Menu

Monthly Archives: December 2020

SideWinder APT Targets Nepal, Afghanistan in Wide-Ranging Spy Campaign
Microsoft Patch Tuesday fixes 58 flaws

The last Patch Tuesday of the year brings another fresh batch of fixes for Microsoft products and while the number may be lower the patches are no less important. The post Microsoft Patch Tuesday fixes 58 flaws appeared first on WeLiveSecurity

COVID-19 Vaccine Cyberattacks Steal Credentials, Spread Zebrocy Malware
D-Link Routers at Risk for Remote Takeover from Zero-Day Flaws

The updated packages fix some problems found in version 86 and security vulnerabilities. References: – https://bugs.mageia.org/show_bug.cgi?id=27630

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 8 vulnerabilities, contains one feature and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Using OPA for multicloud policy and process portability
Bitter war of words erupts between UK cops and web security expert over alleged flaws in Cyberalarm monitoring tool
Cybersecurity giant FireEye says it was hacked by govt-backed spies who stole its crown-jewels hacking tools
FireEye hacked. “State-sponsored attackers” blamed as Red Team tools stolen. Here’s what you need to know
Google Patches Critical Wi-Fi and Audio Bugs in Android Handsets
Patch Tuesday brings bug fixes for OpenSSL, IBM, SAP, Kubernetes, Adobe, and Red Hat. And Microsoft, of course
FireEye Cyberattack Compromises Red-Team Security Tools
Court orders encrypted email biz Tutanota to build a backdoor in user’s mailbox, founder says ‘this is absurd’
Divers Pull Rare Surviving WWII Enigma Cipher Machine from Bottom of the Baltic

security update

security update

Microsoft Wraps Up a Lighter Patch Tuesday for the Holidays
Apple Manufacturer Foxconn Confirms Cyberattack
The Internal Revenue Service expands identity protection to all tax‑payers

U.S. tax-payers will be able to enroll in the Identity Protection PIN program that was previously available only to certain users starting mid-January. The post The Internal Revenue Service expands identity protection to all tax‑payers appeared first on WeLiveSecurity

The Remote-Work Transition Shifts Demand for Cyber Skills
Oblivious DoH, OPAQUE passwords, Encrypted Client Hello: Cloudflare’s protocol proposals to protect privacy
Critical, Unpatched Bugs Open GE Radiological Devices to Remote Code Execution
Adobe Warns Windows, macOS Users of Critical-Severity Flaws
Vishing criminals let rip with two scams at once
Spearphishing Attack Spoofs Microsoft.com to Target 200M Office 365 Users
Foxconn hit with record-breaking $34 million ransom demand after cyber attack
‘Amnesia:33’ TCP/IP Flaws Affect Millions of IoT Devices

David Benjamin discovered a flaw in the GENERAL_NAME_cmp() function which could cause a NULL dereference, resulting in denial of service. Additional details can be found in the upstream advisory:

Pure frustration: What happens when someone uses your email address to sign up for PayPal, car hire, doctors, security systems and more

An update that solves 6 vulnerabilities and has one errata is now available.

An update for mariadb-galera is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of High. A Common Vulnerability Scoring System (CVSS) base score, which

Iran to issue license for national bug bounty program to clean up its code base
Cops raid home of ousted data scientist who created her own Florida COVID-19 dashboard
Kremlin hackers are right now exploiting security hole in VMware software to hijack systems, NSA warns
NSA Warns: Patched VMware Bug Under Active Attack
When is a remote-code-execution bug in Teams not an RCE? When Microsoft says it isn’t, flaw finder discovers
Rana Android Malware Updates Allow WhatsApp, Telegram IM Snooping
Europol Warns COVID-19 Vaccine Rollout Vulnerable to Fraud, Theft
‘Free’ Cyberpunk 2077 Downloads Lead to Data Harvesting
Google patches four high‑severity flaws in Chrome

The new release patches a total of eight vulnerabilities affecting the desktop versions of the popular browser. The post Google patches four high‑severity flaws in Chrome appeared first on WeLiveSecurity

