Menu

Monthly Archives: January 2021

An update for dnsmasq is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for dnsmasq is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for compliance-content-container, ose-compliance-openscap-container, ose-compliance-operator-container, and ose-compliance-operator-metadata-container is now available for Red Hat OpenShift Container Platform 4.6.

AnyVan confirms digital break-in, says customer names, emails and hashed passwords exposed
Scottish environmental agency still struggling after Christmas Eve ransomware attack
Swanky Wentworth golf club hacked, details of 4000 members stolen in ransomware attack
Scottish Environment Protection Agency refuses to pay ransomware crooks over 1.2GB of stolen data
Bye bye, said Trump admin to Huawei: You give a cheque-ie to our techies, but there’s no licence to ply
Cryptocurrency scammers hijack verified accounts once again, jumping on Elon Musk’s Twitter threads
Medical Device Security: Diagnosis Critical

Red Hat OpenShift Container Platform release 4.6.12 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

An update for the postgresql:9.6 module is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the postgresql:10 module is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libpq is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenShift Container Platform release 4.6.12 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.6.

Hallowed Bugtraq infosec list killed then resurrected over the weekend: We heard your feedback, says Accenture

The updated packages fix security vulnerabilities. See upstream releasenotes. References:

An issue in caribou, that was exposed by a CVE fix in X.org server, permits a screensaver-lock bypass. It is possible to crash the screensaver and unlock the desktop via the virtual keyboard. References:

The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path. (CVE-2021-23239).

Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc (CVE-2020-29361). A heap-based buffer over-read has been discovered in the RPC protocol used by

In Synergy before version 1.12.0, a Synergy server can be crashed by receiving a kMsgHelloBack packet with a client name length set to 0xffffffff (4294967295) if the servers memory is less than 4 GB. It was verified that this issue does not cause a crash through the exception handler if the available memory of the […]

A flaw was found in Resteasy, where an improper input validation results in returning an illegal header that integrates into the server’s response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed (CVE-2020-1695).

security update

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 5 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

security update

Tractors, Pod Ice Cream and Lipstick Awarded CES 2021 Worst in Show
Microsoft Implements Windows Zerologon Flaw ‘Enforcement Mode’

security update

Signal boost: Secure chat app is wobbly at the moment. Not surprising after gaining 30m+ users in a week, though
Apple Kills MacOS Feature Allowing Apps to Bypass Firewalls
CES 2021: Car spying – your insurance company is watching you

Your ‘networked computer on wheels’ has a privacy problem – and you may not be in the driver’s seat when it comes to your data The post CES 2021: Car spying – your insurance company is watching you appeared first on WeLiveSecurity

Google Boots 164 Apps from Play Marketplace for Shady Ad Practices

The container suse/sle15 was updated. The following patches have been included in this update:

Using OpenSCAP to help achieve HIPAA compliance with Red Hat Enterprise Linux 8.3

In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions, no HTML escaping was being performed when

Multiple vulnerabilites in wavpack were found, like OOB read (which could potentially lead to a DOS attack), unexpected control flow, crashes, integer overflow, and segfaults.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Facebook: Malicious Chrome Extension Developers Scraped Profile Data
Europol announces bust of “world’s biggest” dark web marketplace
Florida Ethics Officer Charged with Cyberstalking
Coming in at number 5, it’s a blast from the past! Tenable’s 2020 security flaw chart show features hits of yesteryear
Telegram Bots at Heart of Classiscam Scam-as-a-Service
CES 2021: Router swarms invade your home (and know where you are)

New mesh Wi-Fi routers may be the answer to your wireless signal woes, but how about your privacy and security? The post CES 2021: Router swarms invade your home (and know where you are) appeared first on WeLiveSecurity

Cloud Attacks Are Bypassing MFA, Feds Warn
Ministry of Defence’s cyber warfare drive is helping burn a hole through its budget, warns UK’s National Audit Office
Cybercriminals are bypassing multi-factor authentication to access organisation’s cloud services
Ring Adds End-to-End Encryption to Quell Security Uproar

Release of OpenShift Serverless 1.12.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each

LibreOffice slideshow aborts with stack smashing in cairo’s composite_boxes (CVE-2020-35492). References: – https://bugs.mageia.org/show_bug.cgi?id=28084

Use-after-free write when handling a malicious COOKIE-ECHO SCTP chunk. (CVE-2020-16044) See upstream releasenotes for other changes. References:

NVIDIA GPU Display Driver Linux contains a vulnerability in the kernel mode layer (nvidia.ko) IOCTL in which user-mode clients can access legacy privileged APIs, which may lead to denial of service, escalation of privileges, and information disclosure (CVE”2021”1052).

