Menu

Monthly Archives: March 2020

Watering-Holes Target Asian Ethnic Victims with Flash Update Decoy
Houseparty denies hacking user accounts; offers $1 million reward
Epic Games floats $1m bounty to ID source of ‘commercial smear’ claiming Houseparty chat app has been hacked
Zoom Scrutinized As Security Woes Mount
8-Year-Old VelvetSweatshop Bug Resurrected in LimeRAT Campaign
Marriott Hotels hacked AGAIN: Two compromised employee logins abused to siphon off guests’ personal info
Marriott International confirms data breach of up to 5.2 million guests

An issue has been found in apng2gif, a tool for converting APNG images to animated GIF format.

Several issues have been found in gst-plugins-bad0.10, a package containing GStreamer plugins from the “bad” set.

Millions of Guests Impacted in Marriott Data Breach, Again
The UK Cabinet is meeting on Zoom… here’s the meeting ID

An update that fixes 9 vulnerabilities is now available.

A minor security issue and a severe packaging bug have been fixed in tinyproxy, a lightweight http proxy daemon.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Watch out; cyber criminals are Zoom-bombing video conferences
Patch now! Critical flaw found in OpenWrt router software
Dharma ransomware source code on sale for $2,000
With Kubernetes Operators comes great responsibility
Has Houseparty really been hacked? $1 million reward offered to unearth who is behind widespread claims
Data on almost every citizen of Georgia posted on hacker forum
Researchers speed the death of ‘bad’ data in the race against good
Covid-19 Poll Results: One in Four Prioritize Health Over Privacy
Have you backed up your smartphone lately?

With World Backup Day upon us, we walk you through the ways to back up your iPhone or Android phone so that your personal information remains safe The post Have you backed up your smartphone lately? appeared first on WeLiveSecurity

“Instant bank fraud” warning spread on WhatsApp is a hoax
5 tips for keeping your data safe this World Backup Day
Personal details & phone numbers of 42M Iranians sold on a hacking forum
Nation-State Attacks Drop in Latest Google Analysis
No, Houseparty hasn’t hacked your phone and stolen your bank details
Zoom Kills iOS App’s Data-Sharing Facebook Feature
Zeus Sphinx Banking Trojan Arises Amid COVID-19
Working from home? Hackers can drop malware with fake Zoom apps
How to stay on top of coronavirus scams – and all the others too
Cyber volunteers needed to help protect our health services during the Coronavirus outbreak
Work from home: Videoconferencing with security in mind

With COVID-19 concerns canceling face-to-face meetings, be aware of the security risks of videoconferencing and how to easily overcome them The post Work from home: Videoconferencing with security in mind appeared first on WeLiveSecurity

An update that solves three vulnerabilities and has one errata is now available.

“Secure” cloud storage provider exposes customer data in plain-text
Apple’s iOS 13.4 hit by VPN bypass vulnerability

Multiple vulnerabilities have been found in QEMU, the worst of which could result in the arbitrary execution of code.

Poured your info out on a call to 118 118 Money? Bad luck. Credit provider ‘fesses up that hacker nabbed customer service phone recordings

Multiple vulnerabilities have been found in FFmpeg, the worst of which allows remote attackers to execute arbitrary code.

Multiple vulnerabilities have been found in libxls, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in GNU IDN Library 2, the worst of which could result in the remote execution of arbitrary code.

A buffer overflow in GNU Screen might allow remote attackers to corrupt memory.

Chrome may bring back ‘www’ with option to show full URLs
I made a guest appearance on Technado, talking cybersecurity from the safety of my shed
Should governments track your location to fight COVID-19?
Google sent ~40K warnings to targets of state-backed attackers in 2019
You know all those stories of leaky cloud buckets taken offline? Well, some may still be there, just badly hidden
First-ever SANS Women in Cybersecurity survey reveals significant mentorship gaps

An update that solves two vulnerabilities and has one errata is now available.

