Menu

Latest articles

WTF is Boeing on? Not just customer databases lying around on the web. 787 jetliner code, too, security bugs and all

A minor version update (from 7.3 to 7.4) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

FBI, NSA to hackers: Let us be blunt. Weed need your help. We’ll hire you even if you’ve smoked a little pot in the past

New kdelibs packages are available for Slackware 14.2 and -current to fix a security issue.

Black Hat 2019: Microsoft Protocol Flaw Leaves Azure Users Open to Attack
Black Hat 2019: 5G Security Flaw Allows MiTM, Targeted Attacks

**PHP version 7.2.21** (01 Aug 2019) **Date:** * Fixed bug php#69044 (discrepency between time and microtime). (krakjoe) **EXIF:** * Fixed bug php#78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042) (Stas) * Fixed bug php#78222 (heap-buffer-overflow on exif_scan_thumbnail). (CVE-2019-11041) (Stas) **Fileinfo:** * Fixed bug php#78183 (finfo_file shows

Fixed out of bounds heap read in function rtreenode() Enhance the rtreenode() function of rtree (used for testing) so that it uses the newer sqlite3_str object for better performance and improved error reporting.

**PHP version 7.2.21** (01 Aug 2019) **Date:** * Fixed bug php#69044 (discrepency between time and microtime). (krakjoe) **EXIF:** * Fixed bug php#78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042) (Stas) * Fixed bug php#78222 (heap-buffer-overflow on exif_scan_thumbnail). (CVE-2019-11041) (Stas) **Fileinfo:** * Fixed bug php#78183 (finfo_file shows

Black Hat 2019: Ethical Hackers Must Protect Digital Human Rights

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Hack computers to steal someone’s identity in China? Why? You can just buy one from a bumpkin for, like, $3k
There’s fraud, and then there’s backdoor routers, fenced logins, malware, and bribing AT&T staff seven figures to unlock 2m phones
Hack-age delivery! Wardialing, wardriving… Now warshipping: Wi-Fi-spying gizmos may lurk in future parcels
Black Hat 2019: Security’s Powerful Cultural Transformation
AT&T workers bribed to install malware on company network and unlock iPhones
Top Dangers That Online Gamers Face
Smominru Cryptominer Scrapes Credentials for Half-Million Machines
Don’t let the crooks ‘borrow’ your home router as a hacking server
8chan down after Cloudflare & hosting firms boots it off
10 Typical Mistakes in Scientific Research Paper Writing

An update that solves one vulnerability and has one errata is now available.

New SWAPGS Side-Channel Attack Bypasses Spectre and Meltdown Defenses

Rack could allow cross-site scripting (XSS) attacks.

Scammers recruiting money mules on dating sites is on the rise, says FBI
Security Vulnerabilities Are Increasingly Putting Kids at Risk
Don’t fall for fake Equifax settlement sites, warns FTC
Black Hat: LeapFrog Tablet Flaws Let Attackers Track, Message Kids

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

PHP could be made to denial of service, expose sensitive information or execute arbitrary code if it received a specially crafted regular expression.

Banking PINs exposed in Monzo secure storage slip-up
Latest Android patches fix critical ‘QualPwn’ Wi-Fi flaws
FBI warns of romance scams using online daters as money mules

Up to 30 percent of romance fraud victims in 2018 are estimated to have been used as money mules The post FBI warns of romance scams using online daters as money mules appeared first on WeLiveSecurity

SWAPGS attack: The Spectre-like flaw affecting Intel CPUs

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libssh2 is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for augeas is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for systemd is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for perl is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

Your mid-week infosec news bonanza: Cisco bugs, VMware-Nvidia guest escapes, KDE hijacking, and more
Deja-wooo-oooh! Intel chips running Windows potentially vulnerable to scary Spectre variant
They say piracy killed the Amiga. Know what else it’s killing? Malware sales. Awww, diddums
Democrats and Doctors Behind Latest Wave of Leaked Data
Cryptolocking WordPress Plugin Locks Up Blog Posts
Add passwords to list of stuff CafePress made hash of storing, says infoseccer. 11m+ who used Facebook ‘n’ pals to sign in were lucky
Mass Spoofing Campaign Takes Aim at Walmart
Millions of Android Smartphones Vulnerable to Trio of Qualcomm Bugs

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

You really should listen to the award-winning “Smashing Security” podcast
Baldr malware unpicked with a little help from crooks’ bad opsec

Mercurial could be made to overwrite files.

