Menu

Monthly Archives: May 2021

Want to be a cybersecurity manager? Colonial Pipeline is recruiting
NHS-backed org reacted to GitHub leak disclosure with legal threats and police call, complains IT pro
Don’t migrate your problems to the cloud
Report: Colonial Pipeline paid ransomware attackers $5 million, but still had to rely on its own backups
Scumbag ransomware attackers hit Irish Health Service
Cloudflare launches campaign to ‘end the madness’ of CAPTCHAs
Gamers beware! Crooks take advantage of MSI download outage…
Colonial Pipeline Shells Out $5M in Extortion Payout, Report
Ransomware Going for $4K on the Cyber-Underground

The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available for portable Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available for Windows. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The Red Hat Build of OpenJDK 11 (java-11-openjdk) is now available for portable Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The Red Hat Build of OpenJDK 11 (java-11-openjdk) is now available for Windows. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Update to feature release 3003-1 for Python 3, Security fix for CVE-2021-31607

Several vulnerabilities have been discovered in the chromium web browser. CVE-2021-21201

Ransomware victim Colonial Pipeline paid $5m to get oil pumping again, restored from backups anyway – report
1 million risky apps rejected or removed from Apple’s App Store in 2020

Apple also claims to have foiled US$1.5 billion worth of potentially fraudulent transactions The post 1 million risky apps rejected or removed from Apple’s App Store in 2020 appeared first on WeLiveSecurity

ESET Research goes to RSA Conference 2021 with two presentations

We will explore two threats – Android stalkerware and XP exploits The post ESET Research goes to RSA Conference 2021 with two presentations appeared first on WeLiveSecurity

Beyond MFA: Rethinking the Authentication Key
S3 Ep32: AirTag jailbreak, Dell vulns, and a never-ending scam [Podcast]
Fresh Loader Targets Aviation Victims with Spy RATs
Muddy waters. Ofwat reveals it has received 20,000 spam and phishing emails so far this year
Apple’s ‘Find My’ Network Exploited via Bluetooth
Five Critical Password Security Rules Your Employees Are Ignoring
Colonial Pipeline was looking to hire cybersecurity manager before ransomware attack shut down operations
Smashing Security podcast #227: Phishing foul-up, Twitter tip jars, and Facebook’s Apple fury
Pipeline Update: Biden Executive Order, DarkSide Detailed and Gas Bags
Oops, says Manchester City Council after thousands of number plates exposed in parking ticket spreadsheet
When it comes to cybersecurity, there’s always time for summer school or winter training

“What Bitcoin was to 2011, NFTs are to 2021.” That’s a claim from the highly respected “techno-geek” bible Ars Technica in it’s wonderful explainer on NFTs, or non-fungible tokens. Since cryptocurrencies were, are and will continue to be impactful technologies, surely NFTs are a topic worth exploring. They exploded into public consciousness this year as […]

Although they didn’t always call themselves a managed service provider, that’s exactly what T-Consulting has been since its inception. According to Vera Tucci, founder and CEO of the Italy-based MSP, it was her mission to give her clients more than a basic hardware/software bundle with a few hours of IT consultation. She knew her clients […]

Aging infrastructure in the United States is not confined to crumbling roads and bridges. Recent events have shown that connected devices in our pipelines, water treatment facilities and power grids are also vulnerable to exploitation. As of now, we still don’t know much about the ransomware attack against the operators of the Colonial Pipeline. Details […]

Manchester City win the Carabao Cup Final, many illegal streamers lose The COVID pandemic has led to a surge in content consumption as people stayed home and turned to Netflix, Youtube and other streaming services for entertainment. Not everyone agrees with paying for the latest episode or album, however, and this rise has ran parallel […]

Researchers Flag e-Voting Security Flaws
Apple’s Find My network can be abused to leak secrets to the outside world via passing devices
Telegram Fraudsters Ramp Up Forged COVID-19 Vaccine Card Sales
Gig Workers Being Paid $500 for Payroll Passwords
Happy to pay out to ransomware masterminds? Yup, we thought so
‘FragAttacks’: Wi-Fi Bugs Affect Millions of Devices
Tempted by cryptocoins? Fake trading apps get personal…
TeaBot Trojan Targets Banks via Hijacked Android Handsets
Britain to spend £22m influencing Indo-Pacific nations’ cybersecurity policies against ‘authoritarian regimes’
ESET Research goes to RSA Conference 2021 with record number of presentations

