Menu

Monthly Archives: June 2021

Add proposed patches for CVE-2021-29338 and a heap buffer overflow.

Add proposed patches for CVE-2021-29338 and a heap buffer overflow.

Unpatched Bugs Found Lurking in Provisioning Platform Used with Cisco UC

security update

Baby Clothes Giant Carter’s Leaks 410K Customer Records
REvil Hits US Nuclear Weapons Contractor: Report
Google fixes actively exploited Chrome zero‑day

The latest Chrome update patches a bumper crop of security flaws across the browser’s desktop versions The post Google fixes actively exploited Chrome zero‑day appeared first on WeLiveSecurity

BackdoorDiplomacy: Upgrading from Quarian to Turian

ESET researchers discover a new campaign that evolved from the Quarian backdoor The post BackdoorDiplomacy: Upgrading from Quarian to Turian appeared first on WeLiveSecurity

UK tells UN that nation-states should retaliate against cyber badness with no warning
Cyberpunk 2077 Hacked Data Circulating Online
ALPACA – the wacky TLS security vulnerability with a funky name
Monumental Supply-Chain Attack on Airlines Traced to State Actor

The package wireshark-cli before version 3.4.6-1 is vulnerable to denial of service.

The package kube-apiserver before version 1.21.1-1 is vulnerable to insufficient validation.

The package nettle before version 3.7.3-1 is vulnerable to denial of service.

The package isync before version 1.4.2-1 is vulnerable to arbitrary code execution.

The package python-websockets before version 9.1-1 is vulnerable to private key recovery.

The package python-urllib3 before version 1.26.5-1 is vulnerable to denial of service.

Police Grab Slilpp, Biggest Stolen-Logins Market
EA Games looted by intruders: Publisher says ‘no player data accessed’ after reported theft of FIFA 21, Frostbite source
Hackers Steal FIFA 21 Source Code, Tools in EA Breach
Complexity is the biggest threat to cloud success and security
Smashing Security podcast #231: Sexy snaps and encrypted chat traps
Seven-year-old make-me-root bug in Linux service polkit patched
China arrests over 1000 for using cryptocurrency to help launder proceeds of phone scams
‘Fancy Lazarus’ Cyberattackers Ramp up Ransom DDoS Efforts

security update

security update

Chrome Browser Bug Under Active Attack
STEM Audio Table Rife with Business-Threatening Bugs
Gelsemium: When threat actors go gardening

ESET researchers shed light on new campaigns from the quiet Gelsemium group The post Gelsemium: When threat actors go gardening appeared first on WeLiveSecurity

Microsoft: Big Cryptomining Attacks Hit Kubeflow
Steam Gaming Platform Hosting Malware
JBS Paid $11M to REvil Gang Even After Restoring Operations
S3 Ep36: Trickbot coder busted, passwords cracked, and breaches judged [Podcast]

An update for servicemesh-operator is now available for OpenShift Service Mesh 2.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Chrome zero-day, hot on the heels of Microsoft’s IE zero-day. Patch now!
Student Loans Company splashes out on 20,000 cybersecurity training courses – for just 3,300 employees

libwebp could be made to crash or run programs as your login if it opened a specially crafted file.

An update for the postgresql:13 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

South Korea’s data watchdog barks warnings at Microsoft and five local firms

An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Ransomware-skewered meat producer JBS confesses to paying $11m for its freedom

An update for the container-tools:3.0 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

ALPACA gnaws through TLS protection to snarf cookies and steal data
Huawei flings open the doors of its third privacy and security transparency centre
Risk and reward: Nefilim ransomware gang mainly targets fewer, richer companies and that strategy is paying off, warns Trend Micro
PrivacyMic looks to keep your home smart without Google, Alexa, Siri and pals listening in
Mysterious Custom Malware Collects Billions of Stolen Data Points
How could the FBI recover BTC from Colonial’s ransomware payment?
‘I put the interests of the country first’: Colonial Pipeline CEO on why oil biz paid off ransomware crooks
Intel Plugs 29 Holes in CPUs, Bluetooth, Security
Mysterious Gelsemium APT was behind February compromise of NoxPlayer, says ESET

rxvt, VT102 terminal emulator for the X Window System, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q).

mrxvt, lightweight multi-tabbed X terminal emulator, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q).

eterm, an enlightened terminal emulator, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q).

