Menu

Monthly Archives: January 2020

Advanced Obfuscation Marks Widespread Info-Stealing Campaign
Evil Corp Returns With New Malware Infection Tactic
Cyber criminals using Coronavirus emergency to spread malware

In Qt5’s plugin loader code as found in qtbase-opensource-src, it was possible to (side-)load plugins from “the” local folder in addition to a system-widely defined library path.

Iranian Hackers Target U.S. Gov. Vendor With Malware
Remember those infosec fellas who were cuffed while testing the physical security of a courthouse? The burglary charges have been dropped

* Fix issues while trying to play a video on NextCloud. * Make sure the GL video sink uses a valid WebKit shared GL context. * Fix vertical alignment of text containing arabic diacritics. * Fix build with icu 65.1. * Fix page loading errors with websites using HSTS. * Fix web process crash when […]

Reading Time: ~ 2 min. Indonesian Magecart Hackers Arrested At least three individuals were arrested in connection to the infamous Magecart information stealing malware. Thanks to the combined efforts of several international law enforcement agencies, numerous servers issuing commands to awaiting Magecart scripts have been taken down in both Indonesia and Singapore. While these are […]

Top 10 Best Writing Tools

Several vulnerabilities were fixed in libjackson-json-java. CVE-2017-7525

Travelex hobbles back online, one month after ransomware hit it hard
Serious Security – How ‘special case’ code blew a hole in OpenSMTPD
Zero Day Initiative Bug Hunters Rake in $1.5M in 2019
$20,000 up for grabs in Xbox Live security hole hunt
€13 million Maltese bank cyber-heist – six men arrested in UK
Sodinokibi Ransomware Group Sponsors Hacking Contest
UN hacked via unpatched SharePoint server
China’s Winnti hackers (apparently): Forget the money, let’s get political and start targeting Hong Kong students for protest info
US Interior Dept extends drone grounding over foreign hacking fears
Sonos goofs again – this time revealing customers’ email addresses in Cc: blunder
Financial tech firms disagree on ban of customer data screen-scraping
A year after Bank of Valletta ‘cyber heist’, cuffs applied as cash-cleansing case continues
Microsoft Offers Rewards of Up to $20,000 in New Xbox Bug Bounty Program
Avast acknowledges collecting user data; shuts down Jumpshot
Attempts to define international infosec rules of the road bogged down by endless talkshops, warn diplomats
Facebook to pay $550m to settle face-tagging suit

An update that solves one vulnerability and has three fixes is now available.

200K WordPress Sites Vulnerable to Plugin Flaw

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanag es memory, as demonstrated by IRC DCC commands in EMU_IRC.

* Fix issues while trying to play a video on NextCloud. * Make sure the GL video sink uses a valid WebKit shared GL context. * Fix vertical alignment of text containing arabic diacritics. * Fix build with icu 65.1. * Fix page loading errors with websites using HSTS. * Fix web process crash when […]

Update to 79.0.3945.130. Fixes the following security issues: * CVE-2020-6378 * CVE-2020-6379 * CVE-2020-6380

This is January 2020 OpenJDK security update for java-latest-openjdk packages. The sources are updated to the 13.0.2+8 tag.

Update to bugfix release 2.9.3. See https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst

Enterprise laptops vulnerable to critical direct memory access attack

security update

security update

Coronavirus Campaigns Spread Emotet, Malware
Bezos, WhatsApp Cyberattacks Show Growing Mobile Sophistication
Cisco Patches Two High-Severity Bugs in its Small Business Switch Lineup
UN hacked, becomes target of massive state-sponsored spying op
Trello exposed! Search turns up huge trove of private data
97% of airports showing signs of weak cybersecurity
Facebook knows a lot about your online habits – here’s how to stop it
U.N. Hack Stemmed From Microsoft SharePoint Flaw
The autofill email goof that exposed vulnerable students and cost the University of East Anglia £140,000
Difficult season: Antivirus-flinger Avast decides to ‘wind down’ Jumpshot
ProtonMail and StartMail blocked as Russia hunts for bomb threat spammers
The NHS has only suffered six ransomware attacks since the WannaCry worm, investigation reveals
Employers can’t force you to get microchipped, Indiana reps say

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code.

