Menu

Monthly Archives: December 2020

Kmart, Latest Victim of Egregor Ransomware – Report
TrickBot Returns with a Vengeance, Sporting Rare Bootkit Functions
Crooks posing as COVID-19 ‘cold chain’ company phished EU for vaccine intel, says IBM
iPhone hack allowed device takeover via Wi‑Fi

Using a zero-click exploit, an attacker could have taken complete control of any iPhone within Wi-Fi range in seconds The post iPhone hack allowed device takeover via Wi‑Fi appeared first on WeLiveSecurity

DeathStalker APT Spices Things Up with PowerPepper Malware
Turla Crutch: Keeping the “back door” open

ESET researchers discover a new backdoor used by Turla to exfiltrate stolen documents to Dropbox The post Turla Crutch: Keeping the “back door” open appeared first on WeLiveSecurity

Reverse Engineering Tools: Evaluating the True Cost
Cyberattacks Target COVID-19 Vaccine ‘Cold-Chain’ Orgs
As Modern Mobile Enables Remote Work, It Also Demands Security
Android devs: If you’re using the Google Play Core Library, update it against this remote file inclusion CVE. Pronto
Clop Gang Gallops Off with 2M Credit Cards from E-Land
Code42 Incydr Series: Honing in on High-Risk Users with Code42 Incydr
ACLU sues US govt, demands to know if agents are buying their way around warrants to track suspects’ smartphones
FBI warns of hackers abusing email forwarding rules in recent attacks
Google Play Apps Remain Vulnerable to High-Severity Flaw
Smashing Security podcast #207: Cyber biowarfare, giant ladybugs, and strippers

An update that solves 5 vulnerabilities and has one errata is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that solves 5 vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

How a nightmare wormable, wireless, automatic hijack-a-nearby-iPhone security flaw was found and fixed
Spotify Wrapped 2020 Rollout Marred by Pop Star Hacks
Think-Tanks Under Attack by Foreign APTs, CISA Warns
Hacker given three years for stealing secret Nintendo Switch blueprints, collecting child sex abuse vids

security update

Xerox DocuShare Bugs Allows Data Leaks
Turla’s ‘Crutch’ Backdoor Leverages Dropbox in Espionage Attacks
Healthcare 2021: Cyberattacks to Center on COVID-19 Spying, Patient Data
How to steal photos off someone’s iPhone from across the street
Mac users warned of more Ocean Lotus malware targeted attacks
Microsoft Revamps ‘Invasive’ M365 Feature After Privacy Backlash
DNS Filtering: A Top Battle Front Against Malware and Phishing
iPhone Bug Allowed for Complete Device Takeover Over the Air
Verifying Linux Server Security: What Every Admin Needs to Know>

An update that fixes one vulnerability is now available.

2021 Global Tech Outlook, A Red Hat Report: Digital transformation, security and hybrid cloud use stand out

An update is now available for Red Hat Ceph Storage 4.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

Misconfigured Docker Servers Under Attack by Xanthe Malware
Android Messenger App Still Leaking Photos, Videos
Ever had a bogus call from someone claiming to be the IRS? A tax scam ringleader just got sent down for 20 years
How the human immune system inspired a new approach to email security
Cayman Islands Bank Records Exposed in Open Azure Blob
Cyberattackers could trick scientists into producing dangerous substances

Without ever setting foot in the lab, a threat actor could dupe DNA researchers into creating pathogens, according to a study describing “an end-to-end cyber-biological attack” The post Cyberattackers could trick scientists into producing dangerous substances appeared first on WeLiveSecurity

Zoom Impersonation Attacks Aim to Steal Credentials
Electronic Medical Records Cracked Open by OpenClinic Bugs
Mobile payment apps: How to stay safe when paying with your phone

Are mobile payments and digital wallets safe? Are the apps safer than credit cards? What are the main risks? Here’s what to know. The post Mobile payment apps: How to stay safe when paying with your phone appeared first on WeLiveSecurity

As if Productivity Score wasn’t creepy enough, Microsoft has patented tech for ‘meeting quality monitoring devices’
Magecart Attack Convincingly Hijacks PayPal Transactions at Checkout
Supreme Court mulls whether a cop looking up a license plate for cash is equivalent to watching Instagram at work
Cayman Islands investment fund left entire filestore viewable by world+dog in unsecured Azure blob
Yes, we’re all going to be at home for the foreseeable future. Does that leave you feeling insecure?

An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-nodejs12-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes one vulnerability is now available.

An update for rh-php73-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes one vulnerability is now available.

An update that fixes 10 vulnerabilities is now available.

New study: DNS spoofing doubles in six years … albeit from the point of naff all
Forget Snow Day: Baltimore’s 115,000+ public school kids get Ransomware Day, must check Win PCs for infection