Menu

Monthly Archives: March 2021

U.S. DoD Weapons Programs Lack ‘Key’ Cybersecurity Measures
WordPress Injection Anchors Widespread Malware Campaign
Massive Supply-Chain Cyberattack Breaches Several Airlines

Security update for CVE-2021-26937

Update to latest upstream release 1.4.1 (#1931574)

Multiple security issues were discovered in activemq, a message broker built around Java Message Service. CVE-2017-15709

Critics Blast Google’s Aim to Replace Browser Cookie with ‘FLoC’

A vulnerability was discovered in mqtt-client wher unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.

Oh SITA: Airline IT provider confirms passenger data leaked after major ‘cyber-attack’
D-Link, IoT Devices Under Attack By Tor-Based Gafgyt Variant

This update fixes a buffer-overrun bug related to the MNG LOOP chunk (which gets noticed even in PNG files if the -s option is used). (RHBZ#1908559). It also fixes a buffer overrun for certain invalid MNG PPLT chunk contents.

Infinite loop in SML lexer may lead to DoS. When the SMLLexer gets fed the string “exception” it seems to loop indefinitely (rhbz#1922136). References: – https://bugs.mageia.org/show_bug.cgi?id=28319

While Reg readers know the difference between a true hacker and cyber-crook, for everyone else, hacking means illegal activity
How ESET’s work on SafetyNet® helps protect children online

For over a decade, ESET and the San Diego Police Foundation have been working together to help keep children safe from online threats The post How ESET’s work on SafetyNet® helps protect children online appeared first on WeLiveSecurity

Dutch government: Did we say 10 ‘high data protection risks’ in Google Workspace block adoption? Make that 8
Biden administration labels China top tech threat, promises proportionate responses to cyberattacks
Microsoft, FireEye Unmask More Malware Linked to SolarWinds Attackers
Cyberattackers Target Top Russian Cybercrime Forums
AdGuard names 6,000+ web trackers that use CNAME chicanery: Feel free to feed them into your browser’s filter
Microsoft rushes out fixes for four zero‑day flaws in Exchange Server

At least one vulnerability is being exploited by multiple cyberespionage groups to attacks targets mainly in the US, per ESET telemetry The post Microsoft rushes out fixes for four zero‑day flaws in Exchange Server appeared first on WeLiveSecurity

National Surveillance Camera Rollout Roils Privacy Activists
CISA Orders Federal Agencies to Patch Exchange Servers
COVID-19 Vaccine Spear-Phishing Attacks Jump 26 Percent
Russian cybercriminal forum hacked, user details exposed
Wall Street targeted by new Capital Call investment email scammers
Like a challenge in a high profile ‘face-of-IT’ role? Welcome to the Home Office

jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components (CVE-2021-3272). A flaw was found in jasper. An out of bounds read issue was found in jp2_decode

In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn’t correctly handling the case where a Type 3 char referred to another char in the same Type 3 font (CVE-2020-25725).

Yi’it Can Y±lmaz discovered that GNOME Autoar could extract files outside of the intended directory. If a user were tricked into extracting a specially crafted archive, a remote attacker could create files in arbitrary locations, possibly leading to code execution (CVE-2020-36241).

A buffer overflow vulnerability was discovered in the SPNEGO implementation affecting the GSSAPI security policy negotiation in BIND, which could result in denial of service (daemon crash), or potentially the execution of arbitrary code (CVE-2020-8625).

Felix Weinmann reported a flaw in the handling of combining characters in screen, which can result in denial of service, or potentially the execution of arbitrary code via a specially crafted UTF-8 character sequence (CVE-2021-26937).

Paul Kehrer discovered that OpenSSL incorrectly handled certain input lengths in EVP functions. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service (CVE-2021-23840). Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer

Using TikTok? Check out these six security tips
Cybersecurity risks and challenges facing the financial industry

A primer on various threats looming over financial companies and the steps that the organizations can take to counter them The post Cybersecurity risks and challenges facing the financial industry appeared first on WeLiveSecurity

Would you let users vouch for unknown software’s safety with an upvote? Google does
Another Chrome zero-day exploit – so get that update done!
Smashing Security podcast #217: Would you cuddle this revolting robot? – with Robert Llewellyn
How (NOT?!) to jailbreak your iPhone
Unpatched Bug in WiFi Mouse App Opens PCs to Attack
Google Patches Actively-Exploited Flaw in Chrome Browser
Malaysia Air Downplays Frequent-Flyer Program Data Breach
Home-Office Photos: A Ripe Cyberattack Vector
RTM Cybergang Adds New Quoter Ransomware to Crime Spree
Malicious Code Bombs Target Amazon, Lyft, Slack, Zillow
Qualys hit with ransomware: Customer invoices leaked on extortionists’ Tor blog
Proof of concept code published for latest Saltstack CVE: Don’t be an update laggard
Cybersecurity threats aren’t getting any smaller. Could big data help?
Microsoft Exchange Zero-Day Attackers Spy on U.S. Targets
Patch your Exchange email server now! flaws exploited by hackers to download corporate email
Receive the latest trending threat insights delivered to your inbox with Recorded Future’s free Cyber Daily newsletter. Sign up now!
I see you: your home-working photos reveal more than you think!
It’s not easy being green: EV HTTPS cert seller Sectigo questions Chrome’s logic in burying EV HTTPS cert info
Hacking is not a crime – and the media should stop using ‘hacker’ as a pejorative
Not all cybercriminals are sophisticated

