Menu

Monthly Archives: June 2020

Why updating your PC fleet lowers TCO, bolsters security – and makes life easier for your IT admins
Update Firefox: Mozilla just patched three hijack-me holes and a bunch of other flaws
Anatomy of a business email scam: FBI dossier details how fraudster pocketed $500k+ by redirecting payments
Smashing Security podcast #181: Anti-cybercrime ads, tricky tracing, and a 5G Bioshield
Sophisticated Info-Stealer Targets Air-Gapped Devices via USB
Attackers Target 1M+ WordPress Sites To Harvest Database Credentials
$5bn+ sueball bounces into Google’s court over claims it continues to track netizens in ‘private browsing mode’
Google adds Nest devices to Advanced Protection Program

You can now shore up your smart home security by leveraging Google’s top security offering The post Google adds Nest devices to Advanced Protection Program appeared first on WeLiveSecurity

TrickBot Adds BazarBackdoor to Malware Arsenal
Critical SAP ASE Flaws Allow Complete Control of Databases

Reading Time: ~ 2 min. Bank of America Breach Reveals PPP Information After processing over 300,000 Paycheck Protection Program applications, Bank of America has revealed that a data breach occurred within the U.S. Small Business Administration’s program that allowed all other SBA-authorized lenders to view highly sensitive data. The data includes tax information and social […]

Firefox fixes cryptographic data leakage in latest security update
VMware flaw allows takeover of multiple private clouds
Amtrak breached, some customers’ logins and PII potentially exposed
Defending critical national infrastructure… hmm. Does Zoom count as critical now?

An update that fixes one vulnerability is now available.

Hackers disrupt Chicago police radios with anti-cop songs
Enterprise Mobile Phishing Attacks Skyrocket Amidst Pandemic
Coincheck cryptocurrency exchange targeted by hackers, customer emails exposed

An update that solves three vulnerabilities and has 18 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Tor soups up onion sites with bountiful browser bump: No more tears trying to find the secure sites you want
Joomla Resources Directory Users Exposed in Leaky AWS Bucket
Office supplies biz owned by UK council snubs ransomware demand for 102 Bitcoin
Two Critical Android Bugs Open Door to RCE
Bug in ‘Sign in with Apple’ could have allowed account hijacking

The tech giant rewards the bug bounty hunter who found the severe flaw in its login mechanism with US$100,000 The post Bug in ‘Sign in with Apple’ could have allowed account hijacking appeared first on WeLiveSecurity

3 things to discuss with your kids before they join social media

What are some of the key things your children should know about before they make their first foray into social media? The post 3 things to discuss with your kids before they join social media appeared first on WeLiveSecurity

The mystery of the expiring Sectigo web certificate
Severe Cisco DoS Flaw Can Cripple Nexus Switches
Octopus Scanner Sinks Tentacles into GitHub Repositories
Hackers use Github bot to steal $1,200 in ETH within 100 seconds
What the NHS Test and Trace scheme could learn from banks about stopping scams

An update that solves one vulnerability and has one errata is now available.

Apple Jailbreak Zero-Day Gets a Patch
Hacker posts database stolen from Dark Net free hosting provider DH
Crime agency turns to Google ads to deter teen DDoS hackers
Podcast: Why Identity Access Management is the New Perimeter

An update for openshift-istio-kiali-rhel7-operator-container is now available for Openshift Service Mesh 1.0 and 1.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

8Belts exposes personal data of 100,000 e-learners globally
‘Beyond stupid’: Linus Torvalds trashes 5.8 Linux kernel patch over opt-in Intel CPU bug mitigation

Reading Time: ~ 3 min. Working from home is no longer something some of us can get away with some of the time. It’s become essential for our health and safety. So, what does the future of work look like in a post-COVID world? We asked some of our cybersecurity and tech experts for their […]

An update for jaeger, kiali, and servicemesh-grafana is now available for OpenShift Service Mesh 1.0. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 7 vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 13 vulnerabilities is now available.

Contact-tracer spoofing is already happening – and it’s dangerously simple to do
Had a bad weekend? Probably, if you’re a Sectigo customer, after root cert expires and online chaos ensues
Get rich quick! Work from home! Earn $100,000 easy – just find a critical flaw in Apple’s sign-in system
Cisco hacked: Six backend servers used by customer VIRL-PE deployments compromised via SaltStack
Remember when Republicans said Dems hacked voting systems to rig Georgia’s election? There were no hacks
Database of dark web host with 7600 websites leaked by KingNull

In httplib2, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts

Apple Pays $100K Bounty for Critical ‘Sign in With Apple’ Flaw
REvil ransomware gang publishes ‘Elexon staff’s passports’ after UK electrical middleman shrugs off attack
Minneapolis Police Department Hack Likely Fake, Says Researcher
No password required! “Sign in with Apple” account takeover flaw patched
Hosting Provider’s Database of Crooked Customers Leaked
Mobile payment app BHIM leaked financial data of 7 million Indians

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2344

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2337

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2334

Flask could be made to consume a large amount of memory if it received a specially crafted input.

Joomla suffers security breach exposing user records

An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Github uncovers malicious ‘Octopus Scanner’ targeting developers
Facebook to verify identities on accounts that churn out viral posts
UK.gov dangles £400k over makers of IoT Things: Go on, let’s see how you’d make a security cert scheme
The inevitable coronavirus-inspired cyber-attacks are stepping up. Are you ready?