Menu

Monthly Archives: April 2021

security update

security update

PortDoor Espionage Malware Takes Aim at Russian Defense Sector
WeSteal: A Cryptocurrency-Stealing Tool That Does Just That
A Tale of Two Hacks: From SolarWinds to Microsoft Exchange
FBI teams up with ‘Have I Been Pwned’ to alert Emotet victims

The data breach notification site now allows you to check if your login credentials may have been compromised by Emotet The post FBI teams up with ‘Have I Been Pwned’ to alert Emotet victims appeared first on WeLiveSecurity

Bill to protect UK against harmful foreign investment becomes law
PHP community sidesteps its third supply chain attack in three years
Happy Friday? Darktrace gets 40 per cent boost on London IPO debut
Microsoft Warns 25 Critical Vulnerabilities in IoT, Industrial Devices
DigitalOcean admits data breach exposed customers’ billing details
Australia proposes teaching cyber-security to five-year-old kids
Stealthy Linux backdoor malware spotted after three years of minding your business
Babuk Ransomware Gang Mulls Retirement
BadAlloc: Microsoft looked at memory allocation code in tons of devices and found this one common security flaw

security update

F5 Big-IP Vulnerable to Security-Bypass Bug
Experian API Leaks Most Americans’ Credit Scores
Multi-Gov Task Force Plans to Take Down the Ransomware Economy
COVID-19 Results for 25% of Wyoming Accidentally Posted Online
Anti-Vaxxer Hijacks QR Codes at COVID-19 Check-In Sites
SaaS Attacks: Lessons from Real-Life Misconfiguration Exploits
Vivaldi update unleashes the ‘Cookie Crumbler’ to simply block any services asking for consent (sites may break)
S3 Ep30: AirDrop worries, Linux pests and ransomware truths [Podcast]
DoppelPaymer Gang Leaks Files from Illinois AG After Ransom Negotiations Break Down
Billions in data protection lawsuits rides on Google’s last-ditch UK Supreme Court defence for Safari Workaround sueball
Smashing Security podcast #225: Master of your domain, gripe sites, and John Deere Farmergeddon
48 ways you can avoid file-scrambling, data-stealing miscreants – or so says the Ransomware Task Force
Prime targets: Governments shouldn’t go it alone on cybersecurity

A year into the pandemic, ESET reveals new research into activities of the LuckyMouse APT group and considers how governments can rise to the cybersecurity challenges of the accelerated shift to digital The post Prime targets: Governments shouldn’t go it alone on cybersecurity appeared first on WeLiveSecurity

When you’re building a cybersecurity pro, you need to get the foundations right
Digital Ocean springs a leak: Miscreant exploits hole to peep on unlucky customers’ billing details for two weeks

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp3 was updated. The following patches have been included in this update:

New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Update to Jetty 9.4.40 (fixes multiple CVEs)

security update

Microsoft Office SharePoint Targeted With High-Risk Phish, Ransomware Attacks
Etsy-owned musical instrument marketplace Reverb suffers data breach
Google Chrome V8 Bug Allows Remote Code-Execution
Apple patches severe macOS security flaw

Mac users are being urged to update to macOS Big Sur 11.3 as at least one threat group is exploiting the zero-day bug to sneak past the operating system’s built-in security mechanisms The post Apple patches severe macOS security flaw appeared first on WeLiveSecurity

Ransomware crooks who broke into Merseyrail used director’s email address to brag about it – report
Gamers update! Nvidia patches GPU driver kernel escalation bugs
Brit MPs and campaigners come together to oppose COVID status certificates as ‘divisive and discriminatory’
Chase Bank Phish Swims Past Exchange Email Protections
Was the email account of Merseyrail’s MD hacked to spread word of ransomware attack?
Cybersecurity World Mourns Over Security Researcher Dan Kaminsky’s Passing>
Protect Your WordPress Sites with CrowdSec>
Minified Linux Offerings Boost Containers and Edge Processing>
Arrest after man replaces official COVID-19 check-in signs with anti-vaxxer QR code
Update your Macs! Malware attacks can exploit critical flaws in Apple’s built-in defences
Nintendo Sues Video-Game Pirates
Linux Kernel Bug Opens Door to Wider Cyberattacks
Here’s what Russia’s SVR spy agency does when it breaks into your network, says US CISA infosec agency
Smishing: Why Text-Based Phishing Should Be on Every CISO’s Radar
Babuk Ransomware Gang Targets Washington D.C. Police
Ransomware: don’t expect a full recovery, however much you pay
Washington DC police force confirms data breach after ransomware upstart Babuk posts trophies to Tor blog
Shells makes using Linux in the cloud incredibly easy>
Apple Patches Zero-Day MacOS Bug That Can Bypass Anti-Malware Defenses
Talking malware party tricks and cybersecurity trends

Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

An update for openldap is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for nss is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Patched Exchange to head off Hafnium? You might only be halfway to safety
Flubot Spyware Spreading Through Android Devices
HashiCorp reveals exposure of private code-signing key after Codecov compromise
Nvidia Warns: Severe Security Bugs in GPU Driver, vGPU Software
Security vendor Proofpoint snapped up by private equity for $12.3bn but still in search of profit
Secure, orchestrate, and manage your company’s infrastructure secrets with 1Password Secrets Automation
Naked Security Live – Just how (un)safe is AirDrop?
Scam victims find same fraudulent ads lurking on Facebook and Google even after flagging them up
4 common ways scammers use celebrity names to lure victims

All that glitters is not gold – look out for fake celebrity endorsements and other con jobs that aren’t going out of fashion any time soon The post 4 common ways scammers use celebrity names to lure victims appeared first on WeLiveSecurity

Ethics isn’t a county east of London, but it’s the only way to look at security
GCHQ boss warns China can rewrite ‘the global operating system’ in its own authoritarian image
Cloud security threats are growing – crucially, is your skills toolkit keeping pace?
India orders takedowns of social media posts it claims harm fight against raging COVID-19 outbreak
Emotet malware self-destructs after cops deliver time-bomb DLL to infected Windows PCs
Homebrew fixes Cask repo GitHub Actions bug that would have let anyone sneak malicious code onto machines
Volunteer-run pirate Manga website attacked, loses hashed passwords, has ‘nobody’ to fix the mess

security update

security update

security update

security update

security update

Computer security world in mourning over death of Dan Kaminsky, aged 42

security update

security update

security update

security update

Oscar-Bait, Literally: Hackers Abuse Nominated Films for Phishing, Malware
Prometei Botnet Could Fire Up APT-Style Attacks
5 Fundamental But Effective IoT Device Security Controls
Apple AirDrop has “significant privacy leak”, say German researchers
AirDrop flaws could leak phone numbers, email addresses

You can only stay safe by disabling AirDrop discovery in the system settings of your Apple device, a study says The post AirDrop flaws could leak phone numbers, email addresses appeared first on WeLiveSecurity

Apple AirDrop flaws could let hackers grab users’ phone numbers and email addresses