Menu

Monthly Archives: September 2020

Update to .NET Core SDK 3.1.107 and Runtime 3.1.7. This fixes CVE-2020-1597 – Release Notes: https://github.com/dotnet/core/blob/master/release- notes/3.1/3.1.7/3.1.7.md

Don’t pay the ransom, mate. Don’t even fix a price, say Australia’s cyber security bods
APT28 Mounts Rapid, Large-Scale Theft of Office 365 Logins
Office 365 Phishing Attack Leverages Real-Time Active Directory Validation
It’s No ‘Giggle’: Managing Expectations for Vulnerability Disclosure
Who is calling? CDRThief targets Linux VoIP softswitches

ESET researchers have discovered and analyzed malware that targets Voice over IP (VoIP) softswitches. The post Who is calling? CDRThief targets Linux VoIP softswitches appeared first on WeLiveSecurity

WordPress Plugin Flaw Allows Attackers to Forge Emails
What an IDORable Giggle: AI-powered ‘female only’ app gets in Twitter kerfuffle over breach notification
Serious Security: Hacking Windows passwords via your wallpaper
“Yourefired” was Donald Trump’s Twitter password, claim hackers

Multiple vulnerabilities were discovered in WordPress, a popular content management framework. CVE-2019-17670

Adtech’s bogeymen are tracking everything – even your web visits to mental health charities, claim campaigners

Reading Time: ~ 3 min. This year more than others, for many of us, it’s gaming that’s gotten us through. Lockdowns, uncertainty, and some pretty darn good releases have kept our computers and consoles switched on in 2020. GamesIndustry.biz, a website tracking the gaming sector, reported a record number of concurrent users on the gaming […]

Secure your Zoom account with Two-Factor Authentication

An update that solves 8 vulnerabilities and has 12 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Stop unauthorized applications with RHEL 8’s File Access Policy Daemon

8u265 update, disable LTO

Update built with the new CMake settings Number of files which should have been owned by the testsuite subpackage are now owned by it Started building MeCab plugin

Three middle-aged Dutch hackers slipped into Donald Trump’s Twitter account days before 2016 US election
Billions of Bluetooth gadgets bothered by ‘BLURtooth’ miscreant-in-the-middle bug
China, Russia and Iran all attacking US elections and using some nasty new tactics, says Microsoft

Reading Time: ~ 4 min. Today’s work-from-home environment has created an abundance of opportunities for offering new cybersecurity services in addition to your existing business. With cyberattacks increasing in frequency and sophistication, business owners and managers need protection now more than ever. MSPs are ideally positioned to deliver the solutions businesses need in order to […]

Microsoft Warns of Cyberattacks on Trump, Biden Election Campaigns
Razer Gaming Fans Caught Up in Data Leak
Portland passes the strictest facial recognition technology ban in the US yet 

Oregon’s largest city aims to be a trailblazer when it comes to facial recognition legislation . The post Portland passes the strictest facial recognition technology ban in the US yet  appeared first on WeLiveSecurity

How to talk vulnerability management with the C-suite – and make them care
Bluetooth Bug Opens Devices to Man-in-the-Middle Attacks
Ransomware And Zoom-Bombing: Cyberattacks Disrupt Back-to-School Plans
Pension scheme cold caller fined £130,000 by UK data watchdog
Govt.-Backed Contact-Tracing Apps Raise Privacy Hackles

libX11 1.6.12 (CVE-2020-14363, CVE 2020-14344)

QEMU: usb: out-of-bounds r/w access issue [XSA-335, CVE-2020-14364] (#1871850)

The 5.8.7 stable kernel update contains a number of important fixes across the tree.