Recruitment giant Randstad hit by ransomware, sensitive data stolen
Israel shaken by data leak after ransomware attack at Shirbit insurance company
Insider Report: Healthcare Security Woes Balloon in COVID-Era
Chinese Breakthrough in Quantum Computing a Warning for Security Teams
Healthcare in Crisis: Diagnosing Cybersecurity Shortcomings in Unprecedented Times
QNAP High-Severity Flaws Plague NAS Systems
Channel Isles cop sacked after abusing police database to track down women drivers for Instagram ‘comic’ page
It’s not just the economy and bad management messing with Kmart – ransomware crews are there too
Australia Post isn’t smoking meth, despite what its website may have said
German divers find Enigma crypto machine on seabed

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 5 vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Travel agent leaked customer data by – this is embarrassing – giving it away in a hackathon
What if you could call on SANS experts for training that fits your schedule?

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable (CVE-2020-26970).

In PDFResurrect before 0.20, lack of header validation checks causes a heap-buffer-overflow in pdf_get_version() (CVE-2020-20740). References: – https://bugs.mageia.org/show_bug.cgi?id=27704

Mutt before 2.0.2 did not ensure that $ssl_force_tls was processed if an IMAP server’s initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle (CVE-2020-28896).

Food bank loses nearly $1,000,000 in Business Email Compromise scam

Security fix for CVE-2020-8037

security update

security update

Cybersecurity Advent Calendar: Let Santa in, keep hackers out!

Santa will soon come down the chimney, but there are potential entry points into your home and digital life that you should never leave open The post Cybersecurity Advent Calendar: Let Santa in, keep hackers out! appeared first on WeLiveSecurity

The package musl before version 1.2.1-2 is vulnerable to arbitrary code execution.

The package webkit2gtk before version 2.30.3-1 is vulnerable to arbitrary code execution.

The package gitea before version 1.12.6-1 is vulnerable to insufficient validation.

The package neomutt before version 20201120-1 is vulnerable to silent downgrade.

The package matrix-synapse before version 1.20.1-1 is vulnerable to denial of service.

Biological Worries Over Malware Attacks Researchers have recently unveiled the latest potential victim for malware authors: biological laboratories. By illicitly accessing these facilities, hackers may be able to digitally replace sections of DNA strings, causing unexpected results when biologists go to create or experiment with these compounds. While it is fortunate that this specific targeted […]

Making Sense of the Security Sensor Landscape
High-Severity Chrome Bugs Allow Browser Hacks

security update

Novel Online Shopping Malware Hides in Social-Media Buttons

Two vulnerabilities in the certificate list syntax verification and in the handling of CSN normalization were discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. An unauthenticated remote attacker can take advantage of these

Several vulnerabilities were discovered in salt. CVE-2020-16846

According to data from a recent report, only 60% of office workers worldwide believe their company is resilient against cyberattacks. Nearly one in four (23%) admit to not knowing, while nearly one in five (18%) flat-out think it isn’t. In the anonymous, write-in responses to the survey, many workers agreed that their employers could be […]

Cybersecurity Trends 2021: Staying secure in uncertain times

ESET experts look back at some of the key themes that defined the cybersecurity landscape in the year that’s ending and give their takes on what to expect in 2021 The post Cybersecurity Trends 2021: Staying secure in uncertain times appeared first on WeLiveSecurity

Protect your business from DDoS attacks: Join this webinar to find out more
VMware Rolls a Fix for Formerly Critical Zero-Day Bug
Vancouver Metro Disrupted by Egregor Ransomware

An update that fixes 5 vulnerabilities, contains one feature is now available.

An update that fixes 10 vulnerabilities is now available.

Metro Vancouver TransLink hit by Egregor ransomware attack, travellers disrupted

Chiaki Ishikawa discovered a stack overflow in SMTP server status handling which could potentially result in the execution of arbitrary code.

It’s dark out there, and if you want to keep the lights on, you need to update your cyber-security skills with SANS