Menu

Monthly Archives: December 2020

45 Million Medical Images Left Exposed Online
How scammers target PayPal users and how you can stay safe

What are some common ploys targeting PayPal users? Here’s what you should watch out for when using the popular payment service. The post How scammers target PayPal users and how you can stay safe appeared first on WeLiveSecurity

Agent Tesla Keylogger Gets Data Theft and Targeting Update
Millions of Unpatched IoT, OT Devices Threaten Critical Infrastructure
Phishing tricks that really work – and how to avoid them
Ransomware and IP Theft: Top COVID-19 Healthcare Security Scares

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Cruise line operator Hurtigruten crippled in ransomware attack

An update for the nginx:1.16 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

New Red Hat Single Sign-On 7.4.4 packages are now available for Red Hat Enterprise Linux 8. 2. Relevant releases/architectures: Red Hat Single Sign-On 7.4 for RHEL 8 – noarch

A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

New Red Hat Single Sign-On 7.4.4 packages are now available for Red Hat Enterprise Linux 7. 2. Relevant releases/architectures: Red Hat Single Sign-On 7.4 for RHEL 7 Server – noarch

45 million medical scans from hospitals all over the world left exposed online for anyone to view – some servers were laced with malware
Up to 18,000 SolarWinds customers installed poisoned update that could allow state-sponsored attack
SolarWinds: Hey, only as many as 18,000 customers installed backdoored software linked to US govt hacks
Spotify Changes Passwords After Another Data Breach

security update

Ransomware masterminds claim to have nabbed 53GB of data from Intel’s Habana Labs
House purchases in Hackney fall through following cyber attack against council
Ex-Cisco Employee Convicted for Deleting 16K Webex Accounts
DHS Among Those Hit in Sophisticated Cyberattack by Foreign Adversaries – Report
SolarWinds’ ‘breached by nation state spies’ software is in wide use throughout the British public sector
Microsoft Office 365 Credentials Under Attack By Fax ‘Alert’ Emails

The cybersecurity industry and end-of-year predictions go together like Fall and football or champagne and the New Year. But on the heels of an unprecedented year, where a viral outbreak changed the landscape of the global workforce practically overnight, portending what’s in store for the year ahead is even trickier than usual.   One thing […]

New Windows Trojan Steals Browser Credentials, Outlook Files
You’re invited to the “Smashing Security” Christmas party!
Anatomy of a Linux Ransomware Attack>

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for xorg-x11-server is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Ad blocking made Google throw its toys out of the pram – and now even more control is being taken from us

Red Hat OpenShift Container Platform release 4.6.8 is now available with updates to packages and images that fix several bugs. This release includes a security update for openshift-enterprise-builder-container for Red Hat OpenShift Container

An update for libexif is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Red Hat OpenShift Container Platform release 4.6.8 is now available with updates to packages and images that fix several bugs. An update for ironic-images, openshift, openshift-ansible, openshift-clients, and python-eventlet, cri-o, openshift-kuryr,

An update for libpq is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

US Treasury, Dept of Commerce hacks linked to SolarWinds IT monitoring software supply-chain attack

Yaniv Nizry discovered that the clean module of lxml, Python bindings for libxml2 and libxslt could be bypassed. For the stable distribution (buster), this problem has been fixed in

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Ruild with hardening flags enabled; also, add -doc subpackage, fix .so version symlinking, make -devel dependency on main package strict (arched), and other minor improvements

New version 3.4.0. Security fix for CVE-2020-26575, CVE-2020-28030.

Rogue ex-Cisco employee who crippled WebEx conferences and cost Cisco millions gets two years in US prison

The container caasp/v4.5/velero-restic-restore-helper was updated. The following patches have been included in this update:

The container caasp/v4.5/velero-plugin-for-microsoft-azure was updated. The following patches have been included in this update:

The container caasp/v4.5/velero-plugin-for-gcp was updated. The following patches have been included in this update:

The container caasp/v4.5/velero-plugin-for-aws was updated. The following patches have been included in this update:

The container caasp/v4.5/velero was updated. The following patches have been included in this update:

The container caasp/v4.5/skuba-tooling was updated. The following patches have been included in this update:

