6 month notification for the retirement of Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions (E4S) and Telecommunications Update Service (TUS). This notification applies only to those customers subscribed to the Update Services for SAP Solutions (E4S) and

An update for go-toolset-1.11 and go-toolset-1.11-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

A million devices still vulnerable to ‘wormable’ RDP hole
What a teen grade hacker’s confession can teach us

An update is now available for JBoss Core Services on RHEL 6 and RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Red Hat JBoss Core Services Pack Apache Server 2.4.29 Service Pack 2 zip release for RHEL 6 and RHEL 7 is available. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Nightwatch Cybersecurity Research team identified a XSS vulnerability in tomcat7. The SSI printenv command echoes user provided data without escaping. SSI is disabled by default. The printenv command is intended

The aftermath of a data breach: A personal story

Criminals used my account to launder credit card transactions into cash, at least where the company transacted with was willing to refund The post The aftermath of a data breach: A personal story appeared first on WeLiveSecurity

Chinese software nasty enslaves stadium-load of servers, puts them to work digging up digital dosh in crypto-mines

– https://www.drupal.org/project/entity/releases/7.x-1.9 – https://www.drupal.org/sa-contrib-2018-013

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Git your patches here! GitHub offers to brew automatic pull requests loaded with vuln fixes
‘5G is Coming,’ But Can the Security Industry Keep Up?
ProtonMail filters this into its junk folder: New claim it goes out of its way to help cops spy

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

5G IoT: Literally a Matter of Life or Death

Risk Level: Very Low. Type: Trojan.

IEEE tells contributors with links to Chinese corp: Don’t let the door hit you on Huawei out
News aggregator app Flipboard hacked; user data stolen
WordPress Plugin Has Unpatched Privilege Escalation Flaw, Warn Researchers
Top UK Official: Huawei Is ‘Bad Security’

An update that fixes two vulnerabilities is now available.

Teen hacked Apple twice hoping for a job
50k Servers Infected with Cryptomining Malware in Nansh0u Campaign

Reading Time: ~ 4 min. Cities are expanding their technological reach. Many of their efforts work to increase public protections, such as using GPS tracking to help first responders quickly locate the site of a car accident. But, in the rush for a more secure and technologically advanced city, privacy can fall by the wayside. We’ve reviewed the top cities around the […]

News aggregator app Flipboard hacked: All passwords reset after hackers pinch user data
What Red Hat learns at our Security Symposium events: a product manager’s point of view
New research generates deepfake video from a single picture
Three tech-support scammers charged with ripping off the elderly
Infosec bloke claims: Pornhub owner shafted me after I exposed gaping holes in its cartoon smut platform
Hackers stole Flipboard users’ email addresses and hashed passwords
Researchers uncover smart padlock’s dumb security
A dive into Turla PowerShell usage

ESET researchers analyze new TTPs attributed to the Turla group that leverage PowerShell to run malware in-memory only The post A dive into Turla PowerShell usage appeared first on WeLiveSecurity

An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Guilty of hacking in the UK? Worry not: Stats show prison is unlikely

Two more security issues have been corrected in multiple demuxers and decoders of the libav multimedia library.

Contain yourself, Docker: Race-condition bug puts host machines at risk… sometimes, ish
Online graphic-design tool Canva hacked; 139 million accounts stolen

Update to version 0.9.5.4. Resolves CVE-2018-20433 and CVE-2019-5427.

Two weeks after Microsoft warned of Windows RDP worms, a million internet-facing boxes still vulnerable

**MySQL 8.0.16** **Release notes:** https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-16.html **Devel Blog:** https://mysqlserverteam.com/the-mysql-8-0-16-maintenance-release- is-generally-available/ **Bugs fixed:** A lot of tests fixed **CVEs fixed:** Unfortunatelly, I don’t have the list of truly CVEs affecting

Update to version 0.9.5.4. Resolves CVE-2018-20433 and CVE-2019-5427.

Germany mulls giving end-to-end chat app encryption das boot: Law requiring decrypted plain-text is in the works
200k Personal Records Exposed by Events Planning Firm
Gatekeeper Bug in MacOS Mojave Allows Malware to Execute
Millions of Canva users’ data stolen as GnosticPlayers strikes again
Equifax stripped of ‘stable’ outlook over 2017 breach

Add that to the US$1.4 billion that the massive incident has cost the company so far The post Equifax stripped of ‘stable’ outlook over 2017 breach appeared first on WeLiveSecurity

One Million Devices Open to Wormable Microsoft BlueKeep Flaw

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The package webkit2gtk before version 2.24.2-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

Google-protected mobile browsers were open to phishing for over a year

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

pacemaker: Insufficient local IPC client-server authentication on the client’s side can lead to local privesc (CVE-2018-16877) * pacemaker: Insufficient verification inflicted preference of uncontrolled processes can lead to DoS (CVE-2018-16878) * pacemaker: Information disclosure through use-after-free (CVE-2019-3885) SL7 x86_64 pacemaker-1.1.19-8.el7_6.5.x86_64.rpm pacemaker-cl [More…]

World’s most dangerous laptop has been sold for $1.3 million
Redditor can stay anonymous, court rules
Hackers breach US license plate scanning company

The package firefox before version 67.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, same-origin policy bypass, content spoofing, information disclosure, cross-site scripting and denial of service.

The package thunderbird before version 60.7.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, same-origin policy bypass, information disclosure and denial of service.

US Senate passes anti-robocalling bill

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has 9 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes four vulnerabilities is now available.

Seize the chance to boost your IT security skills: SANS London has plenty of courses for you