Menu

Monthly Archives: April 2021

REvil’s Big Apple Ransomware Gambit Looks to Pay Off
3 cloud architecture mistakes we all make, but shouldn’t
Received an unexpected request to “confirm your Twitter account”?
If you have a QNAP NAS, stop what you’re doing right now and install latest updates. Do it before Qlocker gets you

security update

Mount Locker Ransomware Aggressively Changes Up Tactics
US aviation regulator warns of mid-air collision risk if Garmin TCAS boxes are not updated
Spotlight on Cybercriminal Supply Chains
Google rushes out fix for zero‑day vulnerability in Chrome

The update patches a total of seven security flaws in the desktop versions of the popular web browser The post Google rushes out fix for zero‑day vulnerability in Chrome appeared first on WeLiveSecurity

Linux team in public bust-up over fake “patches” to introduce bugs
S3 Ep29: Anti-tracking, rowhammer problems and IoT vulns [Podcast]
REvil ransomware – what you need to know
MI5 wants to shed its cocktail-guzzling posho image – so it’s opened an Instagram account
Telegram Platform Abused in ‘ToxicEye’ Malware Campaigns
It’s Easy to Become a Cyberattack Target, but a VPN Can Help
Smashing Security podcast #224: The Lazarus Heist, Facebook faux pas, and no-cost security
Apple, you’ve AirDrop’d the ball: Academics detail ways to leak contact info of nearby iThings for spear-phishing
Asian buyers set for security spending spree to catch up on shabby strategies
Signal app’s Moxie says it’s possible to sabotage Cellebrite’s phone-probing tools with booby-trapped file
4 Innovative Ways Cyberattackers Hunt for Security Bugs

security update

QR Codes Offer Easy Cyberattack Avenues as Usage Spikes
Do you expect me to talk? Yes, Mr Bond, I expect you to reply: 10k Brits targeted on LinkedIn by Chinese, Russian spies

Although cybercriminal activity throughout 2020 was as innovative as ever, some of the most noteworthy threat activity we saw came from the old familiar players, namely ransomware, business email compromise (BEC) and phishing. According to the 2021 Webroot BrightCloud® Threat Report, each of these threat types saw significant fluctuations as people all over the world […]

Apple supplier Quanta Computer confirms it’s fallen victim to ransomware attack
WhatsApp Pink: Watch out for this fake update

The malware sends automated replies to messages on WhatsApp and other major chat apps The post WhatsApp Pink: Watch out for this fake update appeared first on WeLiveSecurity

Pulse Secure Critical Zero-Day Security Bug Under Active Exploit
UK.gov wants mobile makers to declare death dates for their new devices from launch
Half of Q1’s malware traffic observed by Sophos was TLS encrypted, hiding inside legit requests to legit services
Swiss Army Knife for Information Security: What Is Comprehensive Protection?
When cryptography attacks – how TLS helps malware hide in plain sight
Novel Email-Based Campaign Targets Bloomberg Clients with RATs
REvil ransomware gang claims it stole top-secret tech designs – including Apple lappies – from Quanta Computer
Your cloud security is static – and you’re open to more risk than you realize
Japan accuses Chinese military of cyber-attacks on its space agency
China broke into govt, defense, finance networks via zero-day in Pulse Secure VPN gateways? No way
Mozilla Fixes Firefox Flaw That Allowed Spoofing of HTTPS Browser Padlock
Would be so cool if everyone normalized these pesky data leaks, says data-leaking Facebook in leaked memo
Google’s Project Zero to wait longer before disclosing bug details

The 30-day grace period is designed to speed up the rollout and adoption of patches The post Google’s Project Zero to wait longer before disclosing bug details appeared first on WeLiveSecurity

Firefox 88 patches bugs and kills off a sneaky JavaScript tracking trick
GEICO Alerts Customers Hackers Stole Driver License Data for Two Months
LinkedIn was vector for 10,000 hostile state recruiting efforts against Brits, warns MI5
Facebook suffers a data breach about how it’s hoping to stop the media talking about its last data breach
Cluley and Cisco: Preparing for cybersecurity threats in a permanently hybrid world
We need to talk about criminal adversaries who want you to eat undercooked onion rings
Bank of England ponders minting ‘Britcoin’ to sit alongside the Pound
Who knew Uncle Sam had strike teams for SolarWinds, Exchange flaws? Well, anyway, they are disbanded
WordPress core contributor proposes treating Google FLoC as a security vulnerability
NitroRansomware Asks for $9.99 Discord Gift Codes, Steals Access Tokens
Won’t somebody please think of the children!!! UK to mount fresh assault on end-to-end encryption in Facebook
Ransomware: A Deep Dive into 2021 Emerging Cyber-Risks
Codecov dev tool warns of stolen credentials from compromised script, undiscovered for two months
Six million male members may have been exposed after hack of gay dating service
What COVID-19 Taught Us: Prepping Cybersecurity for the Next Crisis
Sysadmin for FIN7 criminal cracking group gets 10 years in US prison for managing card slurping malware scam
Naked Security Live – To hack or not to hack?
Sysadmin of fake cybersecurity company sentenced to jail after billion-dollar crime spree
Serious Security: Rowhammer is back, but now it’s called SMASH
Brit authorities could legally do an FBI and scrub malware from compromised boxen without your knowledge
Pakistan cut off Facebook, Twitter, WhatsApp, and Telegram – for just four hours

