Menu

Monthly Archives: September 2021

An update that solves one vulnerability and has one errata is now available.

Two vulnerabilities were discovered in the Nextcloud desktop client, which could result in information disclosure. For the oldstable distribution (buster), these problems have been fixed

The legacy 1.0 version of OpenSSL, a cryptography library for secure communication, fails to validate alternate trust chains in some conditions. In particular this breaks connecting to servers that use Let’s Encrypt certificates, starting 2021-10-01.

Multiple vulnerabilities were discovered in nettle, a low level cryptographic library, which could result in denial of service (remote crash in RSA decryption via specially crafted ciphertext, crash on ECDSA signature verification) or incorrect verification of ECDSA signatures.

Yes, of course there’s now malware for Windows Subsystem for Linux

GnuTLS, a portable cryptography library, fails to validate alternate trust chains in some conditions. In particular this breaks connecting to servers that use Let’s Encrypt certificates, starting 2021-10-01.

Porn Problem: Adult Ads Persist on US Gov’t, Military Sites
Something phishy: Tech recruiters jabbed by fake COVID-19 Passport scam
Ditch the Alert Cannon: Modernizing IDS is a Security Must-Do
Is it OK to use stolen data? What if it’s scientific research in the public interest?
AT&T Phone-Unlocking Malware Ring Costs Carrier $200M
Free decryptor for past REvil ransomware victims released
Microsoft MSHTML Flaw Exploited by Ryuk Ransomware Gang
Applying DevSecOps practices to Kubernetes: security analysis and remediation

Update to 2.2.17

Upstream annoucement: [WordPress 5.8.1 Security and Maintenance Release](https://wordpress.org/news/2021/09/wordpress-5-8-1-security-and- maintenance-release/)

Another race in XENMAPSPACE_grant_table handling [XSA-384, CVE-2021-28701] bugfix for XSA-380

Fake Walmart press release causes cryptocurrency price surge
WTF? Microsoft makes fixing deadly OMIGOD flaws on Azure your job

The container caasp/v4.5/kube-scheduler was updated. The following patches have been included in this update:

The container caasp/v4.5/kube-proxy was updated. The following patches have been included in this update:

The container caasp/v4.5/kube-controller-manager was updated. The following patches have been included in this update:

CISA, FBI: State-Backed APTs May Be Exploiting Critical Zoho Bug
Aviation-themed phishing campaign pushed off-the-shelf RATs into inboxes for 5 years
Airline Credential-Theft Takes Off in Widening Campaign
Hack yourself before someone else does it for you
Microsoft Patch Tuesday fixes actively exploited zero‑day and 85 other flaws

The most recent Patch Tuesday includes a fix for the previously disclosed and actively exploited remote code execution flaw in MSHTML. The post Microsoft Patch Tuesday fixes actively exploited zero‑day and 85 other flaws appeared first on WeLiveSecurity

OMIGOD, an exploitable hole in Microsoft open source code!
Ransomware-hit law firm secures High Court judgment against unknown criminals

Several security issues were fixed in Python.

Several security issues were fixed in Qt.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Libgcrypt could be made to expose sensitive information.

Financial Cybercrime: Following Cryptocurrency via Public Ledgers
REvil/Sodinokibi Ransomware Universal Decryptor Key Is Out
DDoS Attacks: A Flourishing Business for Cybercrooks – Podcast
Computer and data scientists should be as highly regarded as ‘warriors’ says top UK cybergeneral
HP Omen Hub Exposes Millions of Gamers to Cyberattack
Azure Zero-Day Flaws Highlight Lurking Supply-Chain Risk

An update that solves one vulnerability and has three fixes is now available.

De-identify, re-identify: Anonymised data’s dirty little secret
It’s time to delete that hunter2 password from your Microsoft account, says IT giant
This is AUKUS for China – US, UK, Australia reveal defence tech-sharing pact
Smashing Security podcast #243: Breaking news, Apple zero-clicks, and bad blood
No Patch for High-Severity Bug in Legacy IBM System X Servers
Don’t miss Predict 21 – Recorded Future’s intelligence summit, October 12-13 2021
WhatsApp announces end‑to‑end encrypted backups

The Facebook-owned messaging service plans to roll out the feature to both iOS and Android users in the coming weeks. The post WhatsApp announces end‑to‑end encrypted backups appeared first on WeLiveSecurity

What is a cyberattack surface and how can you reduce it?

