Menu

Monthly Archives: June 2021

Brave launches its own, privacy‑focused search engine

The Brave Search engine takes on Google, promising to let users surf the web without leaving a trace The post Brave launches its own, privacy‑focused search engine appeared first on WeLiveSecurity

Report picks holes in the Linux kernel release signing process
Musk-Themed ‘$SpaceX’ Cryptoscam Invades YouTube Advertising
S3 Ep38: Clop busts, destructive Linux hacking, and rooted bicycles [Podcast]
Critical VMware Carbon Black Bug Allows Authentication Bypass
Smashing Security podcast #233: Peloton problems, romance regret, and Weiner woes

The package pigeonhole before version 0.5.15-1 is vulnerable to denial of service.

The package dovecot before version 2.3.15-1 is vulnerable to information disclosure.

The package tpm2-tools before version 5.1.1-1 is vulnerable to man-in- the-middle.

The package exiv2 before version 0.27.4-1 is vulnerable to multiple issues including arbitrary code execution, denial of service and information disclosure.

The package keycloak before version 14.0.0-1 is vulnerable to certificate verification bypass.

The package helm before version 3.6.1-1 is vulnerable to information disclosure.

Tulsa’s Police-Citation Data Leaked by Conti Gang
Google pushes bug databases to get on the same page for open-source security
UK watchdog fines biz £130k for 900,000+ direct marketing calls to folk who had opted out
Atlassian Bugs Could Have Led to 1-Click Takeover
30M Dell Devices at Risk for Remote BIOS Attacks, RCE
Fashion titan French Connection says ‘FCUK’ as REvil-linked ransomware makes off with data
Three things that have vanished: $3.6bn in Bitcoin, a crypto investment biz, and the two brothers who ran it
John McAfee dead: Antivirus tycoon killed himself in prison after court OK’d extradition, says lawyer
Iran Media Websites Seized by U.S. in Disinformation Campaign
Pandemic-Bored Attackers Pummeled Gaming Industry
Critical Palo Alto Cyber-Defense Bug Allows Remote ‘War Room’ Access
REvil Ransomware Code Ripped Off by Rivals
Boffins promise protection and perfect performance with new ZeRØ, No-FAT memory safety techniques
Unpatched Linux Marketplace Bugs Allow Wormable Attacks, Drive-By RCE

An update is now available for Red Hat OpenShift Jaeger 1.17. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Get serious about enterprise password management – download this 1Password white paper now
SonicWall ‘Botches’ October Patch for Critical VPN Bug

An update for qemu-kvm-rhev is now available for Red Hat Virtualization for Red Hat Virtualization Host 7. Red Hat Product Security has rated this update as having a security impact of

How to tell if a website is safe

It can be difficult to tell a legitimate website apart from an unsafe one – follow these steps to identify and protect yourself from bad websites The post How to tell if a website is safe appeared first on WeLiveSecurity

The components for Windows Container Support for Red Hat OpenShift 2.0.1 are now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Several security issues were fixed in the Linux kernel.

The system could be made to run programs as an administrator.

Several security issues were fixed in the Linux kernel.

Sure looks like someone’s pirating the REvil ransomware, tweaking the binary in a hex editor for their own crimes
SEC still digging into SolarWinds fallout, nudges undeclared victims
‘Set it and forget it’ attitude to open-source software has become a major security problem, says Veracode
BEC Losses Top $1.8B as Tactics Evolve
There’s no ‘Skype’ in Teams: Microsoft lets signing key for its Debian Skype repository slip gently into the night
Cryptominers Slither into Python Projects in Supply-Chain Campaign
Email Bug Allows Message Snooping, Credential Theft
Kids’ Apps on Google Play Rife with Privacy Violations
Lexmark Printers Open to Arbitrary Code-Execution Zero-Day
Ransomware: What REALLY happens if you pay the crooks?

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Zephyr OS Bluetooth vulnerabilities left smart devices open to attack
Six Flags to Pay $36M Over Collection of Fingerprints

An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

MI5 still risks breaking the law on surveillance data through poor controls – years after it was first warned

An update for the virt:8.2 and virt-devel:8.2 modules is now available for Advanced Virtualization for RHEL 8.2.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Smart thermostats cranked up remotely by Texas energy firms, as consumers swelter in heat wave
Don’t name your Wi-Fi hotspot this, unless you want to crash your iPhone
US Air Force announces plan to assassinate molluscs with hypersonic missile
To CAPTCHA or not to CAPTCHA? Gartner analyst says OK — but don’t be robotic about it

Several security issues were fixed in OpenEXR.