Facebook to Pay $550M to Settle Class Action Case Over Facial Recognition
Smashing Security #163: Russian heists and Ring wrongs
Government spyware company spied on hundreds of innocent people

Two vulnerabilities have recently been discovered in the stream-tcp code of the intrusion detection and prevention tool Suricata.

If only 3 in 100,000 cyber-crimes are prosecuted, why not train cops to bring these crooks to justice once and for all, suggests think-tank veep
Dell, HP Memory-Access Bugs Open Attacker Path to Kernel Privileges
IoT laws are coming: What to expect

No more default logins on new IoT devices if UK legislators get their way The post IoT laws are coming: What to expect appeared first on WeLiveSecurity

An update that solves one vulnerability and has four fixes is now available.

Teleworking threats in the security spotlight in the run-up to the Tokyo Olympics
Anatomy of OpenBSD’s OpenSMTPD hijack hole: How a malicious sender address can lead to remote pwnage
Kali Linux 2020.1 released – Download now
UN didn’t patch SharePoint, got mega-hacked, covered it up, kept most staff in the dark, finally forced to admit it
Apple Security Updates Tackle iOS Device Tracking, RCE Flaws
Stolen card data of millions of Wawa customers sold on dark web
Google Sets Record High in Bug-Bounty Payouts
Apple patches critical bugs on iPhone and Mac – update now!
Canadian insurer paid for ransomware decryptor. Now it’s hunting the scum down
Critical Flaws in Magento e-Commerce Platform Allow Code-Execution
Video: Zoom Researcher Details Web Conference Security Risks, 2020 Threats
Intel promises fix after researchers reveal ‘CacheOut’ CPU flaws
Anatomy of a “free” gift – how online surveys can harm your digital health
Only 6 ransomware attacks on the UK’s NHS since WannaCry worm hit in 2017 – report
Cynet Empowers IT Resellers and Service Providers to Become Fully Qualified MSSPs
Let’s make ransomware MORE illegal, says Maryland

Several vulnerabilities have been discovered in the otrs2 package that may lead to unauthorized access, remote code execution and spoofing.

Fraud spike prompts Chrome developer lock-out

Apache Solr could be made to run programs if it received specially crafted network traffic.

Win $1.5 million hacking an Android phone
Wawa Breach May Have Affected More Than 30 Million Customers
Time to celebrate Data Privacy Day!
15 NFL teams’ Twitter hijacked in lead-up to the Super Bowl
How AI will improve API security

The following vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2019-8835

It was discovered that there were a large number of NULL pointer dereferences due to unchecked return values from malloc and friends in hiredis, a minimalistic C client library.

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes two vulnerabilities is now available.

Dear friends in DevSecOps: Don’t forget, security is your responsibility, too – now learn how to do it right
New ‘CacheOut’ Attack Targets Intel CPUs
Cache flow problems continue for Intel: Yet more data-leaking processor design blunders discovered, patches due soon
Trolls-For-Hire Pave Way For Sophisticated Social Media Hacks
Coronavirus claims new victim: ‘DEF CON cancelled’ joke cancelled after DEF CON China actually cancelled
Ring Doorbell App for Android Caught Sharing User Data with Facebook, Data-Miners
New report suggests anti-virus firm Avast is selling user data to 3rd parties
5 ways to be a bit safer this Data Privacy Day
IoT security? We’ve heard of it, says UK.gov waving new regs
Hackers blitz social media accounts of 15 NFL teams

The league and scores of teams were caught off-guard by the re-emergence of an infamous hacking group The post Hackers blitz social media accounts of 15 NFL teams appeared first on WeLiveSecurity

MTTD and MTTR: Two Metrics to Improve Your Cybersecurity