Discover the best ways to mitigate your organization’s attack surface, in order to maximize cybersecurity. The post What is a cyberattack surface and how can you reduce it? appeared first on WeLiveSecurity

S3 Ep50: Two 0-days plus another 0-day plus a fast food bug [Podcast]

Squashfs-Tools could be made to overwrite files.

Attackers Impersonate DoT in Two-Day Phishing Scam
Ransomware crims saying ‘We’ll burn your data if you get a negotiator’ can’t be legally paid off anyway
Advanced automation and management of Network Bound Disk Encryption with RHEL System Roles

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Several security issues were fixed in curl.

Squashfs-Tools could be made to overwrite files.

The container ses/7/rook/ceph was updated. The following patches have been included in this update:

Ex-US intel, military trio were cyber-mercenaries for UAE, say prosecutors
Microsoft’s end-of-summer software security cleanse crushes more than 80 bugs
Adobe Snuffs Critical Bugs in Acrobat, Experience Manager
Microsoft Patches Actively Exploited Windows Zero-Day Bug
2021’s Most Dangerous Software Weaknesses
Krita art app users targeted by ransomware posing as paid ‘collaboration’ opportunities
ZLoader’s Back, Abusing Google AdWords, Disabling Windows Defender
Beware of these 5 common scams you can encounter on Instagram

From cybercriminal evergreens like phishing to the verification badge scam we look at the most common tactics fraudsters use to trick their victims The post Beware of these 5 common scams you can encounter on Instagram appeared first on WeLiveSecurity

Security bods boost Apple iPhone hardware attack research with iTimed toolkit
Brits open doors for tech-enabled fraudsters because they ‘don’t want to seem rude’
Pair of Google Chrome Zero-Day Bugs Actively Exploited
Unpatched Bugs Plague Databases; Your Data Is Probably Not Secure – Podcast
Romance, BEC Scams Lands Soldier in Jail for 46 Months
Thousands of internet-connected databases contain high or critical CVEs, says report by cloud security biz

An update that fixes four vulnerabilities is now available.

BlackMatter Ransomware Hits Japanese Tech Giant Olympus

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Open-Source Tool of the Month: Uptycs Addresses Modern Cloud-Native & Containerization Security Challenges with its Uptycs Security Analytics Platform>
SPDX becomes internationally recognized standard>

The 5.13.15 stable kernel update contains a number of important fixes across the tree.

update to 1.1.1l

ExpressVPN bought for $1bn by Brit biz with an intriguing history in adware
Apple products vulnerable to FORCEDENTRY zero-day attack – patch now!
Apple emergency patches fix zero-click iMessage bug used to inject NSO spyware
Apple Issues Emergency Fix for NSO Zero-Click Zero Day
How a glitch in the Matrix led to apps potentially exposing encrypted chats
REvil’s Back; Coder Fat-Fingered Away Its Decryptor Key?
WhatsApp’s End-to-End Encryption Isn’t Actually Broken
Honing Cybersecurity Strategy When Everyone’s a Target for Ransomware
WooCommerce Multi Currency Bug Allows Shoppers to Change eCommerce Pricing
Serious Security: How to make sure you don’t miss bug reports!
“Foolish” university hacker jailed after selling exam papers to fellow students
Open redirect on UK council website was being used for Royal Mail-themed parcel payments scam

This advisory resolves CVE issues filed against XP2 releases that have been fixed in the underlying EAP 7.3.x base. There are no changes to the EAP XP2 code base. NOTE: This advisory is informational only. There are no code changes

Time is running out for CentOS 8>
CloudLinux Adds TuxCare Support for CentOS 8 Through 2025>

This update upgrades Thunderbird to version 78.14.0. * Mozilla: Memory safety bugs fixed in Firefox 92, Firefox ESR 78.14 and Firefox ESR 91.1 (CVE-2021-38493) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 – thunderbird-78.14.0-1.el7_9.x86_64.rpm – thunderbird-debuginfo-78.1 [More…]

This update upgrades Firefox to version 78.14.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 92, Firefox ESR 78.14 and Firefox ESR 91.1 (CVE-2021-38493) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 – firefox-78.14.0-1.el7_9.i686.rpm – firefox-78.14.0-1.el7_9.x86_64.r [More…]

An update that contains security fixes can now be installed.