Product Overview: Cynet Takes Cyber Threat Protection Automation to the Next Level with Incident Engine
Cryptocurrency exchange Eterbase hacked, $5.4 million worth of funds stolen
Ireland unfriends Facebook: Oh Zucky Boy, the pipes, the pipes are closing…from glen to US, and through the EU-side

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

CDRThief Malware Targets VoIP Gear in Carrier Networks

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dovecot is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

China’s UK embassy calls for probe into ‘hack of Ambassador’s Twitter account’
Now that’s a somewhat unexpected insider threat: Zoombombings mostly blamed on rogue participants, unique solution offered
Don’t be BlindSided: Watch speculative memory probing bypass kernel defenses, give malware root control
Smashing Security podcast #195: Selene Delgado Lopez is not your friend
UK University suffers cyberattack, ransomware gang claims responsibility 

The cyber incident has taken most of Newcastle University’s systems offline and officials estimates it will take weeks to recover.  The post UK University suffers cyberattack, ransomware gang claims responsibility  appeared first on WeLiveSecurity

Fake Facebook email invites you to tell 39 strangers you were duped
Zeppelin Ransomware Returns with New Trojan on Board
Google Squashes Critical Android Media Framework Bug
Lead‑offering business booming as usual!

…but there are no conferences or exhibitions??? The post Lead‑offering business booming as usual! appeared first on WeLiveSecurity

I can ‘proceed without you’, judge tells Julian Assange after courtroom outburst
TeamTNT Gains Full Remote Takeover of Cloud Instances
Critical Flaws in 3rd-Party Code Allow Takeover of Industrial Control Systems

An update that fixes one vulnerability is now available.

Several security issues were fixed in X.Org X Server.

Fake web alerts – how to spot and stop them
Remember the Titans: Yubico jangles new NFC and USB-C touting security key
Spyware Labeled ‘TikTok Pro’ Exploits Fears of US Ban

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Using OPA to safeguard Kubernetes

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 6 fixes is now available.

Enjoyed the US Labor Day weekend? Because it’s September 2020 and Exchange Server can be pwned via email
Microsoft’s Patch Tuesday Packed with Critical RCE Bugs
Critical Intel Active Management Technology Flaw Allows Privilege Escalation

security update

security update

Critical Adobe Flaws Allow Attackers to Run JavaScript in Browsers
TikTok Family Pairing: Curate your children’s content and more

With TikTok being all the rage especially with teens, we look at a feature that gives parents greater control over how their children interact with the app The post TikTok Family Pairing: Curate your children’s content and more appeared first on WeLiveSecurity

Newcastle University, neighbouring Northumbria hit by ransomware attacks
Cryptobugs Found in Numerous Google Play Store Apps
Bug in Google Maps Opened Door to Cross-Site Scripting Attacks

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

The 5.8.6 stable kernel update contains a number of important fixes across the tree.

The 5.8.6 stable kernel update contains a number of important fixes across the tree.

Several security issues were fixed in libx11.

Mystery surrounds alleged Paytm Mall hack, as security firm hit by legal threat
China proposes ‘Global Initiative on Data Security’ forbidding stuff it and Huawei are accused of doing already

security update

Newcastle University says it will take “several weeks” to recover from cyber attack
How Zero Trust and SASE Can Redefine Network Defenses for Remote Workforces

lemonldap-ng community fixed a vulnerability in the Nginx default configuration files (CVE-2020-24660). Debian package does not install any default site, but documentation provided insecure examples in Nginx configuration before this version.

Update to the new upstream 3.6.15 release.

The 5.8.6 stable kernel update contains a number of important fixes across the tree.

The 5.8.6 stable kernel update contains a number of important fixes across the tree.

The 5.8.6 stable kernel update contains a number of important fixes across the tree.

Update to cryptsetup 2.3.4. Security fix for CVE-2020-14382

CEOs Could Be Held Personally Liable for Cyberattacks that Kill
Darknet market’s peacemaker sentenced to 11 years in prison

Multiple vulnerabilities have been found in Dovecot, the worst of which could allow remote attackers to cause a Denial of Service condition.

A flaw was found in GnuTLS, possibly allowing a Denial of Service condition.

security update

security update

An update that solves 7 vulnerabilities and has 129 fixes is now available.

An update that solves 7 vulnerabilities and has 130 fixes is now available.

An update that fixes four vulnerabilities is now available.