Menu

Monthly Archives: November 2020

Multiple Industrial Control System Vendors Warn of Critical Bugs
Defining Security Policies to Manage Remote Insider Threats
ThreatList: Pharma Mobile Phishing Attacks Turn to Malware
COVID-19 Antigen Firm Hit by Malware Attack
Microsoft brings Trusted Platform Module functionality directly to CPUs under securo-silicon architecture Pluton
A visit to a crafted webpage would have been enough for a bad guy to munch all your Firefox for Android cookies
Zoom Takes on Zoom-Bombers Following FTC Settlement
Lazarus supply‑chain attack in South Korea

ESET researchers uncover a novel Lazarus supply-chain attack leveraging WIZVERA VeraPort software The post Lazarus supply‑chain attack in South Korea appeared first on WeLiveSecurity

Cisco Patches Critical Flaw After PoC Exploit Code Release
Legendary hacker and L0pht member Peiter Zatko joins Twitter as security chief
Some Apple Apps on macOS Big Sur Bypass Content Filters, VPNs

An update that fixes one vulnerability is now available.

An update that fixes 29 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Kerberos could be made to consume unlimited resources if it received specially crafted ASN.1.

Apple’s privacy pledges: We sent dev checks over plain HTTP, logged IP addresses. We bypass firewall apps
End the year as you mean to go on… with world-class cyber-security training
Micropayments company Coil distributes new privacy policy with email that puts users’ addresses in the ‘To:’ field
Cult videogame company Capcom pays a big round $0.00 to ransomware crooks
Dating Site Bumble Leaves Swipes Unsecured for 100M Users
Attackers Target Porn Site Goers in ‘Malsmoke’ Zloader Attack
Citrix SD-WAN Bugs Allow Remote Code Execution
Hacked Security Software Used in Novel South Korean Supply-Chain Attack
Exposed Database Reveals 100K+ Compromised Facebook Accounts
Street Fighter maker says soz after ransomware hadoukens servers leaving 350,000 folks’ data at risk of compromise
Up to 350,000 people at risk after Capcom ransomware attack
Cybercrime Moves to the Cloud to Accelerate Attacks Amid Data Glut

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

International infosec rules delivered to make nations and non-state actors behave themselves online
This year’s biggest innovators? Hackers and cybercriminals. Again

An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the virt:8.2 and virt-devel:8.2 modules is now available for Advanced Virtualization for RHEL 8.2.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Australia to track Coronavirus encounters with payment card records

Apache Ant uses various insecure temporary files possibly allowing local code execution.

A vulnerability in MIT Kerberos 5 could lead to a Denial of Service condition.

A vulnerability in libmaxminddb could lead to a Denial of Service condition.

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation. (CVE-2020-0452)

The Kleopatra component before 20.07.80 for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary library. (CVE-2020-24972).

A flaw was found in Go standard library packages. Both the net/http/cgi and net/http/fcgi packages use a default Content-Type response header value of “text/html”, rather than “text/plain”. An attacker could exploit this in applications using these packages by uploading crafted files, allowing for a cross-site scripting attack (XSS) (CVE-2020-24553).

A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick was too tolerant against an invalid Transfer-Encoding header. This may lead to inconsistent interpretation between WEBrick and some HTTP proxy servers, which may allow the attacker to ”smuggle” a request (CVE-2020-25613).

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-8694) Observable discrepancy in the RAPL interface for some Intel(R) Processors may

Scams Ramp Up Ahead of Black Friday Cybercriminal Craze
Stick a fork in SGX, it’s done: Intel’s cloud-server security defeated by $30 chip and electrical shenanigans

Update to latest upstream version.

security update

– Fix CVE-2020-28196 (DoS in ASN.1 parsing due to missing recursion depth checks) – fc32 + fc33 only: pull-up to rawhide

Add correct fix for CVE-2020-24977 (RHBZ#1877788), thanks: Jan de Groot.

CVE-2020-0181, CVE-2020-0198, and CVE-2020-0452

Ex-missile systems worker jailed for breaching Official Secrets Act after last-second guilty plea
Amazon Sues Instagram, TikTok Influencers Over Knockoff Scam
Botnet Attackers Turn to Vulnerable IoT Devices
Nation-State Attackers Actively Target COVID-19 Vaccine-Makers
2020 Reader Survey: Share Your Feedback to Help Us Improve

USN-4607-1 introduced a regression in OpenJDK.

