Menu

Monthly Archives: August 2020

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes four vulnerabilities is now available.

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Samba could be made to crash if it received specially crafted network traffic.

An update for libvncserver is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Pay ransomware crooks, or restore the network? Guess which way this city chose after weighing up the costs
Monday review – catch up with the latest articles

Reading Time: ~ 2 min. Multiple Individuals Charged for Twitter Hack Three people were charged with last month’s Twitter hack, which generated over $100,000 in bitcoin by hijacking high-profile accounts. Of the 130 accounts used to spread the Bitcoin scam, major names included Elon Musk and Bill Gates, who have been portrayed in similar past […]

xrdp-sesman service in xrdp can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them

Qualcomm Bugs Open 40 Percent of Android Handsets to Attack
Attackers Horn in on MFA Bypass Options for Account Takeovers
Have I Been Pwned Set to Go Open-Source

ruby-kramdown processes the template option inside Kramdown documents by default, which allows unintended read access (such as template=”/etc/passwd”) or unintended embedded Ruby code execution (such as a string that begins with template=”string://

An update that fixes 26 vulnerabilities is now available.

Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt

# rpki-client 6.7p1 * Security fix: Incorrect use of `EVP_PKEY_cmp` allowed an authentication bypass

The following CVE(s) have been reported against src:wpa. CVE-2019-10064

An update that fixes 7 vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

A use-after-free was found in iproute2, possibly allowing a Denial of Service condition.

A buffer overflow in gThumb might allow remote attacker(s) to execute arbitrary code.

Multiple vulnerabilities have been found in Apache, the worst of which could result in the arbitrary execution of code.

What happens when holes perfect for spyware are found in the engine room of millions of Qualcomm-based phones? Let’s find out
How did you spend your time at university? Pizza, booze, sleeping? This Oxford student is snooping on satellites

security update

Blackbaud data breach: What you should know

Here’s what to be aware of if your personal data was compromised in the breach at the cloud software provider The post Blackbaud data breach: What you should know appeared first on WeLiveSecurity

An update that contains security fixes can now be installed.

An update that fixes 12 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Hackers Dump 20GB of Intel’s Confidential Data Online
Augmenting AWS Security Controls
Business Email Compromise – fighting back with machine learning
Android user chucks potential $10bn+ sueball at Google over ‘spying’, ‘harvesting data’… this time to build supposed rival to TikTok called ‘Shorts’

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3253

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3344

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3233

So you’ve decided you want to write a Windows rootkit. Good thing this chap’s just demystified it in a talk
Chrome Web Store slammed again after 295 ad-injecting, spammy extensions downloaded 80 million times
Trump administration labels WeChat, TikTok ‘threats’ to national security, bans transactions with both
Capital One fined $80m for shoddy public cloud security. Yeah, same bank in that 106m customer-record hack
Black Hat 2020: Influence Campaigns Are a Cybersecurity Problem
Foreshadow returns to the foreground: Secrets-spilling speculative-execution Intel flaw lives on, say boffins
When it comes to hacking societies, Russia remains the master at sowing discord and disinformation online
Black Hat 2020: Mercedes-Benz E-Series Rife with 19 Bugs
Canon Admits Ransomware Attack in Employee Note, Report

security update

Beyond KrØØk: Even more Wi‑Fi chips vulnerable to eavesdropping

At Black Hat USA 2020, ESET researchers delved into details about the KrØØk vulnerability in Wi-Fi chips and revealed that similar bugs affect more chip brands than previously thought The post Beyond KrØØk: Even more Wi‑Fi chips vulnerable to eavesdropping appeared first on WeLiveSecurity

Black Hat 2020: Satellite Comms Globally Open to $300 Eavesdropping Hack
Intel NDA blueprints – 20GB of source code, schematics, specs, docs – spill onto web from partners-only vault
NSA shares advice on how to limit location tracking

The intelligence agency warns of location tracking risks and offers tips for how to reduce the amount of data shared The post NSA shares advice on how to limit location tracking appeared first on WeLiveSecurity

Yunus ‘ad±rc± found an issue in the SUBSCRIBE method of UPnP, a network protocol for devices to automatically discover and communicate with each other. Insuficient checks on this method allowed attackers to use vulnerable UPnP services for DoS attacks or possibly to bypass

High-Severity Cisco DoS Flaw Plagues Small-Business Switches

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 10 vulnerabilities is now available.

