Menu

Monthly Archives: November 2020

Post-Cyberattack, UVM Health Network Still Picking Up Pieces
Conti Gang Hits IoT Chipmaker Advantech with $14M Ransom Demand
Digitally Signed Bandook Trojan Reemerges in Global Spy Campaign
The CEO’s chuckling at their email… you better check your security defenses
MacOS Users Targeted By OceanLotus Backdoor
Pandemic, A Driving Force in 2021 Financial Crime
Conti ransomware attack demands $14 million from industrial IoT firm Advantech

A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This update upgrades Thunderbird to version 78.5.0. * Mozilla: Parsing mismatches could confuse and bypass security sanitizer for chrome privileged code (CVE-2020-26951) * Mozilla: Memory safety bugs fixed in Firefox 83 and Firefox ESR 78.5 (CVE-2020-26968) * Mozilla: Variable time processing of cross-origin images during drawImage calls (CVE-2020-16012) * Mozilla: Fullscreen could be enable [More…]

An update for faq is now available for Red Hat OpenShift Container Platform 4.6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Home Wi-Fi security tips – 5 things to check

Red Hat Ansible Tower 3.7.4-1 – RHEL7 Container 2. Description: * Fixed two jQuery vulnerabilities (CVE-2020-11022, CVE-2020-11023) * Improved Ansible Tower’s web service configuration to allow for

An update for rh-mariadb103-mariadb and rh-mariadb103-galera is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

The package swtpm before version 0.5.1-1 is vulnerable to privilege escalation.

The package rclone before version 1.53.3-1 is vulnerable to private key recovery.

An update that fixes two vulnerabilities is now available.

Some issues have been found in qemu, a fast processor emulator. All issues are related to assertion failures, out-of-bounds access

Update to WebKitGTK 2.30.3: * Fix backdrop filters with rounded borders. * Fix scrolling iframes when async scrolling is enabled. * Allow applications to handle drag and drop on the web view again. * Update Outlook user agent quirk. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-9983, CVE-2020-13584

2021 Healthcare Cybersecurity Priorities: Experts Weigh In

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

Guenal Davalan reported a flaw in x11vnc, a VNC server to allow remote access to an existing X session. x11vnc creates shared memory segments with 0777 mode. A local attacker can take advantage of this flaw for information disclosure, denial of service or interfering with the VNC

security update

Fix for multiple CVEs

fix CVE-2020-27780: authentication bypass when the user doesn’t exist

Update to upstream 17.9.0 for bug and security fixes

TurkeyBombing Puts New Twist on Zoom Abuse
FBI warns of threat actors spoofing Bureau domains, email accounts

The U.S. law enforcement agency shares a sampling of more than 90 spoofed FBI-related domains registered recently The post FBI warns of threat actors spoofing Bureau domains, email accounts appeared first on WeLiveSecurity

SIM swap scam: What it is and how to protect yourself

Here’s what to know about attacks where a fraudster has your number, literally and otherwise The post SIM swap scam: What it is and how to protect yourself appeared first on WeLiveSecurity

Manchester United email servers remain offline amid what is being called a ‘ransomware’ attack
You too can be a security intelligence expert, with these free tools from Recorded Future
UK infoseccer launches petition asking government not to backdoor encryption
Cybersecurity Predictions for 2021: Robot Overlords No, Connected Car Hacks Yes
ThreatList: Cyber Monday Looms – But Shoppers Oblivious to Top Retail Threats

An update that fixes 10 vulnerabilities, contains one feature is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Fertility patients’ sensitive personal information stolen during ransomware attack

An update that fixes 12 vulnerabilities is now available.

security update

Bzzzzzzt! How safe is that keenly priced digital doorbell?
Suspected BEC scammers arrested in Nigeria following year-long Interpol investigation
Federated Learning: A Therapeutic for what Ails Digital Health
Changing Employee Security Behavior Takes More Than Simple Awareness

An update that solves 26 vulnerabilities and has 32 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 26 vulnerabilities and has 32 fixes is now available.

