Menu

Monthly Archives: August 2020

North Korean hackers pwned cryptocurrency sysadmin with GDPR-themed LinkedIn lure, says F-Secure
The Viking Snowden: Denmark spy chief ‘relieved of duty’ after whistleblower reveals illegal snooping on citizens
Google Fixes High-Severity Chrome Browser Code Execution Bug

security update

Iran-Linked ‘Newbie’ Hackers Spread Dharma Ransomware Via RDP Ports

An update that fixes 21 vulnerabilities is now available.

Several security issues were fixed in Net-SNMP.

APIs Are the Next Frontier in Cybercrime

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update for openshift-enterprise-hyperkube-container is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for jenkins and openshift is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Canadian shipping company Canpar gets an unwanted delivery – ransomware
Bletchley Park Trust can’t crack COVID-caused revenue slump without losing staff

Chrony’s method of opening its PID file could allow a compromised chrony user account to overwrite files in certain parts of the filesystem with chrony’s PID, using a symlink attack (CVE-2020-14367). References:

Reading Time: ~ 2 min. Ransomware Attack Targets Major Cruise Line Officials for Carnival Cruises have confirmed that a portion of their IT systems were encrypted following a cyberattack identified over the weekend. The company also revealed that sensitive information for both employees and customers was illicitly accessed, though they did not admit to what […]

Security fix for CVE-2020-14367

Several vulnerabilities have been discovered in sqlite3, a C library that implements an SQL database engine. CVE-2018-8740

Several memory leaks were discovered in proftpd-dfsg, a versatile, virtual-hosting FTP daemon, when mod_facl or mod_sftp is used which could lead to memory exhaustion and a denial-of-service.

Jason A. Donenfeld found an ansi escape sequence injection into software-properties, a manager for apt repository sources. An attacker could manipulate the screen of a user prompted to install an additional repository (PPA).

News Wrap: AWS Cryptojacking Worm, IBM Privacy Lawsuit and More

Multiple vulnerabilities were discovered in Python2.7, an interactive high-level object-oriented language.

Tim Starling discovered two vulnerabilities in firejail, a sandbox program to restrict the running environment of untrusted applications.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Utes gotta be kidding me… University of Utah handed $457K to ransomware creeps
Appearing on the Easy Prey podcast
Outlook “mail issues” phishing – don’t fall for this scam!
University of Utah Pays $457K After Ransomware Attack
CREST exam cheat-sheet scandal: New temp chairman at UK infosec body as lawyers and ex-copper get involved

An update that solves one vulnerability and has 22 fixes is now available.

An update that solves one vulnerability and has 19 fixes is now available.

Researchers Sound Alarm Over Malicious AWS Community AMIs
Using AI to fight hand-crafted Business Email Compromise
Shared memory vulnerability in IBM’s Db2 database could let nefarious insiders wreak havoc – so get patching
Former Uber CSO Charged With Paying ‘Hush Money’ in 2016 Breach Cover-Up

Several security issues were fixed in Bind.

Physical locks are less hackable than digital locks, right? Maybe not: Boffins break in with a microphone

An update that solves 7 vulnerabilities and has 109 fixes is now available.

Ex-Uber chief security officer charged, accused of covering up theft of personal info from databases by hackers

The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function. (CVE-2020-14148) References:

– fix expired pointer dereference via multi API with `CURLOPT_CONNECT_ONLY` option set (CVE-2020-8231)

IBM Settles Lawsuit Over Weather Channel App Data Privacy
How to prepare and protect your digital legacy

It’s never too soon to plan for what will happen to your digital presence after you pass away The post How to prepare and protect your digital legacy appeared first on WeLiveSecurity

Transparent Tribe Mounts Ongoing Spy Campaign on Military, Government
Microsoft Out-of-Band Security Update Fixes Windows Remote Access Flaws
Experian says it recovered and deleted data on 24 million South Africans after giving it to random ‘marketing’ person

Multiple vulnerabilities were found in ghostscript, an interpreter for the PostScript language and for PDF, allowing an attacker to escalate privileges and cause denial of service via crafted PS/EPS/PDF files.

An update that solves two vulnerabilities and has 6 fixes is now available.

Senate Bill Would Expand Facial-Recognition Restrictions Nationwide
Cisco Critical Flaw Patched in WAN Software Solution
Warehouse management software biz SnapFulfil hit by ransomware: It’s not just the big dogs getting KO’d
IBM AI-Powered Data Management Software Subject to Simple Exploit
Sloppy string sanitization sabotages system security of millions of Java-powered 3G IoT kit: Patch me if you can

curl could be made to expose sensitive information over the network.

