Menu

Monthly Archives: August 2021

Un-carrier? Definitely Unsecure: T-Mobile US admits 48m customers’ details stolen after downplaying reports
Unpatched Fortinet Bug Allows Firewall Takeovers
HolesWarm Malware Exploits Unpatched Windows, Linux Servers   

This update upgrades Firefox to version 78.13.0 ESR. * Mozilla: Uninitialized memory in a canvas object could have led to memory corruption (CVE-2021-29980) * Mozilla: Incorrect instruction reordering during JIT optimization (CVE-2021-29984) * Mozilla: Race condition when resolving DNS names could have led to memory corruption (CVE-2021-29986) * Mozilla: Memory corruption as a result of […]

exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp (CVE-2021-31291) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE – Scientific Linux Development Team

China orders annual security reviews for all critical information infrastructure operators
Apple says its CSAM scan code can be verified by researchers. Corellium starts throwing out dollar bills
The Overlooked Security Risks of The Cloud
Video surveillance network hacked by researchers to hijack footage
LockBit 2.0 Ransomware Proliferates Globally
Bug in Millions of Flawed IoT Devices Lets Attackers Eavesdrop
If you haven’t updated your ThroughTek DVR since 2018 do so now, warns Mandiant as critical vuln surfaces
Terrorist Watchlist Exposed Online with Nearly 1.9M Records
The cloud changes the game for cybersecurity incident response – here’s how to master the new rules
Apple: CSAM Image-Detection Backdoor ‘Narrow’ in Scope

Several security issues were fixed in HAProxy.

How to Reduce Exchange Server Downtime in Case of a Disaster?

Several vulnerabilities were discovered in HAProxy, a fast and reliable load balancing reverse proxy, which can result in HTTP request smuggling. By carefully crafting HTTP/2 requests, it is possible to smuggle another HTTP request to the backend selected by the HTTP/2

British defence supplier Ultra Electronics to be sold for £2.6bn to US-controlled firm

sssd: shell command injection in sssctl (CVE-2021-3621) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE – Scientific Linux Development Team

kernel: Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks (CVE-2021-22543) * kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c (CVE-2021-22555) * kernel: race condition for removal of the HCI controller (CVE-2021-32399) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other relate [More…]

kernel: Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks (CVE-2021-22543) * kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c (CVE-2021-22555) * kernel: race condition for removal of the HCI controller (CVE-2021-32399) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other relate [More…]

hw: Vector Register Data Sampling (CVE-2020-0548) * hw: L1D Cache Eviction Sampling (CVE-2020-0549) * hw: Special Register Buffer Data Sampling (SRBDS) (CVE-2020-0543) * hw: Information disclosure issue in Intel SGX via RAPL interface (CVE-2020-8695) * hw: Vector Register Leakage-Active (CVE-2020-8696) * hw: Fast forward store predictor (CVE-2020-8698) * hw: vt-d related privilege escala [More…]

Survey finds vast majority of people reusing personal passwords in the workplace, despite security training
Phishing Costs Nearly Quadrupled Over 6 Years
Pakistan’s tax office services go dark after migration project goes awry
Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets
Remote code execution flaws lurk in countless routers, IoT gear, cameras using Realtek Wi-Fi module SDKs
T-Mobile US probes claims of 100m stolen customer records up for sale on dark web
XSS Bug in SEOPress WordPress Plugin Allows Site Takeover
Copyright scammers turn to phone numbers instead of web links
100m T-Mobile Customer Records Purportedly Up for Sale
Dallas cops lost 8TB of criminal case data during bungled migration, says the DA… four months later
Indra hacking group blamed for attack on Iranian railway system that trolled country’s supreme leader
T-Mobile USA investigates possible breach after hacker offers to sell customer data
Apple’s iPhone computer vision has the potential to preserve privacy but also break it completely

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 9 stretch, these problems have been fixed in version

It was discovered that systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis (Spectre v2).

An update for exiv2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Security Spotlight: Experience Enhanced Privacy & Security with Predator-OS>

An update that fixes one vulnerability is now available.

Updated sylpheed and claws-mail packages fix security vulnerability: The textview_uri_security_check() function in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click (CVE-2021-37746).

Updated thunderbird packages fix security vulnerabilities: Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash (CVE-2021-29980).

Updated qtwebengine5 packages fix security vulnerabilities: The qtwebengine5 package has been updated to version 5.15.5, fixing several security issues in the bundled chromium code.

