Menu

Monthly Archives: December 2020

Simplifying Proactive Defense With Threat Playbooks
Dark Web Pricing Skyrockets for Microsoft RDP Servers, Payment-Card Data
Critical Bugs in Dell Wyse Thin Clients Allow Code Execution, Client Takeovers
Dell Wyse Thin Client scores two perfect 10 security flaws
Hacker Dumps Crypto Wallet Customer Data; Active Attacks Follow
Hacker publishes stolen email and mailing addresses of 270,000 Ledger cryptocurrency wallet users
Business and enterprise anti-virus products put through a long-term test – which performed the best?
SolarWinds releases known attack timeline but new data suggests hackers may have done a dummy run last year
Modernize Your Intrusion Detection Strategy with an AI-Powered, Open-Source NIDS>
Telemed Poll Uncovers Biggest Risks and Best Practices
‘Best tech employer of the year’ threatened trainee with £15k penalty fee for quitting to look after his sick mum

It was discovered that there was an issue in node-ini, a .ini format parser and serializer for Node.js, where an application could be exploited by a malicious input file.

Well, on the bright side, the SolarWinds Sunburst attack will spur the cybersecurity field to evolve all over again

An update for thunderbird is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Container Platform release 4.6.9 is now available with updates to packages and images that fix several bugs and add enhancements. This release also includes a security update for Red Hat OpenShift Container Platform 4.6.

An update for openssl is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes 5 vulnerabilities is now available.

Trump administration says Russia behind SolarWinds hack. Trump himself begs to differ

A heap-buffer overwrites error was discovered in lib/openjp2/mqc.c in OpenJPEG 2.3.1. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution (CVE-2020-27814). A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass

An issue has been found in influxdb, a scalable datastore for metrics, events, and real-time analytics. By using a JWT token with an empty shared secret, one is able to bypass

An update that solves one vulnerability and has one errata is now available.

SCAP Security Guide: helping you to achieve security policy compliance

An update that fixes two vulnerabilities is now available.

Two vulnerabilities were discovered in the PEAR Archive_Tar package for handling tar files in PHP, potentially allowing a remote attacker to execute arbitrary code or overwrite files.

The update for lxml released as 4810-1 introduced a regression when running under Python 2. Updated lxml packages are now available to correct this issue.

security update

Cloud is King: 9 Software Security Trends to Watch in 2021

– Update to Firefox 84 – Built with system nss Please give karma to nss packages which are needed for this update: https://bodhi.fedoraproject.org/updates/FEDORA-2020-c489b93b18 https://bodhi.fedoraproject.org/updates/FEDORA-2020-d04a8e97b3 —- – New upstream version (Firefox 84) – Enabled WebRender by default on Gnome Wayland

Update to latest upstream version.

This update backports a patch for CVE-2020-27828.

Sunburst’s C2 Secrets Reveal Second-Stage SolarWinds Victims
Operation SignSight: Supply‑chain attack against a certification authority in Southeast Asia

ESET researchers have uncovered a supply-chain attack on the website of a government in Southeast Asia. The post Operation SignSight: Supply‑chain attack against a certification authority in Southeast Asia appeared first on WeLiveSecurity

Microsoft Caught Up in SolarWinds Spy Effort, Joining Federal Agencies
Cyberpunk 2077 Headaches Grow: New Spyware Found in Fake Android Download
Insider Threats: What Are They, Really?
Unsecured Azure blob exposed 500,000+ highly confidential docs from UK firm’s CRM customers
Ransomware attackers are making threatening phone calls to their victims, warns FBI

Trickbot spreading through Subway company emails Customers of Subway U.K. have been receiving confirmation emails for recent orders that instead contain malicious links for initiating Trickbot malware downloads. Subway has since disclosed that it discovered unauthorized access to several of its servers, which then launched the campaign. Users who do click on the malicious link […]

The container caasp/v4/nginx-ingress-controller was updated. The following patches have been included in this update:

‘Long-standing vulns’ in 5G protocols open the door for attacks on smartphone users

Several vulnerabilities have been discovered in the Linux kernel that may lead to the execution of arbitrary code, privilege escalation, denial of service or information leaks.

