Menu

Monthly Archives: February 2021

Unpatched Android App with 1 Billion Downloads Threatens Spying, Malware
Member Profile: My Expedition Through nmap Lab How to get through the NMAP room in Tryhackme >
Linux 5.11 is out with AMD and Intel improvements (and Linus Torvalds is happy)>
Microsoft Azure and Canonical Ubuntu Linux have a user privacy problem>
Get trending threat insights delivered to your inbox with Recorded Future’s free Cyber Daily newsletter
Beware of COVID‑19 vaccine scams and misinformation

The vaccination push provides a vital shot in the arm for the world’s battle against the pandemic, but it’s also a topic ripe for exploitation by fraudsters and purveyors of misinformation The post Beware of COVID‑19 vaccine scams and misinformation appeared first on WeLiveSecurity

An update that contains security fixes can now be installed.

An update for the nodejs:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for the nodejs:10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for nss is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

France’s cyber-agency says Centreon IT management software sabotaged by Russian Sandworm
How one man silently infiltrated dozens of high-tech networks
Cybercrooks Rake in $304M in Romance Scams
Could an ex-employee be planting ransomware on your firm’s network?
NurseryCam has serious security issues, claims researcher
UK watchdog fines two firms £270k for cold-calling 531,000 people who had opted out
Egregor ransomware criminals allegedly busted in Ukraine

An update that fixes one vulnerability is now available.

Let’s Encrypt completes huge upgrade, can now rip and replace 200 million security certs in ‘worst case scenario’

An update that fixes one vulnerability is now available.

Busybox, utility programs for small and embedded systems, was affected by several security vulnerabilities. The Common Vulnerabilities and Exposures project identifies the following issues.

Joakim Hindersson discovered that Open vSwitch, a software-based Ethernet virtual switch, allowed a malicious user to cause a denial-of-service by sending a specially crafted packet.

Microsoft says it found 1,000-plus developers’ fingerprints on the SolarWinds attack

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The 5.10.15 stable kernel update contains a number of important fixes across the tree. —- The 5.10.14 stable kernel updates contain a number of important fixes across the tree.

The 5.10.15 stable kernel update contains a number of important fixes across the tree.

xterm through Patch #365 allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Thomas Akesson discovered a remotely triggerable vulnerability in the mod_authz_svn module in Subversion, a version control system. When using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option an unauthenticated remote client can take advantage of this flaw

security update

Supermicro spy chips, the sequel: It really, really happened, and with bad BIOS and more, insists Bloomberg
mHealth Apps Expose Millions to Cyberattacks

Update to Zypper 1.14.42 and libzypp 17.25.6 to remediate CVE-2017-9271

Update to Zypper 1.14.42 and libzypp 17.25.6 to remediate CVE-2017-9271

CVE-2021-3281: Potential directory-traversal via archive.extract()

Yandex Data Breach Exposes 4K+ Email Accounts
‘Annoyingly Believable’ Tax Scam Targets Mobile Users
Dev creeped out after he fired up Ubuntu VM on Azure, was immediately approached by Canonical sales rep
Singtel Suffers Zero-Day Cyberattack, Damage Unknown
Fallen victim to online fraud? Here’s what to do…
Protecting the water supply – hacker edition

What can municipalities do to better protect their water supply systems? The post Protecting the water supply – hacker edition appeared first on WeLiveSecurity

Florida Water Plant Hack: Leaked Credentials Found in Breach Database
Footfallcam kerfuffle: Firm apologises, promises to fix product after viral Twitter thread, infoseccer backlash

Several security vulnerabilities have been corrected in unbound, a validating, recursive, caching DNS resolver. Support for the unbound DNS server has been resumed, the sources can be found in the unbound1.9 source package.

After hackers blackmailed their clients, Finnish therapy firm declares bankruptcy
“Microosft”. Patch Tuesday goof points users to typo-bait website

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

The package helm before version 3.5.2-1 is vulnerable to insufficient validation.

The package privoxy before version 3.0.31-1 is vulnerable to denial of service.

The package python2-jinja before version 2.11.3-1 is vulnerable to denial of service.

SMS tax scam unmasked: Bogus but believable – don’t fall for it!
Apple iOS 14.5 will hide Safari users’ IP addresses from Google’s Safe Browsing

In today’s rapidly evolving cybersecurity landscape, the battle for privacy and security is relentless. Cybercriminals are masters at using technology and psychology to exploit basic human trust and compromise businesses of all sizes. What’s more, they often hide in plain sight, using both covert and overt tactics to cause disruption, steal money and data, and […]

Pre-Valentine’s Day Malware Attack Mimics Flower, Lingerie Stores
Phishing awareness gone wrong: Facebook tries to seize websites set up for staff security training

While we can all rejoice that 2020 is over, cybersecurity experts agree we haven’t seen the last of the pandemic-related rise in cyberattacks. Throughout the last year, we’ve seen huge spikes in phishing, malicious domains, malware and more, and we don’t expect that to slow down. As employees around the world continue to work from […]

Celeb SIM-Swap Crime Ring Stole $100M from U.S. Victims
How Email Attacks are Evolving in 2021
Various Malware Lurks in Discord App to Target Gamers
Creeped-out dev spins up an Ubuntu VM on Azure only to be immediately approached by a Canonical sales rep
Eight men arrested following celebrity SIM-swapping attacks
Military, Nuclear Entities Under Target By Novel Android Malware
Smashing Security podcast #214: Lockdown love scams, SolarWinds, and a data deletion bungle

An update for openvswitch2.13 is now available for Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Open Source Vulnerabilities database: Nice idea but too many Google-shaped hoops to jump through at present

Red Hat JBoss Web Server 5.4.1 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 and Windows. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Updated Red Hat JBoss Web Server 5.4.1 packages are now available for Red Hat Enterprise Linux 7, and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Web Server 3.1, for RHEL 7 and Windows. Red Hat Product Security has rated this release as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Web Server 3.1 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for rh-nodejs12-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

This scumbag stole and traded victims’ nude pics and vids after guessing their passwords, security answers
No joy for Julian Assange as Uncle Sam confirms it will keep pushing for WikiLeaker’s extradition to America
SAP Commerce Critical Security Bug Allows RCE
Hacker Sets Alleged Auction for Witcher 3 Source Code

security update

security update

security update

Hybrid, Older Users Most-Targeted by Gmail Attackers
Microsoft patches actively exploited Windows kernel flaw

This month’s relatively humble bundle of security updates fixes 56 vulnerabilities, including a zero-day bug and 11 flaws rated as critical The post Microsoft patches actively exploited Windows kernel flaw appeared first on WeLiveSecurity

8 Brits arrested after probe into SIM-swapping scam targeting US celebs
Intel Squashes High-Severity Graphics Driver Flaws
The time for Insider Risk Management is now: Code42 2021 Data Exposure Report Reveals a Perfect Storm
Supply-Chain Hack Breaches 35 Companies, Including PayPal, Microsoft, Apple
Patch now to stop hackers blindly crashing your Windows computers

An update for .NET 5.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for .NET Core 2.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

All grown up: Raspberry Pis running Ubuntu added to IoT patching service KernelCare

An update for rh-dotnet50-dotnet is now available for .NET on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-dotnet31-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-dotnet21-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Understanding Multipath TCP: High availability for endpoints and the networking highway of the future
No phish for the likes of you, thank you very much! Google finds email villains are picky about demographics, country
North Korean attacks on crypto exchanges reportedly netted $316m in two years

security update