We will explore Android stalkerware, air-gapped networks and XP exploits The post ESET Research goes to RSA Conference 2021 with record number of presentations appeared first on WeLiveSecurity

Blessed are the cryptographers, labelling them criminal enablers is just foolish
Beijing twirls ban-hammer at 84 more apps it says need to stop slurping excess data
South Korea orders urgent review of energy infrastructure cybersecurity
Tech industry quietly patches FragAttacks Wi-Fi flaws that leak data, weaken security

security update

Wormable Windows Bug Opens Door to DoS, RCE
SolarWinds CEO describes overhauled Orion build system after that ‘very small, unique’ security breach
GitHub Prepares to Move Beyond Passwords
Microsoft emits more fixes for Exchange Server plus patches for remote-code exec holes in HTTP stack, Visual Studio
Hackers Leverage Adobe Zero-Day Bug Impacting Acrobat Reader
Fake Chrome App Anchors Rapidly Worming ‘Smish’ Cyberattack
Shifting Threats in a Changed World: Edge, IoT and Vaccine Fraud
UK’s Computer Misuse Act to be reviewed, says Home Secretary as she condemns ransomware payoffs
200K Veterans’ Medical Records May Have Been Stolen by Ransomware Gang
NHS App gets go-ahead for vaccine passport use despite protest from privacy groups
DarkSide Wanted Money, Not Disruption from Colonial Pipeline Attack
App Tracking: Apps plead for users to press allow, but 85% of Apple iOS consumers are not opting in
The DarkSide ransomware gang must be shitting itself right now
Apple AirTag jailbroken already – hacked in rickroll attack
WhatsApp will limit features for users who don’t accept new data‑sharing rules

Your account won’t be deleted, but here’s what you may want to be aware of if not even repeated reminders do the trick The post WhatsApp will limit features for users who don’t accept new data‑sharing rules appeared first on WeLiveSecurity

Compsci boffin publishes proof-of-concept code for 54-year-old zero-day in Universal Turing Machine

An update is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Train operator phlunks phishing test by teasing employees with non-existent COVID bonus
Tencent research team scores free powerups for electric cars with Raspberry Pi-powered X-in-the-middle attack
Indian government says 5G doesn’t cause COVID-19. Also points out India has no 5G networks
Trend Micro hosted email service is down, inboxes still stuck in cloudy limbo

Update to latest upstream version.

This update fixes several issues in djvulibre. These are mostly related to opening of corrupted files.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

Never say never! Warren Buffett caught up in integer overflow error…
Kubecon 2021: A largely dry and corporate affair where the best bits involved a spot of Kubernetes-hacking roleplay

Openshift Logging Bug Fix Release (5.0.3) This release includes a security update. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for postgresql is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

It was discovered that there was potential directory-traversal vulnerability in Django, a popular Python-based web development framework.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Colonial Pipeline’s Ransomware Attack Sparks Emergency Declaration
Lemon Duck Cryptojacking Botnet Changes Up Tactics
City of Tulsa struck by ransomware attack
Uncle Sam wants ‘ethical hackers’ to crack its planetary defenses, but don’t expect a pay-day from this bug bounty
Major US oil pipeline shut down after ransomware attack
Namecheap hosted 25%+ of fake UK govt phishing sites last year – NCSC report
US declares emergency after ransomware shuts oil pipeline that pumps 100 million gallons a day
Major U.S. Pipeline Crippled in Ransomware Attack
iPhone Hack Allegedly Used to Spy on China’s Uyghurs
Russian cyber-spies changed tactics after the UK and US outed their techniques – so here’s a list of those changes

Several vulnerabilities were discovered in mediawiki, a wiki website engine for collaborative work. CVE-2021-20270

The Qualys Research Labs reported several vulnerabilities in Exim, a mail transport agent, which could result in local privilege escalation and remote code execution.

Privacy activist Max Schrems on Microsoft’s EU data move: It won’t keep the NSA away
80% of Net Neutrality Comments to FCC Were Fudged
Insurer AXA says it will no longer cover ransomware payments in France
Chinese smart TVs caught hoovering up data about devices on customers’ networks
When not to use edge computing
Cisco HyperFlex web interface has critical flaw that lets attackers get root and execute arbitrary commands