NVIDIA patches high-severity bugs in Windows GPUs and SHIELD
Fake Dell support rep admits to talking US colleges out of $874,000
500,000 Monzo banking customers told to change their PINs
GitHub ‘encourages’ hacking, says lawsuit following Capital One breach
Attackers ransom bookseller’s exposed MongoDB database

An update that solves two vulnerabilities and has one errata is now available.

An update for perl-Archive-Tar is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for dhcp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for linux-firmware is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libtiff is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for python-requests is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Need to automatically and securely verify a download is legit? You bet rget this new tool
It’s 2019 – and you can completely pwn a Qualcomm-powered Android over the air
PIN the blame on us, says Monzo in mondo security blunder: Bank card codes stored in log files as plain text
F-B-Yikes! FBI bod allegedly hid spy camera under desk to snap coworker’s upskirt pics
Googlers hate it! This one weird trick lets websites dodge Chrome 76’s defenses, detect you’re in Incognito mode

security update

E3 Website Leaks Private Addresses for Thousands of Journalists
How to avoid getting burned at Black Hat, destroyed at DEF CON or blindsided by Bsides

Reading Time: ~ 3 min. 1949, 1971, 1979, 1981, 1983 and 1991. Yes, these are numbers. You more than likely even recognize them as years. However, without context you wouldn’t immediately recognize them as years in which Sicily’s Mount Etna experienced major eruptions. Data matters, but only if it’s paired with enough context to create […]

Tobias Maedel discovered that the mod_copy module of ProFTPD, a FTP/SFTP/FTPS server, performed incomplete permission validation for the CPFR/CPTO commands.

July CPU update. See: http://openjdk.java.net/groups/vulnerability/advisories/2019-07-16 and https://mail.openjdk.java.net/pipermail/jdk-updates-dev/2019-July/001423.html

This release includes four security fixes: – Prevent an attack where a federated server could send redactions for arbitrary events in v1 and v2 rooms. – Prevent a denial-of-service attack where cycles of redaction events would make Synapse spin infinitely. – Prevent an attack where users could be joined or parted from public rooms without […]

This kernel update is based on the upstream 5.1.20 and fixes atleast the following security issue: With Xen, virtual device backends and device models running in domain 0, or other backend driver domains, need to be able to map guest memory

Puzzling Gwmndy Botnet Focuses on Low-Volume Proxy Connections
The sea is dangerous and no one likes robots, so why not send a drone on rescue missions?
Microsoft Lab Offers $300K For Working Azure Exploits
Google and ARM Tackle Android Bugs with Memory-Tagging
Google and Apple suspend contractor access to voice recordings
Hackers exploit SMS gateways to text millions of US numbers
FileZilla fixes show how far we’ve come since Heartbleed
GermanWiper isn’t ransomware. It’s worse than that
Class-action sueball flung at Capital One and GitHub over theft of 106 million folks’ details
We’ve, um, changed our password policy, says CafePress amid reports of 23m pwned accounts

A system hardening measure could be bypassed.

What we Can Learn from the Recent VLC Security Vulnerability Fiasco: A Conversation with VideoLAN President Jean-Baptiste Kempf
MegaCortex Ransomware Revamps for Mass Distribution
How to write an information security analyst job description
Amazon now lets you opt-out of having humans review your Alexa conversations
Sharpening the Machete

ESET research uncovers a cyberespionage operation targeting the Venezuelan military The post Sharpening the Machete appeared first on WeLiveSecurity

It’s Black Hat and DEF CON in Vegas this week. And yup, you know what that means. Hotel room searches for guns