Menu

Latest articles

Latest 4G, 5G phone-location slurp attack is a doozy, but won’t Torpedo Average Joe or Jane
‘Cloudborne’ IaaS Attack Allows Persistent Backdoors in the Cloud

LinuxSecurity.com: The package logstash before version 6.6.1-1 is vulnerable to information disclosure.

LinuxSecurity.com: The package elasticsearch before version 6.6.1-1 is vulnerable to privilege escalation.

Harassment, hate and bile, suicide instructions for kids… anything else social media’s good at? Ah yes, cybercrime

LinuxSecurity.com: An update for polkit is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

6 Pieces of Tech Every Office Needs
High-Severity SHAREit App Flaws Open Files for the Taking

LinuxSecurity.com: LDB could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: USN-3866-2 introduced a regression in Ghostscript.

LinuxSecurity.com: GNOME Keyring could be made to expose sensitive information.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

Critical WinRAR Flaw Found Actively Being Exploited
Google aims for password-free app and site logins on Android

With FIDO2 certification for Android, Google is setting the stage for password-less app and website sign-ins on a billion devices The post Google aims for password-free app and site logins on Android appeared first on WeLiveSecurity

LinuxSecurity.com: ultiple vulnerabilities have been discovered in liblivemedia, the LIVE555 RTSP server library: CVE-2019-6256

Mozilla fears encryption law could turn its employees into insider threats
ICANN demands DNSSEC combats DNS hijacking

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 7 vulnerabilities is now available.

LinuxSecurity.com: The package kibana before version 6.6.1-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

Two weeks after hackers tried to steal 13 million euros, Bank of Valletta goes offline again
The Dark Sides of Modern Cars: Hacking and Data Collection
Facebook apps secretly sending sensitive data back to the mothership
Android nudges passwords closer to the cliff edge with FIDO2 support
Who needs malware? IBM says most hackers just PowerShell through boxes now, leaving little in the way of footprints
Threatpost Data: Password Managers Are Worth the Risk, Readers Say
Jeez, what a Huawei to go: Now US senators want Chinese kit ripped out of national leccy grid
Check your VPN DNS test tool legitimacy: Is it “good” or deceptive
China’s tech giants are a security threat to the UK, says Brit spy bigwig

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

Risk Level: Very Low. Type: Trojan.

ToRPEDO Privacy Attack on 4G/5G Networks Affects All U.S. Carriers
Russian creator of NeverQuest banking trojan pleads guilty in American court

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Burger chain Wendy’s serves up settlement, NeverQuest hacker guilty, cloudy payroll users hacked and more
Escalating DNS attacks have domain name steward worried

The keeper of the internet’s ‘phone book’ is urging a speedy adoption of security-enhancing DNS specifications The post Escalating DNS attacks have domain name steward worried appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in Bind.

Google Ditches Passwords in Latest Android Devices
Your $350 Nike self-lacing sneakers aren’t as smart as you hoped
Missile warning sent from hijacked Tampa mayor’s Twitter account
Facebook tricked kids into in-game purchases, say privacy advocates
Adobe patches the same critical Reader flaw twice in one week

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: A newer version of waagent is needed for several features of the Azure platform. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: The package msmtp before version 1.8.3-1 is vulnerable to certificate verification bypass.

LinuxSecurity.com: The package python-mysql-connector before version 8.0.15-1 is vulnerable to authentication bypass.

Nike’s $350 “Back to the Future” trainers crash, have feet of brick
Understanding VPN through open systems interconnection model
Major Android ad fraud scam campaign drains battery & eats data
Severe flaws in password managers let hackers extract clear-text passwords
Setting up a Django application on RHEL 8 Beta
Phishing Scam Cloaks Malware With Fake Google reCAPTCHA
Reddit Gold: Alice and Bob, Caught in a Web of Lies
Entrust Datacard lined up to unburden Thales of nCipher biz as price for Gemalto buyout
Video: HackerOne CEO on the Evolving Bug Bounty Landscape
Data Breaches of the Week: Tales of PoS Malware, Latrine Status
Threatpost News Wrap Podcast For Feb. 22

Reading Time: ~2 min. Email Phishers Find New Filter Bypass Since email filters have gained popularity over the last decade, scammers have been forced to adapt their attacks. To bypass a normal URL filter that would check for malicious links, these scammers have found a way to alter the “document relationship” file (xml.rels) and continue […]

Android banking malware distributed with fake Google reCAPTCHA
Taking Care of Your Personal Online Security (For Paranoids)
Infosec in spaaace! NCC and Surrey Uni to pore over satellite security
Facebook lets Android users block location tracking
Cyber-extortionists take aim at lucrative targets

A new report shines some light on multiple aspects of the growing threat of cyber-extortion The post Cyber-extortionists take aim at lucrative targets appeared first on WeLiveSecurity

Advertisers flee YouTube after video comments get even more disgusting
Microsoft fixes web server DDoS bug
Flash “security bypass” list hidden in Microsoft Edge browser
Threatpost Poll: Are Password Managers Too Risky?
Bluetooth “gas station” warning on Facebook – truth or hoax? [VIDEO]
WTF PDF: If at first you don’t succeed, you may be Adobe re-patching its Acrobat, Reader patches

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft .NET Framework and Visual Studio are prone to an security vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.

ThreatList: Porn-Focused Malware Triples, Dark Web Loves It
Adobe Re-Patches Critical Acrobat Reader Flaw
Black-hat sextortionists required: Competitive salary and dental plan
Highly Critical Drupal RCE Flaw Affects Millions of Websites
Password managers leaking data in memory, but you should still use one
19-Year-Old WinRAR Flaw Plagues 500 Million Users
Hacker Lauri Love denied bid to get computers back
Toyota Australia driven offline by cyber attack, as heart hospital hit by ransomware
Sorry, we didn’t mean to keep that secret microphone a secret, says Google

Reading Time: ~3 min. “Internet of things” (IoT) is a term that’s becoming increasingly commonplace in our daily lives. Internet-connected devices are being designed and implemented at a rapid clip, especially in our own homes. The internet is not just at our fingertips anymore, but also at our beck and call with smart speakers and […]

How costly are sweetheart swindles?

And that’s on top of the heartache experienced by the tens of thousands of people who fall for romance scams each year The post How costly are sweetheart swindles? appeared first on WeLiveSecurity

Data breach rumours abound as UK Labour Party locks down access to member databases
Welcome to the sunlit uplands of HTTP/2, where a naughty request can send Microsoft’s IIS into a spin
139 US bars, restaurants and coffeeshops infected by credit-card stealing malware
Bored bloke takes control of British Army ‘psyops’ unit’s Twitter
Check yo self before you HyperWreck yo self: Cisco fixes gimme-root holes in HyperFlex, plus more security bugs
Where’s Zero Cool when you need him? Loose chips sink ships: How hackers could wreck container vessels
Smashing Security #116: Stalking debtors, Facebook farce, and a cyber insurance snag
No RESTful the wicked: If your website runs Drupal, you need to check for security updates – unless you enjoy being hacked
Behold… a WinRAR security bug that’s older than your child’s favorite YouTuber. And yes, you should patch this hole
Facebook hoax? Can you sniff out gas station card skimmers using Bluetooth?
Researcher: Not Hard for a Hacker to Capsize a Ship at Sea
Separ Malware Plucks Hundreds of Companies’ Credentials in Ongoing Phish

security update