Red Hat OpenShift Container Platform release 3.11.452 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 3.11.

DarkSide Pwned Colonial With Old VPN Password
Intel’s latest patch set plugs some serious holes in CPU, Bluetooth, server, and – ironically – security lines

An update that fixes three vulnerabilities is now available.

Identity and access in the DevSecOps life cycle

Several security issues were fixed in Intel Microcode.

Security researcher says attacks on Russian government have Chinese fingerprints – and typos, too
Extra urgency in June’s Patch Tuesday: Microsoft warns six more bugs are being exploited
FBI paid renegade developer $180k for backdoored AN0M chat app that brought down drug underworld
Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws
Lewd Phishing Lures Aimed at Business Explode
TrickBot Coder Faces Decades in Prison
Google Patches Critical Android RCE Bug
Hundreds of suspected criminals arrested after being tricked into using FBI‑run chat app

Law enforcement around the world used a messaging app called AN0M to monitor the communications of alleged criminals The post Hundreds of suspected criminals arrested after being tricked into using FBI‑run chat app appeared first on WeLiveSecurity

‘An0m’ Encrypted-Chat Sting Leads to Arrest of 800
Cryptography whizz Phil Zimmermann looks back at 30 years of Pretty Good Privacy
Siloscape malware targets Windows containers, breaks through to the underlying Kubernetes cluster
DoS vulns in 3 open-source MQTT message brokers could leave users literally locked out of their homes or offices
Billions of Compromised Records and Counting: Why the Application Layer is Still the Front Door for Data Breaches

Memory safety bugs fixed in Firefox 89 and Firefox ESR 78.11 Mozilla developers Gabriele Svelto, Anny Gakhokidze, Alexandru Michis, Christian Holler reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been […]

Fixed format string vulnerability allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file (CVE-2021-30145). References: – https://bugs.mageia.org/show_bug.cgi?id=29058 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QVXB4F67QODLPKYBZX7SBXTE7ESGKGOD/

This update patches the vendored `smallvec` Rust crate in librsvg to fix a security vulnerability: The Iterator implementation mishandles destructors, leading to a double free (CVE-2021-25900). References:

A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability (CVE-2021-20193). References: – https://bugs.mageia.org/show_bug.cgi?id=29049 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XRDSUUE3LUKBDRLPB7GTT5QZRPV5J7O4/

Exponential entity expansion attack bypasses all existing protection mechanisms. (CVE-2021-3541). References: – https://bugs.mageia.org/show_bug.cgi?id=29039 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/NYSYJVWYEQHFG2TBIQJRJ5COUR5LNFJJ/

A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmasq, only needs to guess the random transmission ID to forge a […]

Evil Corp Impersonates PayloadBin Group to Avoid Federal Sanctions
Criminal networks smashed after using “secure” chat app secretly run by cops
I think therefore IAM: It’s not cool, it’s not sexy, but it’s one of the most important and difficult areas in modern IT
Uncle Sam recovers 63.7 of 75 Bitcoins Colonial Pipeline paid to ransomware crew
Australian cops, FBI created backdoored chat app, told crims it was secure – then snooped on 9,000 users’ plots
FBI drops subpoena to identify readers of USA Today article about shootout with agents
Everything Apple announced: Tor-ish Safari anonymization. Cloaked iCloud addresses. Cloud CI/CD. And more
Google, Facebook, Chaos Computer Club join forces to oppose German state spyware
FBI Claws Back Millions of DarkSide’s Ransom Profits
US House Rep on cyber committees tweets Gmail password, PIN in Capitol riot lawsuit outrage
Bad Apple: App Store Rife with Fraud, Fleeceware
Novel ‘Victory’ Backdoor Spotted in Chinese APT Campaign
Windows Container Malware Targets Kubernetes Clusters
Latvian woman charged with writing malware for the Trickbot Group
Remember Anonymous? It/they might be back, and it/they are angry with Elon Musk

USN-4937-1 introduced a regression in GNOME Autoar.

We’re right behind Computer Misuse Act reforms for busting ransomware gangs, says UK infosec industry

USN-4969-1 introduced a regression in DHCP.