Menu

Latest articles

An update that solves one vulnerability and has four fixes is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

It was discovered that there was a path traversal vulnerability in the “mercurial” distributed revision version control system. Symbolic links and subrepositories could be used defeat Mercurial’s

Hacker could locate thousands of cars and kill their engines remotely via poorly-secured GPS tracking apps

Reading Time: ~3 min. Public concern about online privacy and security is rising, and not without reason. High-profile data breaches make headlines almost daily and tax season predictably increases instances of one of the most common types of identity theft, the fraudulent filings for tax returns known as tax-related identity theft.  As a result, more than half of global internet users are more concerned about their safety than […]

Blochainbandit stole $54 million of Ethereum by guessing weak keys
DNSpionage group’s Karkoff malware selectively pick victims
Atlanta Hawks fall prey to Magecart credit card skimming group
Teen sues Apple for $1 billion over Apple stores’ facial recognition

An update that solves two vulnerabilities and has four fixes is now available.

An update that fixes one vulnerability is now available.

It’s your what in a box? Here’s a thing to make your bosses think about malware responses
Smashing Security #125: Pick of the thief!
Over 23 million breached accounts used ‘123456’ as password

The notorious six-digit string continues to ‘reign supreme’ among the most-hacked passwords The post Over 23 million breached accounts used ‘123456’ as password appeared first on WeLiveSecurity

Bind could be made to consume resources if it received specially crafted network traffic.

tcpflow could be made to crash or expose sensitive information over the network if it opened a specially crafted file or received specially crafted network traffic.

Several security issues were fixed in PHP.

Updated Red Hat AMQ Clients 2.3.1 packages are now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

FYI: Yeah, the cops can force your finger onto a suspect’s iPhone to see if it unlocks, says judge
Facebook May Face $5 Billion FTC Fine for Data Misuse
Sophos antivirus tools. Working Windows box. Latest Patch Tuesday fixes. Pick two: ‘Puters knackered by bad combo

Reading Time: ~4 min. These are the places your digital tracks can be dug up. With a little sleuthing. Experts have warned for years of the risks of using public computers such as those found in libraries, hotels, and airline lounges.  Many warnings focused on the potential for hackers to plant keystroke loggers, or intercept […]

Hackers using Google Sites to spread banking malware
Adware-Ridden Apps in Google Play Infect 30 Million Android Users
WiFi finder app exposes millions of WiFi network passwords
‘We’re not omnipotent,’ trills National Cyber Security Centre in open-armed pitch to UK biz
Point Blank Gamers Targeted with Backdoor Malware
Poll: Are You Creeped Out by Facial Recognition?
Brit spy chief: We need trust or we won’t have a ‘licence to operate in cyberspace’

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 24 fixes is now available.

An update that fixes three vulnerabilities is now available.

Latest Qbot Variant Evades Detection, Infects Thousands
Facial Recognition is Here: But Are We Ready?
Ex-student records himself using USB Killer to fry college computers

An update that solves one vulnerability and has 23 fixes is now available.

The package dovecot before version 2.3.5.2-1 is vulnerable to denial of service.

The package flashplugin before version 32.0.0.171-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

The package jenkins before version 2.172-1 is vulnerable to multiple issues including access restriction bypass and cross-site scripting.

The package ghostscript before version 9.27-1 is vulnerable to sandbox escape.

NYPD forgets to redact facial recognition docs, asks for them back
Gunpoint domain hijack turns out to have been a family affair
DNS over HTTPS is coming whether ISPs and governments like it or not
Bodybuilding.com suffers data breach; issues password reset for all users
WannaCryptor ‘accidental hero’ pleads guilty to malware charges

Marcus Hutchins, who is best known for his inadvertent role in blunting the WannaCryptor outbreak two years ago, may now face a stretch behind bars The post WannaCryptor ‘accidental hero’ pleads guilty to malware charges appeared first on WeLiveSecurity

Carbanak Source Code Unveils a Startlingly Complex Malware
Exploits for Social Warfare WordPress Plugin Reach Critical Mass
Wall Street market exit scam? Admins steal $30 million worth of crypto
FBI: BEC Scam Losses Almost Double To Reach $1.2 Billion
Phone fingerprint scanner fooled by chewing gum packet

AdvanceCOMP could be made to run arbitrary code if it opened a specially crafted file.

Hotspot finder app blabs 2 million Wi-Fi network passwords

A security update is now available for Red Hat Single Sign-On 7.2 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Security updates for Red Hat Single Sign-On 7.2.7 packages are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Security updates for Red Hat Single Sign-On 7.2.7 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Once again, it’s 123456: the password that says ‘I give up’

An update that fixes 6 vulnerabilities is now available.

Building a VPN for Mobile Devices at the Network Level

Reading Time: ~5 min. From Landline Hacking to Cryptojacking By its very nature, cybercrime must evolve to survive. Not only are cybersecurity experts constantly working to close hacking loopholes and prevent zero-day events, but technology itself is always evolving. This means cybercriminals are constantly creating new attacks to fit new trends, while tweaking existing attacks to avoid detection. To understand how cybercrime might evolve […]

Several security issues were fixed in PHP.

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for ovmf is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Cedric Buissart discovered two vulnerabilities in Ghostscript, the GPL PostScript/PDF interpreter, which could result in bypass of file system restrictions of the dSAFER sandbox.

Several security issues were fixed in PHP.

Several security issues were fixed in Pacemaker.

Like that other bloke who rose from the grave, the El Reg security desk is back this week…
Wi-Fi Hotspot Finder Spills 2 Million Passwords
Is Privacy Really iPhone? Researchers Weigh in on Apple’s Targeted Ad Tracking
Evil TeamViewer Attacks Under the Guise of the U.S. State Department
France’s ‘Secure’ Telegram Replacement Hacked in an Hour
WannaCry Hero Pleads Guilty to Kronos Malware Charges
Can you get hit by someone else’s ransomware? [VIDEO]
Millions of Medical Documents for Addiction and Recovery Patients Leaked

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Out-of-bounds read and write conditions have been fixed in clamav. CVE-2019-1787

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

This update fixes a [bug](https://github.com/mesonbuild/meson/issues/5268) in the Meson build system which caused binaries and libraries to incorrectly be marking as requiring an executable stack. This makes them more vulnerable to security issues, and also can result in errors caused by SELinux denials. This update also provides rebuilds of all the packages that were built with […]

WannaCry hero Hutchins now officially a convicted cybercriminal
The Weather Channel goes offline after ransomware attack

debian-security-support, the Debian security support coverage checker, has been updated in jessie. The jessie relevant changes are: * Mark spice-xpi as end-of-life for Jessie.

An update that solves one vulnerability and has two fixes is now available.

A cross-site scripting vulnerability has been found in Drupal, a fully-featured content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2019-006 .

security update

WannaCry hero MalwareTech pleads guilty to writing banking malware
Wannacry-slayer Marcus Hutchins pleads guilty to two counts of banking malware creation