Menu

Monthly Archives: August 2021

Fortress Home Security Open to Remote Disarmament
Cream Finance DeFi Platform Rooked For $29M

An update that solves two vulnerabilities, contains one feature and has one errata is now available.

Proxyware Services Open Orgs to Abuse – Report
Ragnarok ransomware gang shuts down, universal decryption key released
US officials, experts fear China ransacked Exchange servers for data to train AI systems
Flaw in the Quebec vaccine passport: analysis

ESET’s cybersecurity expert Marc-Étienne Léveillé analyses in-depth the Quebec’s vaccine proof apps VaxiCode and VaxiCode Verif. The post Flaw in the Quebec vaccine passport: analysis appeared first on WeLiveSecurity

Don’t use single‑factor authentication, warns CISA

The federal agency urges organizations to ditch the bad practice and instead use multi-factor authentication methods The post Don’t use single‑factor authentication, warns CISA appeared first on WeLiveSecurity

Skimming the CREAM – recursive withdrawals loot $13M in cryptocash
WooCommerce Pricing Plugin Allows Malicious Code-Injection
QNAP Is Latest to Get Dinged by OpenSSL Bugs Fallout
Leaked Guntrader firearms data file shared. Worst case scenario? Criminals plot UK gun owners’ home addresses in Google Earth

NTFS-3G could be made to execute arbitrary code if it received a specially crafted image file.

Top 3 APIs Vulnerabilities: Why Apps are Owned by Cyberattackers

sssd: shell command injection in sssctl (CVE-2021-3621) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Memory leak in the simple access provider * id lookup is failing intermittently * SSSD is NOT able to contact the Global Catalog […]

kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c (CVE-2021-22555) * kernel: race condition for removal of the HCI controller (CVE-2021-32399) * kernel: powerpc: RTAS calls can be used to compromise kernel integrity (CVE-2020-27777) * kernel: Local privilege escalation due to incorrect BPF JIT branch displacement computation (CVE-2021-29154) * kernel: [More…]

bind: Broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly (CVE-2021-25214) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 bind-9.11.4-26.P2.el7_9.7.x86_64.rpm bind-chroot-9.11.4-26.P2.el7_9.7.x86_64.rpm bind-debuginfo-9.11.4-26.P2.el7_9.7.i68 [More…]

libsndfile: Heap buffer overflow via crafted WAV file allows arbitrary code execution (CVE-2021-3246) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 libsndfile-1.0.25-12.el7_9.1.i686.rpm libsndfile-1.0.25-12.el7_9.1.x86_64.rpm libsndfile-debuginfo-1.0.25-12.el7_9.1.i686.rpm li [More…]

hivex: stack overflow due to recursive call of _get_children() (CVE-2021-3622) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 hivex-1.3.10-6.12.el7_9.i686.rpm hivex-1.3.10-6.12.el7_9.x86_64.rpm hivex-debuginfo-1.3.10-6.12.el7_9.i686.rpm hivex-debuginfo-1.3.10-6.12.el7_9.x86_64 [More…]

Where are you on your DevSecOps journey?
LockFile Ransomware Uses Never-Before Seen Encryption to Avoid Detection
Drowning in cybersecurity info? Make a dash to Security SOS Week 2021
Bangkok Airways hit by LockBit ransomware attack, loses lotsa data after refusing to pay

security update

Boffins find if you torture AMD Zen+, Zen 2 CPUs enough, they are vulnerable to Meltdown-like attack
HPE Warns Sudo Bug Gives Attackers Root Privileges to Aruba Platform
Army Testing Facial Recognition in Child-Care Centers
The Underground Economy: Recon, Weaponization & Delivery for Account Takeovers
Microsoft Exchange ‘ProxyToken’ Bug Allows Email Snooping
LockBit Gang to Publish 103GB of Bangkok Air Customer Data

APR could be made to expose sensitive information if it received a specially crafted input.

grilo could be made to allow MITM attacks.

An update for libsndfile is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libX11 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several vulnerabilities have been discovered in Exiv2, a C++ library and a command line utility to manage image metadata which could result in denial of service or the execution of arbitrary code if a malformed file is parsed.

An update for libsndfile is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

New upstream stable version 1.24.6; fixes CVE-2021-3716.

New upstream stable version 1.26.5; fixes CVE-2021-3716.

security update

An issue has been found in gthumb, an image viewer and browser. A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c allows attackers to

Michael Catanzaro reported a problem in Grilo, a framework for discovering and browsing media. TLS certificate verification is not enabled on the SoupSessionAsync objects created by Grilo, leaving users vulnerable to network MITM attacks.

– CVE-2021-37750 (explicit NULL deref on KDC)

A security flaw was found on rubygem-addressable that a crafted template may cause DOS. This issue is now assinged as CVE-2021-32740. This new rpm should fix this issue.

