Menu

Latest articles

An update for rh-redis32-redis is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

You can probably be identified from your anonymized data
Red Hat Certificate System achieves Common Criteria certification
Interview with Security Expert and Author Ira Winkler: Advanced Persistent Security, Threat Intelligence, Social Engineering and more

An update that solves two vulnerabilities and has one errata is now available.

Several security issues were fixed in VLC.

libEBML could be made to crash if it opened a specially crafted file.

Jeremy Harris discovered that Exim, a mail transport agent, does not properly handle the ${sort } expansion. This flaw can be exploited by a remote attacker to execute programs with root privileges in non-default (and unusual) configurations where ${sort } expansion is used for items

Smashing Security #138: Logic bombs, brain data exploitation, and Digga D tweets

security update

Popular File-Sharing Service WeTransfer Used in Malicious Spam Campaigns

Update including July CPU fixes.

Update including July CPU fixes.

ThreatList: Human Error is Behind One Quarter of Data Breaches

security update

security update

security update

Several security issues were fixed in Ansible.

Sanctions-hit Russian developers fingered for crafting ‘Monokle’ Android snoopware
New malware attack turns Elasticsearch databases into DDoS botnet
Unique Monokle Android Spyware Self-Signs Certificates

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes 10 vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

Man arrested over UK’s Lancaster University data breach hack allegations

Several security issues were fixed in Patch.

Data breaches can haunt firms for years

The compromised company may bear the financial brunt of the breach within the first year after the incident occurs, but the price tag is still far from final The post Data breaches can haunt firms for years appeared first on WeLiveSecurity

Police arrest man after Lancaster University hacking attack

An update that fixes 5 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Several security issues were fixed in Patch.

Sky worries users with phishy-looking password reset email
Apple’s July patchfest fixes bugs in multiple products
Facebook admits to Messenger Kids security hole

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

An update is now available for CloudForms Management Engine 5.10. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

With more hints dropped online on how to exploit BlueKeep, you’ve patched that Windows RDP flaw, right?
Low Barr: Don’t give me that crap about security, just put the backdoors in the encryption, roars US Attorney General
Citrix Confirms Password-Spraying Heist of Reams of Internal IP
Dodgy vids can hijack PCs via VLC security flaw, US, Germany warn. Software’s makers not app-y with that claim
WordPress Plugin Flaws Exploited in Ongoing Malvertising Campaign
Malware-Loader ‘Brushaloader’ Grows More Menacing
SharePoint Online scam – sadly, phishing’s not dead
Popular Samsung, LG Android Phones Open to ‘Spearphone’ Eavesdropping

Reading Time: ~ 4 min. You’ve likely heard of the dark web. This ominous sounding shadow internet rose in prominence alongside cryptocurrencies in the early 2010s, eventually becoming such an ingrained part of our cultural zeitgeist that it even received its own feature on an episode of Law & Order: SVU. But as prominent as […]

Jann Horn discovered that the ptrace subsystem in the Linux kernel mishandles the management of the credentials of a process that wants to create a ptrace relationship, allowing a local user to obtain root privileges under certain scenarios.

VLC Media Player Plagued By Unpatched Critical RCE Flaw

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 12 vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Programmer from hell plants logic bombs to guarantee future work
Lancaster Uni data breach hits at least 12,500 wannabe students
Big password hole in iOS 13 beta spotted by testers
Your Android’s accelerometer could be used to eavesdrop on your calls
FSB hackers drop files online
It’s 2019 and you can still pwn an iPhone with a website: Apple patches up iOS, Mac bugs in July security hole dump

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Cloud hosting provider iNSYNQ hit by MegaCortex ransomware
Equifax to world+dog: If we give you this $700m, can you pleeeeease stop suing us about that mega-hack thing?
Critical RCE Flaw in Palo Alto Gateways Hits Uber
700 million reasons for Equifax to remember to patch its vulnerable IT systems in future
Tackling the Collaboration Conundrum

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Large-Scale Government Hacks Hit Russia, Bulgaria
VLC player has a critical flaw – and there’s no patch yet

On the flip side, there are currently no known cases of the vulnerability being exploited in the wild The post VLC player has a critical flaw – and there’s no patch yet appeared first on WeLiveSecurity

Amazon Alexa, Google Home On Collision Course With Regulation
Equifax to Pay $700 Million in 2017 Data Breach Settlement
iCloud account hacker jailed for three years after preying on rappers and sports celebrities
Chrome 76 blocks websites from detecting incognito mode

Several security issues were fixed in Squid.

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

No, the Met Police wasn’t hacked. But its Twitter account and website were hijacked

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745) * OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762) * OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769) * OpenJDK: Missing URL format validation (Networking, 822151 [More…]

Hacked Bulgarian database reaches online forums
Cisco ‘in talks’ to borg with web app protector Signal Sciences for its web app firewall tech

Several vulnerabilities were found in libxslt the XSLT 1.0 processing library. CVE-2016-4610

What makes a secure & successful website: A Guide

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

ClamAV could be made to expose sensitive information if it received a specially crafted CHM file.

Stop facial recognition trials now, warns UK committee

An update for rh-nodejs8-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-redis5-redis is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Marketing biz bares folks’ data in the act of asking for their GDPR comms preferences

Risk Level: Very Low. Type: Trojan.