Menu

Monthly Archives: October 2020

Google Boots 21 Bogus Gaming Apps from Play Marketplace

Reading Time: ~ 4 min. For the third year running, we’ve examined the year’s biggest cyber threats and ranked them to determine which ones are the absolute worst. Somewhat unsurprisingly, phishing and RDP-related breaches remain the top methods we’ve seen cybercriminals using to launch their attacks. Additionally, while new examples of malware and cybercriminal tactics […]

Several security issues were fixed in Perl.

An update that fixes three vulnerabilities is now available.

An update for jenkins-2-plugins, openshift-clients, podman, runc, and skopeo is now available for Red Hat OpenShift Container Platform 4.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Brit startup would like to beam 5G connectivity down at you from hydrogen-fuelled drones

An update is now available for Red Hat Satellite 6.8 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Santander downplays ‘hack’ of PagoFX cash transfer biz, says nothing to worry about
Phone scamming – friends don’t let friends get vished!
Microsoft IE Browser Death March Hastens

security update

security update

‘Among Us’ Mobile Game Under Siege by Attackers
Containerd Bug Exposes Cloud Account Credentials
Hackers rummaged about in Finnish psychotherapy clinic – now patients extorted with public data dump threats
Vastaamo Breach: Hackers Blackmailing Psychotherapy Patients
Nando’s Hackers Feast on Customer Accounts
Report: UK colleges face testing times with ageing kit, iffy connectivity, and some IT staff supporting 1k+ users

Open Liberty 20.0.0.11 Runtime is now available from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that fixes 16 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Sopra Steria confirms it was hit by new strain of Ryuk ransomware, will take weeks to return to normal operations

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

Several vulnerabilities were found in package phpmyadmin. CVE-2019-19617

An update that solves one vulnerability and has two fixes is now available.

Update to freetype 2.10.4 which fixes security flaw CVE-2020-15999.

JavaScript-based address bar spoofing vulns patched in Safari, Yandex, Opera

Reading Time: ~ 5 min. October 21 is Wonder Woman Day. It commemorates Wonder Woman’s first appearance in All Star Comics #8. With the upcoming release of Wonder Woman 1984, we took the opportunity to talk superheroes, superpowers and protecting data with our very own Briana Butler, Engineering Services Manager at Webroot. Q: Wonder Woman […]

U.S. Levies Sanctions Against Russian Research Institution Linked to Triton Malware
IoT Device Takeovers Surge 100 Percent in 2020
Louisiana Calls Out National Guard to Fight Ransomware Surge
Election Security: Beyond Mail-In Voting
Georgia Election Data Hit in Ransomware Attack
Palo Alto Networks threatens to sue security startup for comparison review, says it breaks software EULA
Fraudsters crave loyalty points amid COVID‑19

Scammers even run their own dark-web “travel agencies”, misusing stolen loyalty points and credit card numbers The post Fraudsters crave loyalty points amid COVID‑19 appeared first on WeLiveSecurity

COVID-19 Vaccine-Maker Hit with Cyberattack, Data Breach
EU slaps extra sanctions on Russian spy chief and APT28 malware dev over 2015 Bundestag hack

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has four fixes is now available.

An update that fixes 13 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 27 vulnerabilities is now available.

Nvidia Warns Gamers of Severe GeForce Experience Flaws
Ransomware Takes Down Network of French IT Giant
Securing medical devices: Can a hacker break your heart?

Why are connected medical devices vulnerable to attack and how likely are they to get hacked? Here are five digital chinks in the armor. The post Securing medical devices: Can a hacker break your heart? appeared first on WeLiveSecurity

Ed Snowden doesn’t need to worry about being turfed out of Russia any more
After Dutch bloke claims he hacked Trump’s Twitter by guessing password, web biz says there’s ‘no evidence’
China reveals audit of 320,000 local apps, with 34 booted from app stores and hundreds of devs warned they could suffer same fate
After first floating $20bn penalty, DoJ suggests $60m fine for UMC’s theft of Micron’s DRAM secrets
Is it Iran or Russia’s hackers we need to worry about? The Russians, definitely the Russians, says US intelligence

security update

security update

Researcher: I Hacked Trump’s Twitter by Guessing Password
Facebook, News and XSS Underpin Complex Browser Locker Attack
Microsoft Teams Phishing Attack Targets Office 365 Users
Google patches Chrome zero‑day under attack

In addition to patching the actively exploited bug, the update also brings fixes for another four security loopholes The post Google patches Chrome zero‑day under attack appeared first on WeLiveSecurity

Fake Instagram follower services slapped with lawsuit
Chrome 86 Aims to Bar Abusive Notification Content
Donald Trump’s Twitter password is “maga2020!”, and there’s no 2FA, claims hacker
French IT outsourcer Sopra Steria hit by ‘cyberattack’, Ryuk ransomware suspected

An update that fixes three vulnerabilities is now available.

An update that fixes 11 vulnerabilities is now available.

Feds: Iran Behind ‘Proud Boys’ Email Attacks on Democratic Voters

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Time for a mobile privacy reset?
Fort Bragg fails to keep a firm grip on its Twitter account, as it blames hacker for saucy tweets

An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Over one million WordPress sites receive forced update to security plugin after severe vulnerability discovered
Samsung to introduce automatic call blocking on Android 11-capable flagships
Sopra Steria hit by cyber attack. IT services group suspected of falling victim to ransomware
Iran sent threatening pro-Trump emails to American Democrats, Russia close behind, says US intelligence
Smashing Security podcast #201: Robin Hood, Flippy, and the web ad bubble
Thought the FBI were the only ones able to unlock encrypted phones? Pretty much every US cop can get the job done

security update

security update

Bug Parade: NSA Warns on Cresting China-Backed Cyberattacks
Coronavirus outbreak triggered a rush of online attacks against retail loyalty schemes, Akamai reckons
Cisco Warns of Severe DoS Flaws in Network Security Software
How much does Oracle love you? Thiiiis much: Latest patch bundle has 402 fixes
Oracle Kills 402 Bugs in Massive October Patch Update
How safe is your USB drive?

What are some of the key security risks to be aware of when using USB flash drives and how can you mitigate the threats? The post How safe is your USB drive? appeared first on WeLiveSecurity

Egregor Claims Responsibility for Barnes & Noble Attack, Leaks Data
Chrome zero-day in the wild – patch now!

An update that solves 6 vulnerabilities and has 36 fixes is now available.

An update that solves 6 vulnerabilities and has 36 fixes is now available.

Cybercriminals Step Up Their Game Ahead of U.S. Elections

Several security issues were fixed in iTALC.

Google Patches Actively-Exploited Zero-Day Bug in Chrome Browser
The Recorded Future Express browser extension – elite security intelligence for zero cost

A flaw was found in the way the Linux kernel Bluetooth implementation handled L2CAP packets with A2MP CID. A remote attacker in adjacent range could use this flaw to crash the system causing denial of service or potentially execute arbitrary code on the system by sending a specially crafted L2CAP packet. The highest threat from […]

GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the middle to present a different invalid certificate to intercept incoming and outgoing mail. (CVE-2020-24661)

8 video chat apps compared: Which is best for security?