security update

Two security issues have been discovered in python2.7: CVE-2019-16935

An update that fixes two vulnerabilities is now available.

Upgrade to Ruby 2.7.3.

Upgrade to Ruby 2.7.3.

Can Linux Be Used To Offer More Security In A WFH World (On And Offline)?>

security update

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

BazarLoader Malware Abuses Slack, BaseCamp Clouds
iOS Kids Game Morphs into Underground Crypto Casino
NSA: 5 Security Bugs Under Active Nation-State Cyberattack
Russian infosec firm Positive Technologies trying to stay positive after US sanctions
One in six people use pet’s name as password

Other common and easily hackable password choices include the names of relatives and sports teams, a UK study reveals The post One in six people use pet’s name as password appeared first on WeLiveSecurity

Microsoft received almost 25,000 requests for consumer data from law enforcement over the last six months
Mandiant Front Lines: How to Tackle Exchange Exploits
S3 Ep28.5: Hacking back – is attack an acceptable form of defence? [Podcast]
Google Project Zero Cuts Bug Disclosure Timeline to a 30-Day Grace Period
Watchdog thinks Google tricked Australians into giving up data, sues. Judge semi-agrees
Top Tips for Securing Your Linux System in 2021>
A Call to Action: Recent PHP Hack Highlights the Need for Better Security>
Linux Lite 5.4 Released With Bug Fixes And UI Enhancements>
Red Hat Launches RHEL Stream to Compete With the Rising Popularity of CentOS Stream>
Spring cleaning? Don’t forget about your digital footprint

Here are some quick and easy tips to help you clean up your cyber-clutter and keep your digital footprint tidy The post Spring cleaning? Don’t forget about your digital footprint appeared first on WeLiveSecurity

At Webroot, we could go on and on about user experience (UX) design. The study of the way we interact with the tools we use has spawned entire industries, university programs and professions. A Google Scholar search of the term returns over 300 thousand results. Feng Shui, Leonardo Davinci and Walt Disney are all described […]

Pen testing is the art of attempting to breach an organization’s network, computers and systems to identify possible means of bypassing their defenses. It’s an “art” because there is no one-size-fits-all method or process. Testers need a variety of skills, knowledge and tools to make the attempt. Most testers are hackers trying to use their […]

Mobile app security standard for IoT, VPNs proposed by group backed by Big Tech

security update

Biden Races to Shore Up Power Grid Against Hacks
FBI removes web shells from compromised Exchange servers

Authorities step in to thwart attacks leveraging the recently-disclosed Microsoft Exchange Server vulnerabilities The post FBI removes web shells from compromised Exchange servers appeared first on WeLiveSecurity

Gafgyt Botnet Lifts DDoS Tricks from Mirai
It was Russia wot did it: SolarWinds hack was done by Kremlin’s APT29 crew, say UK and US
University of Hertfordshire pulls the plug on, well, everything after cyber attack
White House launches plan to protect US critical infrastructure against cyber attacks
Attackers Target ProxyLogon Exploit to Install Cryptojacker
S3 Ep28: Pwn2Own hacks, dark web hitmen and COVID-19 privacy [Podcast]

Appled all the changes from the upstream 2.53.7.1 update. Fixed tab opening in background and tab choosing on a tab close. —- Fix updating and support of legacy javascript extensions. —- Update to 2.53.7 Enable support for module scripts. (To turn it off, toggle “dom.moduleScripts.enabled” in about:config). For sending mail, now “Thunderbird” is advertised in […]

Upstream release, security fix for CVE-2021-20307

This is the ninth maintenance release of Python 3.8. [Changelog](https://docs.py thon.org/release/3.8.9/whatsnew/changelog.html#python-3-8-9). Contains a security fix for CVE-2021-3426.

Upstream release, security fix for CVE-2021-20307