Menu

Monthly Archives: May 2021

Kids in Hong Kong and other highly surveilled states worry infosec careers are just asking for trouble
Google Play to require privacy labels on apps in 2022, almost two years after Apple
Google will make you use two-step verification to login

What’s better for getting your business’ name out there and boosting sales than having a killer business marketing plan with well-placed ads, zippy copy, and a slick design? The answer is: having a group of dedicated real-world customers who use their own platforms to advocate for your business and its offerings. Thanks to social media, […]

Popular routers found vulnerable to hacker attacks

Millions of Brits could be at risk of cyberattacks due to poor default passwords and a lack of firmware updates The post Popular routers found vulnerable to hacker attacks appeared first on WeLiveSecurity

Qualcomm Chip Bug Opens Android Fans to Eavesdropping
Critical Cisco SD-WAN, HyperFlex Bugs Threaten Corporate Networks
Ryuk Ransomware Attack Sprung by Frugal Student
DDoS attack knocks Belgian government websites offline

The attack overwhelmed the systems of a Belgian ISP, leading to widespread service outages and disruptions The post DDoS attack knocks Belgian government websites offline appeared first on WeLiveSecurity

Vulnerability in Snapdragon 855 SoCs could pwn Android modems, allow baddies to snoop on conversations
Massive DDoS Attack Disrupts Belgium Parliament
S3 Ep31: Apple zero-days, Flubot scammers and PHP supply chain bug [Podcast]
NSA offers advice: connecting OT to the rest of the net can lead to “indefensible levels of risk”
Firefox for Android gets critical update to block cookie-stealing hole
How to accurately match OVAL security data to installed RPMs
Smashing Security podcast #226: Cryptocrazies and NFTs
Fantastic passwords and where your children can find them

How witches, wizards and superheroes can help your kids stay safe from cyber-villains, plus other parenting hacks to encourage your children to use secure passwords The post Fantastic passwords and where your children can find them appeared first on WeLiveSecurity

Crane horror Reg reader uses his severed finger to unlock Samsung Galaxy phone
Chrome on Windows turns on Intel, AMD chip-level defenses against malicious websites
JET engine flaws can crash Microsoft’s IIS, SQL Server, say Palo Alto researchers
Signal says its Instagram ads were banned for being too honest
New Crypto-Stealer ‘Panda’ Spread via Discord
Anti-Spam WordPress Plugin Could Expose Website User Data
Raft of Exim Security Holes Allow Linux Mail Server Takeovers
Microsoft will soon remove Flash Player from Windows 10 devices

The Patch Tuesday security update due in July should hammer the last nail in the coffin of Adobe Flash Player The post Microsoft will soon remove Flash Player from Windows 10 devices appeared first on WeLiveSecurity

21 nails in Exim mail server: Vulnerabilities enable ‘full remote unauthenticated code execution’, millions of boxes at risk
Peloton’s Leaky API Spilled Riders’ Private Data
Peloton exercise bikes found exposing user data – company dawdles in its response
East London council blurts thousands of residents’ email addresses in To field blunder
Feds Shut Down Fake COVID-19 Vaccine Phishing Website
Dell fixes exploitable holes in its own firmware update driver – patch now!
21Nails: Multiple Critical Vulnerabilities Discovered in Exim Mail Server – Patch Now!>
Twilio’s private GitHub repositories cloned by Codecov attacker, cloud comms platform confirms
Compliance clarity with Red Hat Insights
Ousaban: Private photo collection hidden in a CABinet

Another in our occasional series demystifying Latin American banking trojans The post Ousaban: Private photo collection hidden in a CABinet appeared first on WeLiveSecurity

What not to expect when you’re expecting: Fertility apps may be selling intimate health secrets

Red Hat OpenShift Container Platform release 4.6.27 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Four security issues have been discovered in cgal. A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL. CVE-2020-28601

An update that fixes one vulnerability is now available.

Update to bugfix release 4.1.0 Security fix for CVE-2017-9438, CVE-2021-3402, CVE-2019-19648, CVE-2017-9438

Global Phishing Attacks Spawn Three New Malware Strains

security update

‘Millions’ of Dell PCs will grant malware, rogue users admin-level access if asked nicely

Typically, when cryptocurrency values change, one would expect to see changes in crypto-related cybercrime. In particular, trends in Bitcoin values tend to be the bellwether you can use to predict how other currencies’ values will shift, and there are usually corresponding shifts in crypto-based crime, such as ransomware, though it’s not necessarily the kind of […]

Red Hat open-sources StackRox Kubernetes security product
Pulse Secure VPNs Get a Fix for Critical Zero-Day Bugs
INTERPOL aims to deal a blow to digital piracy

The agency’s new initiative will also warn about the high cost of the free lunch – the increased risk of malware exposure The post INTERPOL aims to deal a blow to digital piracy appeared first on WeLiveSecurity

Apple Fixes Zero‑Day Security Bugs Under Active Attack
Hundreds of Millions of Dell Users at Risk from Kernel-Privilege Bugs
Sneakers, Gaming, Nvidia Cards: Retailers Can Stop Shopping Bots
Bait Boost: Phishers Delivering Increasingly Convincing Lures
Apple products hit by fourfecta of zero-day exploits – patch now!

An update that fixes one vulnerability is now available.

Boystown, dark web child abuse image website with 400,000 members, shut down by police

The Qualys Research Labs reported several vulnerabilities in Exim, a mail transport agent, which could result in local privilege escalation and remote code execution.

Several vulnerabilities were discovered in BIND, a DNS server implementation. CVE-2021-25214

One security issue has been discovered in subversion: CVE-2020-17525:

Apple patches iOS, macOS, iPadOS, watchOS, kitchen-sinkOS bugs said to be exploited in the wild

security update

Several vulnerabilities have been discovered in the chromium web browser. CVE-2021-21227

Scripps Health Cyberattack Causes Widespread Hospital Outages

Exiv2 update fixing security issues.

New Attacks Slaughter All Spectre Defenses 

security update

Hewlett Packard Enterprise Plugs Critical Bug in Edge Platform Tool
Deepfake Attacks Are About to Surge, Experts Warn
New Buer Malware Downloader Rewritten in E-Z Rust Language
Naked Security Live – Beware ‘Flubot’: the home delivery scam with a difference

An update for bind is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for bind is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for bind is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

An update for bind is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for bind is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Upgrade to 2.9.20 bugfix and security update.

security update