Menu

Latest articles

An update that solves 8 vulnerabilities and has 73 fixes is now available.

Several security issues identified in ikiwiki fixed by updating to version 3.20190228. See references for details References: – https://bugs.mageia.org/show_bug.cgi?id=24453

Sextortion – what’s new, and what to do [VIDEO]

Reading Time: ~2 min. Georgia County Pays Six Figure Ransom to Restore IT Systems Following a ransomware attack earlier this month, officials in Jackson County, Georgia decided to pay a $400,000 ransom in order to obtain a decryption key and return their systems to normal operations. While it’s not normally recommended to pay ransoms, but […]

Unpatched Fujitsu Wireless Keyboard Bug Allows Keystroke Injection
You left WHAT on that USB drive?!
Public spending watchdog snipes at UK.gov’s £1.3bn infosec plan – but broadly nods it through
Facebook outage coincides with (or causes?) 3m new Telegram users
How to make DuckDuckGo your default Chrome search engine
Will the next version of Android get location privacy right?
So you need an IT security center. Fret not: Let an automated solution take the strain
Threatlist: IMAP-Based Attacks Compromising Accounts at ‘Unprecedented Scale’
Zero-Days in Counter-Strike Client Used to Build Major Botnet
Open-source 64-ish-bit serial number gen snafu sparks TLS security cert revoke runaround
Don’t be a WordPress RCE-hole and patch up this XSS vuln, pronto

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Serious Security: What we can all learn from #PiDay
Cisco Patches Critical ‘Default Password’ Bug
GlitchPOS Malware Appears to Steal Credit-Card Numbers
Online training site says it is spamming insecure printers with adverts

An update that fixes two vulnerabilities is now available.

Protip: If you’d rather cyber-scoundrels didn’t know the contents of your comp, don’t apply for a Pakistani passport
Man drives 3,300 miles to talk to YouTube about deleted video
“BreedReady” database of 1.8m Chinese women surfaced online
More than Half of Android apps ask for dangerous permissions. Is yours among?
Hackers cop a FILA thousands of UK card deets after slinking onto clothing brand’s servers

An update is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openstack-octavia is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openstack-ceilometer is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Pakistani Govt’s passport application tracking site hacked with Scanbox framework
US Senators say it shouldn’t be a secret when they’ve been hacked
Insider Threats Get Mean, Nasty and Very Personal
Google needs breaking up, says news chief
Update now! Microsoft’s March 2019 Patch Tuesday is here
Facebook suffer most severe outage ever

Facebook owned Instagram and WhatsApp also affected by unexplained interruption The post Facebook suffer most severe outage ever appeared first on WeLiveSecurity

An update for haproxy is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for haproxy is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

What do sexy selfies, search warrants, tax files have in common? They’ve all been found on resold USB sticks

Multiple vulnerabilities have been found in Oracles JDK and JRE software suites.

Multiple vulnerabilities have been found in BIND, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been found in WebkitGTK+, the worst of which could result in the arbitrary execution of code.

A vulnerability was discovered in XRootD which could lead to the remote execution of code.

Multiple Information Disclosure vulnerabilities in OpenSSL allow attackers to obtain sensitive information.

A vulnerability in the GNU C Library could result in a Denial of Service condition.

Thought you were done patching this week? Not if you’re using an Intel-powered PC or server
Smashing Security #119: Hijacked homes, porn passports, and ransomware regret
New Samsung Galaxy S10 review and features

security update

security update

Purveyor of Cracked Netflix, Hulu, Spotify Accounts Arrested
Just Android things: 150m phones, gadgets installed ‘adware-ridden’ mobe simulator games

Type: Vulnerability. Microsoft NuGet is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Common Control Library is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Azure is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Visual Studio is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a security-bypass vulnerability; fixes are available.

Intel Windows 10 Graphics Drivers Riddled With Flaws
Facebook and Instagram are down around the world
Open-source key gen snafu sparks 63-bit TLS cert revoke runaround

Multiple buffer overflow security issues have been found in libsdl2, a library that allows low level access to a video frame buffer, audio output, mouse, and keyboard.

Multiple buffer overflow security issues have been found in libsdl1.2, a library that allows low level access to a video frame buffer, audio output, mouse, and keyboard.

openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) (CVE-2018-5407) Bug Fix(es): * Perform the RSA signature self-tests with SHA-256 SL7 x86_64 openssl-1.0.2k-16.el7_6.1.x86_64.rpm openssl-debuginfo-1.0.2k-16.el7_6.1.i686.rpm openssl-debuginfo-1.0.2k-16.el7_6.1.x86_64.rpm openssl-libs-1.0.2k-16.el7_6.1.i686.rpm openssl-libs-1.0.2k-16.el [More…]

cockpit: Crash when parsing invalid base64 headers (CVE-2019-3804) SL7 x86_64 cockpit-173.2-1.el7.x86_64.rpm cockpit-bridge-173.2-1.el7.x86_64.rpm cockpit-debuginfo-173.2-1.el7.i686.rpm cockpit-debuginfo-173.2-1.el7.x86_64.rpm cockpit-ws-173.2-1.el7.i686.rpm cockpit-ws-173.2-1.el7.x86_64.rpm cockpit-doc-173.2-1.el7.x86_64.rpm cockpit-173.2-1.el7.src.rpm noa [More…]

Risk Level: Very Low. Type: Trojan.

MAGA ‘Safe Space’ App Developer Threatens Security Researcher

An update for tomcat is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Three Ways DNS is Weaponized and How to Mitigate the Risk
Threat Groups SandCat, FruityArmor Exploiting Microsoft Win32k Flaw

Updates for rh-dotnetcore10-dotnetcore, rh-dotnetcore11-dotnetcore, rh-dotnet21-dotnet, and rh-dotnet22-dotnet are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

It was found that the fix for CVE-2018-19758 was incomplete. That has been addressed in this update. The description for CVE-2018-19758 follows:

Online safety cartoons for young kids
“FINAL WARNING” email – have they really hacked your webcam?
Chrome will soon block drive-by-download malvertising

An update for cockpit is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openssl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Update now! WordPress abandoned cart plugin under attack
Misconfigured Box accounts leak terabytes of companies’ sensitive data
Man arrested for selling one million Netflix, Spotify, Hulu passwords

Reading Time: ~3 min. The True Cost of Free WiFi Ease-of-access is a true double-edged sword. Like all powerful technologies, WiFi (public WiFi in particular) can be easily exploited. You may have read about attacks on publicly accessible WiFi networks, yet studies show that more than 70% of participants admit to accessing their personal email […]

Ross Geerlings discovered that the XMLTooling library didn’t correctly handle exceptions on malformed XML declarations, which could result in denial of service against the application using XMLTooling.

Why Your Current Approach to Email Security May Not Be Enough
New bill would give parents an ‘Eraser Button’ to delete kids’ data
This is the Send, encrypted end-to-end, this is the Send, my Mozillan friend

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Microsoft changes DHCP to ‘Dammit! Hacked! Compromised! Pwned!’ Big bunch of security fixes land for Windows
Federal Focus on Cyber Plays Out in President’s Budget, IoT Legislation