Some perpetrators of online crime and fraud don’t use advanced methods to profit at the expense of unsuspecting victims and to avoid getting caught The post Not all cybercriminals are sophisticated appeared first on WeLiveSecurity

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

TPG buys Thycotic, immediately merges it with Centrify to create ~$230m access management monster

Red Hat OpenShift Container Platform release 3.11.394 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Microsoft promises end-to-end encrypted Teams calls for some, invites you to go passwordless with Azure AD
Eugene Kaspersky says cyber-crooks coined it during COVID and will take a break to spend their loot

An update for the container-tools:2.0 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Microsoft fixes four zero-day flaws in Exchange Server exploited by China’s ‘Hafnium’ spies to steal victims’ data
Post-Cyberattack, Universal Health Services Faces $67M in Losses

security update

Jailbreak Tool Works on iPhones Up to iOS 14.3
Popular password manager in the spotlight over web trackers

While the trackers in LastPass’ Android app don’t collect any personal data, the news may not sit well with some privacy-minded users The post Popular password manager in the spotlight over web trackers appeared first on WeLiveSecurity

Compromised Website Images Camouflage ObliqueRAT Malware

It was discovered that SPIP, a website engine for publishing, would allow a malicious user to perform cross-site scripting attacks, access sensitive information, or execute arbitrary code.

Ryuk Ransomware: Now with Worming Self-Propagation
Search crimes – how the Gootkit gang poisons Google searches
Crypto firm Tether says it won’t pay $24 million ransom after being threatened with document leak

Upstream details at : https://access.redhat.com/errata/RHSA-2021:0671

Red Hat Risk Report: A tour of 2020’s branded security flaws

Security fix for CVE-2021-27803

Update to CVE release 3002.5-1 for Python 3 Fixed on this release: CVE-2021-25283 Fixed in 3002.3: CVE-2020-28243 CVE-2020-28972 CVE-2020-35662 CVE-2021-3148 CVE-2021-3144 CVE-2021-25281 CVE-2021-25282 CVE-2021-25283 CVE-2021-25284 CVE-2021-25284 CVE-2021-3197

Update to CVE release 3001.6-1 for Python 3 Fixed in 3001.5: CVE-2020-28243 CVE-2020-28972 CVE-2020-35662 CVE-2021-3148 CVE-2021-3144 CVE-2021-25281 CVE-2021-25282 CVE-2021-25283 CVE-2021-25284 CVE-2021-3197

* Bring back the WebKitPluginProcess that was removed by mistake. (It will disappear again soon.) * Fix RunLoop objects leaked in worker threads. * Use Internet Explorer quirk for Google Docs. (Yes, even this new quirk is broken already.) * Security fixes: CVE-2020-13558

Gootkit malware crew using SEO to get pwned websites in front of unwitting marks
Perl.com theft blamed on social engineering attack: Registrar ‘convinced’ to alter DNS records by miscreants

security update

Mobile Adware Booms, Online Banks Become Prime Target for Attacks
Malware Loader Abuses Google SEO to Expand Payload Delivery
Passwords, Private Posts Exposed in Hack of Gab Social Network
Chinese businessman plotted with GE insider to steal transistor secrets, say Feds
Malware attack that crippled Mumbai’s power system came from China, claims infosec intel outfit Recorded Future
Firewall Vendor Patches Critical Auth Bypass Flaw
“Mentally ill demon hackers” blamed for massive Gab data leak

Update to security and bugfix release 2.9.18.

bind: Buffer overflow in the SPNEGO implementation affecting GSSAPI security policy negotiation (CVE-2020-8625) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 bind-debuginfo-9.11.4-26.P2.el7_9.4.i686.rpm bind-debuginfo-9.11.4-26.P2.el7_9.4.x86_64.rpm bind-export-libs-9 [More…]

Update to security and bugfix release 2.9.18.

Gizmodo gives poor password advice

An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for bind is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for podman is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Cyber-attackers work 24/7 … but what about your security team?
Mobile spyware fan Saudi Crown Prince accused by US intel of Khashoggi death