Menu

Monthly Archives: July 2021

security update

Sysadmins: Why not simply verify there’s no backdoor in every program you install, and thus avoid any cyber-drama?

The container ses/7/ceph/ceph was updated. The following patches have been included in this update:

NSA Warns Public Networks are Hacker Hotbeds

The package vivaldi before version 4.1.2369.11-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution, content spoofing, incorrect calculation, information disclosure and insufficient validation.

The package powerdns before version 4.5.1-1 is vulnerable to denial of service.

The package 389-ds-base before version 2.0.7-1 is vulnerable to multiple issues including authentication bypass and denial of service.

The package geckodriver before version 0.29.1-1 is vulnerable to cross- site request forgery.

The package containerd before version 1.5.4-1 is vulnerable to directory traversal.

security update

A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Tackling the insider threat to the new hybrid workplace

Now that organizations are set to evolve a hybrid blend of home and office-based work for most employees, it is more important then ever to address the risks that insider threat can – willingly or unwitingly – pose. The post Tackling the insider threat to the new hybrid workplace appeared first on WeLiveSecurity

Ransomware via a call centre? BazaCall means no email attachment or link required for infection
Here’s 30 servers Russian intelligence uses to fling malware at the West, beams RiskIQ
Instagram influencer Hushpuppi admits his part in scams that stole more than $24 million
Novel Meteor Wiper Used in Attack that Crippled Iranian Train System
Six Malicious Linux Shell Scripts Used to Evade Defenses and How to Stop Them
S3 Ep43: Apple 0-day, pygmy hippos, hive nightmares and Twitter hacker bust [Podcast]

An update that fixes one vulnerability is now available.

Malware and Trojans, but there’s only one horse the boss man wants to hear about
We can’t believe people use browsers to manage their passwords, says maker of password management tools

Update to 2.53.8.1 Includes fixes for mailnews archiving, as well as account creation after news subscribing. Show just an icon (instead of a big image etc.) when moving in drag-and-drop operations to make sure the target is visible. (You can change it back by toggling boolean preference “nglayout.enable_drag_images” in about:config).

**Archive_Tar 1.4.14** * Properly fix symbolic link path traversal (**CVE-2021-32610**)

**Archive_Tar 1.4.14** * Properly fix symbolic link path traversal (**CVE-2021-32610**)

security update

UC San Diego Health Breach Tied to Phishing Attack
BlackMatter rises from the ashes of notorious cybercrime gangs to pose new ransomware threat
CISA’s Top 30 Bugs: One’s Old Enough to Buy Beer

An issue has been found in libsndfile, a library for reading/writing audio files. A crafted WAV file can trigger a heap buffer overflow and might allow exectution of arbitrary code.

Leading cybersecurity agencies reveal list of most exploited vulnerabilities of the past 2 years

There are 30 vulnerabilities listed in total; organizations would do well to patch their systems if they haven’t done so yet The post Leading cybersecurity agencies reveal list of most exploited vulnerabilities of the past 2 years appeared first on WeLiveSecurity

Booking your next holiday? Watch out for these Airbnb scams

With vacations in full swing, cybercriminals will be looking to scam vacationers looking for that perfect accommodation. The post Booking your next holiday? Watch out for these Airbnb scams appeared first on WeLiveSecurity

Israeli Government Agencies Visit NSO Group Offices
Spam is Chipotle’s secret ingredient: Marketing email hijacked to dish up malware
Upcoming Android privacy changes include ability to blank advertising ID, and ‘safety section’ in Play store

PEAR could be made to overwrite files as the administrator.

Several security issues were fixed in QPDF.

libsndfile could be made to crash or run programs as your login if it opened a specially crafted file.

Smashing Security podcast #238: Fashion captain, fraud family, and DEF CON. D’oh!

An update that solves one vulnerability, contains two features and has two fixes is now available.

libsndfile could be made to crash or run programs as your login if it opened a specially crafted file.

Israeli authorities investigate NSO Group over Pegasus spyware abuse claims
Here’s a list of the flaws Russia, China, Iran and pals exploit most often, say Five Eyes infosec agencies
‘Woefully insufficient’: Biden administration’s assessment of critical infrastructure infosec protection
Over 100 Taiwanese political figures’ messages leaked outta LINE app
Microsoft researcher found Apple 0-day in March, didn’t report it

* Properly set the cookies settings after a network process crash. * Fix accessibility tree after a cross site navigation with PSON enabled. * Ensure WebKitScriptWorld::window-object-cleared signal is always emitted. * Fix several crashes and rendering issues. * Security fixes: CVE-2021-21775, CVE-2021-21779, CVE-2021-30663, CVE-2021-30665, CVE-2021-30689, CVE-2021-30720,

Security breaches where working from home is involved are costlier, claims IBM report
Most Twitter users haven’t enabled 2FA yet, report reveals

Twitter’s transparency report revealed that users aren’t quick to adopt 2FA and once they do enable it, they choose the least secure option The post Most Twitter users haven’t enabled 2FA yet, report reveals appeared first on WeLiveSecurity

BlackMatter & Haron: Evil Ransomware Newborns or Rebirths
Reboot of PunkSpider Tool at DEF CON Stirs Debate
Iranian state-backed hackers posed as flirty Scouser called Marcy to target workers in defence and aerospace

Several security issues were fixed in WebKitGTK.

