Menu

Monthly Archives: February 2021

security update

– New upstream version (86.0)

Update to 88.0.4324.182. Fixes CVE-2021-21149 CVE-2021-21150 CVE-2021-21151 CVE-2021-21152 CVE-2021-21153 CVE-2021-21154 CVE-2021-21155 CVE-2021-21156 CVE-2021-21157

Get started with CrowdSec v.1.0.X>

The container suse/sle15 was updated. The following patches have been included in this update:

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that solves 5 vulnerabilities and has one errata is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2021:0661

Upstream details at : https://access.redhat.com/errata/RHSA-2021:0656

Upstream details at : https://access.redhat.com/errata/RHSA-2021:0024

Upstream details at : https://access.redhat.com/errata/RHSA-2020:5408

Upstream details at : https://access.redhat.com/errata/RHSA-2020:5402

Beast Glatisant and Jelmer Vernooij reported that python-aiohttp, a async HTTP client/server framework, is prone to an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a different website.

security update

Amazon Dismisses Claims Alexa ‘Skills’ Can Bypass Security Vetting Process
Imperva pretty adamant that security analytics aggregator product Sonar is not ‘one dashboard to rule them all’
Stalkerware Volumes Remain Concerningly High, Despite Bans
Lazarus Targets Defense Companies with ThreatNeedle Malware
Yeezy Fans Face Sneaker-Bot Armies for Boost ‘Sun’ Release  
Malware Gangs Partner Up in Double-Punch Security Threat
Podcast: Ransomware Attacks Exploded in Q4 2020
Protecting Sensitive Cardholder Data in Today’s Hyper-Connected World

An update that fixes one vulnerability is now available.

Google looks at bypass in Chromium’s ASLR security defense, throws hands up, won’t patch garbage issue
Npower scraps app, and urges customers to change passwords, after data breach
Championing worthy causes: How ESET gives a helping hand

A snapshot of some of the ways ESET makes an impact supporting the well-being of people, communities and the environment The post Championing worthy causes: How ESET gives a helping hand appeared first on WeLiveSecurity

Half a million stolen French medical records, drowned in feeble excuses

Several issues have been found in python-pysaml2, a pure python implementation of SAML Version 2 Standard. CVE-2017-1000433

The container suse/sles12sp5 was updated. The following patches have been included in this update:

India’s demand to identify people on chat apps will ‘break end-to-end encryption’, say digital rights warriors

security update

security update

Update postgresql and libpq to the new upstream release.

Update postgresql and libpq to the new upstream release.

Linux: display frontend “be-alloc” mode is unsupported (comment only) [XSA-363, CVE-2021-26934] (#1929549) arm: The cache may not be cleaned for newly allocated scrubbed pages [XSA-364, CVE-2021-26933] (#1929547)

Cyberattacks Launch Against Vietnamese Human-Rights Activists
1Password has none, KeePass has none… So why are there seven embedded trackers in the LastPass Android app?
Facebook ramps up fight against child abuse content

Two new tools will warn users about the risks of searching for and sharing content that exploits children, including the potential legal consequences of doing so The post Facebook ramps up fight against child abuse content appeared first on WeLiveSecurity

Health Website Leaks 8 Million COVID-19 Test Results
Malicious Mozilla Firefox Extension Allows Gmail Takeover
Google’s Password Checkup tool rolling out to Android devices

People who use devices running Android 9 or newer will be alerted if their login credentials have been stolen The post Google’s Password Checkup tool rolling out to Android devices appeared first on WeLiveSecurity

Cisco Warns of Critical Auth-Bypass Security Flaw
Recorded Future’s free Cyber Daily newsletter brings trending threat insights straight to your inbox
UK’s National Cyber Security Centre sidles in to help firm behind hacked NurseryCam product secure itself
Ever felt that a few big tech companies are following you around the internet? That’s because … they are
Defense in depth with Red Hat Insights

An update that fixes one vulnerability is now available.

Alexa, swap out this code that Amazon approved for malware… Installed Skills can double-cross their users

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or information disclosure.