Subway sandwich scam mystifies loyalty card users

Hackers, never at a loss for creative deception, have engineered new tactics for exploiting the weakest links in the cybersecurity chain: ourselves! Social engineering and business email compromise (BEC) are two related cyberattack vectors that rely on human error to bypass the technology defenses businesses deploy to deter malware. Social Engineering Social Engineering is when […]

Security Issues in PoS Terminals Open Consumers to Fraud

Cybercrime surpasses $1Trillion in global costs A recent study has put the global cost of cybercrime at over $1 trillion for 2020. This figure is up significantly from 2018, which was calculated at around $600 billion. And while most effects are financial, roughly 92% of affected organizations cited by the study reported additional issues stemming […]

Adrozek Malware Delivers Fake Ads to 30K Devices a Day
PGMiner, Innovative Monero-Mining Botnet, Surprises Researchers
British voyeur escapes US extradition over 770 cases of webcam malware
Feds: K-12 Cyberattacks Dramatically on the Rise
Cybersecurity Advent calendar: Tips for buying gifts and not receiving coal

While shopping for the perfect presents, be on the lookout for naughty cybercriminals trying to ruin your Christmas cheer by tricking you out of both gifts and money The post Cybersecurity Advent calendar: Tips for buying gifts and not receiving coal appeared first on WeLiveSecurity

Operation StealthyTrident: corporate software under attack

LuckyMouse, TA428, HyperBro, Tmanger and ShadowPad linked in Mongolian supply-chain attack The post Operation StealthyTrident: corporate software under attack appeared first on WeLiveSecurity

Facebook Shutters Accounts Used in APT32 Cyberattacks
Subway email weirdness: Suspicion grows over apparent Trickbot trojan delivery campaign

An update that solves 11 vulnerabilities and has 62 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability, contains one feature and has 6 fixes is now available.

An update that fixes 8 vulnerabilities is now available.

An update that solves four vulnerabilities and has 11 fixes is now available.

These free tools from Recorded Future can make you a security intelligence expert
After police raid on COVID-19 whistleblower, it’s revealed password was publicly posted on Florida Department of Health’s website
Was there a “COVID-19 vaccine hack” against the European Medicines Agency?
Defending the Intelligent Edge from Evolving Attacks
Ad-scamming, login-stealing Windows malware is hitting Chrome, Edge, Firefox, Yandex browsers, says Microsoft
Pfizer COVID-19 Vaccine Targeted in EU Cyberattack

security update

security update

‘Malwareless’ ransomware campaign operators pwned 83k victims’ MySQL servers, 250k databases up for sale
MoleRats APT Returns with Espionage Play Using Facebook, Dropbox
The patch that wasn’t: Cisco emits fresh fixes for NTLM hash-spilling vuln and XSS-RCE combo in Jabber app
PLEASE_READ_ME Ransomware Attacks 85K MySQL Servers
Zero-Click Wormable RCE Vulnerability in Cisco Jabber Gets Fixed, Again

The update of sqlite3 released as DLA-2340-1 contained an incomplete fix for CVE-2019-20218. Updated sqlite3 packages are now available to correct this issue.

Goodbye to Flash – if you’re still running it, uninstall Flash Player now
Cyber Monday is Every Monday: Securing the ‘New Normal’

An update that solves 12 vulnerabilities and has 72 fixes is now available.

UK union pens letter to data watchdog on icky workplace monitoring systems like Microsoft’s Productivity Score

An update that solves one vulnerability, contains one feature and has 7 fixes is now available.

An update that solves 12 vulnerabilities and has 72 fixes is now available.

Smashing Security podcast #208: Hidden treasure, COVID tracker trauma, and happy holidays with IoT
Misery of Ransomware Hits Hospitals the Hardest
Center for Internet Security (CIS) compliance in Red Hat Enterprise Linux using OpenSCAP
Public-Key Cryptography Standard (PKCS) #11 v 3.0 has been released: What is it, and what does it mean for RHEL?
Critical Steam Flaws Could Let Gamers Crash Opponents’ Computers
UK Ministry of Defence: We won’t prosecute bug bounty hunters – oh btw, we now have one of those

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Google Chrome’s crackdown on ad blockers and browser extensions, Manifest v3, is now available in beta
South Korea kills ActiveX-based government digital certificate service
Record Levels of Software Bugs Plague Short-Staffed IT Teams in 2020

security update

EU Medicines Agency hacked, BioNTech-Pfizer coronavirus vaccine paperwork stolen, probe launched