Podcast: Why Securing Active Directory Is a Nightmare
UK’s National Cyber Security Centre needs its posh Westminster digs, says Cabinet Office, because of WannaCry
Google revamps bug bounty program
Biden warns ‘real shooting war’ will be sparked by severe cyber attack

An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for rh-nodejs12-nodejs and rh-nodejs12-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Tencent suspends signups to WeChat, citing ‘security upgrade’ and need to comply with Chinese laws
eBay ex-security boss sent down for 18 months for cyber-stalking, witness tampering

* Update to go1.16.6 * Security fix for CVE-2021-34558

No More Ransom Saves Victims Nearly €1 billion Over 5 Years
Misconfigured Azure Blob at Raven Hengelsport exposed records of 246,000 anglers – and took months to tackle, claim infosec researchers
Scam-baiting YouTube channel Tech Support Scams taken offline by tech support scam

Red Hat OpenShift Container Platform release 4.8.2 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.8.

Red Hat OpenShift Container Platform release 4.8.2 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.8.

Tech biz must tell us about more security breaches, says UK.gov as it ponders lowering report thresholds

OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) (CVE-2021-2388) * OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341) * OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369) For more details about the security issue(s), including the [More…]

OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) (CVE-2021-2388) * OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341) * OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369) For more details about the security issue(s), including the [More…]

Apple releases patch for zero‑day flaw in iOS, iPadOS and macOS

The vulnerability is under active exploitation by unknown attackers and affects a wide range of Apple’s products. The post Apple releases patch for zero‑day flaw in iOS, iPadOS and macOS appeared first on WeLiveSecurity

Zimbra Server Bugs Could Lead to Email Plundering
Despite all the advice, 97.7% of Twitter users have still not enabled two-factor authentication
Three Zero-Day Bugs Plague Kaseya Unitrends Backup Servers
Apple emergency zero-day fix for iPhones and Macs – get it now!
Apple Patches Actively Exploited Zero-Day in iOS, MacOS
Compsci student walks off with $50,000 after bug bounty report blows gaping hole in Shopify software repos
Data controls in the DevSecOps life cycle

An update that fixes 8 vulnerabilities is now available.

Patch your iPhones and Macs against “actively exploited” zero-day right now
It takes intuition and skill to find hidden evidence and hunt for elusive threats
SSD belonging to Euro-cloud Scaleway was stolen from back of a truck, then turned up on YouTube

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Apple patches zero-day vulnerability in iOS, iPadOS, macOS under active attack
Black Hat USA & DEFCON 2021 Coverage on LinuxSecurity: What You Need to Know>
Podcast: IoT Piranhas Are Swarming Industrial Controls
Babuk Ransomware Gang Ransomed, New Forum Stuffed With Porn

* Update to upstream 20210716 release * update NXP 8897/8997 firmware images * rtlwifi: de-dupe rtl8723b/rtl8192e SDIO/USB WiFi firmware * Mediatek: update WiFi/bluetooth chip (MT7921) * Mediatek: update MT7915 firmware to 20201105 * Mellanox: Add new mlxsw_spectrum firmware xx.2008.2946 * cxgb4: Update firmware to revision 1.26.0.0 * firmware/i915/guc: Add HuC v7.9.3 for TGL & DG1 […]

You, too, can be a Windows domain controller and do whatever you like, with this one weird WONTFIX trick
Microsoft Rushes Fix for ‘PetitPotam’ Attack PoC

This update upgrades Thunderbird to version 78.12.0. * Mozilla: IMAP server responses sent by a MITM prior to STARTTLS could be processed (CVE-2021-29969) * Mozilla: Use-after-free in accessibility features of a document (CVE-2021-29970) * Mozilla: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 (CVE-2021-29976) * chromium-browser: Out of bounds write in ANGLE […]

Who us??? Kaseya says it hasn’t paid anybody for its ransomware decryption key
Average ransomware payments decline… but that’s not good news
No More Ransom website celebrates five years of providing free ransomware recovery tools and advice
Malware Makers Using ‘Exotic’ Programming Languages
Good news! I’m getting a salary increase!
The True Impact of Ransomware Attacks

Aspell could be made to execute arbitrary code or cause a crash if it received a specially crafted input.

An update is now available for Red Hat OpenShift Container Platform 4.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Stay sharp this summer with security tips from the experts – sign up to 1Password’s Security Summer School today
Windows “PetitPotam” network attack – how to protect against it