Menu

Monthly Archives: September 2021

Revealed: How to steal money from victims’ contactless Apple Pay wallets
Google Emergency Update Fixes Two Chrome Zero Days

Fix for CVE-2021-20208 Update to 6.13 cifs.upcall: fix regression in kerberos mount mount.cifs: fix crash when mount point does not exist —- Fix for CVE-2021-20208: cifs.upcall kerberos auth leak in container

Fix for CVE-2021-20208 Update to 6.13 cifs.upcall: fix regression in kerberos mount mount.cifs: fix crash when mount point does not exist —- Fix for CVE-2021-20208: cifs.upcall kerberos auth leak in container

Several problems were corrected in TagLib, a library for reading and editing audio meta data. CVE-2017-12678

Military’s RFID Tracking of Guns May Endanger Troops

Several vulnerabilities were fixed in MIT Kerberos, a system for authenticating users and services on a network. CVE-2018-5729

Ransomware crim: Yeah, what I do is bad. No, I don’t care. Yes, infosec bods are all mouth and no trousers
Tips & Tricks for Unmasking Ghoulish API Behavior
Baby’s Death Alleged to Be Linked to Ransomware
Innovative Proxy Phantom ATO Fraud Ring Haunts eCommerce Accounts
CISA and NSA release guidance for securing VPNs

What your organization should consider when it comes to choosing a VPN solution and hardening it against attacks The post CISA and NSA release guidance for securing VPNs appeared first on WeLiveSecurity

How to steal money via Apple Pay using the “Express Transit” feature
S3 Ep52: Let’s Encrypt, Outlook leak, and VMware exploit [Podcast]
Which? survey finds people would actually pay the online giants not to take their data
Apple Pay with Visa Hacked to Make Payments via Locked iPhones
Beware poisoned Apple AirTags that exploit unpatched “Lost Mode” flaw
Secret backdoor allegedly lets the REvil ransomware gang scam its own affiliates
US cryptocurrency expert pleads guilty to helping North Korea evade sanctions

An update for the virt:av and virt-devel:av modules is now available for Red Hat Enterprise Linux Advanced Virtualization 8.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The Top Ransomware Threats Aren’t Who You Think
Thousands of University Wi-Fi Networks Expose Log-In Credentials

Several vulnerabilities were fixed in the chat client WeeChat. CVE-2020-8955

UK MoD data strategy calls for social media surveillance on behalf of ‘local authorities’
How to prevent CSRF attacks in ASP.NET Core
Attacks against Remote Desktop Protocol endpoints have exploded this year, warns ESET’s latest Threat Report

Red Hat AMQ Broker 7.9.0 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

The container sles-15-sp3-chost-byos-v20210927 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20210927-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20210927-gen2 was updated. The following patches have been included in this update:

Anonymous: We’ve leaked disk images stolen from far-right-friendly web host Epik
Keep Attackers Out of VPNs: Feds Offer Guidance
Smashing Security podcast #245: The Julian Assange assassination plot, and IoT toilets
Don’t look a GriftHorse in the mouth: Trojan trampled 10 million Android devices
Apple AirTag Zero-Day Weaponizes Trackers
Unpatched flaw ‘weaponises’ Apple AirTags to turn them into the phisherman’s friend
GriftHorse Money-Stealing Trojan Takes 10M Android Users for a Ride
Akamai beefs up cybersecurity portfolio with ransomware-tastic Guardicore acquisition
Conti Ransomware Expands Ability to Blow Up Backups
Kaspersky links new Tomiris malware to Nobelium group
SAS 2021: ‘Tomiris’ Backdoor Linked to SolarWinds Malware
Threat Actors Weaponize Telegram Bots to Compromise PayPal Accounts

An update that fixes one vulnerability is now available.

The Migration Toolkit for Containers (MTC) 1.6.0 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Red Hat OpenShift Container Platform release 4.7.32 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

Give put-upon infosec bods professional recognition to keep them working for you, says chartered institute

Red Hat OpenShift Container Platform release 4.6.46 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

REvil customers complain ransomware gang uses backdoors to filch ransoms

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

How secrets (mis)management is the next big cybersecurity threat – download the 1Password report
How to Prevent Account Takeovers in 2021
Gamers Beware: Malware Hunts Steam, Epic and EA Origin Accounts
ASUS patches ROG Armoury Crate app after researcher spots all-too-common flaw
SAS 2021: FinSpy Surveillance Kit Re-Emerges Stronger Than Ever
Google releases emergency fix to plug zero‑day hole in Chrome

The emergency release comes a mere three days after Google’s previous update that plugged another 19 security loopholes The post Google releases emergency fix to plug zero‑day hole in Chrome appeared first on WeLiveSecurity

Serious Security: Let’s Encrypt gets ready to go it alone (in a good way!)
Latest FinFisher spyware upgrades ‘particularly worrying,’ says Kaspersky
Romance scammers arrested in Texas for defrauding elderly lonely hearts
Assume Nothing: The story of the TalkTalk hack
Working Exploit Is Out for VMware vCenter CVE-2021-22005 Flaw
SolarWinds Attackers Hit Active Directory Servers with FoggyWeb Backdoor
How to secure cloud infrastructure across the development lifecycle
UK umbrella payroll firm GiantPay confirms it was hit by ‘sophisticated’ cyber-attack

USN-5090-1 introduced a regression in Apache HTTP Server.

All You Need To Know About IT Security Audits and Its Importance>

Several security issues were fixed in Vim.

USN-5090-1 introduced a regression in Apache HTTP Server.

Microsoft warns: Active Directory FoggyWeb malware being actively used by Nobelium gang

An update for fwupd, shim, shim-unsigned-aarch64, and shim-unsigned-x64 is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Credential Spear-Phishing Uses Spoofed Zix Encrypted Email

An update that fixes 5 vulnerabilities is now available.

Q2 2022 should see networking sales boom – when payouts to replace Huawei and ZTE kit start to flow
Emails, chat logs, more leaked online from far-right militia linked to US Capitol riot
Blockhead admits to helping North Korea mine crypto-bucks, faces 20 years jail
India, Japan flex cyber-defence muscles as China kicks the Quad
Story of the creds-leaking Exchange Autodiscover flaw – the one Microsoft wouldn’t fix even after 5 years
5 Steps to Securing Your Network Perimeter
Women, Minorities Are Hacked More Than Others
Move faster with continuous security scanning in the cloud
EU: Russia Behind ‘Ghostwriter’ Campaign Targeting Germany
3.8 Billion Users’ Combined Clubhouse, Facebook Data Up for Sale
UK’s National Crime Agency WLTM Deputy Director of Digital Data & Technology

Several security issues were fixed in Apache HTTP Server.

Fake ‘BT’ caller fleeces elderly victim of £30k in APP app scam

Several security issues were fixed in Apache HTTP Server.

Apache Santuario, XML Security for Java, is vulnerable to an issue where the “secureValidation” property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3438

Cyber security in the public cloud

An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

‘Quad’ group seeks to set security standards for global tech industry

An issue has been found in openssl, a Secure Sockets Layer toolkit. Ingo Schwarze reported a buffer overrun flaw when processing ASN.1 strings, which can result in denial of service.

An update that fixes 19 vulnerabilities is now available.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes one vulnerability is now available.

Update to latest in git.

update for sharpziplib 1.3.3 which contains a security fix

update for sharpziplib 1.3.3 which contains a security fix

Update to v1.41.1 Fix CVE-2021-39163, CVE-2021-39164