Fix CVE-2018-19655

Fix CVE-2018-19655

Hackers sending malware infected USBs with Best Buy Gift Cards

Fix CVE-2018-19655

* New upstream release 5.3.1 (rhbz#1814882) * Fixes CVE-2020-1747 (rhbz#1807367,1809011)

An update that fixes 7 vulnerabilities is now available.

“Operation Poisoned News” infecting iPhones with LightSpy spyware
How To Keep Your Router And WiFi Safe From Hackers
Yeah, that Zoom app you’re trusting with work chatter? It lives with ‘vampires feeding on the blood of human data’

security update

Reading Time: ~ 2 min. World Health Organization Sees Rise in Cyberattacks Officials for the World Health Organization (WHO) have announced that many of their sites and servers have been under attack by unsuccessful hackers trying to capitalize on the latest health scare. The attack stemmed from the use of several malicious domains that attempted […]

Dark web hosting firm quits after hackers delete its database
Apple Unpatched VPN Bypass Bug Impacts iOS 13, Warn Researchers

An update that fixes one vulnerability is now available.

Cybersecurity insurance firm Chubb investigates its own ransomware attack
Cyber crime marketplace DEER.IO seized, admin arrested from JFK airport
Android apps are snooping on your installed software
Firefox 76 will have option to enforce HTTPS-only connections

ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c (CVE-2020-5208) SL7 x86_64 ipmitool-1.8.18-9.el7_7.x86_64.rpm ipmitool-debuginfo-1.8.18-9.el7_7.x86_64.rpm noarch bmc-snmp-proxy-1.8.18-9.el7_7.noarch.rpm exchange-bmc-os-info-1.8.18-9.el7_7.noarch.rpm – Scientific Linux Development Team

Thousands of Dark Web sites deleted in attack on free hosting service
FBI takes down hacker platform Deer.io
Zeek and Jitsi: 2 open source projects we need now

The 5.5.11 stable kernel update contains a number of important fixes across the tree.

* New upstream release 5.3.1 (rhbz#1814882) * Fixes CVE-2020-1747 (rhbz#1807367,1809011)

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has 37 fixes is now available.

Hackers exploiting vulnerable routers to drop malicious “WHO” COVID-19 app

security update

Critical CODESYS Bug Allows Remote Code Execution
AMD dials 911, emits DMCA takedowns after miscreant steals a load of GPU hardware blueprints, leaks on GitHub
Tupperware Cyberattack Stores Away Customer Payment Cards
Hacker Steals & Leaks Xbox Series X GPU Source Code
Emerging APT Mounts Mass iPhone Surveillance Campaign
As Zoom Booms, Incidents of ‘ZoomBombing’ Become a Growing Nuisance
Watch out! Scummy scammers target home deliveries
Hackers Hijack Routers to Spread Malware Via Coronavirus Apps
Critical vulnerabilities found in popular Password Managers
Apple Safari now blocks all third-party cookies by default
Hey, China. Maybe you should have held your hackers off for a bit while COVID-19 ravaged the planet. Just a suggestion
Third-party data breach exposes GE employees’ personal information
Responding to the New Normal: How to Prevent Added Risk in Your Business
HPE issues fix to stop some SSDs from self‑destructing

If left unpatched, a firmware flaw in some enterprise-class solid-state drives could make data on them unrecoverable as early as this fall The post HPE issues fix to stop some SSDs from self‑destructing appeared first on WeLiveSecurity

Adobe issues emergency fix for file-munching bug

A minor version update (from 7.5 to 7.6) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

Hijacked Twitter accounts used to advertise face masks
Smashing Security #171: WhatsApp hoaxes, Zoombombs, and 8-bit love

An update for ipmitool is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Multiple vulnerabilities have been found in PHP, the worst of which could result in the execution of arbitrary shell commands.

Tokyo Olympics Postponed, But 5G Security Lessons Shine