Menu

Monthly Archives: March 2020

Exchange rate service’s customer details hacked via AWS

An update that fixes 7 vulnerabilities is now available.

5 Best Android Emulators for PC
Covid-19 Spurs Facial Recognition Tracking, Privacy Fears
New Mirai Variant ‘Mukashi’ Targets Zyxel NAS Devices

Reading Time: ~ 2 min. DDoS Attack Strikes U.S. Health Department Amidst the panic caused by the novel coronavirus, millions of people began navigating to the U.S. Department of Health’s website to find more information on the illness, but instead found the site to be offline after a DDoS attack overwhelmed its servers. This comes […]

COVID-19 disruption delays release of Chrome version 81
Location-tracking wristbands required on all incoming travelers to Hong Kong
What to do if your Twitter account has been hacked

Losing access to your account can be stressful, but there are steps you can take to get it back – and to avoid getting hacked again The post What to do if your Twitter account has been hacked appeared first on WeLiveSecurity

Firefox to burn FTP out of its browser, starting slowly in version 77 due in April

The package bluez before version 5.54-1 is vulnerable to access restriction bypass.

The package chromium before version 80.0.3987.149-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution and information disclosure.

In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView’s JavaScript literal escape helpers.

‘Dirty little secret’ extortion email threatens to give your family coronavirus

Update to 80.0.3987.132. Lots of security fixes here. VAAPI re-enabled by default except on NVIDIA. List of CVEs fixed (since last update): * CVE-2019-20446 * CVE-2020-6381 * CVE-2020-6382 * CVE-2020-6383 * CVE-2020-6384 * CVE-2020-6385 * CVE-2020-6386 * CVE-2020-6387 * CVE-2020-6388 * CVE-2020-6389 * CVE-2020-6390 * CVE-2020-6391 * CVE-2020-6392 *

Coronavirus Poll Results: Cyberattacks Ramp Up, WFH Prep Uneven

Update to WebKitGTK 2.28.0. * Add API to enable Process Swap on (Cross-site) Navigation. * Add user messages API for the communication with the web extension. * Add support for same-site cookies. * Service workers are enabled by default. * Add support for Pointer Lock API. * Add flatpak sandbox support. * Make ondemand hardware […]

What do you not want right now? A bunch of Cisco SD-WAN, Webex vulnerabilities? Here are a bunch of them
Security flaws found in popular password managers

Not all they’re cracked up to be? Several password vaults contain vulnerabilities, both new and previously disclosed but never patched, a study says The post Security flaws found in popular password managers appeared first on WeLiveSecurity

Russian state-sponsored hackers have been sniffing Middle East defence firms, warns Trend Micro
Dark Web: Hackers launch Coronavirus sale to sell hacking tools
Whatever happened to cryptojacking?
Cisco Warns of High-Severity SD-WAN Flaws
NIST shared dataset of tattoos that’s been used to identify prisoners
Work from home: Improve your security with MFA

Remote work can be much safer with the right cyber‑hygiene practices in place – multi‑factor authentication is one of them The post Work from home: Improve your security with MFA appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

Multiple vulnerabilities have been found in Apache Tomcat, the worst of which could lead to arbitrary code execution.

Cloud Misconfig Mistakes Show Need For DevSecOps
What is the Best Defense Against Phishing Attacks?

Multiple vulnerabilities have been found in libgit2, the worst of which could result in the arbitrary execution of code.

A heap-based buffer overflow in GNU FriBidi might allow remote attackers to execute arbitrary code.

Multiple vulnerabilities have been found in Cacti, the worst of which could lead to the remote execution of arbitrary code.

An SQL injection vulnerability in phpMyAdmin may allow attackers to execute arbitrary SQL statements.

Cryptojacking is almost conquered – crushed along with coinhive.com

Reading Time: ~ 3 min. We’re all thinking about it, so let’s call it out by name right away. The novel coronavirus, COVID-19, is a big deal. For many of us, the structure of our lives is changing daily; and those of us who are capable of doing our work remotely are likely doing so […]

Oh-so-generous ransomware crooks vow to hold back from health organisations during COVID-19 crisis
Smashing Security #170: PornHub, Coronavirus apps, and remote working
Delayed Adobe patches fix long list of critical flaws
More business websites hit by credit-card skimming malware
Facebook accidentally blocks genuine COVID-19 news
Stantinko’s new cryptominer features unique obfuscation techniques