Smashing Security podcast #206: Robo dogs, deepfakes and dirty deceptions with Tim Harford
Privacy campaigner flags concerns about Microsoft’s creepy Productivity Score
Sophos security breach exposes customer support records

security update

Major BEC Phishing Ring Cracked Open with 3 Arrests
Critical MobileIron RCE Flaw Under Active Attack
Up to 350,000 Spotify accounts hacked in credential stuffing attacks

This won’t be music to your ears – researchers spot an unsecured database replete with records used for an account hijacking spree The post Up to 350,000 Spotify accounts hacked in credential stuffing attacks appeared first on WeLiveSecurity

How to Update Your Remote Access Policy – And Why You Should Now
Laser-Based Hacking from Afar Goes Beyond Amazon Alexa

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has one errata is now available.

An update that solves 12 vulnerabilities and has 103 fixes is now available.

An update that fixes one vulnerability is now available.

Ticketmaster: We’re not liable for credit card badness because the hack straddled GDPR day
Google binned two apps by China’s Baidu, which says researchers got it wrong by linking it to personal info leaks
Post-Breach, Peatix Data Reportedly Found on Instagram, Telegram
‘Minecraft Mods’ Attack More Than 1 Million Android Devices

This November 28 may be the most important Small Business Saturday since the occasion was founded by American Express in 2010. As early as July, nearly half (43 percent) of small businesses had closed at least temporarily, according to a study published in the Proceedings of the National Academy of Sciences. Research also suggests that […]

VMware urges sysadmins to apply workarounds after critical Workspace command execution vuln found
Gift card hack exposed – you pay, they play
Smart Doorbells on Amazon, eBay, Harbor Serious Security Issues
Baidu Apps in Google Play Leak Sensitive Data
Blackrota Golang Backdoor Packs Heavy Obfuscation Punch

An update that solves 21 vulnerabilities and has 21 fixes is now available.

OctopusWAF: A Customizable Open-Source WAF for High Performance Applications>

An update that solves 17 vulnerabilities and has 15 fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Tesla Hacked and Stolen Again Using Key Fob
Fake Minecraft mods installed on over one million Android devices

net-snmp: Improper Privilege Management in EXTEND MIB may lead to privileged commands execution (CVE-2020-15862) SL6 x86_64 net-snmp-5.5-60.el6_10.2.x86_64.rpm net-snmp-debuginfo-5.5-60.el6_10.2.i686.rpm net-snmp-debuginfo-5.5-60.el6_10.2.x86_64.rpm net-snmp-libs-5.5-60.el6_10.2.i686.rpm net-snmp-libs-5.5-60.el6_10.2.x86_64.rpm net-snmp-devel-5.5-60.el6_10.2.i686.rpm [More…]

This update upgrades Thunderbird to version 78.4.3. * Mozilla: Write side effects in MCallGetProperty opcode not accounted for (CVE-2020-26950) SL6 x86_64 thunderbird-78.4.3-1.el6_10.x86_64.rpm thunderbird-debuginfo-78.4.3-1.el6_10.x86_64.rpm i386 thunderbird-78.4.3-1.el6_10.i686.rpm – Scientific Linux Development Team

Imagine things are bad enough that you need a payday loan. Then imagine flaws in systems of loan lead generators leave your records in the open… for years

An update that fixes 5 vulnerabilities is now available.

Marketers for an Open Web ask UK competition watchdog to block launch of Google’s anti-tracking Privacy Sandbox
Crooks social-engineer GoDaddy staff into handing over control of crypto-biz domain names
Critical VMware Zero-Day Bug Allows Command Injection; Patch Pending
Apple’s global security boss accused of bribing cops with 200 free iPads in exchange for concealed gun permits
GoDaddy Employees Tricked into Compromising Cryptocurrency Sites

REvil Ransomware Strikes Hosting Provider In recent days the web hosting provider Managed.com has been working to recover from a ransomware attack targeting many of their core systems. While the company was able to stop the spread of the attack by shutting down their systems and client websites, it remains unclear what information may have […]

Security flaws in smart doorbells may open the door to hackers

The peace of mind that comes with connected home security gadgets may be false – your smart doorbell may make an inviting target for unwanted visitors The post Security flaws in smart doorbells may open the door to hackers appeared first on WeLiveSecurity

Manchester United versus a “sophisticated” cyber attack
TA416 APT Rebounds With New PlugX Malware Variant
Spotify Users Hit with Rash of Account Takeovers