Menu

Latest articles

Dragonblood: Data-leaking flaw in WPA3 Wi-Fi authentication
Top The Pirate Bay Alternatives – Best Torrent Download Sites (2019)
Can you detect hidden cameras in hotel rooms? [VIDEO]
Wikileaks founder Julian Assange arrested in London
Nasty Android & iOS malware found using govt surveillance tech

Several security vulnerabilities were discovered in Graphicsmagick, a collection of image processing tools. Heap-based buffer over-reads and a memory leak may lead to a denial-of-service or information disclosure.

This update backports a fix for CVE-2018-20096, CVE-2018-20097, CVE-2018-20098, CVE-2018-20099.

* Yaws ver. 2.0.6

The update of jasper issued as DLA-1628-1 caused a regression due to the fix for CVE-2018-19542, a NULL pointer dereference in the function jp2_decode, which could lead to a denial-of-service. In some cases not only invalid jp2 files but also valid jp2 files were rejected.

This update fixes security vulnerability – Checkstyle loads external DTDs by default. Upstream issue: https://github.com/checkstyle/checkstyle/issues/6474 https://github.com/checkstyle/checkstyle/issues/6478 References: https://checkstyle.org/releasenotes.html#Release_8.18

An update that solves two vulnerabilities and has four fixes is now available.

rssh could be made to run arbitrary commands if it received specially crafted input.

This update fixes security vulnerability – Checkstyle loads external DTDs by default. Upstream issue: https://github.com/checkstyle/checkstyle/issues/6474 https://github.com/checkstyle/checkstyle/issues/6478 References: https://checkstyle.org/releasenotes.html#Release_8.18

Hackers post private data of thousands of Federal agents online
IE under fire, Triton goes under the microscope, and Norsk still reeling from ransomware attack

Reading Time: ~4 min. The process of bringing a cybersecurity product to market can be long and tedious, but Kiran Kumar, Product Director at Webroot, loves to oversee all the moving parts. It keeps him on his toes and immersed in the ever-changing world of security technology. We sat down to chat with Kumar about […]

security update

US-Cert alert! Thanks to a massive bug, VPN now stands for “Vigorously Pwned Nodes”

security update

security update

Risk Level: Very Low. Type: Trojan, Worm.

Bucharest’s Bayrob boys blasted based on bogus buys, Bitcoin banditry, bound to be behind bars
Romanian Duo Convicted of Malware Scheme Infecting 400,000 Computers

Reading Time: ~2 min. Tax Extortion Emails Bring Major Threats A new email campaign has been spotted threatening ransomware and DDoS attacks over fake tax documents allegedly held by the attackers if a Bitcoin ransom isn’t paid. The campaign authors also threaten to send fake tax documents to the IRS through a poorly-worded ransom email […]

North Korea’s Hidden Cobra Strikes U.S. Targets with HOPLIGHT

An update that fixes one vulnerability is now available.

WordPress Yellow Pencil Plugin Flaws Actively Exploited

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 13 fixes is now available.

ThreatList: Tax Scammers Launch a Raft of Fake Mobile Apps
Bayrob malware gang convicted of infecting over 400,000 computers worldwide, stealing millions through online auction fraud
Hackers crack university defenses in just two hours

More than 50 universities in the United Kingdom had their cyber-defenses tested by ethical hackers, and the ‘grades’ aren’t pretty The post Hackers crack university defenses in just two hours appeared first on WeLiveSecurity

Assange arrested, faces extradition for hacking
Hear me speak about how to make a billion dollars through cybercrime
Feds say Russian 2016 election meddling spanned all US states
Flickr tackling online image theft with new AI service

An update that fixes one vulnerability is now available.

US: We’ll pull security co-operation if you lot buy from Huawei
Android phones transformed into anti-phishing security tokens

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0710

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0697

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0717

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0711

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has 15 fixes is now available.

Risk Level: Very Low. Type: Trojan, Worm.

Bug-hunters punch huge holes in WPA3 standard for Wi-Fi security
Client-attorney privilege? Not when you’re accused of leaking Vault 7 CIA code
Juniper slips out update after hardcoded credentials left in switches
As Alexa’s secret human army is revealed, we ask: Who else has been listening in on you?
WordPress Urges Users to Uninstall Yuzo Plugin After Flaw Exploited
SAS 2019: Fake News Peddlers Adopt Clever New Trick to Fool Facebook, Twitter
WPA3 flaws may let attackers steal Wi-Fi passwords

The new wireless security protocol contains multiple design flaws that hackers could exploit for attacks on Wi-Fi passwords The post WPA3 flaws may let attackers steal Wi-Fi passwords appeared first on WeLiveSecurity

Serious Security: How web forms can steal your bandwidth and harm your brand
Uncle Sam charges Julian Assange with conspiracy to commit computer intrusion
High-rolling hacker jailed after launching malware attacks via porn websites
Patch blues-day: Microsoft yanks code after some PCs are rendered super secure (and unbootable) following update
Amazon Auditors Listen to Echo Recordings, Report Says

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Ban the use of ‘dark patterns’ by tech companies, say US lawmakers
App could have let attackers locate and take control of users’ cars
Toddler locks father out of iPad for 25.5 MILLION minutes, or until 2067

Several security issues were fixed in Ruby.

An update for ceph and grafana is now available for Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

As you wrap up this month’s patch installs, don’t forget these four Intel fixes

An update for httpd24-httpd and httpd24-mod_auth_mellon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Mathy Vanhoef (NYUAD) and Eyal Ronen (Tel Aviv University & KU Leuven) found multiple vulnerabilities in the WPA implementation found in wpa_supplication (station) and hostapd (access point). These vulnerability are also collectively known as “Dragonblood”.

The package apache before version 2.4.39-1 is vulnerable to multiple issues including privilege escalation, access restriction bypass and denial of service.

The package thunderbird before version 60.6.1-1 is vulnerable to arbitrary code execution.

The package gnutls before version 3.6.7-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

The package evolution before version 3.32.0-1 is vulnerable to content spoofing.

Lazarus Group rises again from the digital grave with Hoplight malware for all
Smashing Security #123: Backups – a necessary evil?
The Samsung Galaxy S10’s ultrasonic fingerprint scanner is hacked

Backport more patches: – shared/install: Preserve escape characters for escaped unit names (https://github.com/coreos/bugs/issues/2569) – timedate: fix emitted value when ntp client is enabled/disabled (#1696586) – udev: run programs in the specified order (#1696784) – core: add Manager::honor_device_enumeration flag (https://pagure.io/fedora-

The scourge of stalkerware

Multiple vulnerabilities have been found in Git, the worst of which could result in the arbitrary execution of code.

SAS 2019: Joe FitzPatrick Warns of the ‘$5 Supply Chain Attack’
Taj Mahal and SneakyPastes: Kaspersky reveals pair of attacks menacing Asia, Middle East
You Can Now Get This Award-Winning VPN For Just $1/month

Type: Vulnerability. Microsoft Azure DevOps Server and Team Foundation Server are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server and Team Foundation Server are prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server is prone to a spoofing vulnerability; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure DevOps Server is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Open Enclave SDK is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.