Menu

Monthly Archives: May 2020

The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

Gollem, as used in Horde Groupware Webmail Edition and other products, had been affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting

The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

An update that solves one vulnerability and has one errata is now available.

New upstream release with bug and security fixes. Also, consolidates duplicate pakages marked and nodejs-marked. I tested upgrades from both, but may have missed some wonky situation.

New version 3.2.4, enabled build with androiddump.

Fake mobile version of Valorant game spreading malware

Two memory management issues were found in the asfdemux element of the GStreamer “ugly” plugin collection, which can be triggered via a maliciously crafted file.

Two memory handling issues were found in gst-plugins-good0.10, a collection of GStreamer plugins from the “good” set:

It was discovered that there was both an invalid memory and heap overflow vulnerability in dosfstools, a collection of utilities for making and checking MS-DOS FAT filesystems.

New AWS phishing scam steals credentials via fake AWS notification

Several vulnerabilities were discovered in package salt, a configuration management and infrastructure automation software.

New version 3.2.4, enabled build with androiddump.

An update that fixes one vulnerability is now available.

Famous video apps with 157M+ installations operating as spyware
Steganography Anchors Pinpoint Attacks on Industrial Targets
Minted confirms data breach as Shiny Hunters sell its database
People know reusing passwords is risky – then do it anyway

And most people don’t change their password even after hearing about a breach, a survey finds The post People know reusing passwords is risky – then do it anyway appeared first on WeLiveSecurity

NTT Communications Data Breach Affects Customers, Threatens Supply Chain
NSA Warns of Sandworm Backdoor Attacks on Mail Servers
Clearview AI facial recogition sued again – this time by ACLU
OPSEC fail! “Super-hacker” accidentally outs himself through careless clues left on social media
‘Hack-For-Hire’ Firms Spoof WHO To Target Google Credentials
ACLU Sues Clearview AI Over Faceprint Collection, Sale
The Increasing Need For Application Security During COVID-19
COVID-19 tests, PPE and antivirual drugs find a home on the dark web

An update that solves one vulnerability and has two fixes is now available.

Great news. Patch load drops 20% for the first time in 10 years. Bad news: Well, you’ve heard about coronavirus?
Windows 10 adds new security and privacy features in May update
Google sued by Arizona for tracking users’ locations in spite of settings

git: Crafted URL containing new lines, empty host or lacks a scheme can cause credential leak (CVE-2020-11008) SL7 x86_64 git-1.8.3.1-23.el7_8.x86_64.rpm git-daemon-1.8.3.1-23.el7_8.x86_64.rpm git-debuginfo-1.8.3.1-23.el7_8.x86_64.rpm git-gnome-keyring-1.8.3.1-23.el7_8.x86_64.rpm git-svn-1.8.3.1-23.el7_8.x86_64.rpm noarch emacs-git-1.8.3.1-23.el7_8.noarch.rpm [More…]

It’s not every day the NSA publicly warns of attacks by Kremlin hackers – so take this critical Exim flaw seriously
NTT warns its Singapore cloud was hacked, Japanese customer data compromised

## Python 3.8.3 This is the third maintenance release of Python 3.8. See [the c hangelog](https://docs.python.org/release/3.8.3/whatsnew/changelog.html#changelo g) for details. Contains the security fix for CVE-2020-8492.

Authorities arrest active dark web child abuser in Italy
Inside the Hoaxcalls Botnet: Both Success and Failure
Got $50k spare? Then you can crack SHA-1 – so OpenSSH is deprecating flawed hashing algo in a ‘near-future release’
Hackers Compromise Cisco Servers Via SaltStack Flaws

An update that fixes three vulnerabilities is now available.

Cybercrooks tend to prefer Google-branded phishing to Microsoft-flavoured lures

USN-4369-1 introduced a regression in the Linux kernel.

USN-4367-1 introduced a regression in the Linux kernel.

The Bank of America is the latest victim of a data breach
Critical Android flaw lets attackers hijack almost any app, steal data

Left unpatched, the vulnerability could expose almost all Android users to the risk of having their personal data intercepted by attackers The post Critical Android flaw lets attackers hijack almost any app, steal data appeared first on WeLiveSecurity

Google Location Tracking Lambasted in Arizona Lawsuit
Microsoft warns of PonyFinal ransomware attacks
PonyFinal Ransomware Targets Enterprise Servers Then Bides Its Time

Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine.

