Menu

Monthly Archives: June 2021

Go fuzz to catch hard-to-find bugs in Go
Hacking space: How to pwn a satellite

Hacking an orbiting satellite is not light years away – here’s how things can go wrong in outer space The post Hacking space: How to pwn a satellite appeared first on WeLiveSecurity

Military infosec SNAFUs: What WhatsApp and bears in the woods can teach us

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libwebp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

Multiple security issues have been discovered in libwebp CVE-2018-25009

An update that solves 12 vulnerabilities and has 23 fixes is now available.

An update that fixes 21 vulnerabilities is now available.

Several security issues were fixed in the Linux kernel.

security update

New version 3.4.5, Fix for CVE-2021-22207.

Fix for CVE-2021-25217

New version 3.4.5, Fix for CVE-2021-22207.

security update

Cyberattack Suspected in Cox TV and Radio Outages
Biden expands Chinese tech and military blocklist to 59 companies

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. In adddition two security issues were addressed in the OpenPGP support.

Zero‑day in popular WordPress plugin exploited to take over websites

Websites using Fancy Product Designer are susceptible to remote code execution attacks even if the plugin is deactivated The post Zero‑day in popular WordPress plugin exploited to take over websites appeared first on WeLiveSecurity

Good news for pentesters and network admins: US issues ransomware guidance asking biz to skill up security teams
Supreme Court Limits Scope of Controversial Hacking Law
How to hack into 5500 accounts… just using “credential stuffing”
REvil Ransomware Gang Spill Details on US Attacks
Android banking malware sharply increased in the first chunk of 2021, reckons ESET

An update that fixes one vulnerability is now available.

Is it possible to automate all of cloud operations?
The policy of truth: As ransomware claims rise, what’s a cyber insurer to do?
Brit retailer Furniture Village confirms ‘cyber-attack’ as systems outage rolls into Day 7
How to use Google’s new dependency mapping tool to find security flaws buried in your projects
‘Battle for the Galaxy’ Mobile Game Leaks 6M Gamer Profiles

Backport fixes for CVE-2021-32617, CVE-2021-29623.

Apply fix for CVE-2021-3500. —- Apply fix for CVE-2021-32490, CVE-2021-32491, CVE-2021-32492, CVE-2021-32493

Upgrade to upstream security release 3.7.4

Backport fixes for CVE-2021-32617, CVE-2021-29623.

Apply fix for CVE-2021-3500. —- Apply fix for CVE-2021-32490, CVE-2021-32491, CVE-2021-32492, CVE-2021-32493

Supreme Court narrows Computer Fraud and Abuse Act: Misusing access not quite the same as breaking in

security update

Google PPC Ads Used to Deliver Infostealers
Cryptocurrency hacks wanted – $100,000 prize fund offered in contest run by cybercrime forum
Backup appliance firm pays out $2.6 million ransom to attackers
FireEye sold to McAfee’s new owners for $1.2bn as Mandiant split into standalone firm again
Exchange Servers Targeted by ‘Epsilon Red’ Malware
S3 Ep35: Apple chip flaw, Have I Been Pwned, and Covid tracker trouble [Podcast]
Then and Now: Securing Privileged Access Within Healthcare Orgs
Kubernetes architecture and what it means for security
It’s time to get serious about enterprise password management – download this 1Password white paper now
Smashing Security podcast #230: Flash card f-up and energy pipe pilfering
ESET Threat Report T1 2021

A view of the T1 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T1 2021 appeared first on WeLiveSecurity

European Parliament’s data adequacy objection: Doubts cast on UK’s commitment to privacy protection
Antivirus that mines Ethereum sounds a bit wrong, right? Norton has started selling it
Deadline draws near to avoid auto-joining Amazon’s mesh network Sidewalk
Podcast: The State of Ransomware
Effective Adoption of SASE in 2021

security update

Banking Attacks Surge Along with Post-COVID Economy
Ahem, Huawei, your USB LTE stick has a vuln. I SAID AHEM, Huawei, are you listening?
JBS Foods ransomware gang: White House ‘engaging directly’ with Russia about attack on massive meat producer
REvil Ransomware Ground Down JBS: Sources
UK Special Forces soldiers’ personal data was floating around WhatsApp in a leaked Army spreadsheet
Babuk ransomware gang says it’s no longer interested in encrypting data, would rather kidnap it instead
DoJ Charges Rhode Island Woman in Phishing Scheme Against Politicians

An update for glib2 is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Amazon Sidewalk Poised to Sweep You Into Its Mesh
OpenPGP library RNP updates after Thunderbird decrypt-no-recrypt bug squashed

An update for openvswitch is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This advisory resolves CVE issues filed against XP1 releases that have been fixed in the underlying EAP 7.3.x base. There are no changes to the EAP XP1 code base. NOTE: This advisory is informational only. There are no code changes

Dnsmasq could be exposed to cache poisoning.

Several security issues were fixed in Django.

Network-Bound Disk Encryption improvements in RHEL 8
Feds seize two domains used by SolarWinds intruders for malware spear-phishing op
“Have I Been Pwned” breach site partners with… the FBI!

Applications using Lasso could be made to allow unintended access.

Cyber-Insurance Fuels Ransomware Payment Surge

In a previous post, we talked a bit about what pen testing is and how to use the organizations that provide them to your benefit. But, what about when one of them hands a client a failing grade? Consider this, you’re an MSP and you get a letter or email from one of your customers […]

An update for rh-python36-python-jinja2 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Where Bug Bounty Programs Fall Flat
There’s a lesson here for us all: A third of healthcare orgs in Sophos survey ‘hit with ransomware in 2020’
Remember those wacky cyberpunk costumes in Hackers? They’re on display in London this week
How Mobile Ad Fraud has Evolved in the Year of the Pandemic
Cyberattack Forces Meat Producer to Shut Down Operations in U.S., Australia
World’s biggest meat supplier, JBS, suffers cyber attack
5 common scams targeting teens – and how to stay safe

From knock-off designer products to too-good-to-be-true job offers, here are five common schemes fraudsters use to trick teenagers out of their money and sensitive data The post 5 common scams targeting teens – and how to stay safe appeared first on WeLiveSecurity

Increase confidence in public cloud security: Integrate Intel SGX, says G-Core Labs Cloud
Have I Been Pwned goes open source, bags help from FBI