Menu

Monthly Archives: September 2021

Several security issues were fixed in the kernel.

You can ‘go your own way’ over GDPR, says UK’s new Information Commissioner

Update to Chromium 93. There have been … a few security fixes since the last Fedora chromium update. This update fixes the following CVEs: CVE-2021-30565 CVE-2021-30566 CVE-2021-30567 CVE-2021-30568 CVE-2021-30569 CVE-2021-30571 CVE-2021-30572 CVE-2021-30573 CVE-2021-30574 CVE-2021-30575 CVE-2021-30576 CVE-2021-30577 CVE-2021-30578 CVE-2021-30579 CVE-2021-30580 CVE-2021-30581

security update

It was found that the patch for CVE-2021-3592 introduced a regression which prevented ssh connections to the host system. Since there is no imminent solution for the problem, the patch for CVE-2021-3592 has been reverted. Updated qemu packages are now available to correct this issue.

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the oldstable distribution (buster), this problem has been fixed

WhatsApp to offer end-to-end encrypted backups in iCloud, Google Drive with user-managed keys

security update

security update

security update

MyRepublic Data Breach Raises Data-Protection Questions
Top Steps for Ransomware Recovery and Preparation
Hey – how did you get in here? Number one app security weakness of 2021 was borked access control, says OWASP

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Yandex Pummeled by Potent Meris DDoS Botnet
SOVA, Worryingly Sophisticated Android Trojan, Takes Flight
5 Steps For Securing Your Remote Work Space

* New upstream version (92.0)

Update to latest upstream release 2.0.12

Applying DevSecOps practices to Kubernetes: software supply chain
Stolen Credentials Led to Data Theft at United Nations

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Ghostscript could be made to crash, access files, or run programs if it opened a specially crafted file.

It was discovered that Ghostscript, the GPL PostScript/PDF interpreter, does not properly validate access for the “%pipe%”, “%handle%” and “%printer%” io devices, which could result in the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER

security update

Thousands of Fortinet VPN Account Credentials Leaked
McDonald’s Email Blast Includes Password to Monopoly Game Database
Howard University suffers cyberattack, suspends online classes in aftermath

The university suffered a ransomware attack, however there is no evidence so far of data being accessed or stolen. The post Howard University suffers cyberattack, suspends online classes in aftermath appeared first on WeLiveSecurity

Financial Cybercrime: Why Cryptocurrency is the Perfect ‘Getaway Car’
S3 Ep49: Poison PACs, pointless alarms and phunky bugs [Podcast]
‘Azurescape’ Kubernetes Attack Allows Cross-Container Cloud Compromise
SideWalk Backdoor Linked to China-Linked Spy Group ‘Grayfly’
Microsoft warns of a Windows zero-day security hole that is being actively exploited

Kevin Israel discovered that Postorius, the administrative web frontend for Mailman 3, didn’t validate whether a logged-in user owns the email address when unsubscribing.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Update to CVE release 3003.3-1 https://saltproject.io/security_announcements/salt-security- advisory-2021-sep-02/ CVE-2021-21996 CVE-2021-22004 CVE-2021-31607

Build of libtpms 0.8.5

8u302 update

Update to CVE release 3003.3-1 https://saltproject.io/security_announcements/salt-security- advisory-2021-sep-02/ CVE-2021-21996 CVE-2021-22004 CVE-2021-31607

Zoho Password Manager Zero-Day Bug Under Active Attack Gets a Fix
McDonald’s email blunder broadcasts database creds to comedy competition winners
BladeHawk Attackers Target Kurds with Android Apps
Why distroless containers aren’t the security solution you think they are
Hear me speak about endpoint security and ransomware at two free webinars next week
Smashing Security podcast #242: ProtonMail privacy questioned, and Banksy blunder
LA cops told to harvest social media handles from people they stop, suspect or not
Microsoft fixes flaw that could leak data between users of Azure container services
What Ragnar Locker Got Wrong About Ransomware Negotiators – Podcast

security update

New Zealand DDoS wave targets banks, post offices, weather forecasters and more
Tooling Network Detection & Response for Ransomware
Proton welcomes Sir Tim Berners-Lee to its advisory board – as ProtonMail suffers a privacy backlash
Spoofing Bug Highlights Cybersecurity for Digital Vaccine Passports
3 years, 17 alphas, 2 betas, and over 7,500 commits later, OpenSSL version 3 is here
TeamTNT’s New Tools Target Multiple OS
ProtonMail forced to log user’s IP address after an order from Swiss authorities