An update that solves 19 vulnerabilities and has 92 fixes is now available.

Think carefully about cyber insurance, says NCSC. But don’t worry about buying off ransomware crooks
A scam letter! Warn your vulnerable loved ones to be on their guard
Black Hat 2020: ‘Zero-Click’ MacOS Exploit Chain Uses Microsoft Office Macros
Porn blast disrupts bail hearing of alleged Twitter hacker
Black Hat 2020: Using Botnets to Manipulate Energy Markets for Big Profits

ppp could be made to load arbitrary kernel modules and possibly run programs.

U.S. Offers Reward of $10M for Info Leading to Discovery of Election Meddling

An update that solves one vulnerability and has one errata is now available.

National Crime Agency says Brit teen accused of Twitter hack has not been arrested
USA decides to cleanse local networks of anything Chinese under new five-point national data security plan
Canon not firing on all cylinders: Fledgling cloud loses people’s pics’n’vids, then ‘Maze ransomware’ hits
US voting hardware maker’s shock discovery: Security improves when you actually work with the community
Ever wonder how a pentest turns into felony charges? Coalfire duo explain Iowa courthouse arrest debacle
Black Hat 2020: Linux Spyware Stack Ties Together 5 Chinese APTs
Black Hat 2020: In a Turnaround, Voting Machine Vendor Embraces Ethical Hackers
Twitter Fixes High-Severity Flaw Affecting Android Users
America was getting on top of its electronic voting machine security – then suddenly… A wild pandemic appears
Black Hat 2020: Scaling Mail-In Voting Spawns Broad Challenges
Black Hat 2020: Open-Source AI to Spur Wave of ‘Synthetic Media’ Attacks
FBI warns of surge in online shopping scams

In one scheme, shoppers ordering gadgets or gym equipment are in for a rude surprise – they receive disposable face masks instead The post FBI warns of surge in online shopping scams appeared first on WeLiveSecurity

High-Severity Android RCE Flaw Fixed in August Security Update
Microsoft Teams Patch Bypass Allows RCE
A Cyber ‘Vigilante’ is Sabotaging Emotet’s Return
UK data watchdog having a hard time making GDPR fines stick: Marriott scores another extension, BA prepares to pay 11% of original £183m penalty

An update that fixes 10 vulnerabilities is now available.

An update that fixes 26 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Red Hat Ansible Tower 3.7.2-1 – RHEL7 Container 2. Description: * Updated Named URLs to allow for testing the presence or absence of objects (CVE-2020-14337)

Red Hat Ansible Tower 3.6.5-1 – RHEL7 Container 2. Description: * Removed reports option for Satellite inventory script * Fixed Tower Server Side Request Forgery on Credentials (CVE-2020-14327)

OPA: A general-purpose policy engine for cloud-native

USN-4441-1 introduced a regression in MySQL

NSA warns that mobile device location services constantly compromise snoops and soldiers
China slams President Trump’s TikTok banned-or-be-bought plan in the US
Chinese debt collectors jailed for cyberbullying under ‘soft violence’ laws
Microsoft forked out $13.7m in bug bounties. The reward program’s architect thinks the money could be better spent
NetWalker Ransomware Rakes in $29M Since March

security update

As the world descends into madness, it’s good to see some things never change: Monthly Android patches
Newsletter WordPress Plugin Opens Door to Site Takeover
They say the tooth will set you free… so Brit dentist trade union tells members: ‘Bad news; we’ve been hacked’
Twitter Could Face $250M FTC Fine Over Improper Data Use

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.