Menu

Monthly Archives: June 2020

Verizon Media, PayPal, Twitter Top Bug-Bounty Rankings
EvilQuest Mac Ransomware Has Keylogger, Crypto Wallet-Stealing Abilities

security update

Living on a prayer? Netgear not quite halfway there with patches for 28 out of 79 vulnerable router models
StrongPity APT Back with Kurdish-Aimed Watering Hole Attacks
Remote access at risk: Pandemic pulls more cyber‑crooks into the brute‑forcing game

Poorly secured remote access attracts mostly ransomware gangs, but can provide access to coin miners and backdoors too The post Remote access at risk: Pandemic pulls more cyber‑crooks into the brute‑forcing game appeared first on WeLiveSecurity

Google joins Apple in limiting web certificates to one year
UCSF Pays $1.14M After NetWalker Ransomware Attack
Hackers deface Roblox accounts with pro-Trump messages
NEC insists its face-recog training dataset isn’t biased, but refuses to share details of Neoface system with UK court
DDoS and dingoes: Australia to bolster cyber-defences with 500 hackers amid China spat
CISA: Nation-State Attackers Likely to Exploit Palo Alto Networks Bug
How to Safeguard Data When the Majority of Your Workforce is Remote
7 Best Linux Distros for Security and Privacy in 2020>

An update that fixes two vulnerabilities is now available.

iOS 14 flags TikTok, 53 other apps spying on iPhone clipboards

An update for the virt:rhel module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the virt:rhel module is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Remember when we warned in February Apple will crack down on long-life HTTPS certs? It’s happening: Chrome, Firefox ready to join in, too
REvil Ransomware Gang Adds Auction Feature for Stolen Data
Tuesday’s Magento 1 EOL Leaves Clock Ticking on 100K Online Stores
Microsoft’s Windows File Recovery tool recovers your lost data
AWS Facial Recognition Platform Misidentified Over 100 Politicians As Criminals
Unpatched Wi-Fi Extender Opens Home Networks to Remote Control
University of California San Francisco pays ransomware gang $1.14m as BBC publishes ‘dark web negotiations’
Watching a $1.14 million ransomware negotiation between hackers and scientists searching for COVID-19 treatments
Beware “secure DNS” scam targeting website owners and bloggers

An update that fixes three vulnerabilities is now available.

Voice recordings from domestic violence alerting app exposed on the internet

An update that fixes one vulnerability is now available.

Several vulnerabilities were discovered in coturn, a TURN and STUN server for VoIP. CVE-2020-4067

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Yes, Prime Minister, rewrite the Computer Misuse Act: Brit infosec outfits urge reform

Mailman could be made to inject arbitrary content in the login page if it received a specially crafted input.

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Satori IoT botnet author sentenced to 13 months in prison
Monday review – the hot 10 stories of the week
CyberX, CyberX, does whatever a CyberX does. Locks IoT, machines too, Microsoft got it, so will you
Sony Announces PlayStation Bug Bounty Program

security update

Lucifer malware infects Windows & launch DDoS attack using NSA exploits

An update that solves four vulnerabilities and has four fixes is now available.

It was discovered that there was a “roster push attack” in mcabber, a console-based Jabber (XMPP) client. This is identical to CVE-2015-8688 for gajim.

It was discovered that there was a command injection vulnerability in picocom, a minimal dumb-terminal emulation program.

Several issues have been fixed in zziplib, a library providing read access on ZIP-archives. They are basically all related to invalid memory access and resulting crash or memory leak.

It was found that pngquant, a PNG (Portable Network Graphics) image optimising utility, is susceptible to a buffer overflow write issue triggered by a maliciously crafted png image, which could lead into

It was discovered that libtiprc, a transport-independent RPC library, could be used for a denial of service or possibly unspecified other impact by a stack-based buffer overflow due to a flood of crafted ICMP and UDP

Russian hacker Aleksei Burkov jailed for 9 years in US

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

Major Magecart skimming attack hits 8 local US government sites

A vulnerability was discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in denial of service via malformed HTTP/2 headers.

An update that fixes one vulnerability is now available.

Macs, iPhones, iPads to get encrypted DNS – how’d you like them Apples?

– avoid overwriting a local file with -J (CVE-2020-8177) – fix partial password leak over DNS on HTTP redirect (CVE-2020-8169)

Let’s roll the 3d6 dice on today’s security drama: Ah, 15, that’s LG allegedly hacked, source code stolen by Maze ransomware gang
DarkCrewFriends Returns with Botnet Strategy
8 U.S. City Websites Targeted in Magecart Attacks

An update that fixes one vulnerability is now available.

‘Cardplanet’ Operator Sentenced to 9 Years for Selling Stolen Credit Cards
Mainstream European bank hit by largest ever PPS based DDoS attack
Tune in and watch live: Email encryption doesn’t have to be an all-or-nothing deal
Facial recognition technology banned in another US city

In a move lauded by privacy advocates, Boston joins the ranks of cities that have voted down the municipal use of the technology The post Facial recognition technology banned in another US city appeared first on WeLiveSecurity

Domestic violence assistance app breached placing victims at risk
Satori Botnet Creator Sentenced to 13 Months in Prison
Brit plod’s use of facial-recognition tech is lawful, no need to question us, cops’ lawyer tells Court of Appeal

An update that fixes one vulnerability is now available.

Man sentenced, two others charged, in connection with Satori IoT botnet
Fancy hacking a PlayStation? Sony announces its bug bounty program
TikTok To Stop Clipboard Snooping After Apple Privacy Feature Exposes Behavior

An update that solves two vulnerabilities and has 10 fixes is now available.

When one open-source package riddled with vulns pulls in dozens of others, what’s a dev to do?

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

REvil gang threaten to auction celebrity data from Mariah Carey, Lebron James, MTV and more
Talk about the fox guarding the hen house. Comcast to handle DNS-over-HTTPS for Firefox-using subscribers
US govt: Julian Assange tried to recruit hacker to steal hush-hush dirt and we should know – the hacker was an informant
“I think you appear in this video” phishing scam hijacks Facebook accounts
Nationwide Facial Recognition Ban Proposed By Lawmakers
Golang Worm Widens Scope to Windows, Adds Payload Capacity
Maze Ransomware operators hack LG Electronics stealing critical data
Honeypot behind sold-off IP subnet shows Cyberbunker biz hosted all kinds of filth, says SANS Institute
US indicts WikiLeaks’ Julian Assange for hiring Anonymous & LulzSec
Nvidia Warns Windows Gamers of Serious Graphics Driver Bugs
Find a Playstation 4 vulnerability and earn over $50,000

An update that fixes one vulnerability is now available.

Patch time! NVIDIA fixes kernel driver holes on Windows and Linux
Office 365 Users Targeted By ‘Coronavirus Employee Training’ Phish

An update for nghttp2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The inside story of the Maersk NotPetya ransomware attack, from someone who was there

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 9 fixes is now available.

Reading Time: ~ 3 min. It didn’t take long for COVID-19 to completely alter the way we work. Businesses that succeed in this rapidly changing environment will be the ones that adapt with the same velocity. In our second installment from The Future of Work series, you’ll hear from Webroot Product Marketing Director George Anderson, […]

Twitter apologizes for leaking businesses’ financial data

Red Hat AMQ Broker 7.7 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability