Menu

Monthly Archives: October 2020

An update that solves one vulnerability and has 25 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

Malware campaign poses as Team Blue Take Action email
Russia and China’s ‘digital authoritarianism’ means we need to better arm our cyber troops, warns top UK general
Your comms may be paperless, but are they actually secure? Thought so…
US govt wins right to snaffle Edward Snowden’s $5m+ book royalties, speech fees – and all future related earnings
How’s this for overachieving? Man accused of running software outfit as a Ponzi scheme while on parole from previous fraud
Tokyo Stock Exchange breaks new record. Sadly, not a good one… its longest ever outage

Reading Time: ~ 4 min. Have you ever met a person who thinks they know it all? Or maybe you’ve occasionally been that person in your own life? No shame and no shade intended – it’s great (and important) to be confident about your skills. And in cases where you know your stuff, we encourage […]

Emotet Emails Strike Thousands of DNC Volunteers
Cloud biz Blackbaud admits ransomware crims may have captured folks’ bank info, months after saying that everything’s fine
QR Codes: A Sneaky Security Threat
Microsoft Office 365 Phishing Attack Uses Multiple CAPTCHAs

A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick (bundled along with jruby) was too tolerant against

A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick (bundled along with ruby2.3) was too tolerant against

Microsoft 365 services back online after hours‑long outage

Microsoft resolves a service disruption that affected Office 365, Outlook.com, Teams and other cloud-based services The post Microsoft 365 services back online after hours‑long outage appeared first on WeLiveSecurity

APT‑C‑23 group evolves its Android spyware

ESET researchers uncover a new version of Android spyware used by the APT-C-23 threat group against targets in the Middle East The post APT‑C‑23 group evolves its Android spyware appeared first on WeLiveSecurity

NFL, NBA Players Hacked in Would-Be Cyber-Slam-Dunk
Spammers Smuggle LokiBot Via URL Obfuscation Tactic

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes 12 vulnerabilities is now available.

The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Therefore, there was a need to explicitly specify the number

This package allowed ../ directory traversal to access private resources because resource matching did not ensure that pathnames were in a canonical format.

Huawei’s UK code reviewers say Chinese mega-corp is still totally crap at basic software security. Bad crypto, buffer overflows, logic errors…
What to do first when your company suffers a ransomware attack
Red Hat adopts ROLIE protocol for automated exchange of security compliance assets
#BeCyberSmart – why friends don’t let friends get scammed
UK privacy watchdog confirms probe into NHS England COVID-19 app after complaints of spammy emails, texts
A complete stranger controlled this woman’s home security system, but they’re not the one she’s angry with
InterPlanetary Storm Botnet Infects 13K Mac, Android Devices
Chap beats rap in WhatsApp zap flap: Russian banker walks from insider trading case after deleting software
Smashing Security podcast #198: Chucky the coffee maker
Singapore to treat infosec as equivalent public good to fresh running water
Diplomats are supposed to be subtle and clever. Australia’s just leaked 1,000 citizens’ email addresses