Menu

Monthly Archives: September 2020

An update that fixes one vulnerability is now available.

An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest […]

What price security? Well, for the US ban on Huawei/ZTE kit it’s around $1.8bn, and you’re going to pay most of it

The update of squid3 released as DLA-2278-2 introduced a regression due to the updated fix for CVE-2019-12529. The new Kerberos authentication code prevented base64 token negotiation. Updated squid3 packages are now

Social Media: Thwarting The Phishing-Data Goldmine
Vulnerability Disclosure: Ethical Hackers Seek Best Practices
Microsoft debuts deepfake detection tool

As the US presidential election nears, the company’s new tech should also help assure people that an image or video is authentic The post Microsoft debuts deepfake detection tool appeared first on WeLiveSecurity

Houseparty – should I stay or should I go now?

What’s the benefit of deleting your Houseparty – or any other unused – account, rather than just uninstalling the app? The post Houseparty – should I stay or should I go now? appeared first on WeLiveSecurity

Facebook Debuts Third-Party Vulnerability Disclosure Policy
Attackers Steal Outlook Credentials Via Overlay Screens on Legitimate Sites
Phishing tricks – the Top Ten Treacheries of 2020
India Blocks High-Profile Chinese Apps on Political, Privacy Concerns
WhatsApp Discloses 6 Bugs via Dedicated Security Site
Old and busted: Targeting servers and web bugs. New hotness: Pwning devs with targeted poisoned stacks
Facebook to blab bugs it finds if it thinks code owners aren’t fixing fast enough
Surprise! Voting app maker roasted by computer boffins for poor security now begs US courts to limit flaw finding
When classes are online, how do you get out of school? Florida teen cuffed, charged after crashing cyber-lessons
Sigh. Another day, another reason for WordPress users to get patching: Hackers abuse bug in popular plugin
Attackers Can Exploit Critical Cisco Jabber Flaw With One Message
Google Ups Product-Abuse Bug Bounties

Reading Time: ~ 4 min. Substitute your digital space for your home and encryption for the safe and you have what’s known as ransomware. Ransomware is a type of malware. After the initial infection, your files are encrypted, and a note appears demanding payment, which is usually in the form of cryptocurrency such as bitcoin […]

Vishing scams use Amazon and Prime as lures – don’t get caught!
Norway’s parliament struck by hackers

Unknown threat actors were able to exfiltrate information from the email accounts of several parliamentarians The post Norway’s parliament struck by hackers appeared first on WeLiveSecurity

KryptoCibule: The multitasking multicurrency cryptostealer

ESET researchers analyze a previously undocumented trojan that is spread via malicious torrents and uses multiple tricks to squeeze as many cryptocoins as possible from its victims while staying under the radar The post KryptoCibule: The multitasking multicurrency cryptostealer appeared first on WeLiveSecurity

Python-based Spy RAT Emerges to Target FinTech
US court deems NSA bulk phone-call snooping illegal, possibly unconstitutional, and probably pointless anyway
When trolling your colleagues and boss via an anonymous Twitter account, don’t make this mistake…
NSA Mass Surveillance Program Illegal, U.S. Court Rules
Newly-discovered KriptoCibule malware has been stealing and mining cryptocurrency since 2018

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

geary 3.36.3.1 release: * Fixed handling of pinned, invalid TLS certificates: CVE-2020-24661 * Build bug fixes

Rebased to version 8.0.21

Squid version update to 4.13 and security fixes

CVE-2020-12100: Parsing mails with a large number of MIME parts could have resulted in excessive CPU usage or a crash due to running out of stack memory. CVE-2020-12673: Dovecot’s NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. CVE-2020-10967: lmtp/submission:

Squid version update to 4.13 and security fixes

Hackers hijack Indian PM Narendra Modi Twitter account
Homeland Security demands a 911 for reporting security holes in federal networks: ‘Vulns in internet systems cause real-world impacts’
Smashing Security podcast #194: Carry on droning
U.S. Agencies Must Adopt Vulnerability-Disclosure Policies by March 2021
BEC Wire Transfers Average $80K Per Attack
Triple-Threat Cryptocurrency RAT Mines, Steals and Harvests
WordPress websites attacked via File Manager plugin vulnerability
Joker Spyware Plagues More Google Play Apps

An update that fixes one vulnerability is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

Phishing scam uses Sharepoint and One Note to go after passwords
Live Webinar: XDR and Beyond
Cisco Warns of Active Exploitation of Flaw in Carrier-Grade Routers

New F33 selinux-policy build.

Things are getting back to normal: Chinese hackers revert to bugging Tibetans after brief Euro campaign
Free ebook: Aligning cyber skills with the MITRE ATT&CK framework
China-based APT Debuts Sepulcher Malware in Spear-Phishing Attacks

security update

Magento Sites Vulnerable to RCE Stemming From Magmi Plugin Flaws
Security flaw allows bypassing PIN verification on Visa contactless payments

The vulnerability could allow criminals to rack up fraudulent charges on the cards without needing to know the PINs The post Security flaw allows bypassing PIN verification on Visa contactless payments appeared first on WeLiveSecurity

U.S. Voter Databases Offered for Free on Dark Web, Report
Magecart Credit-Card Skimmer Adds Telegram as C2 Channel
Hackers tricked Apple into approving malicious Adobe Flash Player update
FBI: Ring Smart Doorbells Could Sabotage Cops

An update that fixes two vulnerabilities is now available.

An update that solves 6 vulnerabilities and has 7 fixes is now available.

Pioneer Kitten APT Sells Corporate Network Access

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for bash is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Samsung supremo Lee Jae-yong indicted for fraud over role in 2015 merger deal that made him heir apparent

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Hack this email account… plz plz plz!
Someone’s getting a free trip to the US – well, not quite free. Brit bloke extradited to face $2m+ cyber-scam charges