Menu

Monthly Archives: July 2020

Updated ffmpeg packages fix security vulnerabilities: This update provides ffmpeg version 4.1.6, which fixes several security vulnerabilities and other bugs which were corrected upstream.

Report: Most Popular Home Routers Have ‘Critical’ Flaws
TomTom bill bomb: Why am I being charged for infotainment? I sold my car last year, rages Reg reader

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Digicert will shovel some 50,000 EV HTTPS certificates into the furnace this Saturday after audit bungle
Locating malicious drone operators through deep neural networks
Microsoft Warns on OAuth Attacks Against Cloud App Users
FYI: Someone’s scanning gateways, looking for those security holes Citrix told you not to worry too much about

security update

security update

Proxy or VPN for Netflix – Which is Best?
Popular home routers plagued by critical security flaws

A study paints a dim picture of router security, as none of the 127 devices tested was free of severe vulnerabilities The post Popular home routers plagued by critical security flaws appeared first on WeLiveSecurity

Zoom Zero-Day Allows RCE, Patch on the Way
Smartwatch vulnerability allowed hackers to overdose dementia patients
Joker Android Malware Dupes Its Way Back Onto Google Play
How to build a cyber threat intelligence program while cutting through the noise
15 billion credentials from 100,000 data breaches sold on dark web
BlueLeaks Server Seized By German Police: Report

Several security issues were fixed in OpenSSL.

Cosmic Lynx: The highly-professional cybercrime gang scamming businesses out of millions of dollars
‘Undeletable’ Malware Shows Up in Yet Another Android Device
Smashing Security podcast #186: This one’s for all the Karens!
If you haven’t potentially exposed 1000s of customers once again with networking vulns, step forward… Not so fast, Palo Alto Networks
Social engineering hacks weaken cybersecurity during the pandemic
240 top Microsoft Azure-hosted subdomains hacked to spread malware
Microsoft sues coronavirus phishing spammers to seize their domains amid web app attacks against Office 354.5

FIx CVE-2019-20454

This is a security fix release that includes fixes for the following local buffer overflow vulnerability. – CVE-2022-4044: Local users can perform a buffer overflow attack against the xrdp-sesman service and then impersonate it This update is recommended for all xrdp users.

Remmina 1.4.7 and FreeRDP 2.1.2 to fix many bugs and CVEs

Remmina 1.4.7 and FreeRDP 2.1.2 to fix many bugs and CVEs

Security update for CVE-2020-12695 (CallStranger)

security update

Advertising Plugin for WordPress Threatens Full Site Takeovers
Nasty Cerberus banking trojan found on Google Play Store
One surefire way to get the boss’s attention on network security is to get hacked. But there must be a better way?
Criminals auction off stolen domain admin credentials for up to £95k. Your bank account details? Barely get £50
Attackers target critical flaw in popular networking gear

The vulnerability, which received the highest possible severity score, leaves thousands of devices at risk of being taken over by remote attackers. A patch is available. The post Attackers target critical flaw in popular networking gear appeared first on WeLiveSecurity

Raising children in the social media limelight? Pause before you post

How (over)sharing your children’s triumphs and antics with the world may impact their immediate and distant future – and how to reduce the risks of ‘sharenting’ The post Raising children in the social media limelight? Pause before you post appeared first on WeLiveSecurity

German Police seize DDoSecrets server hosting BlueLeaks data dump
Notorious Hacker ‘Fxmsp’ Outed After Widespread Access-Dealing
Feds indict Fxmsp hacker who breached anti-virus firms to sell data
Microsoft Seizes Malicious Domains Used in Mass Office 365 Attacks

Several security issues were fixed in Thunderbird.

Mozilla turns off “Firefox Send” following malware abuse reports

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2824

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2827

15 Billion Credentials Currently Up for Grabs on Hacker Forums

Several vulnerabilities have been discovered in the interpreter for the Ruby language. CVE-2020-10663

Citrix tells everyone not to worry too much over its latest security patches. NSA’s former top hacker disagrees
Kinda sorta weakened version of EARN IT Act creeps closer

An update that fixes four vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

security update

Shopped recently in a small online store? Check this list to see if it was one of 570 websites infected with card-skimming Magecart
BEC Hotshot with Opulent Social Media Presence to Face U.S. Charges
Keeper Threat Group Rakes in $7M from Hundreds of Compromised E-Commerce Sites
Microsoft launches free Linux memory forensics tool for detecting malware
The Fed shares insight on how to combat synthetic identity fraud

The Federal Reserve looks at ways to counter what is thought to be the fastest-growing type of financial crime in the country The post The Fed shares insight on how to combat synthetic identity fraud appeared first on WeLiveSecurity

Fret not, Linux fans, Microsoft’s Project Freta is here to peer deep into your memory… to spot malware
Cerberus Banking Trojan Unleashed on Google Play
FBI arrests Famous Instagrammer Ray Hushpuppi over $125m BEC scam
Citrix Bugs Allow Unauthenticated Code Injection, Data Theft
Company web names hijacked via outdated cloud DNS records
Lazarus hackers use Magecart attack to steal card data from EU, US sites
Credit-Card Skimmer Has Unlikely Target: Microsoft ASP.NET Sites

Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate trust rules as software updates (CVE-2020-12421) SL6 x86_64 firefox-68.10.0-1.el6_10.x86_64.rpm [More…]

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Mozilla: Memory corruption due to missing sign-extension for ValueTags on ARM64 (CVE-2020-12417) * Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate tr [More…]

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has one errata is now available.

Reading Time: ~ 4 min. “What’s an evasive attack? At a very basic level, it’s exactly what it sounds like; it’s a cyberattack that’s designed to hide from you,” says Grayson Milbourne, Security Intelligence Director at Webroot, an OpenText company. Based on Grayson’s initial explanation, you can imagine that evasive tactics are pretty common throughout […]

First-Ever Russian BEC Gang, Cosmic Lynx, Uncovered
Social media giants move to defy Hong Kong’s new national security law
Flashy Nigerian Instagram star extradited to US to face BEC charges
Hundreds of forgotten corners of mega-corp websites fall into the hands of spammers and malware slingers
Want to kill all the weak passwords? This may be the tool for you
Your 2.3m Instagram fans won’t stop the FBI… Web star accused of plotting to launder millions from cyber-crime
You may be distracted by the pandemic but FYI: US Senate panel OK’s backdoors-by-the-backdoor EARN IT Act

security update

No jail for Yahoo employee who used internal system to hack 6k accounts
Android Users Hit with ‘Undeletable’ Adware
Admins Urged to Patch Critical F5 Flaw Under Active Attack
Google VP boycotts Black Hat 2020 because of its name
Lazarus Group Adds Magecart to the Mix
Techie buys Axon body camera from eBay; finds unencrypted police videos
Purple Fox EK Adds Microsoft Exploits to Arsenal
Think of a number: A tale of iffy discount codes, supermarket loyalty cards and Hotels.com

An update that solves one vulnerability and has two fixes is now available.

Encrypted phone service EncroChat dismantled; leading to 800+ arrests
Appearing on the Hacker Valley Studio podcast

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves 13 vulnerabilities and has one errata is now available.

Three UK: We’re sending you this SMS to warn you not to pay attention to unsolicited texts
Boston bans government use of facial recognition
Make sure you’ve patched your F5 BIG-IP gear. Exploit code for scary bug pair is so trivial, it fits in a tweet

An update for jaeger-all-in-one-rhel7-container and jaeger-query-rhel7-container is now available for Jaeger-1.17. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Security fix for CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag