Menu

Latest articles

Multiple vulnerabilities were found in the PuTTY SSH client, which could result in denial of service and potentially the execution of arbitrary code. In addition, in some situations random numbers could potentially be re-used.

Several vulnerabilities have been found in the Apache HTTP server. CVE-2019-0217

An update that fixes 16 vulnerabilities is now available.

Preinstalled Mobile Security App on Xiaomi Handsets Delivered Vulnerabilities, Not Protection
Facebook and Amazon are Locked in a Blame Game Over Leaked Data: Who’s Really To Blame?
540 million records on Facebook users exposed by third-party apps

The databases, sitting unprotected on cloud servers, contained reams of information amassed by two apps integrated with the social network The post 540 million records on Facebook users exposed by third-party apps appeared first on WeLiveSecurity

Capita bags £13.2m Police Scotland deal for crime-snooping tech
Ethiopia sits on 737 Max report but says pilots followed Boeing drills

An update that fixes 15 vulnerabilities is now available.

Unsecured databases found leaking half a billion resumes onto the net, no password required
Free Cynet Threat Assessment for Mid-sized and Large Organizations
Facebook apps expose millions of users’ Facebook data
You don’t need a PhD to phish a Brit university: Nonprofit claims 100% hit rate is easy peasy
Why ‘PWNED!’ is appearing on some GPS smartwatches
BEC Scam Gang London Blue Evolves Tactics, Targets
Android banking and finance apps’ security found wanting
Facebook won’t ask for your email password any more

Adam Dobrawy, Frederico Silva and Gregory Brzeski from HyperOne.com discovered that pdns, an authoritative DNS server, did not properly validate user-supplied data when building a HTTP request from a DNS query in the HTTP Connector of the Remote backend. This would allow a

AdvanceCOMP could be made to run arbitrary code if it opened a specially crafted file.

Several security issues were fixed in the Apache HTTP Server.

Yup, it’s the new tax year: If you smell a RAT, it’s because crims are ramping up tax scams
Apache needs a patchy! Carpe Diem, update now
SAS 2019 to Tackle APTs, Supply Chains and More
Here’s to you: UK.gov praises Reg-reading techies for keeping on top of cybersecurity
NIST cybersecurity resources for smaller businesses

How can smaller businesses address their cybersecurity risks without the resources of large organizations? The post NIST cybersecurity resources for smaller businesses appeared first on WeLiveSecurity

Smashing Security #122: The big fat con at Office Depot
Who needs foreign servers? Researchers say the USA is doing a fine job of harboring its own crimeware flingers

Multiple vulnerabilities have been found in Xen, the worst of which could result in privilege escalation.

It’s time to reset the ‘Days without a Facebook data loss’ sign after 500 million records left exposed on AWS
Nvidia Fixes 8 High-Severity Flaws Allowing DoS, Code Execution
540 million Facebook users left exposed due to sloppy third-party developer security

An update that fixes three vulnerabilities is now available.

An update that solves three vulnerabilities and has 17 fixes is now available.

An update that solves three vulnerabilities and has 17 fixes is now available.

Security fix for CVE-2018-20662, CVE-2019-9631, CVE-2019-9200 and CVE-2019-9903.

A patchy Apache a-patchin: HTTP server gets fix for worrying root access hole
Facebook Data of Millions Exposed in Leaky Datasets
In its ransomware response, Norsk Hydro is an example for us all
How to Maximize the Value of Your Cybersecurity Investment
Teen TalkTalk hacker denies flogging stolen personal data for Bitcoin
OceanLotus APT Uses Steganography to Shroud Payloads
Toyota data breach: Hackers steal 3.1 million customers’ data
Inside job: Bithumb crypto exchange hacked again; loses $20 million

Reading Time: ~4 min. Although phishing has been around in various forms since the 1980s, our research shows it continues to evolve—and remains a major threat. These days, phishing tactics have gotten so sophisticated, it can be difficult to spot a scam—particularly in the case of hijacked email reply chains. Let’s look at a concrete example. […]

Just the small matter of the bill for scrapping Blighty’s old nuclear submarines: It’s £7.5bn
Researchers trick Tesla’s Autopilot into driving into oncoming traffic
Is your hard drive exposed online?
2m credit cards ripped off from restaurant chain, sold on the dark web
Patch Android now! April updates fixes three critical flaws
Look who’s stalking

Aren’t we just making it too easy for online followers to become real-life trackers with the amount of open data we are posting online? The post Look who’s stalking appeared first on WeLiveSecurity

Razer – perfectly happy to sell you a laptop for over $2,000, but when it comes to fixing security holes… tough sh*t
Ex-Mozilla CTO: US border cops demanded I unlock my phone, laptop at SF airport – and I’m an American citizen
Mystery of the Chinese woman who allegedly tried to sneak into Trump’s Mar-a-Lago with a USB stick of malware
Your next Game of Thrones download can be a malware – Here’s why
ThreatList: Half of All Attacks Aim at Supply Chain

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Mobile-First Phishing Kit Targets Verizon Customers
Tesla autopilot feature hacked to risk oncoming traffic
Google’s April Android Security Bulletin Warns of 3 Critical Bugs
Is Flawless Anonymity Possible?
Hackers don’t just want to pwn networks, they literally want to OWN your network – and no one knows they’re there

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Government spyware hidden in Google Play store apps
TP-Link router zero-day that offers your network up to hackers
Are there viable alternatives to Facebook and Twitter?
VMware patches critical vulnerabilities
Possible Toyota data breach affecting 3.1 million customers
Wrecked Teslas hang onto your (unencrypted) data
Financial Apps are Ripe for Exploit via Reverse Engineering
The curious case of a WordPress plugin, a rival site spammed with traffic, a war of words, and legal threats
How do you sing ‘We’re jamming and we hope you like jamming, too’ in Russian? Kremlin’s sat-nav spoofing revealed
Don’t be an April Fool: Update your Android mobes, gizmos to – hopefully – pick up critical security fixes

Risk Level: Very Low. Type: Trojan.

March Madness Scams Give Attackers Fast Break
Google Warns of Growing Android Attack Vector: Backdoored SDKs and Pre-Installed Apps
ThreatList: Game of Thrones, a Top Malware Conduit for Cybercriminals
Google Play Boots Italian Spyware Apps That Infected Hundreds
AI infosec biz Darktrace boasts near-doubled revenues as firm alumni battle HPE in civil case
Cryptocurrency exchange loses millions in heist

Bithumb believes that, unlike in the past, this theft was the work of rogue insiders The post Cryptocurrency exchange loses millions in heist appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

Hackers using hacked WordPress & Joomla sites to drop malware

It was discovered that missing input sanitising in the file module of Drupal, a fully-featured content management framework, could result in cross-site scripting.

How to Respond to a Cyber Attack on Your Business
Russia accused of massive GPS spoofing campaign
Microsoft slaps down 99 APT35/Charming Kitten domains

An update that fixes two vulnerabilities is now available.