Menu

Latest articles

Razer – perfectly happy to sell you a laptop for over $2,000, but when it comes to fixing security holes… tough sh*t
Ex-Mozilla CTO: US border cops demanded I unlock my phone, laptop at SF airport – and I’m an American citizen
Mystery of the Chinese woman who allegedly tried to sneak into Trump’s Mar-a-Lago with a USB stick of malware
Your next Game of Thrones download can be a malware – Here’s why
ThreatList: Half of All Attacks Aim at Supply Chain

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Mobile-First Phishing Kit Targets Verizon Customers
Tesla autopilot feature hacked to risk oncoming traffic
Google’s April Android Security Bulletin Warns of 3 Critical Bugs
Is Flawless Anonymity Possible?
Hackers don’t just want to pwn networks, they literally want to OWN your network – and no one knows they’re there

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Government spyware hidden in Google Play store apps
TP-Link router zero-day that offers your network up to hackers
Are there viable alternatives to Facebook and Twitter?
VMware patches critical vulnerabilities
Possible Toyota data breach affecting 3.1 million customers
Wrecked Teslas hang onto your (unencrypted) data
Financial Apps are Ripe for Exploit via Reverse Engineering
The curious case of a WordPress plugin, a rival site spammed with traffic, a war of words, and legal threats
How do you sing ‘We’re jamming and we hope you like jamming, too’ in Russian? Kremlin’s sat-nav spoofing revealed
Don’t be an April Fool: Update your Android mobes, gizmos to – hopefully – pick up critical security fixes

Risk Level: Very Low. Type: Trojan.

March Madness Scams Give Attackers Fast Break
Google Warns of Growing Android Attack Vector: Backdoored SDKs and Pre-Installed Apps
ThreatList: Game of Thrones, a Top Malware Conduit for Cybercriminals
Google Play Boots Italian Spyware Apps That Infected Hundreds
AI infosec biz Darktrace boasts near-doubled revenues as firm alumni battle HPE in civil case
Cryptocurrency exchange loses millions in heist

Bithumb believes that, unlike in the past, this theft was the work of rogue insiders The post Cryptocurrency exchange loses millions in heist appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

Hackers using hacked WordPress & Joomla sites to drop malware

It was discovered that missing input sanitising in the file module of Drupal, a fully-featured content management framework, could result in cross-site scripting.

How to Respond to a Cyber Attack on Your Business
Russia accused of massive GPS spoofing campaign
Microsoft slaps down 99 APT35/Charming Kitten domains

An update that fixes two vulnerabilities is now available.

An update that solves 14 vulnerabilities and has 5 fixes is now available.

An update that solves 15 vulnerabilities and has 10 fixes is now available.

An update that solves two vulnerabilities and has 10 fixes is now available.

An update that solves 6 vulnerabilities and has 21 fixes is now available.

Top-secret defense document hoarder Harold Martin pleads guilty
Politicians mistakenly vote the wrong way in controversial internet law
Don’t be foolish when it comes to data security

Dovecot could be made to crash or run programs as an administrator if it opened a specially crafted file.

This update includes the changes in tzdata 2019a for the Perl bindings. For the list of changes, see DLA-1744-1. For Debian 8 “Jessie”, this problem has been fixed in version

VMware emits security alerts, Planet Hollywood chain hacked, SWAT death caller gets 20 years in clink, and more

security update

Several vulnerabilities have been found in php5, a server-side, HTML-embedded scripting language.

security update

Brit founder of Windows leaks website BuildFeed, infosec bod spared jail over Microsoft hack
​Brush up your cybersecurity credentials at SANS Stockholm 2019

Update to 3.0. License has changed to ASL 2.0 + exception. See https://github.com/michaelrsweet/mxml/releases/tag/v3.0 for more info.

Security fix for CVE-2018-19872

Medical Weed Dispensary Exposes Health Data for Thousands

A security vulnerability was discovered in gpsd, the Global Positioning System daemon. A stack-based buffer overflow may allow remote attackers to execute arbitrary code via traffic on port 2947/TCP or crafted JSON inputs.

Multiple security issues have been found in the Thunderbird mail client, which could lead to the execution of arbitrary code or denial of service. For the stable distribution (stretch), these problems have been fixed in

The impact of the GDPR – privacy matters

An update that contains security fixes can now be installed.

An update that fixes three vulnerabilities is now available.

An update that solves two vulnerabilities and has 53 fixes is now available.

Undocumented Intel VISA Tech Can Be Abused, Researchers Allege

security update

An update that solves four vulnerabilities and has 7 fixes is now available.

An update that fixes 11 vulnerabilities is now available.

An update that solves 9 vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Family locator app leaked real-time location data of 238,000 individuals
Critical RCE Bug in Cisco WebEx Browser Extensions Faces ‘Ongoing Exploitation’
Brit founder of Windows leaks website Buildfeed and infosec bod spared jail for hacking Microsoft
New Gustuff Android malware targets cryptocurrency & messaging apps
Magento Patches Critical SQL Injection and RCE Vulnerabilities
Zero-Day Bug Lays Open TP-Link Smart Home Router

Reading Time: ~2 min. First GDPR Fine Issued in Poland The first fine issued from the Polish privacy regulator has been issued to an unnamed firm for quietly gathering personal data for over 6 million Polish citizens and using it for commercial gains without consent. The fine of £187,000 was generated after officials learned that only […]

Terrorist’s mainfesto used to spread disk-wiping malware

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that fixes four vulnerabilities is now available.

Critical Rockwell Automation Bug in Drive Component Puts IIoT Plants at Risk

An update that solves one vulnerability and has four fixes is now available.

An update that fixes two vulnerabilities is now available.

Privacy in 2019: 6 Basic Steps to Keep Yourself Protected
As drones fill the skies, cybercriminals won’t be far behind

This kernel update is based on the upstream 4.14.106 and fixes atleast the following security issue: In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers

The updated live, mplayer, vlc packages fix security vulnerabilities: liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation