Menu

Monthly Archives: February 2021

Is there a widening gulf between you and your remote workers? Yes – and it’s security shaped
Nespresso smart cards hacked to provide infinite coffee after someone wasn’t too perky about security
Smashing Security podcast #213: No security smarts at Mensa, long-term identity theft, and GameStop’s share frenzy
Myanmar’s new military government bans Facebook
Emotet’s Takedown: Have We Seen the Last of the Malware?
More patches for SolarWinds Orion after researchers find flaw allowing low-priv users to execute code, among others
Second SolarWinds Attack Group Breaks into USDA Payroll — Report
New Malware Hijacks Kubernetes Clusters to Mine Monero

We’ve been doing our homework, and two things seem to be true about cybersecurity awareness training simultaneously: It can be very effective at protecting businesses from one of the most common security threats they face (the majority, according to the Ponemon Institute). Namely, phishing. MSPs, often the single most reliable source of cybersecurity for small […]

A video Q&A session
Identity theft spikes amid pandemic

The US Federal Trade Commission received 1.4 million reports of identity theft last year, double the number from 2019 The post Identity theft spikes amid pandemic appeared first on WeLiveSecurity

Dairy farm group faces $30 million ransom The Dairy Farm Group, one of the largest retailers in Asia, has suffered a ransomware attack by the REvil group, which has demanded a roughly $30 million ransom. The attack is still ongoing nearly nine days after being first identified. The attackers still have full control over the […]

Kobalos – A complex Linux threat to high performance computing infrastructure

ESET researchers publish a white paper about unique multiplatform malware they’ve named Kobalos The post Kobalos – A complex Linux threat to high performance computing infrastructure appeared first on WeLiveSecurity

Five Critical Android Bugs Patched, Part of Feb. Security Bulletin

CVE-2020-8020 An improper neutralization of input during web page generation vulnerability in open-build-service allows remote attackers to

Tiny Kobalos malware seen backdooring SSH tools, menacing supercomputers, an ISP, and more – ESET

An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

SolarWinds Orion Bug Allows Easy Remote-Code Execution and Takeover

Several vulnerabilities were discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. An unauthenticated remote attacker can take advantage of these flaws to cause a denial of service (slapd daemon crash, infinite loops) via

Location tracking report: X-Mode SDK use much more widespread than first thought
Rubbish software security patches responsible for a quarter of zero-days last year

An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Container Platform release 4.4.33 is now available with updates to packages and images that fix several bugs and add enhancements. This release also includes a security update for Red Hat OpenShift Container Platform 4.4.

security update

TrickBot Continues Resurgence with Port-Scanning Module

security update

Crypto Crook Hired Steven Seagal to Promote Scam, Now Faces Charges
Tiny Kobalos Malware Bedevils Supercomputers to Steal Logins
Magento Web Skimmers Piggyback in Ongoing Costway Website Compromise
Operation NightScout: Supply‑chain attack targets online gaming in Asia

ESET researchers uncover a supply-chain attack used in a cyberespionage operation targeting online‑gaming communities in Asia The post Operation NightScout: Supply‑chain attack targets online gaming in Asia appeared first on WeLiveSecurity

Agent Tesla Trojan ‘Kneecaps’ Microsoft’s Anti-Malware Interface

Today, the average enterprise uses over 2000 cloud applications and services, and we expect this number will continue to grow as more businesses realize the efficiency, flexibility and collaboration benefits these services bring. But the use of cloud-based applications also comes with a few caveats; for example, the apps themselves may pose potential security vulnerabilities, […]

Identity Theft Spikes Due to COVID-19 Relief

An update that contains security fixes can now be installed.

kernel: use-after-free in fs/block_dev.c (CVE-2020-15436) * kernel: Nfsd failure to clear umask after processing an open or create (CVE-2020-35513) Bug Fix(es): * double free issue in filelayout_alloc_commit_info * Regression: Plantronics Device SHS2355-11 PTT button does not work after update to 7.7 * Openstack network node reports unregister_netdevice: waiting for qr- 3cec0c92-9a to bec [More…]

An update that fixes one vulnerability is now available.

An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated ovirt-engine packages that fix several bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Updated ovirt-engine packages that fix several bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Spanish banished: Google Chrome to snub Camerfirma for lax cert management
In wake of Apple privacy controls, Facebook mulls just begging its iOS app users to let it track them over the web
Wind River Security Incident Affects SSNs, Passport Numbers
US court system ditches electronic filing, goes paper-only for sensitive documents following SolarWinds hack
Hezbollah-Linked Lebanese Cedar APT Infiltrates Hundreds of Servers
SolarWinds Hack Prompts Congress to Put NSA in Encryption Hot Seat

security update

Chrome 89 beta: Google presses on with ‘advanced hardware interactions’ that Mozilla, Apple see as harmful
Critical Libgcrypt Crypto Bug Opens Machines to Arbitrary Code
Alleged Gaming Software Supply-Chain Attack Installs Spyware
Ransomware attack takes out UK Research and Innovation’s Brussels networking office
Hacked road sign talks back after driver complains to council

This kernel-linus update is based on upstream 5.10.12 and fixes atleast the following security issue: An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local

An update that fixes three vulnerabilities is now available.

£30m in contracts awarded in Post Office’s £357m ATM overhaul

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

New Red Hat Single Sign-On 7.4.5 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

New Red Hat Single Sign-On 7.4.5 packages are now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

New Red Hat Single Sign-On 7.4.5 packages are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Countless emails wrongly blocked as spam after Cisco’s SpamCop failed to renew domain name at the weekend
Emotet takedown – Europol attacks “world’s most dangerous malware”