ESET researchers bring to light unique obfuscation techniques discovered in the course of analyzing a new cryptomining module distributed by the Stantinko group’s botnet The post Stantinko’s new cryptominer features unique obfuscation techniques appeared first on WeLiveSecurity

Hong Kong makes wearable trackers mandatory for new arrivals, checks in with ‘surprise calls’ too
Forget James Bond’s super-gadgets, this chap spied for China using SD card dead drops. Now he’s behind bars
Dark web: Child abuse, real-life blackmailing site DarkScandals seized
Android malware uses coronavirus for sextortion and ransomware combo
Dear Adobe, Trend Micro users: Please vaccinate your software – at least some of these security holes were exploited in the wild
WordPress, Apache Struts Attract the Most Bug Exploits
Azure Red Flag: Microsoft Accidentally Fixes Cloud Config ‘Bug’
Trend Micro Fixes Critical Flaws Under Attack
Blizzard hit by massive DDoS attack; EA Sports facing lagging issue
TrickBot Trojan Adds RDP Brute-Forcing to Its Arsenal
Work from home: How to set up a VPN

As the COVID-19 pandemic has many organizations switching employees to remote work, a virtual private network is essential for countering the increased security risks The post Work from home: How to set up a VPN appeared first on WeLiveSecurity

Adobe Discloses Dozens of Critical Photoshop, Acrobat Reader Flaws
Freedom of Information coverup clerk stung for £2k after deleting council audio recording

An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Authorities Eye Using Mobile Phone Tracking COVID-19’s Spread

An update for icu is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for icu is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Android Stalkerware MonitorMinor spies, steals & evades

An update for python-imaging is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

VMware patches virtualisation bugs

Updated okular packages fix security vulnerability: Okular can be tricked into executing local binaries via specially crafted PDF files. This binary execution can require almost no user interaction. No parameters can be passed to those local binaries (CVE-2020-9359).

Updated webkit2 packages fix security vulnerability: WebKitGTK through 2.26.4 contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution (CVE-2020-10018).

Uber to file federal suit against LA over users’ real-time location data
DDoS attack on US Health agency part of coordinated campaign
Small business loans app blamed as 500,000 financial records leak out of … you guessed it, an open S3 bucket
Human traffickers use social media oversharing to gain victims’ trust
Magecart Cyberattack Targets NutriBullet Website
Pervasive digital surveillance of citizens deployed in COVID-19 fight, with rules that send genie back to bottle
A COVID-19 Cybersecurity Poll: Securing a Remote Workforce
This Stalkerware Delivers Extra-Creepy Features
Remember cryptojacking from way, way back (2019)? Site infections are down 99% – thanks to death of Coinhive
FBI warns of human traffickers luring victims on dating apps

The warning highlights one of the potential risks associated with revealing too much private information online The post FBI warns of human traffickers luring victims on dating apps appeared first on WeLiveSecurity

security update

Fake WiseCleaner website spreading CoronaVirus ransomware
APT36 Taps Coronavirus as ‘Golden Opportunity’ to Spread Crimson RAT

An update that fixes one vulnerability is now available.

An update for slirp4netns is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Nigerian spammer made 3X average national salary firehosing macro-laden Word docs at world+dog

An update for python-flask is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Slack fixes account-stealing bug

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for zsh is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for python-pip is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Activities of a Nigerian Cybercriminal Uncovered
Tor browser fixes bug that allows JavaScript to run when disabled
WordPress to get automatic updates for plugins and themes

Reading Time: ~ 3 min. “Cold Cuts Day,” “National Anthem Day,” “What if Cats and Dogs had Opposable Thumbs Day”… If you’ve never heard of World Backup Day, you’d be forgiven for thinking it’s another of the gimmicky “holidays” that seem to be snatching up more and more space on the calendar. (Did you know […]

Talking love and viruses on the BBC World Service
Europol busts up two SIM-swapping hacking rings
Vimeo freezes accounts after malware hunts for logins, coronavirus map app infected with evil code, and more
Virtual machines, real problems: VMware fixes bug trio including guest-to-host hole in Workstation, Fusion
Convincing Google Impersonation Opens Door to MiTM, Phishing
Google & Microsoft launch tools to address Coronavirus outbreak
US Health and Human Services targeted by DDoS scum at just the time it’s needed to be up and running

security update

Microsoft Edge Shares Privacy-Busting Telemetry, Research Alleges
Coronavirus related cyber attacks hit HHS in US, testing center in Czech
Health workers are top of phishers’ target lists thanks to data value
UK intelligence agency warns of cybercriminals exploiting the Coronavirus outbreak