Menu

Monthly Archives: May 2020

Now we know what the P really stands for in PwC: X-rated ads plastered over derelict corner of accountants’ website

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Transport biz Toll Group suffers second ransomware infection in just three months
India acknowledges, but brushes aside, features-not-bugs in Aarogya Setyu virus contact-tracing app

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform various Cross-Side Scripting (XSS) and Cross-Site Request Forgery (CSRF) attacks, create files on the server, disclose private information, create open

security update

security update

Sensitive user data found in Tesla car parts sold on eBay
Kaiji – a new strain of IoT malware seizing control and launching DDoS attacks
InfinityBlack hacking group dismantled; 5 hackers arrested
Spear-Phishing Attack Spoofs EE To Target Executives
Surprise surprise! Hostile states are hacking coronavirus vaccine research, warn UK and USA intelligence
VPN Concerns with Unplanned Remote Employees

An update that solves one vulnerability and has three fixes is now available.

An update that fixes three vulnerabilities is now available.

GoDaddy suffers data breach after hackers access SSH accounts
Ghost blogging platform servers hacked to mine cryptocurrency

Ghost wasn’t the only victim of break-ins over the weekend that exploited critical holes in infrastructure automation software for which patches were available The post Ghost blogging platform servers hacked to mine cryptocurrency appeared first on WeLiveSecurity

GoDaddy hack: Miscreant goes AWOL with 28,000 users’ SSH login creds after vandalizing server-side file
GoDaddy Hack Breaches Hosting Account Credentials
GoDaddy – “unauthorized individual” had access to login info
New Kaiji Botnet Targets IoT, Linux Devices
Google Android RCE Bug Allows Attacker Full Device Access
Malware can extract data from air-gapped PC using power supply
We beg, implore and beseech thee. Stop reusing the same damn password everywhere

Reading Time: ~ 3 min. Your password passing habit may not be as be as harmless as you think. And yes, that includes Netflix login info too. That’s one finding to come out of our newly released study of 2020’s Most (and Least) Cyber-Secure States. In this year’s analysis of the cyber readiness of all […]

It has been 20 years since cybercrims woke up to social engineering with an intriguing little email titled ‘ILOVEYOU’
Firefox’s Private Relay service tests anonymous email alias feature
Reveal the identities of alleged pirates, court tells ISP
More Salt in their wounds: DigiCert hit as hackers wriggle through (patched) holes in buggy config tool
UK finds itself almost alone with centralized virus contact-tracing app that probably won’t work well, asks for your location, may be illegal

A Denial of Service (DoS) vulnerability was discovered in the network time protocol server/client, ntp. ntp allowed an “off-path” attacker to block unauthenticated

An update for sqlite is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Apple-Google COVID-19 virus contact-tracing API to bar location-tracking access

Update to Samba 4.12.2

Update to Samba 4.12.2

Airplane Hack Exposes Weaknesses of Alert and Avoidance Systems
OK, so you’ve air-gapped that PC. Cut the speakers. Covered the LEDs. Disconnected the monitor. Now, about the data-leaking power supply unit…

security update

Hackers Exploit Critical Flaw in Ghost Platform with Cryptojacking Attack
Sweet TCAS! We can make airliners go up-diddly-up whenever we want, say infosec researchers
France’s largest newspaper exposed 8 TB of data with 7.4 billion records

A regression has been found in the patch for CVE-2016-10711 of pound, a reverse proxy, load balancer and HTTPS front-end for Web servers. Without the fix pound can be tricked to use 100% CPU.

Several vulnerabilities were discovered in the Tomcat servlet and JSP engine, which could result in HTTP request smuggling and code execution in the AJP connector (disabled by default in Debian).