Thanks for the memories… now pay up or else: Maze ransomware crew claims to have hacked SK hynix, leaks ‘5% of stolen files’
Smashing Security podcast #192: Ritz and robocalls with Rory

Rebased to version 3.33.0

Update to v0.3.4 release

A security flaw was found on ruby kramdown which may lead to unintended code execution. This vulnerability is now assigned as CVE-2020-14001 . This new rpm should fix this issue.

Researchers Warn of Flaw Affecting Millions of IoT Devices
FritzFrog Botnet Attacks Millions of SSH Servers
Warn your staff about phone spear phishing attacks, as reports rise
Ritz London clients scammed after apparent data breach

Armed with personal data stolen from the hotel’s dining reservation system, fraudsters trick guests into handing over their credit card details The post Ritz London clients scammed after apparent data breach appeared first on WeLiveSecurity

Bletchley Park visitors warned of data breach after Blackbaud ransomware attack

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in QEMU.

Airline DMARC Policies Lag, Opening Flyers to Email Fraud
The Sounds a Key Make Can Produce 3D-Printed Replica

An update that fixes two vulnerabilities is now available.

An update for rh-mysql80-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Floating COVID incubation tank becomes data-leaking ransomware rustbucket: Carnival admits crims made off with personal data booty
Pretty wild that a malicious mailto: link might attach your secret keys and files from your PC to an outgoing message
US senators: WikiLeaks ‘likely knew it was assisting Russian intelligence influence effort’ in 2016 Dem email leak
Researchers Warn of Active Malware Campaign Using HTML Smuggling
Large Orgs Plagued with Bugs, Face Giant Patch Backlogs
US liquor giant hit by ransomware – what the rest of us can do to help
Attack of the Instagram clones

Could your social media account be spoofed, why would anybody do it, and what can you do to avoid having a doppelgänger? The post Attack of the Instagram clones appeared first on WeLiveSecurity

CVE-2020-12100: Receiving mail with deeply nested MIME parts leads to resource exhaustion as Dovecot attempts to parse it. CVE-2020-12673: Dovecot’s NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. CVE-2020-12674: Dovecot’s RPA mechanism implementation accepts zero-length

In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it’s required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory (CVE-2020-15121).

It was reported that firejail does not respect the end-of-options separator (“–“), allowing an attacker with control over the command line options of the sandboxed application, to write data to a specified file (CVE-2020-17367). It was reported that firejail when redirecting output via –output or

Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the ‘Cache-Digest’ header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via “H2Push off” will mitigate this vulnerability for unpatched servers (CVE-2020-9490).

An access flaw was found in targetcli, where the /etc/target and underneath backup directory/files were world-readable. This flaw allows a local attacker to access potentially sensitive information such as authentication credentials from the /etc/target/saveconfig.json and backup files. The highest threat from this vulnerability is to confidentiality (CVE-2020-13867).

Servers where the Handler concurrently reads the request body and writes a response can encounter a data race and crash. The httputil.ReverseProxy Handler is affected (CVE-2020-15586). Certain invalid inputs to ReadUvarint or ReadVarint could cause those functions

AWS Cryptojacking Worm Spreads Through the Cloud
TV stations – stop broadcasting your passwords!
Plymouth Passport Office’s pitiful password privacy
Smashing Security podcast #191: We are on the bird
IcedID Trojan Rebooted with New Evasive Tactics

Reading Time: ~ 3 min. Cyber resilience is being put to the test during the coronavirus pandemic. As more and more users work from home, it’s becoming increasingly difficult for IT teams to ensure uniform cyber security on home devices and networks that they don’t own or control. At the same time, cybercriminals are using […]

Cloudops tool integration is more important than the tools themselves
Please stop hard-wiring AWS credentials in your code. Looking at you, uni COVID-19 track-and-test app makers
‘EmoCrash’ Exploit Stoppered Emotet For 6 Months
Jack Daniels, Ritz London Face Cyberattacks

Reading Time: ~ 2 min. Colorado Town Suffers Ransomware Attack The town of Lafayette, Colorado, fell victim to a ransomware attack last week without the capability to recover from the attack without paying a ransom of $45,000 in cryptocurrency. The attack disabled many city services for a number of days until officials determined they would […]

CREST cancels UK infosec accreditation exams after fresh round of ‘cheat sheets’ are leaked online
Cyberattacks Hit Thousands of Canadian Tax, Benefit Accounts

An update that solves 7 vulnerabilities and has two fixes is now available.