Menu

Monthly Archives: October 2020

security update

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update that solves 8 vulnerabilities and has 5 fixes is now available.

This update corrects a regression in some Xen virtual machine environments. For reference the original advisory text follows. Several vulnerabilities have been discovered in the Linux kernel that

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has three fixes is now available.

Crippling Cyberattacks, Disinformation Top Concerns for Election Day
Windows kernel zero-day disclosed by Google’s Project Zero after bug exploited in the wild by hackers
WordPress Patches 3-Year-Old High-Severity RCE Bug
Firestarter Android Malware Abuses Google Firebase Cloud Messaging
Wisc. GOP’s $2.3M MAGA Hat Debacle Showcases Fraud Concerns
Halloween News Wrap: The Election, Hospital Deaths and Other Scary Cyberattack Stories
Wroba Mobile Banking Trojan Spreads to the U.S. via Texts
The Russians are at it again: Zebrocy backdoor malware is evolving, Uncle Sam warns close to eve of presidential election
IoT security: Are we finally turning the corner?

Better IoT security and data protection are long overdue. Will they go from an afterthought to everyone’s priority any time soon? The post IoT security: Are we finally turning the corner? appeared first on WeLiveSecurity

Adobe Flash – it’s the end of the end of the end of the road at last

A vulnerability in the handling of normalization with modrdn was discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. An unauthenticated remote attacker can use this flaw to cause a denial of service (slapd daemon crash) via a

An update that fixes two vulnerabilities is now available.

Marriott fined £0.05 for each of the 339 million hotel guests whose data crooks were stealing for four years
Marriott data breach fine slashed to £18.4 million by UK regulator
Japanese nuclear agency warns of cyber attack, turns off email systems
Why, yes, you can register an XSS attack as a UK company name. How do we know that? Someone actually did it

Several issues have been found in cimg, a powerful image processing library.

Microsoft Warns Threat Actors Continue to Exploit Zerologon Bug

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Several vulnerabilities have been discovered in the Linux kernel that may lead to the execution of arbitrary code, privilege escalation, denial of service or information leaks.

On Friday the US starts Ender’s hacking game: All local teens can compete for scholarships in cybersecurity
How to plan a password security project
FBI “ransomware warning” for healthcare is a warning for everyone!
NVIDIA Patches Critical Bug in High-Performance Servers
If you haven’t patched WebLogic server console flaws in the last eight days ‘assume it has been compromised’
US hospitals warned of threat of imminent ransomware attack
Kegtap, Singlemalt, Winekey Malware Serve Up Ransomware to Hospitals
Days before the US election, phishers net $2.3m from Wisconsin Republicans
University Email Hijacking Attacks Push Phishing, Malware
Google Safari Workaround case inspires campaign to sue Facebook in UK’s High Court over Cambridge Analytica app

Reading Time: ~ 4 min. Nurul Mohd-Reza knows how to empathize with the customers she serves. Her work with marginalized groups as a college student, she says, helped prepare her for when the pandemic turned many of her customers’ businesses upside down last March. Here she discusses what she’s learned after just 10 months in […]

REvil Gang Promises a Big Video-Game Hit; Claims Massive Revenue
Ryuk this for a game of soldiers: Ransomware-flingers actively targeting hospitals in the US, cyber agencies warn
Over 100,000 machines remain vulnerable to SMBGhost exploitation

The patch for the critical flaw that allows malware to spread across machines without any user interaction was released months ago The post Over 100,000 machines remain vulnerable to SMBGhost exploitation appeared first on WeLiveSecurity

ESET Threat Report Q3 2020

A view of the Q3 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report Q3 2020 appeared first on WeLiveSecurity

Buer Loader “malware-as-a-service” joins Emotet for ransomware delivery
Looking for good news on COVID-19? That’s exactly what cyber attackers want you to do
Become a security intelligence expert, with these free tools from Recorded Future
Home Depot Confirms Data Breach in Order Confirmation SNAFU
Oracle WebLogic Server RCE Flaw Under Active Attack

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that fixes three vulnerabilities is now available.

Lenovo to slap ThinkShield security standard for laptop line-up on its Motorola mobiles
Bug-Bounty Awards Spike 26% in 2020

Two issues have been found in dompurify.js, an XSS sanitizer for HTML, MathML and SVG. Both issues are related to mXSS issues in SVG- or MATH-elements.

Smashing Security podcast #202: The Wu-Tang Clan are Among Us
Xfinity, McAfee Brands Abused by Parked Domains in Active Campaigns
Can we stop megacorps from using and abusing our data? That ship has sailed, ex-NSA lawyer argues in new book
French services outfit Atos told to pay $855m in trade secret pinching case
Malware never switches off – so why should your security supplier?
NSA: We’ve learned our lesson after foreign spies used one of our crypto backdoors – but we can’t say how exactly
2 More Hospitals Hit by Growing Wave of Ransomware Attacks
Microsoft’s SMBGhost Flaw Still Haunts 108K Windows Systems

security update

‘Copyright Violation’ Notices Lead to Facebook 2FA Bypass
Open Source is Revolutionizing Careers in Cybersecurity – What You Need to Know>
Software engineer leaked UK missile system secrets and refused to hand cops his passwords, Old Bailey told
How the Pandemic is Reshaping the Bug-Bounty Landscape
Russian Espionage Group Updates Custom Malware Suite
Iran-linked APT Targets T20 Summit, Munich Security Conference Attendees
Three steps to data-centric security: Discovery, protection, and control
Election Security: How Mobile Devices Are Shaping the Way We Work, Play and Vote
Experian vows to drag UK’s Information Commissioner’s Office to court after being told off for data-slurping practices
North Korea-Backed Spy Group Poses as Reporters in Spearphishing Attacks, Feds Warn

Updated packages that provide Red Hat JBoss Core Services Pack Apache Server 2.4.37 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

Experts Weigh in on E-Commerce Security Amid Snowballing Threats

Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 5 zip release for RHEL 6, RHEL 7, RHEL 8 and Microsoft Windows is available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openstack-cinder is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openstack-selinux is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Trump Campaign Website Defaced by Cryptocurrency Scam

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Donald Trump’s website briefly defaced by cryptomining scammers
Trump’s official campaign website vandalized by hackers who ‘had enough of the President’s fake news’
India and USA to share high-quality satellite imagery and more under new pact
Lax Security Exposes Smart-Irrigation Systems to Attack Across the Globe  
Amazon Fires Employee Who Leaked Customer Names, Emails
Zoom finally adds end-to-end encryption for all, for free – though there are caveats
Facebook “copyright violation” tries to get past 2FA – don’t fall for it!
‘Among Us’ players hit by major spam attack

In-game chats were flooded with messages from somebody who tried to coerce players into subscribing to a dubious YouTube channel The post ‘Among Us’ players hit by major spam attack appeared first on WeLiveSecurity

Researchers: LinkedIn, Instagram Vulnerable to Preview-Link RCE Security Woes
Finnish therapy clinic’s CEO fired after despicable data breach and blackmail threats
Brit accused of spying on 772 people via webcam CCTV software tells court he’d end his life if extradited to US
Majority of Microsoft 365 Admins Don’t Enable MFA

An update that fixes one vulnerability is now available.

Amazon fires employee for leaking customer data
Code42 Incydr Series: Secure Data in the Age of Remote Work
Holiday Shopping Craze, COVID-19 Spur Retail Security Storm

An update is now available for Red Hat OpenShift Container Platform 4.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from