Menu

Latest articles

HMRC to finally erase five million voice records it collected without permission
UK taxman falls foul of GDPR, agrees to wipe 5 million voice recordings used to make biometic IDs
Retefe Banking Trojan Resurfaces, Says Goodbye to Tor
Multiple Sierra Wireless AirLink Routers Open to Remote Code Execution

An update that contains security fixes can now be installed.

Europol takes down Wall Street market: No, the other cesspool of dark international financial skullduggery

An update that contains security fixes can now be installed.

An update that fixes 18 vulnerabilities is now available.

Venture deep into cybersecurity at SANS Amsterdam this month: Full details inside
Criminals are hiding in Telegram – but backdoors are not the answer
Cryptocoin theft, scam and fraud could total more than $1.2b in Q1
Cybersecurity experts battle for right to repair
A day in the life of London seen through spam and weak Wi-Fi
Google rolling out auto-delete for your location and activity history

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Critical Flaws Found in Eight Wireless Presentation Systems
It’s May 2. Know what that means? Yep, it’s the PR orgy that is World Password Day… again
D-Link Cloud Camera Flaw Gives Hackers Access to Video Stream
New Google Chrome mobile phishing scam can steal private data
Ladders, SkyMed Leak Employment, Medical Data for Millions
Dell Security Support Tool Harbors High-Severity Flaws
Google will ‘auto-delete’ your location & web activity data
Japan is developing a computer virus to fight cyberattacks, claim reports
Cisco Warns of Critical Nexus 9000 Data Center Flaw
World Password Day – what (NOT!) to do
World Password Day: A day to review your defenses

So, do you think you’ve been ‘pwned’? That’s the question to ask yourself today The post World Password Day: A day to review your defenses appeared first on WeLiveSecurity

DHS policies allow unlimited, warrantless device search
Is a sticky label the answer to the IoT’s security problems?
Extortionists leak data of huge firms after IT provider refuses to pay

Several security issues were fixed in python-gnupg

US Government halves deadline for applying critical patches to 15 days
‘I do not wish to surrender’ Julian Assange tells court over US extradition bid

An update that fixes two vulnerabilities is now available.

D-Link camera vulnerability allows attackers to tap into the video stream

ESET researchers highlight a series of security holes in a device intended to make homes and offices more secure The post D-Link camera vulnerability allows attackers to tap into the video stream appeared first on WeLiveSecurity

We dunno what’s worse: Hackers ransacked Citrix for FIVE months, or that Equifax was picked to help mop up the mess
Smashing Security #126: Zombie chickens and fast-food victims
Sinister secret backdoor found in networking gear perfect for government espionage: The Chinese are – oh no, wait, it’s Cisco again

**horde 5.2.21** * [mjr] SECURITY: Fix XSS vulnerability in the Cloud Block.

**turba 4.2.24** * [mjr] SECURITY: Fix XSS vulnerability in display of contact tags. * [jan] Clarify objectClass filter examples for LDAP backends (Ralf Lang).

Ad Server Patched to Stop Possible Malware Distribution
Crypto-chaps on scam rap in a flap over Slack chat tap, want court case zapped: ‘Attorney-client priv info’ in messages

**horde 5.2.21** * [mjr] SECURITY: Fix XSS vulnerability in the Cloud Block.

**turba 4.2.24** * [mjr] SECURITY: Fix XSS vulnerability in display of contact tags. * [jan] Clarify objectClass filter examples for LDAP backends (Ralf Lang).

Wipro Attackers Have Operated Under the Radar for Years
DHS Shortens Deadline For Gov Agencies to Fix Critical Flaws
Hey, those warrantless smartphone searches at the US border? Unconstitutional, yeah? Civil-rights warriors ask court to settle this

An update that fixes two vulnerabilities is now available.

An update that solves 5 vulnerabilities and has 5 fixes is now available.

An update that contains security fixes can now be installed.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

May Day! PM sacks UK Defence Secretary Gavin Williamson for Huawei 5G green-light ‘leak’

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Cartoon Network Hacked Worldwide to Show Brazilian Stripper Videos

An unsafe shell call enabling shell injection via a user ID was corrected in gpg-key2ps, a tool to generate a PostScript file with OpenPGP key fingerprint slips.

Muhstik Botnet Variant Targets Just-Patched Oracle WebLogic Flaw
Michael Bublé’s Instagram suffers cock-up

The update of proftpd-dfsg issued as DLA-1753-1 caused a regression when using the sftp module. Login to the sftp server was impossible when the SFTPPAMEngine option was turned on (#926719).

Sky Broadband firmware update bricks routers using third-party DNS settings
Keeping your data safe when traveling
Millions of consumer smart devices exposed by serious security flaw
Julian Assange jailed for 50 weeks over Ecuador embassy bail-jumping
Diabetics are hunting down obsolete insulin pumps with a security flaw
Mystery database exposes data on 80 million US households
NordVPN rapped by ad watchdog over insecure public Wi-Fi claims
Crooks using hacked Microsoft email accounts to steal cryptocurrency

Memcached could be made to crash if it received specially crafted network traffic.

If you’re using Oracle’s WebLogic Server, check for security fixes: Bug exploited in the wild to install ransomware
Don’t be Russian to judgement but… Bloke accused of $1.5m+ tax filing biz hack, fraud

Fix CVE-2019-11372

Fake Jason Statham Bilks a Fan Out of Serious Money

Fix CVE-2019-11372

**horde 5.2.21** * [mjr] SECURITY: Fix XSS vulnerability in the Cloud Block.

**turba 4.2.24** * [mjr] SECURITY: Fix XSS vulnerability in display of contact tags. * [jan] Clarify objectClass filter examples for LDAP backends (Ralf Lang).

security update

New Electrum DDoS botnet steals $4.6M after infecting 152,000 hosts

Type: Vulnerability. Microsoft Internet Explorer is prone to an information-disclosure vulnerability.

New ‘Sodinokibi’ Ransomware Exploits Critical Oracle WebLogic Flaw
Extortionist hacks IT provider used by the stars of tech and big biz, leaks customer info after ransom goes unpaid
Researchers Compromise Netflix Content in Widevine DRM Hack
BEC Hack Cons Catholic Church Out of $1.75 Million
Sensitive data of 80 million US households exposed online

libvirt-domain.c in libvirt supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required. This could lead to could lead to potentially disclosing unintended

Android users: watch out for this fake address bar trick
Oh dear. Sneaky Huawei enterprise router ‘backdoor’ was Telnet service, sighs Vodafone

An update that fixes two vulnerabilities is now available.

An update for openstack-neutron is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Dovecot could be made to crash if it received specially crafted network traffic.

An update for openstack-neutron is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for openstack-ceilometer is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openstack-neutron, openstack-neutron-lbaas, and python-networking-bigswitch is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact

An update for openstack-cinder is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Securing edge devices – how to keep the crooks out of your network

An update is now available for Red Hat Ceph Storage 3.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

A minor version update (from 7.2 to 7.3) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact