article thumbnail

Google discloses a severe flaw in widely used Libgcrypt encryption library

Security Affairs

Google discovered a flaw in GNU Privacy Guard (GnuPG)’s Libgcrypt encryption library that could be exploited to get remote code execution. It’s also the crypto library used by systemd for DNSSEC. The team recommends users to stop using the vulnerable version of the library. which we released last week.

Libraries 359
article thumbnail

CVE-2024-44243 macOS flaw allows persistent malware installation

Security Affairs

An attackers with root access can to add a custom file system bundle to /Library/Filesystems. Since an attacker that can run as root can drop a new file system bundle to/Library/Filesystems, they can later triggerstoragekitdto spawn custom binaries, hence bypassing SIP.” ” concludes Microsoft.

Libraries 280
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Vulnerabilities in Microsoft apps for macOS allow stealing permissions

Security Affairs

These flaws could allow attackers to inject malicious libraries into Microsoft’s apps and steal permissions. Despite these risks, Microsoft considers the issues low-risk and declined to fix them, stating that some apps need to allow unsigned libraries for plugin support. ” continues the report.

Libraries 327
article thumbnail

Apple will delay the rollout of new child pornography protection tools

Security Affairs

Apple will delay the introduction of its new child pornography protection tools due to a heated debate raised by privacy advocates. Apple announced this week that it will delay the rollout of its new child pornography protection tools after many experts and privacy advocated claimed it poses a threat to user privacy.

Privacy 264
article thumbnail

EU launches bug bounty programs for 15 software

Security Affairs

Bug bounties for other nine products ( FLUX TL , KeePass , 7-zip , Digital Signature Services (DSS) , Drupal , GNU C Library ( glibc ) , PHP Symfony , Apache Tomcat , and WSO2 ) are arranged through the Intigrity platform. GNU C Library (glibc). The bug bounty programs are arranged via the HackerOne platform. 15/10/2019.

Libraries 279
article thumbnail

Security Affairs newsletter Round 248

Security Affairs

of the Privacy Framework. Malware attack took down 600 computers at Volusia County Public Library. Expert found a hardcoded SSH Key in Fortinet SIEM appliances. NIST releases version 1.0 The Mystery of Fbot. US-based childrens clothing maker Hanna Andersson discloses a data breach. Yomi Hunter Catches the CurveBall.

Security 283
article thumbnail

Analyzing IP Addresses to Prevent Fraud for Enterprises

Security Affairs

They have often reacted negatively, making privacy online a great worry. They can use a coffee shop or library for free WiFi. Businesses can safely and freely share data through appropriate procedures and agreements, effectively safeguarding the privacy of their consumers in the process. Final Words . Pierluigi Paganini.

Privacy 358