November 2019 Patch Tuesday fixes 13 critical flaws and one zero day

Credit to Author: John E Dunn| Date: Wed, 13 Nov 2019 17:12:34 +0000

November’s Patch Tuesday arrived to plug 73 CVE-level vulnerabilities across Microsoft’s software products, including 13 ‘criticals’.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/mcprAY-1N-s” height=”1″ width=”1″ alt=””/>

Read more

Nvidia patches graphics products and GeForce Experience update tool

Credit to Author: John E Dunn| Date: Tue, 12 Nov 2019 11:58:11 +0000

The update fixes 11 mainly high-severity security flaws in Windows and GeForce graphics card drivers, including three in the program used to update them.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/dRHL2MrNvkw” height=”1″ width=”1″ alt=””/>

Read more

Microsoft urges us to patch after partially effective BlueKeep attack

Credit to Author: Danny Bradbury| Date: Mon, 11 Nov 2019 15:58:08 +0000

Microsoft has urged people to patch their Windows systems following the appearance of mass BlueKeep exploits just over a week ago.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/t3L4UyESmBg” height=”1″ width=”1″ alt=””/>

Read more

Adobe fixes SDK weakness affecting mobile apps

Credit to Author: John E Dunn| Date: Mon, 11 Nov 2019 12:13:21 +0000

Researchers noticed that the main app configuration file, ADBMobileConfig.json, contained settings that could lead to security problems.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/a-eEyz1mh7c” height=”1″ width=”1″ alt=””/>

Read more

WordPress sites hit by malvertising

Credit to Author: Danny Bradbury| Date: Thu, 07 Nov 2019 14:01:01 +0000

An old piece of malware is storming the WordPress community, enabling its perpetrators to take control of sites and inject code of their choosing.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/G42iCdpslDg” height=”1″ width=”1″ alt=””/>

Read more

Linux users warned to update libarchive to beat flaw

Credit to Author: John E Dunn| Date: Thu, 07 Nov 2019 13:16:51 +0000

The bug is identified as CVE-2019-18408, a high-priority ‘use-after-free’ bug when dealing with a failed archive.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/r2L9Nrq5wnQ” height=”1″ width=”1″ alt=””/>

Read more

Smartphone and speaker voice assistants can be hacked using lasers

Credit to Author: John E Dunn| Date: Wed, 06 Nov 2019 13:03:16 +0000

A US-Japanese team published a research paper which confirms an interesting and under-estimated possibility – these devices will also accept “signal injection” commands sent to them using pulses of laser light over distances of a hundred metres or more.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/_7WhfQGzceQ” height=”1″ width=”1″ alt=””/>

Read more

Office for Mac 2011 users warned about SYLK file format

Credit to Author: John E Dunn| Date: Tue, 05 Nov 2019 17:14:21 +0000

Still running Office 2011 on a Mac? If so, there are at least two reasons why that might not be a good idea.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/HjBh551ovHI” height=”1″ width=”1″ alt=””/>

Read more

Google patches bug that let nearby hackers send malware to your phone

Credit to Author: Danny Bradbury| Date: Tue, 05 Nov 2019 14:42:47 +0000

Google has patched an Android bug that could have allowed attackers to use NFC to send over a malicious file to the victim’s phone<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/9svl-4gT4-I” height=”1″ width=”1″ alt=””/>

Read more