A security flaw was found on rubygem-addressable that a crafted template may cause DOS. This issue is now assinged as CVE-2021-32740. This new rpm should fix this issue.

An update that fixes one vulnerability is now available.

T-Mobile’s Security Is ‘Awful,’ Says Purported Thief
Microsoft warns of widespread open redirection phishing attack – which Defender can block, coincidentally

When the Institute for Security & Technology’s Ransomware Task Force published its report on combatting ransomware this spring, the Colonial Pipeline, JBS meatpacking and Kaseya VSA attacks were still around the corner. Nevertheless, the report took the danger presented by ransomware to both businesses and global security for granted. Already in 2020, according to the […]

Parallels Offers ‘Inconvenient’ Fix for High-Severity Bug
Experts: WH Cybersecurity Summit Should Be Followed by Regulation, Enforcement

An update that solves one vulnerability and has two fixes is now available.

Winning the Cyber-Defense Race: Understand the Finish Line

An update that fixes 15 vulnerabilities is now available.

FIN8 Targets US Bank With New ‘Sardonic’ Backdoor
Man impersonates Apple support, steals 620,000 photos from iCloud accounts

The man was after sexually explicit photos and videos that he would then share online or store in his own collection The post Man impersonates Apple support, steals 620,000 photos from iCloud accounts appeared first on WeLiveSecurity

Critical Azure Cosmos DB Bug Allows Full Cloud Account Takeover
Slap on wrist for NCC Group over CREST exam-cheating scandal as infosec org agrees to rewrite NDAs and more
Ragnarok Ransomware Gang Bites the Dust, Releases Decryptor

Updated libass packages fix security vulnerability: libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction (CVE-2020-36430).

runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition (CVE-2021-30465).

Top Strategies That Define the Success of a Modern Vulnerability Management Program
‘Pay Ransom’ Screen? Too Late, Humpty Dumpty – Podcast

An update that solves 7 vulnerabilities and has one errata is now available.

An update that solves one vulnerability, contains two features and has 6 fixes is now available.

Azure’s now-fixed Cosmos DB flaw could have been exploited to read, write any database
Big bad decryption bug in OpenSSL – but no cause for alarm
Man Sues Parents of Teens Who Hijacked Nearly $1M in Bitcoin

An update that fixes one vulnerability is now available.

F5 Bug Could Lead to Complete System Takeover
S3 Ep47: Daylight robbery, spaghetti trouble, and mousetastic superpowers [Podcast]
Podcast: Ransomware Up x10: Disrupting Cybercrime Suppy Chains an Opportunity

exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp (CVE-2021-31291) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE7 — SL7 x86_64 – compat-exiv2-023-0.23-2.el7_9.i686.rpm – compat-exiv2-023-0.23-2.el7_9.x86_64.rpm – compat-exiv2-023-debuginfo-0.23-2.el7_9.i686.rpm – compat- [More…]

exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp (CVE-2021-31291) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE7 — SL7 x86_64 – compat-exiv2-026-0.26-3.el7_9.i686.rpm – compat-exiv2-026-0.26-3.el7_9.x86_64.rpm – compat-exiv2-026-debuginfo-0.26-3.el7_9.i686.rpm – compat-e [More…]

Microsoft Breaks Silence on Barrage of ProxyShell Attacks

libssh could be made to crash or run programs if it received specially crafted network traffic.

An update for servicemesh and servicemesh-proxy is now available for OpenShift Service Mesh 2.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libsndfile is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for python27-babel, python27-python, python27-python-jinja2, and python27-python-pygments is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

FBI warns of OnePercent ransomware gang – what you need to know
Red Hat’s open approach to vulnerability management
Watch now: 2021 Red Hat Security Symposium on-demand
Smashing Security podcast #240: 3D printer hijacks, crypto fails, and a tech billionaire’s revenge
Surveillance tech company sues Police Digital Service over ‘flawed’ scoring of bids on £18m contract
Big tech proud as punch about cameos in Joe Biden’s security theatre
Atlassian warns of critical Confluence flaw
Israeli firm Bright Data named as enabler of Philippines government DDOS attacks on opposition groups
Cisco Issues Critical Fixes for High-End Nexus Gear
Man admits impersonating Apple support staff to steal 620,000 photos from iCloud accounts

security update

ProxyLogon flaw, evil emails, SQL injections used to open backdoors on Windows boxes
Win10 Admin Rights Tossed Off by Yet Another Plug-In
Mirai-style IoT botnet is now scanning for router-pwning critical vuln in Realtek kit
Build and improve your company’s culture of security with 1Password
US Media, Retailers Targeted by New SparklingGoblin APT

USN-5037-1 caused a regression in Firefox.

California Man Hacked iCloud Accounts to Steal Nude Photos
Building a DevSecOps culture and shifting security left
Security blind spots persist as companies cross-breed security with devops

An update that fixes one vulnerability is now available.