Menu

Monthly Archives: September 2020

Bad news for ‘cool dads’ trying to bond with their teens: China-owned TikTok and WeChat face US download ban by Sunday
Google’s awkward stalkerware typo said it was ok to spy on your spouse

An update that fixes 14 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Managing the security of your Red Hat Enterprise Linux environment with Red Hat Insights
Hospital patient dies following botched ransomware attack
Iran’s RampantKitten spy crew were snooping on expats and dissidents for six years
Woman dies after hospital is unable to treat her during crippling ransomware infection, cops launch probe
Feeling bad about your last security audit? Check out what just happened to the US Department of Interior
Microsoft open-sources fuzzing test framework
Mozi Botnet Accounts for Majority of IoT Traffic
Apple Bug Allows Code Execution on iPhone, iPad, iPod
Video encoders using Huawei chips have backdoors and bad bugs – and Chinese giant says it’s not to blame
Sports data for ransom – it’s not all just fun and games anymore

Sports and training data are more sophisticated and affordable than ever. With the democratization of (sports) performance data, are your personal information safe? The post Sports data for ransom – it’s not all just fun and games anymore appeared first on WeLiveSecurity

Google Play Bans Stalkerware and ‘Misrepresentation’
APT41 Operatives Indicted as Sophisticated Hacking Activity Continues
GCHQ agency ‘strongly urges’ Brit universities, colleges to protect themselves after spike in ransomware infections
California Elementary Kids Kicked Off Online Learning by Ransomware
The Dunkin’ Donuts data breach leaves a very bad taste in the mouth

libproxy could be made to crash if it received a specially crafted PAC file.

Hackers pumped and dumped GAS cryptocurrency for $16.8 million, alleges US DOJ
Zerologon – hacking Windows servers with a bunch of zeros

apng2gif could be made to expose sensitive information if it opened a specifically crafted APNG file.

The Intel vPro Platform is ‘Built for Business’ – what this means to you

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Samba would allow unintended access to files over the network.

You have to be very on-trend as a cybercrook – hence why coronavirus-themed phishing is this year’s must-have look

LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength. (CVE-2020-15503)

util-linux could be made to run programs when performing bash completion.

Fake Zoom alerts and dodgy medical freebies among COVID-cracks detected by Taiwan’s CERT
Smashing Security podcast #196: Smart guns, smart cars, and smart street lights – oh my!

Reading Time: ~ 4 min. Since launching our web classification service in 2006, we’ve seen tremendous interest in our threat and web classification services, along with an evolution of the types and sizes of cybersecurity vendors and service providers looking to integrate this type of curated data into their product or service. Over the years, […]

Hackers Continue Cyberattacks Against Vatican, Catholic Orgs
Emotet strikes Quebec’s Department of Justice: An ESET Analysis

The cyber attack affects 14 inboxes belonging to the Department of Justice was confirmed by ESET researchers.  The post Emotet strikes Quebec’s Department of Justice: An ESET Analysis appeared first on WeLiveSecurity

Good: US boasts it collared two in Chinese hacking bust. Bad: They aren’t the actual hackers, rest are safe in China
Where China leads, Iran follows: US warns of ‘contract’ hackers exploiting Citrix, Pulse Secure and F5 VPNs
Zoom makes 2FA available for all its users

Zoom now supports phone calls, text messages and authentication apps as forms of two-factor authentication   The post Zoom makes 2FA available for all its users appeared first on WeLiveSecurity

DDoS Attacks Skyrocket as Pandemic Bites
DoJ Indicts Two Hackers for Defacing Websites with Pro-Iran Messages

An update that contains security fixes can now be installed.

An update that solves three vulnerabilities and has 26 fixes is now available.

An update that solves one vulnerability and has 8 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

MCabber could be made to modify the roster and intercept messages if it received specially crafted XMPP packets.

