Menu

Monthly Archives: September 2021

Cumulative bug-fix release from upstream.

– fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165)

Rebuild for CVE-2021-3672 in c-ares library

Update to 1.1.1l version

Update to 2.0.1; fix RHBZ#1932066 (unsafe use of strncpy), fix RHBZ#1932066

security update

Frustrated dev drops three zero-day vulns affecting Apple iOS 15 after six-month wait
Exchange/Outlook Autodiscover Bug Spills $100K+ Email Passwords

An update that solves 20 vulnerabilities and has 106 fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Rebase with Security fix for CVE-2021-3781

Update to 1.93, fixes CVE-2020-19752

Fix issue with incorrect obsoletes.

Bug in macOS Finder allows remote code execution

While Apple did issue a patch for the vulnerability, it seems that the fix can be easily circumvented The post Bug in macOS Finder allows remote code execution appeared first on WeLiveSecurity

FamousSparrow: A suspicious hotel guest

Yet another APT group that exploited the ProxyLogon vulnerability in March 2021 The post FamousSparrow: A suspicious hotel guest appeared first on WeLiveSecurity

TangleBot Malware Reaches Deep into Android Device Functions
S3 Ep51: OMIGOD a gaping hole, waybill scams, and Face ID hacked [Podcast]
Critical Cisco Bugs Allow Code Execution on Wireless, SD-WAN
Apple Patches 3 More Zero-Days Under Active Attack
Lithuania warns firms not to use Xiaomi and Huawei smartphones after investigation finds security and censorship concerns
The real value of continuous security scanning for cloud-based workloads
Stop worrying that crims could break the ‘net, say cyber-diplomats – only nations have tried
Apple warns of arbitrary code execution zero-day being actively exploited on Macs
REvil Affiliates Confirm: Leadership Were Cheating Dirtbags
STILL ALIVE! iOS 12 gets 3 zero-day security patches – update now
5 Tips for Achieving Better Cybersecurity Risk Management

Multiple issues have been discovered in mupdf. CVE-2016-10246

100M IoT Devices Exposed By Zero-Day Bug
How Outlook “autodiscover” could leak your passwords – and how to stop it
Plugging the holes: How to prevent corporate data leaks in the cloud

Misconfigurations of cloud resources can lead to various security incidents and ultimately cost your organization dearly. Here’s what you can do to prevent cloud configuration conundrums. The post Plugging the holes: How to prevent corporate data leaks in the cloud appeared first on WeLiveSecurity

Smashing Security podcast #244: Facebook Ray-Bans, VPN spies, and AI camouflage
US Government tells firms not to give in to ransomware demands, as first crypto exchange sanctioned for laundering cyber ransoms
FamousSparrow APT Wings in to Spy on Hotels, Governments

Red Hat Advanced Cluster Management for Kubernetes 2.1.11 General Availability release images, which provide a security fix and update the container images. Red Hat Product Security has rated this update as having a security impact

Google Report Spotlights Uptick in Controversial ‘Geofence Warrants’ by Police
Acronis Offers up to $5,000 to Users Who Spot Bugs in Its Cyber Protection Products
Domain Brand Monitor: The First Brand Protection Layer by WhoisXML API
UK Ministry of Defence apologises – again – after another major email blunder in Afghanistan

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Large-Scale Phishing-as-a-Service Operation Exposed
Researchers finger new APT group, FamousSparrow, for hotel attacks
Zoom’s $15bn merger with Five9 probed by Uncle Sam for national security risks
Apple tried to patch this security hole in macOS Finder but didn’t consider upper and lowercase characters
Crystal Valley Farm Coop Hit with Ransomware
Predict 21 – the intelligence summit from Recorded Future you cannot afford to miss, October 12-13 2021
Lithuania tells its citizens to throw Xiaomi mobile devices in the bin
Facebook’s Ray-Ban Stories glasses have got a problem
Netgear SOHO Security Bug Allows RCE, Corporate Attacks
Unpatched Apple Zero-Day in macOS Finder Allows Code Execution
European police dismantle cybercrime ring with ties to Italian Mafia

The group used phishing, BEC and other types of attacks to swindle victims out of millions The post European police dismantle cybercrime ring with ties to Italian Mafia appeared first on WeLiveSecurity

How REvil May Have Ripped Off Its Own Affiliates
VMware Warns of Ransomware-Friendly Bug in vCenter Server
TikTok, GitHub, Facebook Join Open-Source Bug Bounty

A security vulnerability has been found in Kaminari, a pagination engine plugin for Rails 3+ and other modern frameworks, that would allow an attacker to inject arbitrary code into pages with pagination links.

Several security issues were fixed in WebKitGTK.

Microsoft Exchange Autodiscover protocol found leaking hundreds of thousands of credentials
VMware patch bulletin warns: “This needs your immediate attention.”

SQL parse could be made to denial of service if it received a specially crafted regular expression.

Red Hat Insights and the delivery of a new security recommendation

IBM s390x systems could be made to crash or run programs as an administrator.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

Break out your emergency change process and patch this ransomware-friendly bug ASAP, says VMware
Database containing personal info on 106m people who traveled to Thailand found open to the internet – report

security update

Suex to be you: Feds sanction cryptocurrency exchange for handling payments from 8+ ransomware variants
Epik Confirms Hack, Gigabytes of Data on Offer
Hackers Are Going ‘Deep-Sea Phishing,’ So What Can You Do About It?
iOS 15 includes Face ID fix for security bypass using fake heads
Turla APT Plants Novel Backdoor In Wake of Afghan Unrest
BlackMatter Strikes Iowa Farmers Cooperative, Demands $5.9M Ransom
46% of On-Prem Databases Globally Contain Vulnerabilities: Is Yours Safe?
Fix network printing or keep Windows secure? Admins would rather disable PrintNightmare patch

Update to 2.32.4: * Do not append .asc extension to downloaded text/plain files. * Fix several crashes and rendering issues. * Fix CVE-2021-30858

– CVE-2021-22947 – STARTTLS protocol injection via MITM – CVE-2021-22946 – protocol downgrade required TLS bypassed – CVE-2021-22945 – use-after-free and double-free in MQTT sending

Backport patch for CVE-2021-23437.

Backport patch for CVE-2021-23437.

UK Ministry of Defence apologises after Afghan interpreters’ personal data exposed in email blunder

Backport patch for CVE-2021-23437.

Backport patch for CVE-2021-23437.

106 arrests as police dismantle Mafia-linked online crime gang
Mafia works remotely, too, it seems: 100+ people suspected of phishing, SIM swapping, email fraud cuffed
You’ve trained at the cutting edge, here’s how to keep your DFIR skills razor sharp
Amazon Driver-Surveillance Cameras Roll Out, Sparking Debate
Apache OpenOffice can be hijacked by malicious documents, fix still in beta

security update

Europol Breaks Open Extensive Mafia Cybercrime Ring
Payment API Bungling Exposes Millions of Users’ Payment Data
Ransomware recovery: Start getting back up before you’re even hit
“Back to basics” as courier scammers skip fake fees and missed deliveries
Bring Your APIs Out of the Shadows to Protect Your Business

Rebase with Security fix for CVE-2021-3781

Rebuild for dovecot 2.3.16 —- Rebuild for dovecot 2.3.16

– fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165)

An update for rh-ruby27-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Tick, tick, tick … TikTok China just limited kids to 40 minutes’ use each day