FILTER_VALIDATE_URL accepts URLs with invalid userinfo (CVE-2020-7071). stream_get_contents() fails with maxlength=-1 or default. See upstream releasenotes for other changes.

It was discovered that Awstats was vulnerable to path traversal attacks. A remote unauthenticated attacker could leverage that to perform arbitrary code execution. The previous fix did not fully address the issue when the default /etc/awstats/awstats.conf is not present (CVE-2020-29600).

Orca Security public cloud security report reveals how most large cloud breaches happen
Smashing Security podcast #210: DC rioters ID’d, Energydots, and ransomware gets you in a pickle
Is a remote workforce making your organisation less secure?
Hackers leak stolen COVID‑19 vaccine documents

The documents related to COVID-19 vaccine and medications were stolen from the EU’s medicines agency last month The post Hackers leak stolen COVID‑19 vaccine documents appeared first on WeLiveSecurity

TikTok Takes Teen Accounts Private
High-Severity Cisco Flaw Found in CMX Software For Retailers

Top gaming companies positioned to be next major cyberattack target After healthcare and higher education emerged as lucrative targets for cyberattacks in 2020, researchers have identified the video gaming industry as another key target. By scouring the dark web for stolen data belonging to any of the top 25 largest gaming firms, over a million […]

Microsoft patches anti-virus bug that allowed boobytrapped files to run malicious code when scanned

“It’s definitely dead,” says Tyler Moffitt, security analyst at Carbonite + Webroot, OpenText companies. “At least,” he amends, “for now.” Maze ransomware, which made our top 10 list for Nastiest Malware of 2020 (not to mention numerous headlines throughout the last year), was officially shut down in November of 2020. The ransomware group behind it […]

Critical WordPress-Plugin Bug Found in ‘Orbit Fox’ Allows Site Takeover
Hackers Leak Stolen Pfizer-BioNTech COVID-19 Vaccine Data
Sophisticated Hacks Against Android, Windows Reveal Zero-Day Trove
Operation Spalax: Targeted malware attacks in Colombia

ESET researchers uncover attacks targeting Colombian government institutions and private companies, especially from the energy and metallurgical industries The post Operation Spalax: Targeted malware attacks in Colombia appeared first on WeLiveSecurity

Home schooling – how to stay secure
Post-Backlash, WhatsApp Spells Out Privacy Policy Updates
CISOs Prep For COVID-19 Exposure Notification in the Workplace

Red Hat OpenShift Container Platform release 4.4.32 is now available with updates to packages and images that fix several bugs and add enhancements. This release also includes a security update for Red Hat OpenShift Container Platform 4.4.

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for .NET 5.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for rh-dotnet50-dotnet is now available for .NET on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

World’s largest dark-web marketplace shuttered after Euro cybercops cuff Aussie
Critical Microsoft Defender Bug Actively Exploited; Patch Tuesday Offers 83 Fixes
Microsoft emits 83 security fixes – and miscreants are already exploiting one of the vulns in Windows Defender
SolarWinds malware was sneaked out of the firm’s Orion build environment 6 months before anyone realised it was there – report
Data Breach at ‘Resident Evil’ Gaming Company Widens
Mimecast Certificate Hacked in Microsoft Email Supply-Chain Attack
BumbleBee Opens Exchange Servers in xHunt Spy Campaign

OpenShift Serverless 1.9.0 release and security update is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Adobe Fixes 7 Critical Flaws, Blocks Flash Player Content
5 common scams and how to avoid them

Fraudsters are quick to exploit current events for their own gain, but many schemes do the rounds regardless of what’s making the news. Here are 5 common scams you should look out for. The post 5 common scams and how to avoid them appeared first on WeLiveSecurity

Europol Reveals Dismantling of ‘Largest’ Underground Marketplace
Ethical Hackers Breach U.N., Access 100,000 Private Records

Several security vulnerabilities were found in ImageMagick, a suite of image manipulation programs. An attacker could cause denial of service and execution of arbitrary code when a crafted image file is processed.

Microsoft’s beefed-up take on Linux server security has hit general availability
Ubiquiti users told to change their passwords following security breach

An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For

An update is now available for Red Hat Ceph Storage 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability