Menu

Latest articles

Citrix Falls Prey to Password-Spraying Attack
Five female technoheroes you might never have heard of…

New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Iranian hackers ransack Citrix, make off with 6TB+ of emails, biz docs, internal secrets

An update that solves 5 vulnerabilities and has 6 fixes is now available.

RSA Conference 2019: Emotet Takes Aim at Latin America

Reading Time: ~2 min. Ransomware as-a-Service Offers Tiered Membership Benefits Jokeroo is the latest ransomware-as-a-service (RaaS) to begin spreading through hacker forums, though it’s differentiating itself by requiring a membership fee with various package offerings. For just $90, a buyer obtains access to a ransomware variant that they can fully customize in exchange for a […]

Serious Security: When randomness isn’t – and why it matters
New backdoor malware hits Slack and Github platforms

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0230

Flaws in smart car alarms exposed 3 million cars to hijack

The vulnerabilities, which resided in associated smartphone apps, were both easy to find and easy to fix The post Flaws in smart car alarms exposed 3 million cars to hijack appeared first on WeLiveSecurity

RSAC 2019: The Dark Side of Machine Learning

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes 15 vulnerabilities is now available.

Nah, National Cyber Security Centre doesn’t need its own minister, UK.gov tells Parliament

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

RSA Conference 2019 Recap
Saudi caller ID app Dalil leaked data of over 5 Million users
Download NSA’s reverse engineering tool GHIDRA
WordPress security: Steps to assess an employee before granting admin access to WordPress
PlayStation serial number leads Feds to bust a massive drug ring
Dark web hacker selling admin access to a Chinese railway company
The Pirate Bay’s preferred cryptominer Coinhive shutting down next week
Hackable car alarms leave three million cars at risk of hijack
RSA conference, USA 2019: Keynotes and key words

A bright tomorrow of technical delight, or a dismal future of digital dysfunction? The post RSA conference, USA 2019: Keynotes and key words appeared first on WeLiveSecurity

No guns or lockpicks needed to nick modern cars if they’re fitted with hackable ‘smart’ alarms
Firefox picks up advertiser-dodging tech from Tor
Zuck says Facebook is becoming more “privacy focused”
RSA 2019: Protecting your privacy in a NIST and GDPR world

Protecting your privacy is no longer just an option but a legal requirement in many parts of the world The post RSA 2019: Protecting your privacy in a NIST and GDPR world appeared first on WeLiveSecurity

Windows Calculator is going open source
Facebook Messenger bug made it possible for hackers to see who you have been chatting with
Developer-only iPhones help reveal Apple’s secret security sauce
Buffer overflow flaw in British Airways in-flight entertainment systems will affect other airlines, but why try it in the air?
What happens when security devices are insecure? Choose the nuclear option
Tech security at Equifax was so diabolical, senators want to pass US laws making its incompetence illegal
IT guy at US govt fraud watchdog stole 16 computers from… US govt fraud watchdog

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Risk Level: Very Low. Type: Trojan.

RSA Conference 2019: Firms Continue to Fail at IoT Security

## drupal8 Upstream: – https://www.drupal.org/project/drupal/releases/8.6.10 – https://www.drupal.org/SA-CORE-2019-003 – https://www.drupal.org/project/drupal/releases/8.6.9 – https://www.drupal.org/project/drupal/releases/8.6.8 – https://www.drupal.org/project/drupal/releases/8.6.7 –

RSA Conference 2019: Ultrasound Hacked in Two Clicks

## drupal8 Upstream: – https://www.drupal.org/project/drupal/releases/8.6.10 – https://www.drupal.org/SA-CORE-2019-003 – https://www.drupal.org/project/drupal/releases/8.6.9 – https://www.drupal.org/project/drupal/releases/8.6.8 – https://www.drupal.org/project/drupal/releases/8.6.7 –

Put down the cat, coffee, beer pint, martini, whatever you’re holding, and make sure you’ve updated Chrome (unless you enjoy being hacked)

When symmetric encryption is used, data can be injected through the passphrase property of the gnupg.GPG.encrypt() and gnupg.GPG.decrypt() methods. The supplied passphrase is not validated for newlines, and the library passes –passphrase-fd=0 to the gpg executable, which expects the passphrase on the first line of stdin, and the ciphertext to be decrypted

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a […]

If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. […]

A flaw was found in Nagios Core version 4.4.1 and earlier. The qh_help function is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket (CVE-2018-13441).