Hackers exploit vulnerability to leak The Last of Us 2 spoiler video
UK COVID-19 contact tracing app data may be kept for ‘research’ after crisis ends, MPs told
ILOVEYOU: The Love Bug virus 20 years on – could it happen again?
Oracle: Unpatched Versions of WebLogic App Server Under Active Attack
Tarkett floored by cyber attack
It was 20 years ago today… The Love Bug remembered
AsSalt-ed at the weekend: Miscreants roast Ghost, LineageOS totters as Salt bug bites
My old-fashioned view on the terms “blacklist” and “whitelist”
Coronavirus pandemic coincides with spike in online puppy scams
Uncle Sam to agencies: No encrypted DNS for you!
Monday review – the hot 11 stories of the week
Xiaomi emits phone browser updates after almighty row over web activity harvested even in incognito mode
India makes contact-tracing app compulsory in viral hot zones despite most local phones not being smart

An update for cri-o is now available for Red Hat OpenShift Container Platform 4.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for haproxy is now available for Red Hat OpenShift Container Platform 4.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Singapore to require smartphone check-ins at all businesses and will log visitors’ national identity numbers

An update that fixes two vulnerabilities is now available.

Hackers breach Ghost blogging platform to mine cryptocurrency

An update that fixes four vulnerabilities is now available.

Ghost blogging platform suffers security breach

A vulnerability was discovered in mailman. GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against

New seamonkey packages are available for Slackware 14.2 and -current to fix security issues.

An update that fixes 5 vulnerabilities is now available.

A security flaw was found on rubygem-json prior to 2.3.0 which was now assigned as CVE-2020-10663. This new rpm contains backport fixes for this issue.

Update to latest upstream OpenVPN 2.4.9 release. It contains a security fix for CVE-2020-11810. This security issue is quite hard to abuse, requiring a fairly precise timing attack combined with guessing a just assigned peer-id reference. If successful, only a single client just initiating a new connection will experience a denial of service situation. This […]

Tokopedia hacked – Login details of 91 million users sold on dark web

security update

Hackers using famous movies to spread malware through torrents

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

A vulnerability was discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. LDAP search filters with nested boolean expressions can result in denial of service (slapd daemon

The 5.6.8 stable kernel update contains a number of important fixes across the tree.

The 5.6.8 stable kernel update contains a number of important fixes across the tree.

The 5.6.8 stable kernel update contains a number of important fixes across the tree.

Spyware slinger NSO to Facebook: Pretty funny you’re suing us in California when we have no US presence and use no American IT services…
Upgraded Cerberus Spyware Spreads Rapidly via MDM

security update

Sextortion scammers still shilling with stolen passwords

The email includes the potential victim’s password as evidence of a hack, but there is more than meets the eye The post Sextortion scammers still shilling with stolen passwords appeared first on WeLiveSecurity

News Wrap: Microsoft Sway Phish, Malicious GIF and Spyware Attacks
Microsoft Teams Impersonation Attacks Flood Inboxes
Maze Ransomware group steals 11m card data from Banco de Costa Rica
TrickBot Attack Exploits COVID-19 Fears with DocuSign-Themed Ploy
Android ransomware found extorting credit card details from users

Reading Time: ~ 3 min. Anyone who has spent late nights scrolling through their social media feed or grinding on video games knows one thing is true: Technology can be a good thing, but only in moderation. Like too much of anything, spending a lot of time on the internet or social media can lead […]

Reading Time: ~ 2 min. As Oil Prices Drop, Hackers Take Aim at Producers With the recent crash in oil prices, and supply rapidly piling up, a new spear phishing campaign has begun targeting executives at several major oil producers. A massive number of emails started being distributed in late March, without the telltale signs […]

Google fights spammy extensions with new Chrome Web Store policy
COVID-19 prompts DHS warning to review Office 365 security
Android trojan EventBot abuses accessibility services to clear out bank accounts – fortunately, it’s ‘in preview’

An update that solves two vulnerabilities and has one errata is now available.

Several vulnerabilities have been discovered in otrs2 (Open source Ticket Request System)

What’s worse than an annoying internet filter? How about one with a pre-auth remote-command execution hole and there’s no patch?

An update that fixes one vulnerability is now available.

OpenJDK 14 April CPU update

Security fix for CVE-2020-5260 and CVE-2020-11008 CVE-2020-5260 – From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.4.txt): > With a crafted URL that contains a newline in it, the credential > helper machinery can be fooled to give credential information for > a wrong host. The

Update to 2.9.10 * Fix CVE-2019-19956, CVE-2019-20388 and CVE-2020-7595