Updated spice packages fix security vulnerability: A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the stable distribution (bullseye), these problems have been fixed in

security update

security update

security update

The recent fix for CVE-2021-33574 released in MGASA-2021-0308 introduced a NULL pointer dereference that will result in segmentation fault. This update adds the missing NULL pointer check to resolve this issue. References:

Updated firefox packages fix security vulnerabilities: Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash (CVE-2021-29980).

Updated mariadb packages fix security vulnerabilities: A security issue has been found in the InnoDB component of MariaDB before version 10.6.4. A difficult to exploit vulnerability allows a high privileged attacker with network access via multiple protocols to

Updated dino packages fix security vulnerability: Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators (CVE-2021-33896).

Updated webkit2 packages fix security vulnerabilities: A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further

Updated libvirt packages fix security vulnerability: insecure sVirt label generation (CVE-2021-3631). References:

I was offered $500k as a thank-you bounty for pilfering $600m from Poly Network, says crypto-thief
Amazon’s Plan to Track Worker Keystrokes: A Sign of Controls to Come?
Cyberattackers Embrace CAPTCHAs to Hide Phishing, Malware
SolarWinds 2.0 Could Ignite Financial Crisis – Podcast
Exchange Servers Under Active Attack via ProxyShell Bugs
Examining threats to device security in the hybrid workplace

As employees split their time between office and off-site work, there’s a greater potential for company devices and data to fall into the wrong hands The post Examining threats to device security in the hybrid workplace appeared first on WeLiveSecurity

Fancy joining the SAS’s secret hacker squad in Hereford as an electronics engineer for £33k?
WordPress Sites Abused in Aggah Spear-Phishing Campaign
Before I agree to let your app track me everywhere, I want something ‘special’ in return (winks)…
Understanding and verifying security of Diffie-Hellman parameters
Use automated snapshots to defend against ransomware with NetApp and Red Hat Ansible Automation Platform

An update that fixes three vulnerabilities is now available.

United Nations calls for moratorium on sale of surveillance tech like NSO Group’s Pegasus
Re-volting: AMD Secure Encrypted Virtualization undone by electrical attack
China stops networked vehicle data going offshore under new infosec rules
FISMA’s a fizzer, says Cisco, and calls on Congress to get cyber security policy right – pronto

An update that fixes one vulnerability is now available.

Several vulnerabilities were fixed in curl, a client-side URL transfer library. CVE-2021-22898

Huawei stole our tech and created a ‘backdoor’ to spy on Pakistan, claims IT biz
GitHub picks Friday 13th to kill off password-based Git authentication

Fedora 33 Fixed 1984005 Fedora 34 – Fixed CVE-2021-36770 – Ensure that UTF-16 decode always includes a trailing NUL. – Replace non-ASCII apostrophes w/ x27, which were introduced in #155 – Addressed: find_encoding returns Internal encoding `Unicode` is no longer a valid encoding name.

Rogue Marketplace AlphaBay Reboots

security update

security update

US govt scores a point against Assange in run-up to extradition appeal showdown
Black Hat: Novel DNS Hack Spills Confidential Corp Data

The system could be made to crash or run programs as an administrator.

Lukas Euler discovered a path traversal vulnerability in commons-io, a Java library for common useful IO related classes. When invoking the method FileNameUtils.normalize with an improper input string, like “//../foo”, or “\..foo”, the result would be the same value, thus possibly providing access

AdLoad Malware 2021 Samples Skate Past Apple XProtect
Think your backups will protect you against ransomware? They’re top of the target list
IISerpent: Malware‑driven SEO fraud as a service

The last in our series on IIS threats introduces a malicious IIS extension used to manipulate page rankings for third-party websites The post IISerpent: Malware‑driven SEO fraud as a service appeared first on WeLiveSecurity

Ransomware Payments Explode Amid ‘Quadruple Extortion’
Lockbit ransomware attack didn’t affect ops, claims Accenture amid lurid payoff rumours
S3 Ep45: Routers attacked, hacking tool hacked, and betrayers betrayed [Podcast]
Accenture hit by apparent ransomware attack
QR Code Scammers Get Creative with Bitcoin ATMs
Microsoft Warns: Another Unpatched PrintNightmare Zero-Day

An update that solves 5 vulnerabilities, contains one feature and has one errata is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability, contains one feature is now available.

Using RHEL System Roles to automate and manage Network Bound Disk Encryption
COVID-19 cases surge as do sales of fake vaccination cards – around $100 for something you could get free