Unclosable browser popup! 13-year-old charged for sharing code
RSAC 2019: For Domestic Abuse, IoT Devices Pose New Threat
NSA might shut down phone snooping program, whatever that means

NVIDIA graphics drivers could be made to expose sensitive information.

Monero cryptominers hijack hundreds of unpatched Docker hosts

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

UK’s ICO event on targeted ads opens floor to the adtech industry: Anybody? No? Speak for 10 minutes. Hello?
Backdoored GitHub accounts spewed secret sneakerbot software
The Pirate Bay spreading malware PirateMatryoshka via reputed seeders
NX-OS-hit! Got Cisco Nexus and MDS 9000 switches? Then you’ve got patching to do, too
RSA Conference 2019: NIST’s Privacy Framework Starts to Take Shape
Thousands of patients impacted by ransomware attack at medical billing company
Latest Chrome update plugs a zero-day hole

Users should waste no time in updating to the browser’s latest version The post Latest Chrome update plugs a zero-day hole appeared first on WeLiveSecurity

TalkTalk kept my email account active for 8 years after I left – now it’s spamming my mates
FBI boss warns businesses of Chinese hackers stealing their intellectual property
Schneier: Don’t expect Uncle Sam to guard your web privacy – it’s Europe riding to the rescue
Smashing Security #118: The ‘s’ in IoT stands for security

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

RSA Conference 2019: UniKey Patches BleedingBit Flaws Granting Access To Hotel Rooms, Cars

An update that solves two vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves four vulnerabilities and has four fixes is now available.

security update

RSA Conference 2019: The Sky’s the Limit For Satellite Hacks
RSA Conference 2019: How to Defend Against an AI vs AI ‘Flash War’
Serious Chrome zero-day – Google says update “right this minute”
UK Ministry of Justice: Surprise! We tested out biometric tech in prisons and ‘visitors’ with drugs up their bums ran away

Several security issues were fixed in PHP.

## 1.7.1 – #475: “Loose” lists will now contain paragraphs in all items, not just some. – #433: Links will no longer be double nested – #525: The info- string when beginning a code block may now contain non-word characters (e.g. `c++`) – #561: The `mbstring` extension (which we already depend on) has been added […]

– https://www.drupal.org/project/link/releases/7.x-1.6 – https://www.drupal.org/sa-contrib-2019-020 – https://www.drupal.org/sa- core-2019-003 – https://www.drupal.org/project/link/releases/7.x-1.5 – https://www.drupal.org/project/link/releases/7.x-1.5-beta3

Fixes: CVE-2018-6358, CVE-2018-7867, CVE-2018-7868, CVE-2018-7870, CVE-2018-7871, CVE-2018-7872, CVE-2018-7875, CVE-2018-9165.

Bump to ignition-dracut 2c69925 * support platform configs and user configs in /boot ^ https://github.com/coreos/ignition-dracut/pull/43 * Add ability to parse config.ign file on boot ^ https://github.com/coreos/ignition-dracut/pull/42

– bugfix {foreach} using new style property access like {$item@property} on Smarty 2 style named foreach loop could produce errors https://github.com/smarty-php/smarty/issues/484 31.08.2018 – bugfix some custom left and right delimiters like ‘{^’ ‘^}’ did not work

RSA Conference 2019: Cryptographers’ Panel Decries Adi Shamir’s Visa Issues
RSA Conference 2019: Data-Wiping Cyberattacks Plague Financial Firms
Google reveals BuggyCow macOS security flaw
RSA – IoT security meets SMB

Some tips that businesses can do to get better at it without breaking the bank The post RSA – IoT security meets SMB appeared first on WeLiveSecurity

Leaky ski helmet speakers expose conversations and data
Google Photos disables sharing on Android TV
RSA Conference 2019: Microsoft, Google, Twitter on Federal Privacy Regs
RSAC 2019: TLS Markets Flourish on the Dark Web
How to keep your flock of users secure: Let them know exactly who and where the wolves are
Did you know?! Ghidra, the NSA’s open-sourced decompiler toolkit, is ancient Norse for ‘No backdoors, we swear!’
Level up Mac security, and say game over to malware? System alerts plus Apple game engine equals antivirus package
How to make people sit up and use 2-factor auth: Show ’em a vid reusing a toothbrush to scrub a toilet – then compare it to password reuse
NSA may kill off mass phone spying program Snowden exposed, says Congressional staffer
Facebook criticised for misuse of phone numbers provided for security
You. Shall. Not. Pass… word: Soon, you may be logging into websites using just your phone, face, fingerprint or token