Menu

Monthly Archives: May 2021

Indonesia’s national health insurance scheme leaks at least a million citizens’ records

security update

– Update to 20.11.7 – Closes security issue CVE-2021-31215

– Security fix for CVE-2021-28363. – Security fix for *pip incorrectly handled unicode separators in git references*.

LinuxSecurity is in Beta: A Customized User Profile is Just the Beginning! >
American insurance giant CNA reportedly pays $40m to ransomware crooks
DarkSide Getting Taken to ‘Hackers’ Court’ For Not Paying Affiliates
Building SIEM for Today’s Threat Landscape
WP Statistics Bug Allows Attackers to Lift Data from WordPress Sites
UK Computer Misuse Act convictions declined last year despite pandemic explosion in online criminal activity
Email Campaign Spreads StrRAT Fake-Ransomware RAT
Here’s how we got persistent shell access on a Boeing 747 – Pen Test Partners
Google’s ‘Ask me anything’ on Privacy Sandbox was more about questions than answers
In search of good cybersecurity
Doncaster insurance firm One Call hit by not-dead-at-all Darkside ransomware gang
Toyota rear-ended by twin cyber attacks that left ransomware-shaped dents

security update

Cyber insurance giant CNA paid out $40 million to its ransomware attackers
100M Android Users Hit By Rampant Cloud Leaks
The Gig Economy Creates Novel Data-Security Risks
Android 12 will give you more control over how much data you share with apps

An all-new privacy dashboard and better location, microphone and camera controls are all aimed at curbing apps’ data-slurping habits The post Android 12 will give you more control over how much data you share with apps appeared first on WeLiveSecurity

Four Android Bugs Being Exploited in the Wild
2021 Attacker Dwell Time Trends and Best Defenses
S3 Ep33: Eufy camera leak, Afterburner crisis, and AirTags (again) [Podcast]
Qlocker ransomware gang shuts shop after extorting owners of QNAP NAS drives
UK data regulator fines American Express up to 0.021p per email after opted-out folk spammed 4.1 million times
Apple Exec Calls Level of Mac Malware ‘Unacceptable’
Smashing Security podcast #228: Pipeline pickle, Blockchain bollocks, and Eufy SNAFU

security update

Can Nanotech Secure IoT Devices From the Inside-Out?
Microsoft, Google Clouds Hijacked for Gobs of Phishing
Scams target families of missing persons, FBI warns

Con artists use social media to find and target victims for various nefarious ends, including to extort relatives of missing persons The post Scams target families of missing persons, FBI warns appeared first on WeLiveSecurity

Keksec Cybergang Debuts Simps Botnet for Gaming DDoS
Fake Microsoft Authenticator extension discovered in Chrome Store
Regulator fines COVID-19 tracker for turning contact data into sales leads
Windows PoC Exploit Released for Wormable RCE
Bug Exposes Eufy Camera Private Feeds to Random Users
Miscreants started scanning for Exchange Hafnium vulns five minutes after Microsoft told world about zero-days
Uptime funk: Microsoft has lifted availability of Azure Key Vault to 99.99%
Colonial Pipeline attack: Hacking the physical world

The attack is a reminder of growing cyberthreats to critical infrastructure while also showing why providers of essential services are ripe targets for cybercriminals The post Colonial Pipeline attack: Hacking the physical world appeared first on WeLiveSecurity

Australian Federal Police hiring digital evidence retrieval specialists: Being a very good boy and paws required
The Microsoft Authenticator extension in the Chrome store wasn’t actually made by Microsoft. Oops, Google
New Zealand hospitals infected by ransomware, cancel some surgeries
Scammers Pose as Meal-Kit Services to Steal Customer Data

security update

security update

Stalkerware Apps Riddled with Security Bugs
Us? Pwn SolarWinds? With our reputation? Russian spy chief makes laughable denial of supply chain attack
Business-intelligence-company-turned-Bitcoin-addict MicroStrategy grabs another $10m crypto-coin fix
It’s Time to Prepare for a Rise in Insider Threats
The UK loves cybersecurity so much, it’s going to regulate managed service providers’ infosec practices in law
Unsuccessful Conti Ransomware Attack Still Packs Costly Punch
1Password unsheathes Rusty key, hopes to unlock Linux Desktop world
Microsoft, Adobe Exploits Top List of Crooks’ Wish List
Apple rejected 215,000 iOS apps due to privacy concerns last year
Latest phones are great at thwarting Wi-Fi tracking. Other devices, not so much – study
Magecart Goes Server-Side in Latest Tactics Changeup
Eufycam Wi-Fi security cameras streamed video feeds from other people’s homes
What a Year It’s Been: RSA 2021 Embraces ‘Resilience’
DarkSide Hits Toshiba; XSS Forum Bans Ransomware
Bizarro Banking Trojan Sports Sophisticated Backdoor
CISOs Struggle to Cope with Mounting Job Stress
Axa insurance offshoots pwned as Ireland reveals second ransomware hit
“Those aren’t my kids!” – Eufy camera owners report video mixups
Take action now – FluBot malware may be on its way

