Menu

Monthly Archives: July 2020

Stick that in your named pipe and smoke it: Flaw in Citrix Workspace could let remote attacker pwn host machine
UK intel committee on Russia: Social media firms should remove state disinformation. What was that, MI5? ████████?
Critical Adobe Photoshop Flaws Patched in Emergency Update
UK Government chose not to investigate if Russian hackers interfered in Brexit referendum, report reveals
The Art of Convenience in A World Run by The Internet of Things

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Diebold ATM Terminals Jackpotted Using Machine’s Own Software
Apple was the only Fortune 50 company to foresee COVID-19 pandemic risk and properly insure against it – Forrester

An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for cloud-init is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that fixes 10 vulnerabilities is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for the mod_auth_openidc:2.3 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Argentina’s largest telecom hacked with hackers demanding $7.5 million

security update

security update

security update

security update

Reading Time: ~ 2 min. Malware Discovered in Chinese Tax Software As part of an official Chinese tax initiative, researchers have found multiple backdoors into mandatory tax software installed on all Chinese business systems. The new malware is called GoldenHelper, in a nod to the command-and-control domain tax-helper.ltd, and has been in active development and […]

Teens arrested after paying Bitcoin to watch livestream abuse & murder
Facebook’s NSO Group Lawsuit Over WhatsApp Spying Set to Proceed
Computer misuse crimes down 9% on last year in England and Wales, says Office of National Statistics
7 VPNs that leaked their logs – the logs that “didn’t exist”
Mac Cryptocurrency Traders Targeted by Trojanized Apps
You’ve had your pandemic holiday, now Microsoft really is going to kill off TLS 1.0, 1.1
Cloud hosting firm Blackbaud pays ransom after thwarting ransomware attack

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An axe age, a sword age, Privacy Shield is riven, but what might that mean for European businesses?
Mitre, the creepy company checking your fingerprints on Facebook for the US Government
Paving the Path to Passwordless
UK.gov admits it has not performed legally required data protection checks for COVID-19 tracing system
Bill & Melinda Gates foundation impersonated in Bitcoin phishing scam

An HTTP request smuggling issue was discovered in the ngx_lua plugin for nginx, a high-performance web and reverse proxy server, as demonstrated by the ngx.location.capture API.

Multiple vulnerabilities were found in Ruby on Rails, a MVC ruby-based framework geared for web application development, which could lead to remote code execution and untrusted user input usage, depending on the application.

An update that contains security fixes can now be installed.

An update that fixes 13 vulnerabilities is now available.

Is your Office 365 locked down in lockdown?
Hey there, want to break into computers like an Iranian hacker crew? IBM finds 40GB of videos that include how-tos
Career Notes podcast – Have to be able to communicate to everybody
Twitter hackers busted 2FA to access accounts and then reset user passwords
Google Cloud adds security capabilities for sensitive workloads

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

security update

security update

security update

security update

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 10 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves 5 vulnerabilities and has one errata is now available.

An update that solves four vulnerabilities and has two fixes is now available.

Seven ‘no log’ VPN providers accused of leaking – yup, you guessed it – 1.2TB of user logs onto the internet
Thousands of Vulnerable F5 BIG-IP Users Still Open to Takeover
Judge green-lights Facebook, WhatsApp hacking lawsuit against spyware biz NSO, unleashing Zuck’s lawyers
40GB of leaked videos expose how Iranian hackers hijack email accounts
Cloud biz Blackbaud caved to ransomware gang’s demands – then neglected to inform customers for two months

An update for .NET Core is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Twitter Hack Update: What We Know (and What We Don’t)
High‑profile Twitter accounts hacked to promote Bitcoin scam

Tech titans and prominent politicians among victims of a sprawling hack that Twitter says leveraged its internal tools The post High‑profile Twitter accounts hacked to promote Bitcoin scam appeared first on WeLiveSecurity

Mac cryptocurrency trading application rebranded, bundled with malware

ESET researchers lure GMERA malware operators to remotely control their Mac honeypots The post Mac cryptocurrency trading application rebranded, bundled with malware appeared first on WeLiveSecurity

Ew, that’s unsanitary: SEO plugin for WordPress would run arbitrary JavaScript inputs instead of scrubbing them
CISA Emergency Directive Orders Immediate Fix of Windows DNS Server Bug
Apple’s latest updates are out for iPhones and Macs – get them now!
7 VPN firms with no-logs policy end up exposing 1.2 TB of user data
Insecure IoT devices could be banned and destroyed if they fail to meet UK security standards
Twitter admits 130 A-lister accounts compromised to promote Bitcoin scam after ‘social engineering’ attack

An update for .NET Core is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

The Twitter hack: Why Elon Musk, Bill Gates, Jeff Bezos and others might have reason to be worried
This week of never-ending security updates continue. Now Apple emits dozens of fixes for iOS, macOS, etc

Update to 3.9.0b4

0.9.24 release

Update to 3.9.0b4

Enterprise Data Security: It’s Time to Flip the Established Approach
Online Jewish service ‘Zoom bombed’ with hate speech & Swastikas

Reading Time: ~ 3 min. Summer is upon us. For some, summer is all about physical fitness. While exercise is essential to our overall well-being, we shouldn’t forget about our digital fitness, either. Just as our bodies serve our needs and help us go about our daily lives, so too do our computers and digital […]

FYI Russia is totally hacking the West’s labs in search of COVID-19 vaccine files, say UK, US, Canada cyber-spies
Hackers Look to Steal COVID-19 Vaccine Research
Microsoft patches critical, wormable flaw in Windows DNS Server

The company urges organizations to waste no time in installing updates to fix the vulnerability that rates a ‘perfect’ 10 on the severity scale The post Microsoft patches critical, wormable flaw in Windows DNS Server appeared first on WeLiveSecurity

Details of 142 million MGM hotel guests selling for US$2,900

It appears that the July 2019 breach at MGM Resorts affected far more people than initially thought The post Details of 142 million MGM hotel guests selling for US$2,900 appeared first on WeLiveSecurity

Mobile security threats amid COVID‑19 and beyond: A Q&A with Lukas Stefanko

ESET malware researcher Lukas Stefanko gives us a peek behind the scenes of his analysis of CryCryptor ransomware and puts the threat into a broader context The post Mobile security threats amid COVID‑19 and beyond: A Q&A with Lukas Stefanko appeared first on WeLiveSecurity

Crypto scam: Twitter’s internal tool was used in hijacking verified accounts
Zoom Addresses Vanity URL Zero-Day
Privacy Shield binned after EU court rules transatlantic data protection arrangements ‘inadequate’

An update that fixes three vulnerabilities is now available.

VPN firm that claims zero logs policy leaks 20 million user logs
Amazon-Themed Phishing Campaigns Swim Past Security Checks
Threat Actors Introduce Unique ‘Newbie’ Hacker Forum

Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate trust rules as software updates (CVE-2020-12421) SL6 x86_64 thunderbird-68.10.0-1.el6_10.x86_64 [More…]

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The Twitter mega-hack. What you need to know
Finally done with all those Patch Tuesday updates? Think again! Here’s 33 Cisco bug fixes, with five criticals
Smashing Security podcast #187: Huawei ban, MGM hack, and a contact-tracing cock-up