Several security issues were fixed in OpenEXR.

Do you want speed or security as expected? Spectre CPU defenses can cripple performance on Linux in tests
APNIC left a dump from its Whois SQL database in a public Google Cloud bucket
It’s 2021 and a printf format string in a wireless network’s name can break iPhone Wi-Fi
Wegmans Exposes Customer Data in Misconfigured Databases
Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks, Data Theft
Ex-NSA bigwig Chris Inglis appointed America’s national cyber director by Senate
Embryology Data Breach Follows Fertility Clinic Ransomware Hit
Racist malware blocks The Pirate Bay by tampering with victims’ Windows hosts file
Agent Tesla RAT Returns in COVID-19 Vax Phish
iPhone Wi-Fi Crushed by Weird Network

Introduction It’s important for a business to be prepared with an exercised business continuity and disaster recovery (BC/DR) plan plan before its hit with ransomware so that it can resume operations as quickly as possible. Key steps and solutions should be followed to prepare and respond to cyber threats or attacks against your organization. It […]

No, you’re not talking to Jason Statham
North Korean hackers exploit VPN bug to gain access to South Korean Atomic Energy Research Institute

Several security issues were fixed in Apache HTTP Server.

Secure Linux Hosting for Businesses>
What Is Threat Intelligence?>
RHEL and CentOS 7 Users Get New Kernel Security Update to Fix Intel Graphics Flaws>
Firefox 89.0.1 Released to Improve WebRender Performance, Fix Scrollbars on GTK Themes>

Several security issues were fixed in Apache HTTP Server.

Several security issues were fixed in Dovecot.

State‑sponsored or financially motivated: Is there any difference anymore?

What does the increasingly fuzzy line between traditional cybercrime and attacks attributed to state-backed groups mean for the future of the threat landscape? The post State‑sponsored or financially motivated: Is there any difference anymore? appeared first on WeLiveSecurity

Sharpen your cybersecurity skills, however and wherever works for you, with these SANS Institute courses
South Korea’s nuclear research agency breached by North Korea-affiliated cyberattackers, says malware analyst group

Update radare2 to 5.3.1 Also fixes CVS-2021-32613 —- bump to radare2 5.3.0 fixes CVE-2021-32613

Update radare2 to 5.3.1 Also fixes CVS-2021-32613 —- bump to radare2 5.3.0 fixes CVE-2021-32613

Update radare2 to 5.3.1 Also fixes CVS-2021-32613 —- bump to radare2 5.3.0 fixes CVE-2021-32613

Backport fix for CVE-2021-3589 and a heap buffer overflow.

Backport fix for CVE-2021-3589 and a heap buffer overflow.

security update

security update

It was discovered that the previous upload of the package prosody versioned 0.9.12-2+deb9u3 introduced a regression in the mod_auth_internal_hashed module. Big thanks to Andre Bianchi for the reporting an issue and for testing the update.

Update to 1.6.15 Security If an authenticated client connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur. Affects versions 1.6 to 2.0.10 inclusive.

CVE-2021-3560 mitigation

Backport fix for CVE-2021-33503.

2.0.11 Security If an authenticated client connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur. Affects versions 1.6 to 2.0.10 inclusive. Broker Fix possible crash having just upgraded from 1.6 if per_listener_settings true is set, and a SIGHUP is sent to the broker before a client has […]

This updates nettle to the latest upstream release 3.7.3, which contains security fix for RSA decryption: https://lists.lysator.liu.se/pipermail/nettle- bugs/2021/009545.html

Can *YOU* blow a PC speaker using only a Linux kernel driver?
Most health apps engage in unhealthy data‑harvesting habits

Most medical and fitness apps in Google Play have tracking capabilities enabled and their data collection practices aren’t transparent The post Most health apps engage in unhealthy data‑harvesting habits appeared first on WeLiveSecurity

What’s Making Your Company a Ransomware Sitting Duck
Repairmen suspected of installing ransomware on customers’ PCs. Arrests in South Korea
Carnival Cruise Cyber-Torpedoed by Cyberattack

The package connman before version 1.40-1 is vulnerable to arbitrary code execution.