Menu

Latest articles

Federal Focus on Cyber Plays Out in President’s Budget, IoT Legislation
Microsoft Patches Two Win32k Bugs Under Active Attack
Yelp-for-MAGAs app maker is warned there are holes in its code. Does it A. Just fix the problem, or B. Threaten to call the FBI, too?
ThreatList: Phishing Attacks Doubled in 2018
Swiss electronic voting system like… wait for it, wait for it… Swiss cheese: Hole found amid public source code audit
ProtonMail back up in Russia, firm says, after regime chokes access over ‘terrorist activity’
Raiding party! UK’s ICO drops in unannounced on couple of dodgy-dialling dirtbag outfits
Unpatched Windows Bug Allows Attackers to Spoof Security Dialog Boxes
Adobe Patches Critical Photoshop, Digital Edition Flaws
Reg webinar: Tune in for some knowledge on how to become an effective leader in IT security
Hey Insiders! DTrace can now run riot in Windows 10, if you really want it to

LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.

Facebook sues developers over data-scraping quizzes
Study throws security shade on freelance and student programmers
Citrix admits attackers breached its network – what we know
Email list-cleaning site may have leaked up to 2 billion records
John Oliver bombards the FCC with anti-robocall robocall campaign
2 security tricks your cloud provider won’t tell you

An update that solves 8 vulnerabilities and has two fixes is now available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge and Internet Explorer are prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows VBScript Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Skype for Business and Lync Server is prone to a spoofing vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and ChakraCore are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows VBScript Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows VBScript Engine is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office Access Connectivity Engine is prone to a remote code-execution vulnerability; fixes are available.

Several security vulnerabilities were discovered in Zabbix, a server/client network monitoring solution. CVE-2016-10742

The package pacman before version 5.1.3-1 is vulnerable to arbitrary code execution.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0462

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

The Handmaid’s Tale or Man-made Fail? Exposed DB of ‘BreedReady’ women probably not as bad as it sounds
Researcher Claims Iranian APT Behind 6TB Data Heist at Citrix
Google Patches Critical Bluetooth RCE Bug
Forrester: Ransomware Set to Resurge As Firms Pay Off Attacks
Citrix hackers may have stolen six terabytes worth of files
NASA’s crap infosec could be ‘significant threat’ to space ops
Hapless engineers leave UK cable landing station gate open, couple of journos waltz right in
Over 2 billion records exposed by email marketing firm

The repository of email addresses and other records would offer a gold mine of data for scammers The post Over 2 billion records exposed by email marketing firm appeared first on WeLiveSecurity

Facebook Alleges Two Ukrainians Scraped Data From 63K Profiles
Facebook sues quiz app developers who allegedly stole users’ private data through browser plugins
Just a reminder: We’re still bad at securing industrial controllers

poppler could be made to crash if it opened a specially craftedfile.

US Army clarifies its killer robot plans
Why Your Email Security Solution May Not Be Enough
Booking a restaurant? Let Google’s Duplex AI make the call for you
FTC says taxpayer voice phishing scams are up nearly 20x
Gaming industry still in the scope of attackers in Asia

Asian game developers again targeted in supply-chain attacks distributing malware in legitimately signed software The post Gaming industry still in the scope of attackers in Asia appeared first on WeLiveSecurity

Freelance devs: Oh, you wanted the app to be secure? The job spec didn’t mention that
Verifications.io breach: Database with 2 billion records leaked

A vulnerability in GNU Wget which could allow an attacker to obtain sensitive information.

Multiple vulnerabilities have been found in systemd, the worst of which may allow execution of arbitrary code.

Multiple vulnerabilities have been discovered in rdesktop, the worst of which could result in the remote execution of arbitrary code.

security update

A vulnerability in Tar could led to a Denial of Service condition.

Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.

Multiple vulnerabilities have been found in cURL, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec, that could be leveraged to cause a denial of service or possibly remote code execution.