Menu

Monthly Archives: April 2021

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Is it still possible to run malware in a browser using JavaScript and Rowhammer? Yes, yes it is (slowly)
Smashing Security podcast #223: Booze, nudes, and insurance dudes
Nigerian email scammer sent down for 40 months in the US, ordered to pay back $2.7m to victims
Report: Aussie biz Azimuth cracked San Bernardino shooter’s iPhone, ending Apple-FBI privacy standoff

In the United States, there are approximately 350,000 companies contracting for the Department of Defense. Each of these companies have to meet varying degrees of compliance and are now subject to the Cybersecurity Maturity Model Certification (CMMC). Effectively, CMMC means that before a DoD contractor can execute on their contract, they have to receive an […]

Security Bug Allows Attackers to Brick Kubernetes Clusters
Ransomware Attack Creates Cheese Shortages in Netherlands
What the FLoC? Browser makers queue up to decry Google’s latest ad-targeting initiative as invasive tracking
School janitor says she was fired for not installing smartphone tracking app
FBI Clears ProxyLogon Web Shells from Hundreds of Orgs
A Post-Data Privacy World and Data-Rights Management
Chrome and Chromium updated after yet another exploit is found in browser’s V8 JavaScript engine
100,000 Google Sites Used to Install SolarMarket RAT
Microsoft Has Busy April Patch Tuesday with Zero-Days, Exchange Fixes
FBI hacks into hundreds of infected US servers (and disinfects them)
Is Linux Mint Turning Into Windows?>
New Linux, macOS malware hidden in fake Browserify NPM package>

An update for libldb is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Apache SpamAssassin 3.4.6 Release Fixes Two Potentially Aggravating Bugs>

Updated Red Hat JBoss Web Server 5.4.2 packages are now available for Red Hat Enterprise Linux 7, and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The 5.11.13 stable kernel update contains a number of important fixes across the tree.

The 5.11.13 stable kernel update contains a number of important fixes across the tree.

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Red Hat JBoss Web Server 5.4.2 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 and Windows. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Spy agency GCHQ told me Gmail’s more secure than Microsoft 365, insists British MP as facepalming security bods tell him to zip it
FBI deletes web shells from hundreds of compromised Microsoft Exchange servers before alerting admins
Google Sites blight: Over 100,000 web pages for business form searches overrun with backdoor RATs

“It is a nightmare. Do all you can to prevent ransomware.” – A survey respondent Many businesses are hesitant to talk about their experiences with ransomware. It can be uncomfortable to cop being hit. Whether it’s shame at not doing more to prevent it, the risk of additional bad publicity from discussing it or some other […]

How the NAME:WRECK Bugs Impact Consumers, Businesses
1Password targets developers with Secrets Automation, acquisition of SecretHub
COVID-Related Threats, PowerShell Attacks Lead Malware Surge
NSA helps out Microsoft with critical Exchange Server vulnerability disclosures in an April shower of patches

Ransomware attacks generate big headlines when the targets are government entities, universities and healthcare organizations. But there’s one increasingly frequent target of ransomware attacks that tends to slip under the radar. Small and midsize businesses (SMBs) have become bigger financial targets for hackers. As Webroot Senior Threat Researcher Kelvin Murray points out in a recent […]

Ransomware attack causes supermarket cheese shortage in the Netherlands
IoT bug report claims “at least 100M devices” may be impacted
Tax Phish Swims Past Google Workspace Email Security
A helpful reminder about just how much Facebook stalks you on the internet
Cracked copies of Microsoft Office and Adobe Photoshop steal your session cookies, browser history, crypto-coins
Adobe Patches Slew of Critical Security Bugs in Bridge, Photoshop
WhatsApp flaw lets anyone lock you out of your account

An attacker can lock you out of the app using just your phone number and without requiring any action on your part The post WhatsApp flaw lets anyone lock you out of your account appeared first on WeLiveSecurity

Chrome Zero-Day Exploit Posted on Twitter
Average convicted British computer criminal is young, male, not highly skilled, researcher finds
Want to turbo-charge your cybersec skills? It’s time to put yourself on the SPOT
1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free
Man Arrested for AWS Bomb Plot
Apple and Google block official UK COVID-19 app update
Zero Trust: The Mobile Dimension
Upstox warns of serious data breach, resets passwords
Mike Lynch-backed Darktrace to file for London IPO in aftermath of Deliveroo flop
Clubhouse in the spotlight after user records posted online

Reports of another trove of scraped user data add to the recent woes of popular social media platforms The post Clubhouse in the spotlight after user records posted online appeared first on WeLiveSecurity

Is Linux A More Secure Option Than Windows For Businesses? >
Naked Security Live – How to spot “government” scammers
Stuxnet sibling theory surges after Iran says nuke facility shut down by electrical fault
United States’ plan to beat China includes dominating tech standards groups – especially for 5G

security update

security update

security update

Texan’s alleged Amazon bombing effort fizzles: Militia man wanted to take out ‘about 70 per cent of the internet’
Pwn2Own 2021: Zoom, Teams, Exchange, Chrome and Edge “fully owned”
UK’s National Cyber Security Centre recommends password generation idea suggested by El Reg commenter
CyberBattleSim: Microsoft’s open-source Holodeck in which autonomous attackers, defenders battle it out
How do we stamp out the ransomware business model? Ban insurance payouts for one, says ex-GCHQ director
India uses controversial Aadhaar facial biometrics to identify COVID vaccination recipients
Combating security challenges with cloud-native AI-driven architecture
Italian charged with hiring “dark web hitman” to murder his ex-girlfriend
S3 Ep27: Census scammers, beg bounties and data breach fines [Podcast]
Belgian police seize 28 tons of cocaine after ‘cracking’ Sky ECC’s chat app encryption
What is unified policy as code, and why do you need it?
There’s a whole wide world of web application firewall options – so how do you choose the right one?
Indian defense chief admits China’s cyber-weapons would ‘disrupt large number of systems’ whenever Beijing presses the button

security update

With investors currently bullish on Bitcoin, is its high value is driving cybercriminals to pursue crypto-generating forms of cybercrime like ransomware and illicit miners? At time of writing, the value of one Bitcoin is north of $58 thousand. Famously volatile, a crash is widely expected to accompany the current bubble, perhaps before the end of […]

Another supply-chain attack? Android maker Gigaset injects malware into victims’ phones via poisoned update
Update on PHP source code compromise: User database leak suspected
Cybercrooks targeting UK organisations started 2020 strong only for attacks to wither away by Christmas
Atheists appeal to higher power for intercession over alleged sins against privacy
Too slow! Booking.com fined for not reporting data breach fast enough
SAP: It takes exploit devs about 72 hours to turn one of our security patches into a weapon against customers
Their ‘next job could be in cyber’: UK Cyber Security Council launches itself by pointing world+dog to domain it doesn’t own
What is operations-centric security?
‘Anomalous surge in DNS queries’ knocked Microsoft’s cloud off the web last week

security update

Facebook says dump of 533m accounts is old news. But my date of birth, name, etc haven’t changed in years, Zuck

security update

QNAP caught napping as disclosure delay expires, critical NAS bugs revealed

security update

Criminals send out fake “census form” reminder – don’t fall for it!
S3 Ep26: Apple 0-day, crypto vulnerabilities and PHP backdoor [Podcast]
Dutch watchdog fines Booking.com €475k after it kept customer data thefts quiet for more than 3 weeks
Wi-Fi slinger Ubiquiti hints at source code leak after claim of ‘catastrophic’ cloud intrusion emerges
Shifting left: Davie Street Enterprises implements DevSecOps

security update

security update