Menu

Latest articles

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that solves 9 vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

Uber Deployed ‘Surfcam Spyware’ in Australia to Crush the Competition – Report
Google hit with €1.49 billion antitrust fine by EU

The third penalty that Europe has levied on the tech giant in less than two years brings the total to €8.25 billion The post Google hit with €1.49 billion antitrust fine by EU appeared first on WeLiveSecurity

The package wordpress before version 5.1-1 is vulnerable to directory traversal.

The package libelf before version 0.176-1 is vulnerable to denial of service.

MySpace loses 12 years worth of photos, songs & video files

Multiple vulnerabilities have been found in OpenSSH, the worst of which could allow a remote attacker to gain unauthorized access.

Google researcher discovers new type of Windows security weakness
Researchers fret over Netflix interactive TV traffic snooping
Hacked tornado warning systems leave Texans in the dark
Firefox 66 now blocks autoplaying audio by default
Elsevier exposes users’ emails and passwords online
Hydro working hard to recover following ransomware attack
Fake or Fake: Keeping up with OceanLotus decoys

ESET researchers detail the latest tricks and techniques OceanLotus uses to deliver its backdoor while staying under the radar The post Fake or Fake: Keeping up with OceanLotus decoys appeared first on WeLiveSecurity

Israeli fintech firms hit by Cardinal RAT malware

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0597

Silence of the WANs: FBI DDoS-for-hire greaseball takedowns slash web flood attacks ‘by 11%’

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Cardinal RAT Resurrected to Target FinTech Firms
Host of Flaws Found in CUJO Smart Firewall

security update

Podcast: The High-Risk Threats Behind the Norsk Hydro Cyberattack
Ransomware drops the Lillehammer on Norsk Hydro: Aluminium giant forced into manual mode after systems scrambled
Old Tech Spills Digital Dirt on Past Owners
Youve Been Pwned! Best Practices to Prevent Your Email Account from Being Compromised in a Data Breach
New scam accuses you of child abuse, offers to remove evidence

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

cloud-init: extra ssh keys added to authorized_keys on the Azure platform (CVE-2019-0816) SL7 x86_64 cloud-init-18.2-1.el7_6.2.x86_64.rpm – Scientific Linux Development Team

You should pick your Android security app wisely, test shows

It’s prudent to get a security solution for your device, but a test by AV-Comparatives shows why you need to choose judiciously The post You should pick your Android security app wisely, test shows appeared first on WeLiveSecurity

Researcher Says NSA’s Ghidra Tool Can Be Used for RCE
Sorry, Linux. We know you want to be popular, but cyber-crooks are all about Microsoft for now

An update that fixes 9 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Norsk Hydro Calls Ransomware Attack ‘Severe’
Microsoft won’t patch Windows registry warning problem
Gargantuan Gnosticplayers breach swells to 863 million records

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0482

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0485

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0483

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0512

It has been discovered that OTRS (Open source Ticket Request System) is susceptible to code injection vulnerability. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully

ThreatList: DDoS Attack Sizes Drop 85 Percent Post FBI Crackdown
Court: Embarrassing leaks of internal Facebook emails are fishy
Epic in hot water over Steam-scraping code
MySpace loses 50 million songs in server migration
I didn’t see what you did, redux

Cyberblackmail/sextortion again raises its not-so-pretty little head The post I didn’t see what you did, redux appeared first on WeLiveSecurity

Child-friendly search engines: How safe is Kiddle?
PuTTY in your hands: SSH client gets patched after RSA key exchange memory vuln spotted

An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Bandersnatch to gander snatched: Black Mirror choices can be snooped on, thanks to privacy-leaking Netflix streams

security update

Bad cup of Java leaves nasty taste in IBM Watson’s ‘AI’ mouth: Five security bugs to splat in analytics gear

The CLI tools in python-rdflib-tools can load python modules found in the current directory. This happens because “python -m” appends the current directory in the python path.

The ikiwiki maintainers discovered that the aggregate plugin did not use LWPx::ParanoidAgent. On sites where the aggregate plugin is enabled, authorized wiki editors could tell ikiwiki to fetch potentially undesired URIs even if LWPx::ParanoidAgent was installed:

Fourth Major Credential Spill in a Month Hits DreamMarket
Mirai Variant Goes After Enterprise Systems
Google Gives Users More Choice with Location-Tracking Apps
This headline is proudly brought to you by wired keyboards: Wireless Fujitsu model hacked
Home DNA kit company now lets users opt out of FBI data sharing
Privacy Regulations Needed for Next-Gen Cars

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that solves four vulnerabilities and has one errata is now available.

Two vulnerabilities were discovered in SQLALchemy, a Python SQL Toolkit and Object Relational Mapper.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has four fixes is now available.

LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.

Counter-Strike 1.6 game client 0-day exploited to spread Belonard trojan
Hackers are using 19-year-old WinRAR bug to install nasty malware
SimBad malware on Play Store infected millions of Android devices

Several security issues were fixed in file.

Lone staffer killed our shields, claims etailer Gearbest after infosec bods peep at user deets

An update for openstack-octavia is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for ansible is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

DARPA is working on an open source, secure e-voting system
Intel releases patches for code execution vulnerabilities
G Suite admins can now disallow SMS and voice authentication
53% of Britain’s most frequent porn watchers aren’t aware that they’re about to be blocked
WordPress 5.1.1 patches dangerous XSS vulnerability
MySpace has lost all the music users uploaded between 2003 and 2015
Karpeles walks, Google and Microsoft board up Windows hole, and Android AV still sucks
UK code breakers drop Bombe, Enigma and Typex simulators onto the web for all to try

An update that fixes 18 vulnerabilities is now available.

Security fix CVE-2019-9210

Q&A: Crypto-guru Bruce Schneier on teaching tech to lawmakers, plus privacy failures – and a call to techies to act

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that fixes three vulnerabilities is now available.

What was that P word? Ah. Privacy. Yes, we’ll think about privacy, says FCC mulling cellphone location data overhaul

Reading Time: ~2 min. In late February, the notorious cryptojacking script engine called Coinhive abruptly announced the impending end to its service. The stated reason: it was no longer economically viable to run. Coinhive became infamous quickly following its debut as an innovative javascript-based cryptomining script in 2018. While Coinhive maintained that its service was […]

Welcome. You’re now in a timeline in which US presidential hopeful Beto was a member of a legendary hacker crew
Zillow sued for $60 million after mansion listing hijacked
Lenovo Patches High-Severity Arbitrary Code Execution Flaws

An update that fixes four vulnerabilities is now available.