Report Looks at COVID-19’s Massive Impact on Cybersecurity
Bluetooth Spoofing Bug Affects Billions of IoT Devices
Best File and Disk Encryption Tools For Linux>
Microsoft open-sources fuzzing tool it uses in-house to keep Windows so very secure
Worried about bootkits, rootkits, UEFI nasties? Have you tried turning on Secure Boot, asks the No Sh*! Agency
Data Breaches Exposes Vets, COVID-19 Patients
Dunkin’ Donuts drops some dough to glaze over lawsuit accusing it of covering up customer account hacks

security update

QR Codes Serve Up a Menu of Security Concerns
IBM Spectrum Protect Plus Security Open to RCE
£2.5bn sueball claims Google slurps kids’ YouTube browsing habits then sells them on
Windows Exploit Released For Microsoft ‘Zerologon’ Flaw

Apache XML-RPC could be made to execute arbitrary code if it received specially crafted data by a malicious XML-RPC server.

Russian hacker selling how-to vid on exploiting unsupported Magento installations to skim credit card details for $5,000
US Customs has one heck of a false positive over “counterfeit Apple AirPods”

An update for librepo is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the mysql:8.0 module is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Update to version 0.9.5 * https://www.libssh.org/2020/09/10/libssh-0-9-5/ * Fixes CVE-2020-16135

QEMU: usb: out-of-bounds r/w access issue [XSA-335, CVE-2020-14364] (#1871850)

Apache Log4j could be made to remotely execute arbitrary code if it received specially crafted log data.

MFA Bypass Bugs Opened Microsoft 365 to Attack
Have hackers, cybercrims worked their way into your corporate net while you’ve been working from home?
Chinese database detailing 2.4 million influential people, their kids, their addresses, and how to press their buttons revealed
Infosec big names rally against US voting app maker’s bid to outlaw unsanctioned bug hunting via T&Cs
What do F5, Citrix, Pulse Secure all have in common? China exploiting their flaws to hack govt, biz – Feds
Feds Warn Nation-State Hackers are Actively Exploiting Unpatched Microsoft Exchange, F5, VPN Bugs
Court hearing on election security is zoombombed on 9/11 anniversary with porn, swastikas, pics of WTC attacks
Take your pick: ‘Hack-proof’ blockchain-powered padlock defeated by Bluetooth replay attack or 1kg lump hammer
Cloud Leak Exposes 320M Dating-Site Records
Personal data from Experian on 40% of South Africa’s population has been bundled onto a file-sharing website
TikTok Fixes Flaws That Opened Android App to Compromise

Reading Time: ~ 3 min. Women of Webroot and Carbonite talk about what drew them to the field and their advice for others looking to break into STEM. The lack of representative diversity in tech has been long acknowledged and well-studied.  Organizations and non-profit groups like National Center for Women & Information Technology (NCWIT), Girls […]

Magecart Attack Impacts More Than 10K Online Shoppers
Sorry we shut you out, says Tutanota: Encrypted email service weathers latest of ongoing DDoS storms

An update that solves 8 vulnerabilities and has 17 fixes is now available.

An update that solves 8 vulnerabilities and has 17 fixes is now available.

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3617

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3631

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3643

Another month, another cryptocurrency exchange hacked and ‘millions of dollars’ stolen by miscreants

An update that fixes one vulnerability is now available.

New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

– https://www.drupal.org/project/drupal/releases/7.72 – [Drupal core – Critical – Cross Site Request Forgery – SA- CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 – https://www.drupal.org/project/drupal/releases/7.71 – https://www.drupal.org/project/drupal/releases/7.70 – [Drupal core –

https://lists.gnupg.org/pipermail/gnutls-help/2020-September/004669.html

– https://www.drupal.org/project/drupal/releases/7.72 – [Drupal core – Critical – Cross Site Request Forgery – SA- CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 – https://www.drupal.org/project/drupal/releases/7.71 – https://www.drupal.org/project/drupal/releases/7.70 – [Drupal core –

An update that fixes one vulnerability is now available.

Update to upstream bugfix and security release 2.9.13.

update to 2.2.16, CVE-2020-24583, CVE-2020-24584

New F31 selinux-policy build

Update to .NET Core SDK 3.1.107 and Runtime 3.1.7. This fixes CVE-2020-1597 – Release Notes: https://github.com/dotnet/core/blob/master/release- notes/3.1/3.1.7/3.1.7.md