Following the incident the company has updated its website and privacy policy to clarify its legal obligations to its userbase The post ProtonMail forced to log user’s IP address after an order from Swiss authorities appeared first on WeLiveSecurity

BladeHawk group: Android espionage against Kurdish ethnic group

ESET researchers have investigated a targeted mobile espionage campaign against the Kurdish ethnic group, and that has been active since at least March 2020. The post BladeHawk group: Android espionage against Kurdish ethnic group appeared first on WeLiveSecurity

Windows zero-day MSHTML attack – how not to get booby trapped!
UK.gov is launching an anti-Facebook encryption push. Don’t think of the children: Think of the nuances and edge cases instead
Microsoft, CISA Urge Mitigations for Zero-Day RCE Flaw in Windows
AT&T Alien Labs warns of ‘zero or low detection’ for TeamTNT’s latest malware bundle
Global pandemic was good for business, say UK infosec pros – but we’re still burning out

kernel: use-after-free in route4_change() in net/sched/cls_route.c (CVE-2021-3715) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * [SL 7.8][s390x][DASD]Crash in __list_del_entry, alias_pav_group list corrupt when running dasd_alias_remove_device() * EMBARGOED CVE-2021-3715 kern [More…]

Update to v1.41.1 Fix CVE-2021-39163, CVE-2021-39164 —- Update to v1.41.0

Cumulative bug-fix release from upstream.

– fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165)

Cumulative bug-fix release from upstream.

Alleged Russian malware developer arrested after being stranded in South Korea due to COVID-19 pandemic

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Patch now? Why enterprise exploits are still partying like it’s 1999
Ransomware attacks are inevitable. Paying the ransom isn’t
Ragnar Locker Gang Warns Victims Not to Call the FBI
Miscreants fling booby-trapped Office files at victims, no patch yet, says Microsoft
Can WhatsApp moderators really read your encrypted texts? Yes … if you forward them to the abuse dept
Netgear Smart Switches Open to Complete Takeover
Jenkins Hit as Atlassian Confluence Cyberattacks Widen
ProtonMail Forced to Log IP Address of French Activist
Authorities Arrest Another TrickBot Gang Member in South Korea

An update for kernel is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Update NTFS-3G to 2021.8.22 to fix multiple CVEs

Update NTFS-3G to 2021.8.22 to fix multiple CVEs

Update NTFS-3G to 2021.8.22 to fix multiple CVEs

Update NTFS-3G to 2021.8.22 to fix multiple CVEs

Update NTFS-3G to 2021.8.22 to fix multiple CVEs

British data watchdog brings cookies to G7 meeting – pop-up consent requests, not the delicious baked treats
If you contact the police, we *will* leak your data – warns Ragnar Locker ransomware gang
Holy Grail of Security: Answers to ‘Did XYZ Work?’ – Podcast
ProtonMail deletes ‘we don’t log your IP’ boast from website after French climate activist reportedly arrested
Guntrader breach perp: I don’t think it’s a crime to dump 111k people’s details online in Google Earth format
Glasgow firm fined £150k after half a million nuisance calls, spoofing phone number, using false trading names

An issue has been found in btrbk, a backup tool for btrfs subvolumes. Due to mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys an arbitrary code execution would

IOMMU page mapping issues on x86 [XSA-378, CVE-2021-28694, CVE-2021-28695, CVE-2021-28696] (#1997531) (#1997568) (#1997537) grant table v2 status pages may remain accessible after de-allocation [XSA-379, CVE-2021-28697] (#1997520) long running loops in grant table handling [XSA-380, CVE-2021-28698] (#1997526) inadequate grant-v2 status frames array bounds check [XSA-382, CVE-2021-28699]

An update that fixes two vulnerabilities is now available.

IOMMU page mapping issues on x86 [XSA-378, CVE-2021-28694, CVE-2021-28695, CVE-2021-28696] (#1997531) (#1997568) (#1997537) grant table v2 status pages may remain accessible after de-allocation [XSA-379, CVE-2021-28697] (#1997520) long running loops in grant table handling [XSA-380, CVE-2021-28698] (#1997526) inadequate grant-v2 status frames array bounds check [XSA-382, CVE-2021-28699]

Human Fraud: Detecting Them Before They Detect You
Poisoned proxy PACs! The NPM package with a network-wide security hole…
Jenkins struck by ‘Confluenza’ as US Cyber Command warns Atlassian flaw ‘cannot wait’
Priti Patel backs ad campaign that criticises Facebook’s stance on end-to-end encryption
IoT Attacks Skyrocket, Doubling in 6 Months
Save your free seat for Recorded Future Predict 21: The intelligence summit