You, Apple Mac fan. Put down the homemade oat-milk latte, you need to patch a load of security bugs, too
Inside a ransomware gang’s attack toolbox
NetWalker ransomware – what you need to know
Alleged data of 47.5 million Truecaller Indian users sold online
Valak Loader Revamped to Rob Microsoft Exchange Servers

An update for freerdp is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Pablo Escobar’s brother sues Apple for $2.6b over FaceTime flaw

An update for freerdp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Various minor vulnerabilities have been addredd in libexif, a library to parse EXIF metadata files.

This is a security update for JBoss EAP Continuous Delivery 19. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Using container technology to make a more secure pipeline

An update that fixes 5 vulnerabilities is now available.

Android ‘StrandHogg 2.0’ flaw lets malware assume identity of any app
Smashing Security podcast #180: Taking care of Clare
Why zero trust security needs strong hardware foundations

security update

security update

DoubleGun Group Builds Massive Botnet Using Cloud Services
26 million logins believed to be stolen from LiveJournal in 2017 pop up on hacker forum
From Agent.BTZ to ComRAT v4: A ten‑year journey

Turla has updated its ComRAT backdoor and now uses the Gmail web interface for Command and Control The post From Agent.BTZ to ComRAT v4: A ten‑year journey appeared first on WeLiveSecurity

‘[F]Unicorn’ Ransomware Impersonates Legit COVID-19 Contact-Tracing App
Apple sends out 11 security alerts – get your fixes now!

An update that fixes three vulnerabilities is now available.

Exclusive: Hacker selling 500 million Facebook user data from 82 countries
26 million LiveJournal users warned that their passwords have been breached
Hackers Sell Data from 26 Million LiveJournal Users on Dark Web

Several security issues were fixed in Unbound.

Fighting exploits with Control-Flow Integrity (CFI) in Clang
Oh cool, tech service prices are plummeting. And by tech services, we mean botnet rentals and stolen credit cards
Open source libraries a big source of application security flaws
10 steps to automating security in Kubernetes pipelines
Google may soon add end-to-end encryption for RCS

Updated transmission packages fix security vulnerability: Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent

Updated sleuthkit packages fix security vulnerabilities: An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table (CVE-2019-14532).

Updated log4net packages fix security vulnerability This patch fixes a security vulnerabiliy reported by Karthik Balasundaram. The security vulnerability was found in the way how log4net parses xml configuration files where it allowed to process XML External Entity Processing. An attacker could use

Advisory text to describe the update. Wrap lines at ~75 chars. Updated dojo package fixes security vulnerabilities: In affected versions of dojo, the deepCopy method is vulnerable to

Microsoft banishes Trend Micro code at center of driver ‘cheatware’ storm from Windows 10, rootkit detector product pulled from site
Mulled Chrome API shines light on long-neglected privacy gap: Sites can snoop on your find-in-page searches
Use of cloud collaboration tools surges and so do attacks
India said its coronavirus contact-tracing app is perfect… adds bug bounty and open-sources it anyway
US lawmakers get a second shot at forcing FBI agents to obtain a warrant before they leaf through web histories
StrandHogg 2.0 Critical Bug Allows Android App Hijacking
If someone could stop hackers pwning medical systems right now, that would be cool, say Red Cross and friends
Crooks threaten to leak customer data stolen from e‑commerce sites

A hack-and-extort campaign takes aim at poorly secured databases replete with customer information that can be exploited for further attacks The post Crooks threaten to leak customer data stolen from e‑commerce sites appeared first on WeLiveSecurity

Two years later, has GDPR fulfilled its promise?

Has the landmark law helped build a culture of privacy in organizations and have consumers become more wary of sharing their personal data? The post Two years later, has GDPR fulfilled its promise? appeared first on WeLiveSecurity

New iPhone jailbreak released
Airline-chasing lawyers leap on Easyjet for £18bn after 9m folks’ data, itineraries nicked
Internet giants unite to stop warrantless snooping on web histories
Turla APT Revamps One of Its Go-To Spy Tools
Docker Desktop danger discovered, patch now
Unmanned drones to slash NHS delivery times to one-fifth of road ‘n’ rail transport

An update that fixes one vulnerability is now available.