Menu

Monthly Archives: September 2020

Reading Time: ~ 5 min. Guest blog by Mit Patel, Managing Director of London based IT Support company, Netstar. In this article, Webroot sits down with Mit Patel, Managing Director of London-based MSP partner, Netstar, to discuss the topic of remote work during a pandemic and tips to stay cyber resilient. Why is it important […]

Alien Android Banking Trojan Sidesteps 2FA

An update that solves 6 vulnerabilities and has two fixes is now available.

An update that fixes 14 vulnerabilities is now available.

Microsoft warns hackers are actively targeting Zerologon vulnerability. Patch pronto!
UK ICO fines biz profiteering from COVID-19 crisis by sending unsolicited marketing texts to Joe Public

Several security issues were fixed in SPIP.

Instagram photo flaw could have helped hackers spy via users’ cameras and microphones

An update that fixes 19 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

Smashing Security podcast #197: Greedy bosses, game cheats, and virtual beheadings
Ex-eBay global intel staffers to admit they cyberstalked online tat bazaar’s critics – who got pig heads, funeral wreath, and more in the mail
Zerologon Patches Roll Out Beyond Microsoft
Gamer Credentials Now a Booming, Juicy Target for Hackers
Doppelpaymer ransomware crew fingered over attack on German hospital that allegedly caused death of a patient
Critical Industrial Flaws Pose Patching Headache For Manufacturers
CISA: LokiBot Stealer Storms Into a Resurgence
OldGremlin Ransomware Group Bedevils Russian Orgs

An update that fixes 19 vulnerabilities is now available.

Microsoft leaks 6.5TB in Bing search data via unsecured Elastic server. *Insert ‘Wow… that much?’ joke here*

RDFLib could be made to made to execute arbitrary code if it were running in a directory with a specially crafted file.

– New upstream version (81.0)

Security fixes for CVE-2020-1472

Fix CVE-2020-25219

Fix for #1876738 and #1876689

Rogue Shopify staff accessed customer records, says ecommerce platform investigating security breach

Reading Time: ~ 4 min. Phishing has been around for ages and continues to be one of the most common threats that businesses and home users face today. But it’s not like we haven’t all been hearing about the dangers of phishing for years. So why do people still click? That’s what we wanted to […]

Proposed US fix for Boeing 737 Max software woes does not address Ethiopian crash scenario, UK pilot union warns
Your latest security headache? Ed from accounting using his kid as an unpaid helpdesk
FBI boasts of dark-web drug bust: 179 collared around the world, $6.5m in cash and 500kg of narcotics seized

Reading Time: ~ 2 min. Magecart Launches Largest E-commerce Attack to Date Roughly 2000 e-commerce sites were compromised in the latest Magecart campaign targeting an out-of-date version of Magento software. It’s believed an additional 95,000 sites that haven’t patched to the latest Magento version could also be targeted by the payment skimming malware. The campaign […]

As you’re scrambling to patch the scary ZeroLogon hole in Windows Server, don’t forget Samba – it’s also affected
It’s been a vintage year for bug bounty hunters, says HackerOne as it boasts of $40m+ passing through its treasure chests
Google Chrome Bugs Open Browsers to Attack
Known Citrix Workspace Bug Open to New Attack Vector
New tool helps companies assess why employees click on phishing emails

NIST’s tool can help organizations improve the testing of their employees’ phish-spotting prowess The post New tool helps companies assess why employees click on phishing emails appeared first on WeLiveSecurity

Mozilla fixes flaw that let attackers hijack Firefox for Android via Wi‑Fi

Attackers could have exploited the flaw to steal victims’ login credentials or install malware on their devices The post Mozilla fixes flaw that let attackers hijack Firefox for Android via Wi‑Fi appeared first on WeLiveSecurity

Microsoft Overhauls Patch Tuesday Security Update Guide
Firefox 81 Release Kills High-Severity Code-Execution Bugs
Activision Refutes Claims of 500K-Account Hack

An update that solves four vulnerabilities and has one errata is now available.

Google Cloud Buckets Exposed in Rampant Misconfiguration

Reading Time: ~ 4 min. People’s fears and fantasies about artificial intelligence predate even computers. Before the term was coined in 1956, computing pioneer Alan Turing was already speculating about whether machines could think. By 1997 IBM’s Deep Blue had beaten chess champion Gary Kasparov at his own game, prompting hysterical headlines and the game […]

Ransomware attack foiled, but details of 540,000 sports referees still stolen by hackers
Securing a Linux Web Server: A Primer>
The new BLESA Bluetooth security flaw can keep billions of devices vulnerable>

An update that fixes 19 vulnerabilities is now available.

An update that solves four vulnerabilities and has one errata is now available.

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Activision denies reports 500,000 Call of Duty accounts have been hacked

Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet.

Several security issues were fixed in FreeImage.

UK Parliament’s human rights committee pushes for better protections of coronavirus contact-tracing data in law
This year’s biggest security flaws – coming soon to a screen near you
Does your business have a Well-Known URL for changing passwords? It should!
‘I don’t want to see another computer for the rest of my life’… Brit Dark Overlord cyber-extortionist thrown in an American clink for five years
Contractor convicted of pinching supercomputer cycles to mine cryptocurrency
TANSTAAFL! The Tragedy of the Commons Meets Open-Source Software>
Fileless Malware Tops Critical Endpoint Threats for 1H 2020
Announcement of the passing of Jari Fredriksson>
Unsecured Microsoft Bing Server Leaks Search Queries, Location Data
DHS Issues Dire Patch Warning for ‘Zerologon’
Firefox for Android Bug Allows ‘Epic Rick-Rolling’
Android Malware Bypasses 2FA And Targets Telegram, Gmail Passwords

An update that fixes one vulnerability is now available.

MP promises to grill UK.gov over revelations that Uber handed ‘2,000 pieces’ of user data to London cops a year
Russians charged for $16.8m crypto-coin heist, but traders warned their cash is only as safe as their security is tight
I’m not interested in this Nigerian restaurant’s emails…

pam_tacplus could be made to expose sensitive information.

An update that fixes 14 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Tesla wins defamation counterclaim against Gigafactory whistleblower
WFH is the new religion – though blind faith isn’t enough to keep your infrastructure secure
US cybersecurity agency issues super-rare emergency directive to patch Windows Server flaw ASAP
Amazon staffers took bribes, manipulated marketplace, leaked data including search algorithms – DoJ claims

An update that fixes 25 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Two security issues were discovered in the modules of the InspIRCd IRC daemon, which could result in denial of service. CVE-2019-20917

An update that solves one vulnerability and has one errata is now available.

security update

security update

Add fix for CVE-2020-24977 (RHBZ#1877788, RHBZ#1877789).

Update to the new upstream 3.6.15 release. —- – Fix memory leak when serializing iovec_t (#1845083) – Fix automatic libraries sonames detection (#1845806)

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

The TikTok Ban: Security Experts Weigh in on the App’s Risks
Stubborn WooCommerce Plugin Bugs Get Third Patch
Online fraud prevention biz fails to prevent CEO’s alleged offline fraud
SecOps Teams Wrestle with Manual Processes, HR Gaps
Security Takeaways from the Great Work-from-Home Experiment
Plugging in a strange USB drive – What could possibly go wrong?

While wanting to return a found USB flash drive is commendable, you should avoid taking unnecessary risks, lest your device get infested and your data compromised. The post Plugging in a strange USB drive – What could possibly go wrong? appeared first on WeLiveSecurity

Maze Ransomware Adopts Ragnar Locker Virtual-Machine Approach
A real-life Maze ransomware attack – “If at first you don’t succeed…”