Menu

Monthly Archives: October 2020

An update that solves 9 vulnerabilities and has 105 fixes is now available.

An update that solves 9 vulnerabilities and has 105 fixes is now available.

K8s on a plane! US Air Force slaps Googly container tech on yet another war machine to ‘run advanced ML algorithms’
Hackers disguise malware attack as new details on Donald Trump’s COVID-19 illness
Apple’s T2 custom secure boot chip is not only insecure – it cannot be fixed without replacing the silicon

An update for go-toolset-1.13 and go-toolset-1.13-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

CVE-2019-11840 An issue was discovered in supplementary Go cryptography libraries, aka golang-googlecode-go-crypto. If more than 256 GiB of keystream is

Reading Time: ~ 4 min. Like many of the technologies we discuss on this blog—think phishing scams or chatbots—deepfakes aren’t necessarily new. They’re just getting a whole lot better. And that has scary implications for both private citizens and businesses alike. The term “deepfakes,” coined by a Reddit user in 2017, was initially most often […]

Red Hat AMQ Interconnect 1.9.0 release packages are available for A-MQ Interconnect on RHEL 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Smashing Security podcast #199: A few tech cock-ups, and one cock lock-up

security update

Had your face stolen lately?

It’s easy to reset your password or PIN after a data breach. But reset your face? Not so much. The post Had your face stolen lately? appeared first on WeLiveSecurity

Wisepay ‘outage’ is actually the school meal payments biz trying to stop an intruder from stealing customer card details
Recorded Future Express gives you elite security intelligence at zero cost

An update that solves four vulnerabilities and has two fixes is now available.

An update that fixes 9 vulnerabilities, contains 10 features is now available.

An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

PoetRAT Resurfaces in Attacks in Azerbaijan Amid Escalating Conflict
IRS COVID-19 Relief Payment Deadlines Anchor Convincing Phish
Infosec researchers pwned Comcast’s voice-activated remote control so it could snoop on household chit-chat
Comcast TV Remote Hack Opens Homes to Snooping

Several security vulnerabilities have been discovered in puma, highly concurrent HTTP server for Ruby/Rack applications. CVE-2020-11076

Disgraced cop, 55, spared prison term after admitting he abused police systems to snoop on his girlfriend’s ex

An update that fixes one vulnerability is now available.

Spice could be made to crash or run programs if it received specially crafted network traffic.

UK, French, Belgian blanket spying systems ruled illegal by Europe’s top court
US gov’t warns against paying off ransomware attackers

Companies facilitating ransomware payments run the risk of facing stern penalties for violating US regulations The post US gov’t warns against paying off ransomware attackers appeared first on WeLiveSecurity

Grindr’s Bug Bounty Pledge Doesn’t Translate to Security
Male Chastity Device Comes with Massive Security Flaws
Verizon: Just 25% of global businesses comply fully with the Payment Card Industry Data Security Standard
Boom! Mobile Customer Data Lost to Fullz House/Magecart Attack
5 steps to secure your connected devices

As we steadily adopt smart devices into our lives, we shouldn’t forget about keeping them secured and our data protected The post 5 steps to secure your connected devices appeared first on WeLiveSecurity

Microsoft Zerologon Flaw Under Attack By Iranian Nation-State Actors
COVID-19 Clinical Trials Slowed After Ransomware Attack
APT Attack Injects Malware into Windows Error Reporting
Unpatched Apple T2 Chip Flaw Plagues Macs

An update that fixes one vulnerability is now available.

Gone phishing: workplace email security in five steps

An update for spice and spice-gtk is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that solves one vulnerability and has two fixes is now available.

Security fix for CVE-2020-5238 – ghc-cmark-gfm updated to 0.2.2 which rebases the bundled cmark-gfm to 0.29.0.gfm.1 https://github.com/github/cmark- gfm/security/advisories/GHSA-7gc6-9qr5-hc85

Security fix for CVE-2020-5238 – ghc-cmark-gfm updated to 0.2.2 which rebases the bundled cmark-gfm to 0.29.0.gfm.1 https://github.com/github/cmark- gfm/security/advisories/GHSA-7gc6-9qr5-hc85

Security fix for CVE-2020-5238 – ghc-cmark-gfm updated to 0.2.2 which rebases the bundled cmark-gfm to 0.29.0.gfm.1 https://github.com/github/cmark- gfm/security/advisories/GHSA-7gc6-9qr5-hc85