The package mumble before version 1.3.4-1 is vulnerable to arbitrary code execution.

The package postgresql before version 13.2-1 is vulnerable to information disclosure.

The package ansible-base before version 2.10.6-1 is vulnerable to information disclosure.

The package keycloak before version 12.0.3-1 is vulnerable to cross- site scripting.

Smashing Security podcast #216: Playboy, prison, and digital ploys – with Garry Kasparov
Tax Season Ushers in Quickbooks Data-Theft Spike
Mozilla Patches Bugs in Firefox, Now Blocks Cross-Site Cookie Tracking
Revealed: The military radar system swiped from aerospace biz, leaked online by Clop ransomware gang
VMWare Patches Critical RCE Flaw in vCenter Server
‘We’re finding bugs way faster than we can fix them’: Google sponsors 2 full-time devs to improve Linux security
Nvidia’s Anti-Cryptomining GPU Chip May Not Discourage Attacks
Microsoft Lures Populate Half of Credential-Swiping Phishing Emails

An update for ansible is now available for Ansible Engine 2 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.9 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Red Hat OpenShift Container Platform release 4.7.0 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Introducing Red Hat Vulnerability Scanner Certification
The history of open source risk reporting

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Think you know all about security pen-testing in the cloud? Here’s how to prove it
Mozilla Firefox keeps cookies kosher with quarantine scheme, 86s third-party cookies in new browser build
What’s CNAME of your game? This DNS-based tracking defies your browser privacy defenses
Indian Railways suffers unspecified security ‘breaches in various IT applications’
Microsoft president asks Congress to force private-sector orgs to publicly admit when they’ve been hacked
VMware warns of critical remote code execution flaw in vSphere HTML5 client
They break into your network but do nothing themselves: ‘Initial access brokers’ resell stolen creds for $7k a pop
Clop ransomware gang leaks online what looks like stolen Bombardier blueprints of GlobalEye radar snoop jet
Daycare Webcam Service Exposes 12,000 User Accounts  
IBM Squashes Critical Remote Code-Execution Flaw
Clubhouse chats streamed to third‑party website

The incident raises concerns about the privacy and security of conversations taking place on the platform The post Clubhouse chats streamed to third‑party website appeared first on WeLiveSecurity

Finnish IT Giant Hit with Ransomware Cyberattack
Keybase secure messaging fixes photo-leaking bug – patch now!
10K Microsoft Email Users Hit in FedEx Phishing Attack
Linux Mint users in hot water for being slow with security updates, running old versions
NurseryCam suffers data breach after security concerns raised
The perils of non-disclosure? China ‘cloned and used’ NSA zero-day exploit for years before it was made public

An update that solves two vulnerabilities and has two fixes is now available.

TDoS Attacks Take Aim at Emergency First-Responder Services
Chinese Hackers Hijacked NSA-Linked Hacking Tool: Report

security update

security update

security update

Assume Clubhouse Conversations Are Being Recorded, Researchers Warn
Brave browser’s Tor mode exposed users’ dark web activity

A bug in the ad blocking component of Brave’s Tor feature caused the browser to leak users’ DNS queries The post Brave browser’s Tor mode exposed users’ dark web activity appeared first on WeLiveSecurity

gdk-pixbuf2 2.42.2 release, fixing CVE-2021-20240 and CVE-2020-29385. This update also includes new gdk-pixbuf2-xlib package that was split out from gdk- pixbuf2 to its own source rpm. The gdk-pixbuf2-xlib and gdk-pixbuf2-xlib-devel binary package names are identical to what they were before the split.

gdk-pixbuf2 2.42.2 release, fixing CVE-2021-20240 and CVE-2020-29385. This update also includes new gdk-pixbuf2-xlib package that was split out from gdk- pixbuf2 to its own source rpm. The gdk-pixbuf2-xlib and gdk-pixbuf2-xlib-devel binary package names are identical to what they were before the split.

An update that fixes one vulnerability is now available.

Happy birthday, Python, you’re 30 years old this week: Easy to learn, and the right tool at the right time

The package python-django before version 3.1.7-1 is vulnerable to url request injection.