Menu

Latest articles

Apple App Store stuffed with hardcore porn and gambling apps
Google paid out $3.4m in bug bounties last year
Update now! Microsoft and Adobe’s February 2019 Patch Tuesday is here
Critical OkCupid Flaw Exposes Daters to App Takeovers
Electric scooters can be hijacked remotely – no password required
When love becomes a nightmare: Online dating scams

Roses are red, violets are blue, watch out for these scams or it may happen to you The post When love becomes a nightmare: Online dating scams appeared first on WeLiveSecurity

Smashing Security #115: Love, Nests, and is 2FA destroying the world?
Cover your NASes: QNAP acknowledges mystery malware but there’s no patch yet
Oh Snapd! Gimme-root-now security bug lets miscreants sock it to your Ubuntu boxes
US counterintelligence agent helped Iran lob cyber-bombs at America, say Uncle Sam’s lawyers
Top tips for Valentine’s Day – and the rest of the year! [VIDEO]
ACLU: Here’s how FBI tried to force Facebook to wiretap its chat app. Judge: Oh no you don’t
Lenovo Watch X Riddled with Security Vulnerabilities
ThreatList: Banking Trojans Are Still The Top Big Bad for Email

security update

Hackers KO Malta’s Bank of Valletta in attempt to nick €13m
‘Dirty Sock’ Flaw in snapd Allows Root Access to Linux Servers
Another flaw found in macOS Mojave’s privacy protection
Unpatched Apple macOS Hole Exposes Safari Browsing History
Evil USB O.MG Cable opens up Wi-Fi to remote attacks
British and US militaries’ drone swarm hackathon definitely isn’t about army tech
620 million records from 16 websites listed for sale on the Dark Web
Security firm beats Adobe by patching reader flaw first
One click and you’re out: UK makes it an offence to view terrorist propaganda even once
Why you should choose a pseudonym at Starbucks

Innocently providing your name at your local coffee shop is just an example of how easy it can be for miscreants to cut through the ‘privacy’ of social media accounts The post Why you should choose a pseudonym at Starbucks appeared first on WeLiveSecurity

The package python2-django before version 1.11.19-1 is vulnerable to denial of service.

The package python-django before version 2.1.6-1 is vulnerable to denial of service.

The package lib32-libcurl-compat before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package lib32-curl before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package lib32-libcurl-gnutls before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package libcurl-gnutls before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package curl before version 7.64.0-1 is vulnerable to arbitrary code execution.

Siemens Warns of Critical Remote-Code Execution ICS Flaw
Double-Stuffed: Dunkin’ Hit by Another Credential-Stuffing Attack
Microsoft Patches Zero-Day Browser Bug Under Active Attack

security update

Critical WordPress Plugin Flaw Allows Complete Website Takeover
Attackers Completely Destroy VFEmail’s Secure Mail Infrastructure
VFEmail suffers ‘catastrophic’ attack, as hacker wipes email service’s primary and backup data
Ever used VFEmail? No? Well, chances are you never will now: Hackers wipe servers, backups in ‘catastrophic’ attack

The package aubio before version 0.4.9-1 is vulnerable to denial of service.

The package libu2f-host before version 1.1.7-1 is vulnerable to arbitrary code execution.

Major Container Security Flaw Threatens Cascading Attacks
Xiaomi M365 Electric Scooter Hacked and Remotely Controlled

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low.

Risk Level: Very Low.

Adobe Fixes 43 Critical Acrobat and Reader Flaws
Linux container bug could eat your server from the inside – patch now!
Apple to pay teenager who uncovered FaceTime bug

The decision to award the bug has been welcomed but one security researcher has said that they need to do more to compensate those who find bugs The post Apple to pay teenager who uncovered FaceTime bug appeared first on WeLiveSecurity

Q. What’s a good thing to put outside a building of spies? A: A banner saying ‘here we are!’
First they came for Equifax and we did nothing because America. Now they are coming for back-end systems and we’re…
Russian ISPs plan internet disconnection test for entire country
Apple sued for ‘forcing’ 2FA on accounts
Kids as young as eight falling victim to online predators
Brave browser explains Facebook whitelist to concerned users
Facebook defends gun-law loophole firm as “political advertisers”
Intel SGX ‘safe’ room easily trashed by white-hat hacking marauders: Enclave malware demo’d

The package spice before version 0.14.0-3 is vulnerable to arbitrary code execution.

The package chromium before version 72.0.3626.81-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, content spoofing and insufficient validation.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

620 million accounts stolen from 16 hacked websites now for sale on dark web, seller boasts
Network kit biz Phoenix takes heat as flaws may leave industrial control system security in ashes
Patch this run(DM)c Docker flaw or you be illin’… Tricky containers can root host boxes. It’s like that – and that’s the way it is

security update

Threatpost Poll: Is It Impossible to Secure Mobile Devices?
U.S. Senators Urge VPN Ban for Federal Workers Over Spying
Temporary Patch Released For Adobe Reader Zero-Day
‘Now is the winter of our disk contents’: Decision on Lauri Love’s seized gear due next week

The package firefox before version 65.0-1 is vulnerable to multiple issues including arbitrary code execution, privilege escalation and access restriction bypass.

The package dovecot before version 2.3.4.1-1 is vulnerable to authentication bypass.

Exposed: Instagram, OKCupid, Mumsnet All Face Data Concerns
First ‘Clipper’ Malware Discovered on Google Play
Managing Enterprise Security After the Data Supernova
Crypto mirror on the wall, who’s the smartest of them all?
Automatic 4K/HD for YouTube extension pulled from Chrome Store for pop-up ad abuse
Accused hacker Lauri Love tries to retrieve Fujitsu lappie and other gear from Britain’s FBI in court
Oh dear, Lads: Spam marketing bosses banned from forming UK firms for clobbering folk with 500k calls and texts
McDonalds app users hatin’ it after being hacked by hungry hamburglars
Secret Service busts online car sales crime ring
What comes after air gaps? DARPA asks world for ideas
Some OkCupid users have their accounts compromised. Why don’t more dating apps use 2FA?
Get-rich-quick social media scams are turning teens into money mules
You can now unsend messages in Facebook Messenger
QNAP NAS user? You’d better check your hosts file for mystery anti-antivirus entries

security update

Botched Mumsnet update allowed users to see details of strangers’ accounts
These iOS apps have been secretly recording your screen activities
Flaws in RDP protocols leaving machines prone to remote code execution
Upcoming Firefox version to offer fingerprinting & cryptomining protection
New cryptocurrency malware SpeakUp hits Linux & Mac devices
Crypto exchange loses access to $145M after CEO dies without giving password