Meet the new aviation insecurity, same as the old aviation insecurity: Next-gen ACAS X just as vulnerable to spoofing as its predecessor
Insurance firm Ardonagh Group disabled 200 admin accounts as ransomware infection took hold
Former antivirus baron John McAfee collared, faces extradition to America on tax evasion, securities allegations
John McAfee arrested on US tax evasion charges
Post Grid WordPress Plugin Flaws Allow Site Takeovers
UEFI malware rears ugly head again: Kaspersky uncovers campaign with whiff of China
Black-T Malware Emerges From Cryptojacker Group TeamTNT
Malware Families Turn to Legit Pastebin-Like Service
Rare Bootkit Malware Targets North Korea-Linked Diplomats
Hackers can rip open your company with AI… But AI can help you fight back
Tenda Router Zero-Days Emerge in Spyware Botnet Campaign
See me keynote at the (ISC)² Security Congress in November 2020
Video-Game Piracy Group ‘Team Xecuter’ Leaders in Custody

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Brotli could be made to crash if it received a specially crafted input.

Fix PAC buffer overflow

Update to 85.0.4183.121. Why? Because security, that’s why. It fixes these CVEs: CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 It also has a fix for an issue where networking… uh… didn’t.

Mumble 1.3.2. === Client * Fixed: Overlay not starting (#4282) Server * Fixed: keychain-error on macOS for custom certificates (#4345) Known issues * Overlay blocked by BattleEye. A request to whitelist it has been made. * Overlay blocked by CS:GO Trusted Mode

UK loses 16,000 COVID-19 cases due to Excel spreadsheet snafu
If you connect it, protect it
Big IQ play from IT outsourcer: Can’t create batch files if you can’t save files. Of any kind
Google warns of security holes in other vendors’ Android phones

security update

Grindr security hole made it easy to hijack accounts

An update that fixes four vulnerabilities is now available.

An update that solves 10 vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Security fixes for CVE-2020-1472

RavenDB: Pioneering Data Management with an Innovative Open-Source Approach>
Imagine running a dating app and being told accounts could be easily hijacked. How did that feel, Grindr?

An update that fixes 5 vulnerabilities is now available.

An update that contains security fixes can now be installed.

And you thought Fuzzilli was a pasta… Google offers up $50k in cloud credits to fuzz the hell out of JavaScript engines

Update to 85.0.4183.121. Why? Because security, that’s why. It fixes these CVEs: CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 It also has a fix for an issue where networking… uh… didn’t. —- Update Chromium to 85.0.4183.102. Fix issue where unpackaged components prevented hardware accelerated rendering from

Mumble 1.3.2. === Client * Fixed: Overlay not starting (#4282) Server * Fixed: keychain-error on macOS for custom certificates (#4345) Known issues * Overlay blocked by BattleEye. A request to whitelist it has been made. * Overlay blocked by CS:GO Trusted Mode

Egregor Ransomware Threatens ‘Mass-Media’ Release of Corporate Data
Voter Registration ‘Error’ Phish Hits During U.S. Election Frenzy
Account Takeover Fraud Losses Total Billions Across Online Retailers

It was found that SNMP Trap Translator does not drop privileges as configured and does not properly escape shell commands in certain functions. A remote attacker, by sending a malicious crafted SNMP trap, could possibly execute arbitrary shell code with the privileges of the

Adventures in SQL Server 2019: Microsoft updates the update that broke the update
Researchers Mixed on Sanctions for Ransomware Negotiators
Aussie telco Telstra says soz after accidentally diverting traffic meant for encrypted email biz through its servers
Cyber Security Awareness Month is here!

A month teaching us that when everyone pitches in and does their part, then almost everyone is protected The post Cyber Security Awareness Month is here! appeared first on WeLiveSecurity

LATAM financial cybercrime: Competitors‑in‑crime sharing TTPs

ESET researchers discover surprisingly many indicators of close cooperation among Latin American banking trojans’ authors The post LATAM financial cybercrime: Competitors‑in‑crime sharing TTPs appeared first on WeLiveSecurity

LatAm Banking Trojans Collaborate in Never-Before-Seen Effort
Let’s talk about data security in the age of the ‘new normal’ with folks from FireEye, Microsoft, Splunk – and more
Years-Long ‘SilentFade’ Attack Drained Facebook Victims of $4M
Complexity has broken computer security, says academic who helped spot Meltdown and Spectre flaws

Several security vulnerabilities have been discovered in Squid, a high- performance proxy caching server for web clients. CVE-2020-15049

305 CVEs and Counting: Bug-Hunting Stories From a Security Engineer

Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, guest-to-host privilege escalation or information leaks.

Serious Security: Phishing without links – when phishers bring along their own web pages

Reading Time: ~ 2 min. Ryuk Shuts Down Universal Health Services Computer systems for all 400 Universal Health Services facilities around the globe have reportedly been shut down following an attack by the Ryuk ransomware group. Ryuk is known for targeting large organizations, but the healthcare industry has been gaining popularity among these groups due […]