Menu

Latest articles

Fix for CVE-2019-5429

Fix for CVE-2019-5429

security update

Airbnb Superhost Secretly Recorded Guests with Hidden Bedroom Camera
The Different Ways a Data Breach Can Impact Businesses
Google Patches Critical Remote Code-Execution Flaws in Android
Lax Telco Security Allows Mobile Phone Hijacking and Redirects
Binance exchange hacked: Bitcoin worth $40.7M stolen
Orange is at it again, buys SecureLink for an eye-watering €515m including debts
Google Touts Android Q’s New Security Update Process and Better Privacy Controls for Apps
Verizon Data Breach Report: Espionage, C-Suite and Cloud Attacks on the Rise
Top 5 Configuration Mistakes That Create Field Days for Hackers
Cynet Provides Security Responders with Free IR Tool to Validate and Respond to Active Threats
Executive hacked competitor’s website to steal students meal preferences
Latest Android security updates, and Google to fix patch delays for Pixel
$40 million worth of Bitcoin stolen from Binance cryptocurrency exchange

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

US foreign minister Mike Pompeo to give UK a bollocking over Huawei 5G plans
Malvertiser behind 100+ million bad ads indicted in the US
Malware takes Wolters Kluwer CCH cloud accounting service offline
School lunch company exec arrested for skewering rival’s site
Researchers’ Evil Clippy cloaks malicious Office macros
Want rootkit-level access without the hassle? Enter, LightNeuron for Exchange Server

An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rhvm-setup-plugins is now available for Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Airbnb host thrown in the clink after guest finds hidden camera inside Wi-Fi router
And in this week’s weird news, Feds seize dark-web news site, accuse admins of getting rich off drug cyber-souk

Risk Level: Very Low. Type: Virus, Worm.

This update enforces that $LoadCode must be enabled to use the feature of evaluating typeglobs, because with the typeglob feature you would be able to set the variable $YAML::LoadCode from a YAML file, and that would be a security issue.

Critical Flaw in Cisco Elastic Services Controller Allows Full System Takeover
Remember those stolen ‘NSA exploits’ leaked online by the Shadow Brokers? The Chinese had them a year before
Freedom Mobile leaked millions of card data with CVV codes in plain text
Chinese Spies Stole NSA Cyberweapons Long Before Shadow Brokers Leak

Risk Level: Very Low. Type: Trojan.

Reading Time: ~3 min. In a recent report by the firm 451 Research, 62% of SMBs reported having a security awareness training program in place for their employees, with half being “homegrown” training courses. The report also found that most complained their programs were difficult to implement, track, and manage. Like those weights in the […]

Be wary of emails with links to … er, Google Drive? Is that right?
Chinese hackers accessed NSA hacking tools before Shadow Brokers leak
Ukrainian Charged With Launching 100 Million Malicious Ads
MegaCortex ransomware distracts victims with Matrix film references

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for python-jinja2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Restore s390x builds. —- 0.7.3.1

Turla LightNeuron: An email too far

ESET research uncovers Microsoft Exchange malware remotely controlled via steganographic PDF and JPG email attachments The post Turla LightNeuron: An email too far appeared first on WeLiveSecurity

Reading Time: ~5 min. Like many Americans, you might think your online habits are safe enough—or, at least, not so risky as to put you in danger for cybercrime. As it happens, most of us in the U.S. are nowhere near as secure as we think we are. As part of our recent survey to […]

‘Software delivered to Boeing’ now blamed for 737 MAX warning fiasco

An update that solves one vulnerability and has three fixes is now available.

An attempt to phish my Amazon Web Services account
Firefox add-ons with obfuscated code will be banned by Mozilla
Dark web marketplace Wall Street Market busted by international police
Blockchain project settles cross-border payment
Facebook sponsored posts selling access to hacked PayPal accounts
Weekly review – the hot 25 stories of last week
Sensitive data can lurk on second-hand hard drives
NSA foreign spying, biotech snooping, Hamas hackers bombed, airline cams, and much more from infosec land

Risk Level: Very Low. Type: Trojan, Virus, Worm.

WP Live Chat WordPress Plugin Re-Patches File Upload Flaw
Feds nab top exec on allegations he hacked a competitor, stole info… about school lunches?!
Oracle WebLogic Exploit-fest Continues with GandCrab Ransomware, XMRig
Free eBook: A Business Owner’s Guide to Cybersecurity
High-Severity Bug Leaves Cisco TelePresence Gear Open to Attack
Avengers: Endgame Sites Promise Digital Downloads, Deliver Info-Harvesting
Israel claims to bomb Hamas’s cyber Ops HQ amidst uncertainties
High-Severity PrinterLogic Flaws Enable Remote Code Execution
Israel bombs building containing alleged Hamas hackers
Tor Security Add-On Abruptly Killed by Mozilla Bug

An update that fixes 16 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Extinguishing the IoT Insecurity Dumpster Fire

jQuery mishandles jQuery.extend(true, {}, …) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. For additional information, please refer to the upstream advisory at

Amid Bug Bounty Hype, Sometimes Security is Left in the Dust
Mozilla bug throws Tor Browser users into chaos

* Mouse cursor doubled on QEMU VNC on ppc64le (bz #1565253) * CVE-2019-3840: NULL deref after running qemuAgentGetInterfaces (bz #1665229)

This update provides an update to the new Virtualbox 6.0 branch, currently 6.0.6. It also fixes the following security issues. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise

An update that solves 13 vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 19 vulnerabilities is now available.

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes 16 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Colin Snover discovered a denial-of-service vulnerability in phpBB3, a full-featured web forum. Previous versions allowed users to run searches that might result in long execution times and load on larger boards when using the fulltext native search engine. To combat this, further

Security fix for CVE-2019-3885, CVE-2018-16877, CVE-2018-16878

Researchers Weigh in on Trump’s Cyber Workforce Executive Order
White House issues Executive Order on cybersecurity, including hacker Hunger Games

Update to April 2019 CPU. See: http://mail.openjdk.java.net/pipermail/jdk- updates-dev/2019-April/000951.html

New upstream release with significantly reworked PKCS#11 support, GSSAPI key exchange and several fixes for CVE-2019-6111 and CVE-2019-6109

New upstream release

News Wrap: Cartoon Network Hack, the Catholic Church and Jason Statham Scams
Mystery Git ransomware appears to blank commits, demands Bitcoin to rescue code
Belgian programmer solves cryptographic puzzle – 15 years too soon!

Reading Time: ~2 min. “FBI Director” Phishing Campaign A new email phishing campaign has been making its way around the web that claims to be from “FBI Director Christopher Wray,” who would love to assist with a massive wire transfer to the victim’s bank account. Unfortunately for anyone hoping for a quick payday, the $10 […]