Menu

Monthly Archives: August 2020

Critical vuln that lets miscreants hijack computers via Slack? *Sucks in air* We’ll give you $1,750 for it
Apple Accidentally Notarizes Shlayer Malware Used in Adware Campaign
Charming Kitten Returns with WhatsApp, LinkedIn Effort
Stolen Fortnite Accounts Earn Hackers Millions Per Year
Critical Slack Bug Allows Access to Private Channels, Conversations

An update that fixes two vulnerabilities is now available.

– New upstream version (80.0)

New F32 selinux-policy build

This release includes the latest stable version of Apache **httpd**, version **2.4.46**. A security issue is addressed in this update: * **CVE-2020-11984** mod_proxy_uwsgi: Malicious request may result in information disclosure or RCE of existing file on the server running under a malicious process environment. For the full list of changes in this release, see

Updates to the latest upstream release of Eclipse. See the upstream release notes for details: https://www.eclipse.org/eclipseide/2020-06/noteworthy/ Also contains security fixes for CVE-2019-17566 and CVE-2019-17638.

Updates to the latest upstream release of Eclipse. See the upstream release notes for details: https://www.eclipse.org/eclipseide/2020-06/noteworthy/ Also contains security fixes for CVE-2019-17566 and CVE-2019-17638.

Microsoft reprieves SHA-1 deprecation in Edge 85 security baseline
The five best Kubernetes security practices

security update

security update

security update

security update

Use of unsafe yaml load was fixed in ros-actionlib, the Robot OS actionlib library. For Debian 9 stretch, this problem has been fixed in version

Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository (CVE-2020-24614). The fossil package has been updated to version 2.10.2, containing fixes for

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Several vulnerabilites have been reported against FreeRDP, an Open Source server and client implementation of the Microsoft RDP protocol. CVE-2014-0791

An update that solves one vulnerability and has one errata is now available.

An update that solves three vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

Faidon Liambotis discovered that Lilypond, a program for typesetting sheet music, did not restrict the inclusion of Postscript and SVG commands when operating in safe mode, which could result in the execution of arbitrary code when rendering a typesheet file with

Multiple security issues were found in the OpenEXR image library, which could result in denial of service and potentially the execution of arbitrary code when processing malformed EXR image files.

Multiple security issues have been found in Thunderbird which could result in the execution of arbitrary code or the unintended installation of extensions.

Reading Time: ~ 3 min. If you’ve landed on this blog, then there’s a good chance you’re already aware that DNS is undergoing a major overhaul. DNS 2.0—aka encrypted DNS, DNS over HTTPS, or DoH—is a method for encrypting DNS requests with the same HTTPS standard used by numerous websites, such as online banking, to […]

Before you head off for the weekend, you have patched your Pulse Secure VPNs, right? Wouldn’t want you to be pwned via a phishing link
Linux Server Security: A Getting Started Guide>

security update

Instagram ‘Help Center’ Phishing Scam Pilfers Credentials
DDoS extortion campaign targets financial firms, retailers

The extortionists attempt to scare the targets into paying by claiming to represent some of the world’s most notorious APT groups The post DDoS extortion campaign targets financial firms, retailers appeared first on WeLiveSecurity

Elon Musk Confirms, Tesla Factory a Target of Foiled Cyberattack
Sloppy Southern Water found leaking customers’ bills and account details

Reading Time: ~ 2 min. Thousands of Android Users fall Victim to Giveaway Fraud Upwards of 65,000 Android users were potentially compromised after installing a malicious app promising free giveaways. Over the year the scam was in effect, roughly 5,000 apps were spoofed to lure victims into downloading in exchange for a phony giveaway. In […]

An update that solves one vulnerability and has 36 fixes is now available.

An update that solves one vulnerability and has 35 fixes is now available.

Fake Android notifications – first Google, then Microsoft affected
DoJ Aims to Seize 280 Cryptocurrency Accounts Used by Hackers

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed (CVE-2020-15664).

evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a “begin TLS” response, eds reads additional data and evaluates it in a TLS context, aka “response injection”. (CVE-2020-14928)

Southern Water customers could view others’ personal data by tweaking URL parameters

An update that fixes one vulnerability is now available.

* The `readUvarint` function would run infinitely given specific input. The function is now terminating if more than 10 bytes of input have been read. Fixes [issue #35](https://github.com/ulikunitz/xz/issues/35) (CVE-2020-16845). * Supports the check-ID None and fixes “Checksum None is invalid” [issue #27](https://github.com/ulikunitz/xz/issues/27).

