Menu

Monthly Archives: July 2020

Who was behind that stunning Twitter hack? State spies? Probably this Florida kid, say US prosecutors

An integer overflow in the getnum function in lua_struct.c CVE-2020-14147 References: – https://bugs.mageia.org/show_bug.cgi?id=26978

Multiple security vulnerabilites in virtualbox allow unauthorized access to critical data or takeover of Oracle VM VirtualBox. See CVE references for details. References:

Updated dnsmasq package fix insecure default configuration potentially making it an open resolver (CVE-2020-14312). In its default configuration, dnsmasq listen and answer query from any address even outside of the local subnet. Thus, it may inadvertently

Bypass of boundary checks in nio.Buffer via concurrent access. (CVE-2020-14583) Incomplete bounds checks in Affine Transformations. (CVE-2020-14593)

The CBC padding operations were not constant time and as a result would leak the length of the plaintext values which were being padded to an attacker running a side channel attack via shared resources such as cache or branch predictor. No information about the contents was leaked, but the length alone might be used […]

Travel company CWT avoids ransomware derailment by paying $4.5m blackmail demand
4 Unpatched Bugs Plague Grandstream ATAs for VoIP Users
Authorities Arrest Alleged 17-Year-Old ‘Mastermind’ Behind Twitter Hack
CWT Travel Agency Faces $4.5M Ransom in Cyberattack, Report
Anti-NATO Disinformation Campaign Leveraged CMS Compromises

An update that fixes 10 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

A flaw in PyCrypto allow remote attackers to obtain sensitive information.

Multiple vulnerabilities have been found in SNMP Trap Translator, the worst of which could allow attackers to execute arbitrary shell code.

Multiple vulnerabilities have been found in WebKitGTK+, the worst of which could result in the arbitrary execution of code.

Twitter: Epic Account Hack Caused by Mobile Spearphishing
First rule of Ransomware Club is do not pay the ransom, but it looks like Carlson Wagonlit Travel didn’t get the memo
Black Hat USA 2020 Preview: Election Security, COVID Disinformation and More

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Burn baby burn, plastic inferno! Infosec researchers turn 3D printers into self-immolating suicide machines
In the market for a second-hand phone? Check it’s still supported by the vendor – almost a third sold are not
Twitter says a “phone spear phishing” attack helped hackers – what’s that?
EU tries to get serious on cybercrime with first sanctions against Wannacry, NotPetya, CloudHopper crews
Fun fact: If you noticed a while ago Zoom’s web client going AWOL for a week, it’s because someone found a passcode-cracking hole
Twitter says spear-phishing attack hooked its staff and led to celebrity account hijack

Reading Time: ~ 3 min. To try to fight the isolation and uncertainty brought on by the COVID-19 outbreak, a few weeks ago we began what we’re referring to as “Office Hours” on the Webroot Community. It’s meant to be a forum where users can come together and pose their COVID/cybersecurity-related questions to some of […]

Reading Time: ~ 2 min. Garmin Hit with WastedLocker Ransomware Nearly a week after the company announced they had suffered a system outage, Garmin has finally admitted to falling victim to a ransomware attack, likely from the increasingly popular WastedLocker variant. As is the norm for WastedLocker, the attack was very specific in its targeting […]

Infosec bod: I’ve found zero-day flaws in Tor’s bridge relay defenses. Tor Project: Only the zero part is right
Zoom Flaw Could Have Allowed Hackers To Crack Meeting Passcodes

security update

security update

Doki Backdoor Infiltrates Docker Servers in the Cloud
ESET Threat Report Q2 2020

A view of the Q2 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report Q2 2020 appeared first on WeLiveSecurity

Zoom bug meant attackers could brute force their way into password-protected meetings
Servers at risk from “BootHole” bug – what you need to know
Critical, High-Severity Cisco Flaws Fixed in Data Center Network Manager

An update that fixes one vulnerability is now available.

Smashing Security podcast #189: DNA cock-up, Garmin hack, and virtual kidnappings
Vermont Taxpayers Warned of Data Leak Over the Past Three Years

Tobias Stoeckmann found an integer overflow issue in JSON-C, a C library to manipulate JSON objects, when reading maliciously crafted large files. The issue could be exploited to cause denial of service or possibly execute arbitrary code.

chromium-browser: Use after free in ANGLE (CVE-2020-6463) * chromium-browser: Inappropriate implementation in WebRTC (CVE-2020-6514) * Mozilla: Potential leak of redirect targets when loading scripts in a worker (CVE-2020-15652) * Mozilla: Memory safety bugs fixed in Firefox 79 and Firefox ESR 68.11 (CVE-2020-15659) SL6 x86_64 firefox-68.11.0-1.el6_10.x86_64.rpm firefox-debuginfo [More…]

If you own one of these 45 Netgear devices, replace it: Gear maker won’t patch vulnerable gear despite live proof-of-concept code

The updated packages fix security vulnerabilities: A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be leveraged by remote attackers to cause a denial-of-service via a crafted pdf file. (CVE-2018-12983)

An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each

It was discovered that there was an issue where kdepim-runtime would default to using unencrypted POP3 communication despite the UI indicating that encryption was in use.

DXC says ransomware attack disrupted customer operations at insurance services arm but barely left a scratch
Critical Magento Flaws Allow Code Execution
YOU… SHA-1 NOT PASS! Microsoft magics away demonic hash algorithm from Windows updates, apps
Billions of Devices Impacted by Secure Boot Bypass
Critical Bugs in Utilities VPNs Could Cause Physical Damage
FBI warns of disruptive DDoS amplification attacks

The Bureau expects cybercriminals to increasingly abuse new threat vectors for large-scale DDoS attacks The post FBI warns of disruptive DDoS amplification attacks appeared first on WeLiveSecurity

GRUB2, you’re getting too bug for your boots: Config file buffer overflow is a boon for malware seeking to drill deeper into a system
Critical Security Flaw in WordPress Plugin Allows RCE
US tax service says, “2FA is a must!”

Several vulnerabilities have been discovered in the GRUB2 bootloader. CVE-2020-10713

Chinese ambassador to UK threatens to withdraw Huawei, £3bn investment if comms giant banned from building 5G

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code.

Thousands of websites at risk from critical WordPress commenting plugin vulnerability
Facial-Recognition Flop: Face Masks Thwart Virus, Stump Security Systems

An update of the Red Hat OpenShift Container Platform 3.11 and 4.4/4.5 container images is now available for Red Hat AMQ Online. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Top 8 File and Disk Encryption Tools for Linux>

An update that fixes one vulnerability is now available.

The Case Against Full-Disk Encryption>
Hacker plays cat-and-mouse with the EBRD’s Twitter account
OkCupid Security Flaw Threatens Intimate Dater Details
No wonder Brit universities report hacks so often: Half of staff have had zero infosec training, apparently
Japan starts work on global quantum crypto network
Reply-All storm flares as email announcing privacy policy puts 500 addresses in the ‘To’ field, not ‘BCC’

security update

Lazarus Group Brings APT Tactics to Ransomware

security update

We’re suing Google for harvesting our personal info even though we opted out of Chrome sync – netizens
Almost 4,000 databases now wiped in ‘Meow’ attacks

The attackers and their motivations remain unknown; however, the incidents yet again highlight the risks of careless data security The post Almost 4,000 databases now wiped in ‘Meow’ attacks appeared first on WeLiveSecurity

Firefox 79 is out – it’s a double-update month so patch now!
Business anti-virus products put to the test – which received the highest score?

An update that fixes 5 vulnerabilities is now available.

Bank of Ireland fined €1.66 million after being tricked by fraudster
Google blames algorithm for adding porn titles to train station search results
The Ultimate Guide to Using Data Encryption on Linux>
Podcast: Security Lessons Learned In Times of Uncertainty
Researchers Warn of High-Severity Dell PowerEdge Server Flaw
MI6 tried to intervene in independent court by stopping judge seeing legal papers – but they said sorry, so it’s OK

A minor version update (from 7.6 to 7.7) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

Linux malware could soon be a thing of the past>

Several security issues were fixed in MySQL.

# July 2020 OpenJDK security update for OpenJDK 11 Full release notes: https://bitly.com/openjdk1108 ## Security fixes – JDK-8230613: Better ASCII conversions – JDK-8231800: Better listing of arrays – JDK-8232014: Expand DTD support – JDK-8233234: Better Zip Naming – JDK-8233239, CVE-2020-14562: Enhance TIFF support – JDK-8233255: Better Swing Buttons –

# July 2020 OpenJDK security update for OpenJDK 8. Full release notes: https://bitly.com/oj8u262 ## New features * [JDK-8223147](https://bugs.openjdk.java.net/browse/JDK-8223147): JFR Backport ## Security fixes – JDK-8028431, CVE-2020-14579: NullPointerException in DerValue.equals(DerValue) – JDK-8028591, CVE-2020-14578:

ClamAV 0.102.4 is a bug patch release to address the following issues: CVE-2020-3350 Fixed a vulnerability a malicious user could exploit to replace a scan target’s directory with a symlink to another path to trick clamscan, clamdscan, or clamonacc into removing or moving a different file (such as a critical system

Find out this week: How to build a cyber threat intelligence program while cutting through the noise
Tune in this week to learn all about an identity-centric approach to zero-trust security
Data-stealing, password-harvesting, backdoor-opening QNAP NAS malware cruises along at 62,000 infections
Microsoft Revamps Windows Insider Preview Bug Bounty Program
Source code of over 50 high profile organizations leaked online
Garmin staggers back online after ransomware attack
Attackers Exploiting High-Severity Network Security Flaw, Cisco Warns
Cloudflare suffered data leak; exposing 3 million IP addresses: Ukraine
Encryption Under ‘Full-Frontal Nuclear Assault’ By U.S. Bills