Menu

Monthly Archives: October 2020

An update for rh-postgresql96-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

How cybercriminals play the domain game
OpenStack haven OpenDev yanks Gerrit code review tool after admin account compromised for two weeks
Top tip, everyone: Chinese hackers are hitting these 25 vulns, so make sure you patch them ASAP, says NSA
Ransomware Group Makes Splashy $20K Donation to Charities

security update

VMware patches, among other things, ESXi flaw that can be abused by miscreants on the network to hijack hosts
Adobe Fixes 16 Critical Code-Execution Bugs Across Portfolio
Russian “government hackers” charged with cybercrimes by the US
Facebook: A Top Launching Pad For Phishing Attacks
Microsoft issues two emergency Windows patches

The flaws, neither of which is being actively exploited, were fixed merely days after the monthly Patch Tuesday rollout The post Microsoft issues two emergency Windows patches appeared first on WeLiveSecurity

Pharma Giant Pfizer Leaks Customer Prescription Info, Call Transcripts
Remember insider threat? Old news now. Focus on malware detection, says EU infosec agency
Office 365 OAuth Attack Targets Coinbase Users
Mobile Browser Bugs Open Safari, Opera Users to Malware
Confronting Data Risk in the New World of Work
Google’s Waze Can Allow Hackers to Identify and Track Users
You’ve open sourced your relational database manager with PostgreSQL – but how can you keep it secure?
Notpetya, Olympics hacking, Novichok probe meddling… America throws the book at six alleged Kremlin hackers

Reading Time: ~ 3 min. Fine-tuning privacy for any preference A DNS filtering service that accommodates DNS over HTTPS (DoH) can strengthen an organization’s ability to control network traffic and turn away threats. DoH can offer businesses far greater control and flexibility over their privacy than the old system. The most visible use of DNS […]

Rapper Scams $1.2M in COVID-19 Relief, Gloats with ‘EDD’ Video
DOJ Charges 6 Sandworm APT Members in NotPetya Cyberattacks
GravityRAT Comes Back to Earth with Android, macOS Spyware
Overlay Malware Targets Windows Users with a DLL Hijack Twist
Ryuk Ransomware Gang Uses Zerologon Bug for Lightning-Fast Attack
UK test and trace data can be handed to police, reveals memorandum
Microsoft Exchange, Outlook Under Siege By APTs
First, Patch Tuesday. Now, Oh Hell, Monday: Microsoft emits bonus fixes for Visual Studio, Windows 10 security bugs
Game Titles Watch Dogs: Legion, Albion Both Targeted by Hackers
Albion Online gamers told to change passwords following forum hack

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

**Version 5.0.3** (2020-10-09) – issue #15983 Require twig ^2.9 – issue Fix option to import files locally appearing as not available – issue #16048 Fix to allow NULL as a default bit value – issue #16062 Fix “htmlspecialchars() expects parameter 1 to be string, null given” on Export xml – issue #16078 Fix no charts […]

Google reveals the most powerful DDoS attack in history… albeit three years late

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Will there be no end to govt attempts to break encryption? Hand over your data or the kiddies get it, threaten Five Eyes spies
Microsoft is the Most-Imitated Brand for Phishing Emails
Hackney Council can’t pay housing benefit after cyber attack

Several vulnerabilities have been discovered in the Linux kernel that may lead to the execution of arbitrary code, privilege escalation, denial of service or information leaks.

createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]

createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]

createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]

createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]

createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]

createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]

security update

RavenDB 5.0: A Versatile Open-Source NoSQL Database with an Intense Focus on Security>

An update that solves four vulnerabilities and has 9 fixes is now available.