Updated images are now available for Red Hat OpenShift Container Storage 4.6.0 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 14 vulnerabilities is now available.

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting or the disclosure of hidden users.

US nuke agency hacked by suspected Russian SolarWinds spies, Microsoft also installed backdoor
“Is it you in the video?” – don’t fall for this Messenger scam

security update

How to Increase Your Security Posture with Fewer Resources
Nuclear Weapons Agency Hacked in Widening Cyberattack – Report
5M WordPress Sites Running ‘Contact Form 7’ Plugin Open to Attack
Ethical power supplier People’s Energy hacked, 250,000 customers’ personal info accessed

security update

Update to 2.16.9 Release notes: https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.9

Police Vouch for Hacker Who Guessed Trump’s Twitter Password
Google, Qualcomm team up to make long-term Android updates easier on Snapdragon
Air-Gap Attack Turns Memory Modules into Wi-Fi Radios
RubyGems Packages Laced with Bitcoin-Stealing Malware
Cryptologists Crack Zodiac Killer’s 340 Cipher
3M Users Targeted by Malicious Facebook, Insta Browser Add-Ons
Cybersecurity Advent calendar: Stay close to one another… Safely!

This year, many of us will be celebrating Christmas with our loved ones virtually, however we shouldn’t underestimate the value of securing our online communication. The post Cybersecurity Advent calendar: Stay close to one another… Safely! appeared first on WeLiveSecurity

Code42 Incydr Series: Bringing Shadow IT into the light with Code42 Incydr
When zombie malware leads to big-money ransomware attacks
Whistleblowers have come to us alleging spy agency wrongdoing, says UK auditor IPCO

An update for openssl is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

How cyber-attackers are coming after you in 2021
Smashing Security podcast #209: Vengeful ex-staff, bad Santas, and iOS app nutrition facts

An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the postgresql:9.6 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

UK Home Office chucks US firm Leidos £30m for help snooping on comms data
Passwords begone: GitHub will ban them next year for authenticating Git operations
Dutch officials say Donald Trump really did protect his Twitter account with MAGA2020! password

security update

security update

SolarWinds’ shares drop 22 per cent. But what’s this? $286m in stock sales just before hack announced?

security update

security update

Log right in, the water’s fine, whispers Microsoft as it adds autofill to Authenticator app
Ryuk, Egregor Ransomware Attacks Leverage SystemBC Backdoor

It was discovered that Apache Tomcat from 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an

The SolarWinds Perfect Storm: Default Password, Access Sales and More
Sextortionist Campaign Targets iOS, Android Users with New Spyware
UK proposes new powers for comms regulator to legally unleash avenging hordes on security-breached telcos

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openssl is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Your ship comms app is ‘secured’ with a Flash interface, doesn’t sanitise SQL inputs and leaks user data, you say?

An update for python-XStatic-Bootstrap-SCSS is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for python-XStatic-jQuery is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

How to leak data via Wi-Fi when there’s no Wi-Fi chip: Boffin turns memory bus into covert data transmitter
We’re not saying this is how SolarWinds was backdoored, but its FTP password ‘leaked on GitHub in plaintext’
Subway Sandwich Loyalty-Card Users Suffer Ham-Handed Phishing Scam
Easy WP SMTP Security Bug Can Reveal Admin Credentials
Gitpaste-12 Worm Widens Set of Exploits in New Attacks
Firefox Patches Critical Mystery Bug, Also Impacting Google Chrome
Medical scans of millions of patients exposed online

Other leaked data included a range of personal information such as names, addresses and personal healthcare information. The post Medical scans of millions of patients exposed online appeared first on WeLiveSecurity

Twitter scores a first for big tech after being fined €450,000 by Ireland’s data watchdog for violating the EU’s GDPR