BeagleBoyz: 2020’s hottest country-rap band, or N. Korea hackers stealing millions. Only one way to find out…

security update

Ex-Cisco Employee Pleads Guilty to Deleting 16K Webex Teams Accounts
New Chrome, Firefox versions fix security bugs, bring productivity features

Chrome gets a new way of managing tabs while Firefox now features a new add-ons blocklist The post New Chrome, Firefox versions fix security bugs, bring productivity features appeared first on WeLiveSecurity

Facebook Hits Back At Apple’s iOS 14 Privacy Update
Magecart’s Success Paves Way For Cybercriminal Credit Card ‘Sniffer’ Market

The handler for the XkbSetNames request does not validate the request length before accessing its contents (CVE-2020-14345). An integer underflow exists in the handler for the XIChangeHierarchy request (CVE-2020-14346).

There is an integer overflow and a double free vulnerability in the way LibX11 handles locales. The integer overflow is a necessary precursor to the double free (CVE-2020-14363). References:

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed (CVE-2020-15664).

The read_xbm_body function in gui/image/qxbmhandler.cpp has a buffer over-read (CVE-2020-17507). References: – https://bugs.mageia.org/show_bug.cgi?id=27173

NSS could be made to expose sensitive information if it received a specially crafted input.

Russian cybercrime suspect arrested in $1m ransomware conspiracy

An update is now available for CloudForms Management Engine 5.10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Malicious Attachments Remain a Cybercriminal Threat Vector Favorite
Revamped Qbot Trojan Packs New Punch: Hijacks Email Threads
‘My wife tried to order some clothes tonight. When she logged in, she was in someone else’s account … Now someone’s charged her card’
DDoS downs New Zealand stock exchange for third consecutive day

security update

Smashing Security podcast #193: Hacking the CIA, Bridgefy, and college lockdowns
Forget your space-age IT security systems. It might just take a $1m bribe and a willing employee to be pwned
North Korean hacking gang targets banks worldwide, US Government warns

security update

Cisco Patches ‘High-Severity’ Bugs Impacting Switches, Fibre Storage
Here’s a neat exploit to trick someone into inadvertently emailing their files to you from their Mac, iPhone via Safari
“Chrome considered harmful” – the Law of Unintended Consequences
Researchers shine light on hackers-for-hire op that hit estate agent with malicious plugin for Autodesk 3ds Max
Hackers Exploit Autodesk Flaw in Recent Cyberespionage Attack
Disinformation Spurs a Thriving Industry as U.S. Election Looms

An update that fixes one vulnerability is now available.

Medical Data Leaked on GitHub Due to Developer Errors
US election 2020: The disinfo operations have evolved, but so have state governments

It was reported that the Lua module for Nginx, a high-performance web and reverse proxy server, is prone to a HTTP request smuggling vulnerability.

Mozilla: Attacker-induced prompt for extension installation (CVE-2020-15664) * Mozilla: Use-After-Free when aborting an operation (CVE-2020-15669) SL6 x86_64 firefox-68.12.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.12.0-1.el6_10.x86_64.rpm firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm i386 firefox-68.12.0-1.el6_10.i686.rpm firefox-d [More…]

How to Write a Cybersecurity Playbook During a Pandemic

Several security issues were fixed in libmysofa.

An update that fixes three vulnerabilities is now available.

– New upstream version (80.0)

security update

Four More Bugs Patched in Microsoft’s Azure Sphere IoT Platform
FBI, CISA warn of spike in vishing attacks

Cybercriminals increasingly take aim at teleworkers, setting up malicious duplicates of companies’ internal VPN login pages The post FBI, CISA warn of spike in vishing attacks appeared first on WeLiveSecurity

Cyber attacks: Several Canadian government services disrupted

Several services from the Canadian government, including the national revenue agency, had to be shut down following a series of credential stuffing cyberattacks. The post Cyber attacks: Several Canadian government services disrupted appeared first on WeLiveSecurity

How to secure your TikTok account

From keeping your account safe to curating who can view your liked content, we look at how you can increase your security and privacy on TikTok The post How to secure your TikTok account appeared first on WeLiveSecurity

Impersonating users of ‘protest’ app Bridgefy was as simple as sniffing Bluetooth handshakes for identifiers
Safari Bug Revealed After Apple Takes Nearly a Year to Patch
Lazarus Group Targets Cryptocurrency Firms Via LinkedIn Messages
Be very afraid! British Army might scrap battle tanks for keyboard warriors – report

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

Shoring Up the 2020 Election: Secure Vote Tallies Aren’t the Problem