New version 3.2.7 Security fix for CVE-2020-25862, CVE-2020-25863, CVE-2020-25866

New version 3.2.7 Security fix for CVE-2020-25862, CVE-2020-25863, CVE-2020-25866

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

Phishers Capitalize on Headlines with Breakneck Speed
Microsoft Fixes RCE Flaws in Out-of-Band Windows Update
If you want to practice writing exploits and worms, there’s a big hijacking hole in SonicWall firewall VPNs
Biden Campaign Staffers Targeted in Cyberattack Leveraging Antivirus Lure, Dropbox Ploy
Celebrating 200 episodes of the “Smashing Security” podcast
Phishing Lures Shift from COVID-19 to Job Opportunities

Reading Time: ~ 2 min. Backdoor Found in Children’s Smartwatch Researchers have discovered that the X4, made by Norwegian smartwatch seller Xplora, contains a backdoor that could allow for information to be stolen. The X4 watch is designed specifically for children with a limited number of capabilities, mostly for children’s security. The backdoor, however, could […]

Having saved credit card details in plaintext since 2015, British Airways is fined £20 million
Zoom to begin rolling out end‑to‑end encryption

The videoconferencing platform is making the feature available to users of both free and paid tiers The post Zoom to begin rolling out end‑to‑end encryption appeared first on WeLiveSecurity

Dickey’s BBQ Breach: Meaty 3M Payment Card Upload Drops on Joker’s Stash
To stop web giants abusing privacy, they must be prevented from respawning. Ever

An update that fixes two vulnerabilities is now available.

An issue has been found in PowerDNS Authoritative Server allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up […]

NULL Pointer Dereference that leads to arbitrary code execution’¯in the context of the current user. (CVE-2020-9746) References: – https://bugs.mageia.org/show_bug.cgi?id=27432

The TCP dissector could crash (CVE-2020-25862). The MIME Multipart dissector could crash (CVE-2020-25863). The BLIP dissector could crash (CVE-2020-25866).

A vulnerability was discovered where an attacker can cause an XSS attack through the transformation feature. If an attacker sends a crafted link to the victim with the malicious JavaScript, when the victim clicks on the link, the JavaScript will run and complete the instructions made by the attacker. (CVE-2020-26934)

US Department of Justice reignites the Battle to Break Encryption
TikTok Launches Bug Bounty Program Amid Security Snafus
News Wrap: Barnes & Noble Hack, DDoS Extortion Threats and More
British Airways fined £20m for Magecart hack that exposed 400k folks’ credit card details to crooks

CVE-2020-26116: HTTP request method CRLF injection in httplib

Critical Magento Holes Open Online Shops to Code Execution

security update

FIFA 21 Blockbuster Release Gives Fraudsters an Open Field for Theft
One alleged Dridex money-launderer set for US extradition, beams UK’s National Crime Agency

Priyank Nigam discovered that HttpComponents Client, a Java HTTP agent implementation, could misinterpret malformed authority component in a request URI and pick the wrong target host for request execution.

COVID-19 security tips: Ensure you sack your staff without leaving their IT access enabled, says Secureworks
50,000 home cameras reportedly hacked, footage posted online

Some footage has already appeared on adult sites, with cybercriminals offering lifetime access to the entire loot for US$150 The post 50,000 home cameras reportedly hacked, footage posted online appeared first on WeLiveSecurity

Zoom Rolls Out End-to-End Encryption After Setbacks
Broadvoice Leak Exposes 350M Records, Personal Voicemail Transcripts
Security much? Twitter should have had a CISO to prevent Bitcoin hack, says US state financial body
Barnes & Noble Hack: A Reading List for Phishers and Crooks
Beware COVID-19 charity fraudsters, warns the FBI
Carnival Corp. Ransomware Attack Affects Three Cruise Lines

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

Barnes & Noble warns customers it has been hacked, customer data may have been accessed

Update to 3.17.7 — https://www.claws-mail.org/news.php

Microsoft would love to hear about ‘critical bugs’ in .NET 5.0 ahead of the ‘unified’ platform’s November launch
Elite security intelligence for zero cost. Meet the Recorded Future Express browser extension
Remember when Zoom was rumbled for lousy crypto? Six months later it says end-to-end is ready
Smashing Security podcast #200: Two flipping hundred
Hackney Council’s cyber attack update is more interesting for what it doesn’t say than what it does
Travelex, Other Orgs Face DDoS Threats as Extortion Campaign Rages On
BEC Attacks: Nigeria No Longer the Epicenter as Losses Top $26B
Intel celebrates security of Ice Lake Xeon processors, so far impervious to any threat due to their unavailability