Menu

Monthly Archives: August 2021

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

Fake Apple rep amasses 620,000+ stolen iCloud pics, vids in hunt for images of nude women to trade

security update

security update

Microsoft Power Apps misconfiguration exposes millions of records

The caches of data that were publicly accessible included names, email addresses and social security numbers The post Microsoft Power Apps misconfiguration exposes millions of records appeared first on WeLiveSecurity

Poly Network Recoups $610M Stolen from DeFi Platform
The SideWalk may be as dangerous as the CROSSWALK

Meet SparklingGoblin, a member of the Winnti family The post The SideWalk may be as dangerous as the CROSSWALK appeared first on WeLiveSecurity

Pegasus Spyware Uses iPhone Zero-Click iMessage Zero-Day
How a gaming mouse can get you Windows superpowers!
Proofpoint wins $14m from ex-VP and French email security rival in IP theft court battle
Custom WhatsApp Build Delivers Triada Malware

Several security issues were fixed in OpenSSL.

Effective Threat-Hunting Queries in a Redacted World

Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit. CVE-2021-3711

What You Need to Know About Linux Rootkits>
Microsoft, Google partner on eBPF
Chinese auto-maker accused of altering data after fatal autonomous car accident

The container suse/sle15 was updated. The following patches have been included in this update:

Several security issues were fixed in the Linux kernel.

update to latest upstream release -fixes CVE-2021-38385

upstream release 1.13.1, including fix for CVE-2021-23358

Microsoft Spills 38 Million Sensitive Data Records Via Careless Power App Configs
Poly Network says it’s got pretty much all of that $610m in stolen crypto-coins back
Razer to fix Windows installer that grants admin powers if you plug in a mouse
38 million records exposed by misconfigured Microsoft Power Apps. Redmond’s advice? RTFM
ProxyShell Attacks Pummel Unpatched Exchange Servers
Worried ransomware merchants know more about file storage than you do? You should be…
What’s *THAT* on my 3D printer? Cloud bug lets anyone print to everyone
Windows 10 Admin Rights Gobbled by Razer Devices
Managing Privileged Access to Secure the Post-COVID Perimeter
Attackers Actively Exploiting Realtek SDK Flaws

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update that solves two vulnerabilities and has three fixes is now available.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Facebook sat on report that reveals most-shared post for months was questionable COVID story

An update that fixes one vulnerability is now available.

An issue has been found in ircii, an Internet Relay Chat client. A crafted CTCP UTC message could allow an attacker to disconnect the victim from an IRC server due to a segmentation fault and client crash.

Sync with F34 for CVE fixes.

Update to version 2.2.1. Resolves CVE-2021-38512 / RUSTSEC-2021-0081.

An update that fixes four vulnerabilities is now available.

T-Mobile confirms fifth data breach in three years

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

The 5.13.12 stable kernel update contains a number of important fixes across the tree.

Web Censorship Systems Can Facilitate Massive DDoS Attacks

– CVE-2021-37750 (explicit NULL deref on KDC)

Are you, the customer, the one paying the ransomware demand?

Ransomware payments may have greater implications than you thought – and not just for the company that gave in to the attackers’ demands The post Are you, the customer, the one paying the ransomware demand? appeared first on WeLiveSecurity

Japanese cryptocoin exchange robbed of $100,000,000
Nigerian Threat Actors Solicit Employees to Deploy Ransomware for Cut of Profits
Cloud load balancer snafu leads to 3D printer user printing on a stranger’s kit

Inetutils could be made to crash if it received specially crafted input.

Tails 4.22 Is Coming Soon! Contribute to Tails by Testing 4.22~rc1>

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 7 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

UK’s Surveillance Camera Commissioner grills Hikvision on China human rights abuses
What’s Next for T-Mobile and Its Customers? – Podcast
How Ready Are You for a Ransomware Attack?
Critical Cisco Bug in Small Business Routers to Remain Unpatched
InkySquid State Actor Exploiting Known IE Bugs

An update that contains security fixes can now be installed.

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 7 and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Windows EoP Bug Detailed by Google Project Zero
Health authorities in 40 countries targeted by COVID‑19 vaccine scammers

Fraudsters impersonate vaccine manufacturers and authorities overseeing vaccine distribution efforts, INTERPOL warns The post Health authorities in 40 countries targeted by COVID‑19 vaccine scammers appeared first on WeLiveSecurity

COVID-19 Contact-Tracing Data Exposed, Fake Vax Cards Circulate
Postmortem on U.S. Census Hack Exposes Cybersecurity Failures
Buyout of British defence supplier Ultra Electronics paused by UK.gov over competition concerns
Want to ban someone from Instagram? That’ll cost you just $60
S3 Ep46: Copyright scams, video snooping and Grand Theft Crypto [Podcast]
Smashing Security podcast #239: TikTok vigilantes, sloppy IoT, and Wikipedia woe
How to use Auth0 with Node.js and Express
After reportedly dragging its feet, BlackBerry admits, yes, QNX in cars, equipment suffers from BadAlloc bug

A potential security flaw was found on xscreensaver 5.45 which may cause buffer overflow or crash xscreensaver daemon. This vulnerability was assigned as CVE-2021-34557. This new rpm should fix this issue. Note that this issue does not affect xscreensaver 6.00 and above, so Fedora 34 xscreensaver is not affected.

Security fix for [CVE-2016-5851](https://nvd.nist.gov/vuln/detail/CVE-2016-5851). Updates to 0.8.11.

– fix CVE-2021-3246: a heap buffer overflow via crafted WAV file allows a arbitrary code execution

Security fix for [CVE-2016-5851](https://nvd.nist.gov/vuln/detail/CVE-2016-5851). Updates to 0.8.11.

OK, so you stole $600m-plus from us, how about you be our Chief Security Advisor, Poly Network asks thief

security update

Bogus Cryptomining Apps Infest Google Play
T-Mobile: >40 Million Customers’ Data Stolen

If you attended Black Hat this year, you couldn’t avoid the topic of supply chain attacks. From keynotes to vendor messaging to booth presentations, they were a ubiquitous topic in Las Vegas this year. Supply chain attacks are cyberattacks targeting an upstream vendor for the ultimate purpose of compromising one or more of its customers. […]

Nearly 2 million records from terrorist watchlist exposed online

The secret list was exposed online for three weeks, allowing anyone to access it without any kind of authentication The post Nearly 2 million records from terrorist watchlist exposed online appeared first on WeLiveSecurity

Dumpster diving is a filthy business

One man’s trash is another man’s treasure – here’s why you should think twice about what you toss in the recycling bin The post Dumpster diving is a filthy business appeared first on WeLiveSecurity

Researchers find high-severity command injection vuln in Fortinet’s web app firewall
Learn how a culture of security can improve security and productivity across your business with 1Password
Memory Bugs in BlackBerry’s QNX Embedded OS Open Devices to Attacks
Kerberos Authentication Spoofing: Don’t Bypass the Spec

An update is now available for Red Hat build of Eclipse Vert.x. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3160

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3154

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3158