Why FluBot is a major threat for Android users, how to avoid falling victim, and how to get rid of the malware if your device has already been compromised The post Take action now – FluBot malware may be on its way appeared first on WeLiveSecurity

We’d love to report on the outcome of the CREST exam cheatsheet probe, but UK infosec body won’t publish it
Cyberinsurance giant AXA hit by ransomware attack after saying it would stop covering ransom payments
7 keys to selecting a low-code platform
Android stalkerware threatens victims further and exposes snoopers themselves

ESET research reveals that common Android stalkerware apps are riddled with vulnerabilities that further jeopardize victims and expose the privacy and security of the snoopers themselves The post Android stalkerware threatens victims further and exposes snoopers themselves appeared first on WeLiveSecurity

Mammoth grab of GP patient data in the UK set to benefit private-sector market access as rules remain unchanged
Apple sent my data to the FBI, says boss of controversial research paper trove Sci-Hub
Singapore bolsters Bluetooth contact-tracing as new COVID wave sends students and workers home again
China signals dissatisfaction with gig economy impact on ride-share drivers

**MariaDB 10.5.10** Release notes: https://mariadb.com/kb/en/mariadb-10510-release-notes/

Several vulnerabilities were discovered in jetty, a Java servlet engine and webserver. An attacker may reveal cryptographic credentials such as passwords to a local user, disclose installation paths, hijack user sessions or tamper with collocated webapps.

An update that solves two vulnerabilities and has one errata is now available.

Multiple security issues have been discovered in the PostgreSQL database system, which could result in the execution of arbitrary code or disclosure of memory content.

One security issue has been discovered in libgetdata CVE-2021-20204

Red Hat AMQ Streams 1.6.4 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 20 vulnerabilities is now available.

An update that contains security fixes can now be installed.

– New upstream version (88.0.1) – Fixes CVE-2021-29952 (https://www.mozilla.org/en-US/security/advisories/mfsa2021-20/) —- – Fixed WebRTC indicator (mozbz#1705048). —- – Enable Wayland backend on Plasma/KDE by default (rhbz#1922608)

Update to Chromium 90.0.4430.93. Fixes the following security issues: CVE-2021-21206 CVE-2021-21220 CVE-2021-21201 CVE-2021-21202 CVE-2021-21203 CVE-2021-21204 CVE-2021-21221 CVE-2021-21207 CVE-2021-21208 CVE-2021-21209 CVE-2021-21210 CVE-2021-21211 CVE-2021-21212 CVE-2021-21213 CVE-2021-21214 CVE-2021-21215 CVE-2021-21216 CVE-2021-21217 CVE-2021-21218 CVE-2021-21219

Exiv2 update fixing security issues.

An update that fixes four vulnerabilities is now available.

security update

security update

Verizon’s 2021 DBIR: Phishing and ransomware threats looming ever larger

The report provides unique insights into how the COVID-19 pandemic affected the data breach landscape The post Verizon’s 2021 DBIR: Phishing and ransomware threats looming ever larger appeared first on WeLiveSecurity

FIN7 Backdoor Masquerades as Ethical Hacking Tool
European police bust major online investment fraud ring

The operation was carried out against an organized group that used online trading platforms to swindle victims out of US$36 million The post European police bust major online investment fraud ring appeared first on WeLiveSecurity

Apple AirTag hacked again – free internet with no mobile data plan!
DarkSide Ransomware Suffers ‘Oh, Crap!’ Server Shutdowns
Free SANS Cyber Security Summits: Sign up now, learn online, keep your network safe
Gamers warned of downloading fake Afterburner overclocking tool to boost graphics card performance
‘Scheme Flooding’ Allows Websites to Track Users Across Browsers
Tor users, beware: ‘Scheme flooding’ technique may be used to deanonymize you
Verizon: Pandemic Ushers in ⅓ More Cyber-Misery
Ransomware’s New Swindle: Triple Extortion
How to Get into the Bug-Bounty Biz: The Good, Bad and Ugly
Hospitals cancel outpatient appointments as Irish health service struck by ransomware