EncroChat hack evidence wasn’t obtained illegally, High Court of England and Wales rules – trial judges will decide whether to admit it
Google patches two new zero‑day flaws in Chrome

The last three weeks have seen a bumper crop of patches for zero-day bugs across software from Google, Apple and Microsoft The post Google patches two new zero‑day flaws in Chrome appeared first on WeLiveSecurity

Hungry for data, ModPipe backdoor hits POS software used in hospitality sector

Backdoor authors show deep knowledge of the targeted POS software, decrypting database passwords from Windows registry values The post Hungry for data, ModPipe backdoor hits POS software used in hospitality sector appeared first on WeLiveSecurity

Ticketmaster Scores Hefty Fine Over 2018 Data Breach
Credential-Stuffing Attack Hits The North Face
Ticketmaster cops £1.25m ICO fine for 2018 Magecart breach, blames someone else and vows to appeal

Reading Time: ~ 2 min. Phony IRS Emails Flooding Inboxes Upwards of 70,000 inboxes have been receiving spam claiming to be from the IRS threatening legal action for late or missing payments. Most recipients are Microsoft Office 365 users and have been receiving threats of lawsuits to, wage garnishment and even arrest. These spoofing scams […]

Report: CISA Chief Expects White House to Fire Him
The North Face resets passwords after credential-stuffing attack
Free tools from Recorded Future that can make you a security intelligence expert

Li Fei found that libproxy, a library for automatic proxy configuration management, was vulnerable to a buffer overflow vulnerability when receiving a large PAC file from a server without a Content-Length header in the response.

2020’s biggest innovators? Hackers and cyber-criminals, again, says Darktrace

A use-after-free was found in Thunderbird, which could potentially result in the execution of arbitrary code. For Debian 9 stretch, this problem has been fixed in version

Ken Gaillot discovered a vulnerability in the Pacemaker cluster resource manager: If ACLs were configured for users in the “haclient” group, the ACL restrictions could be bypassed via unrestricted IPC communication, resulting in cluster-wide arbitrary code execution with

Election security fears doused with reality: Top officials say Nov 3 ‘was the most secure in American history.’ The end

security update

Cyberattackers Serve Up Custom Backdoor for Oracle Restaurant Software
Animal Jam Hacked, 46M Records Roam the Dark Web

Updates the nss package to upstream NSS 3.58 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes

Updates the nss package to upstream NSS 3.58 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes

Reading Time: ~ 3 min. Webroot is a dynamic team of hard-working individuals with diverse backgrounds. One of those hard-working individuals is Ben Jackson, Senior Manager of Software Development, Engineering. Ben started off building pages in HTML. Now he leads high-performing teams and helps develop architectures from his home in the UK. We sat down […]

Digging into the Dark Web: How Security Researchers Learn to Think Like the Bad Guys
Kids’ gaming website Animal Jam breached after miscreants spot private AWS key on pwned Slack channel
Microsoft Patch Tuesday fixes 17 critical flaws, Windows zero‑day

The second Tuesday of the month brings another fresh batch of fixes for security vulnerabilities in various Microsoft products The post Microsoft Patch Tuesday fixes 17 critical flaws, Windows zero‑day appeared first on WeLiveSecurity

Why you should keep your Netflix password to yourself

Sharing is caring – except when it isn’t. Here’s why you shouldn’t share your password for online media services with other people. The post Why you should keep your Netflix password to yourself appeared first on WeLiveSecurity

Bugs in Critical Infrastructure Gear Allow Sophisticated Cyberattacks
UK Conservative Party used 10 million people’s names to derive their country of origin, ethnicity and religion according to ICO report
Microsoft says it’s time for you to stop using SMS and voice calls for multi-factor authentication
2 More Google Chrome Zero-Days Under Active Exploitation
From Triton to Stuxnet: Preparing for OT Incident Response

An update that solves 53 vulnerabilities, contains 14 features and has 5 fixes is now available.

Swiss spies knew about Crypto AG compromise – and kept it from govt overseers for nearly 30 years
Enhancing internet and cloud security with Red Hat’s contribution the Guide to IPsec VPNs

libmaxminddb could be made to crash if it received specially crafted data.

USN-4171-1 introduced a regression in Apport.

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Ransomware gang takes out Facebook ads to apply pressure on victim
Smashing Security podcast #204: Green buttons, Olympic attacks, and… an apology
Samsung finally admitted to Google’s Enterprise Android Recommended club

security update

Microsoft warns against SMS, voice calls for multi-factor authentication: Try something that can’t be SIM swapped