Menu

Monthly Archives: September 2021

An update that fixes one vulnerability is now available.

When the bits hit the fan: What to do when ransomware strikes
Indonesian President’s COVID jab cert leaks – authorities argue that’s perfectly reasonable

security update

Etienne Stalmans discovered that unsquashfs in squashfs-tools, the tools to create and extract Squashfs filesystems, does not validate filenames for traversal outside of the destination directory. An attacker can take advantage of this flaw for writing to arbitrary files to the filesystem

Update to 2.0.1 (fix RHBZ#1998578); fix RHBZ#1932066 (unsafe use of strncpy)

Update NTFS-3G to 2021.8.22 to fix multiple CVEs —- New upstream development version 1.45.7. —- Upstream patch to work with qemu 6.1 (RHBZ#1998820)

Update NTFS-3G to 2021.8.22 to fix multiple CVEs —- New upstream development version 1.45.7. —- Upstream patch to work with qemu 6.1 (RHBZ#1998820)

Update NTFS-3G to 2021.8.22 to fix multiple CVEs —- New upstream development version 1.45.7. —- Upstream patch to work with qemu 6.1 (RHBZ#1998820)

Update NTFS-3G to 2021.8.22 to fix multiple CVEs —- New upstream development version 1.45.7. —- Upstream patch to work with qemu 6.1 (RHBZ#1998820)

An XML external entity (XXE) injection in pywps allows an attacker to view files on the application server filesystem by assigning a path to the entity.

Norwegian student tracks Bluetooth headset wearers by wardriving around Oslo on a bicycle

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

Apple stalls CSAM auto-scan on devices after ‘feedback’ from everyone on Earth
Twitter introduces new feature to automatically block abusive behavior

Dubbed Safety Mode, the feature will temporarily block authors of offensive tweets from being able to contact or follow users. The post Twitter introduces new feature to automatically block abusive behavior appeared first on WeLiveSecurity

The State of Incident Response: Measuring Risk and Evaluating Your Preparedness
FIN7 Capitalizes on Windows 11 Release in Latest Gambit
Rapid7 says Computer Misuse Act should include ‘good faith’ infosec research exemption
New Zealand internet outage blamed on DDoS attack on nation’s third largest internet provider
S3 Ep48: Cryptographic bugs, cryptocurrency nightmares, and lots of phishing [Podcast]

An update that solves one vulnerability and has two fixes is now available.

An update that solves one vulnerability and has one errata is now available.

Brute-Force Attacks Target Inboxes for Gift Card Data

An update that solves one vulnerability and has two fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

Confessions of a ransomware negotiator: Well, somebody’s got to talk to the criminals holding data hostage
Spring or autumn, your biggest cyber threat could be in the cloud
NFT Collector Tricked into Buying Fake Banksy 
FTC bans ‘brazen’ stalkerware maker SpyFone, orders data deletion, alerts to victims
SpyFone & CEO Banned From Stalkerware Biz

Security release for the 0.4 branch: https://lib.openmpt.org/libopenmpt/2021/08/22/security- updates-0.5.11-0.4.23-0.3.32/

NSA: We ‘don’t know when or even if’ a quantum computer will ever be able to break today’s public-key encryption
Bluetooth Bugs Open Billions of Devices to DoS, Code Execution
Autodesk was one of the 18,000 firms breached in SolarWinds attack, firm admits
Pwned! The home security system that can be hacked with your email address
Google Play Sign-Ins Allow Covert Location-Tracking
Cisco Patches Critical Authentication Bug With Public Exploit
“Attackers don’t take the weekends off, and neither should your cybersecurity”
In space, no one can hear cyber security professionals scream
7 Ways to Defend Mobile Apps, APIs from Cyberattacks
WhatsApp Photo Filter Bug Allows Sensitive Info to Be Lifted

An update that solves 11 vulnerabilities and has 7 fixes is now available.

Digital State IDs Start Rollouts Despite Privacy Concerns

An update that fixes two vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

Comcast RF Attack Leveraged Remotes for Surveillance
UK VoIP telco receives ‘colossal ransom demand’, reveals REvil cybercrooks suspected of ‘organised’ DDoS attacks on UK VoIP companies
How to secure REST with Spring Security
How a Bumble dating app vulnerability revealed any user’s exact location
Build a culture of security security and productivity in your business with 1Password
Dissected: A dropper-as-a-service miscreants pay to push their malware onto potentially 1,000s of victims

The container sles-15-sp3-chost-byos-v20210827 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20210827-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20210827-gen2 was updated. The following patches have been included in this update:

Smashing Security podcast #241: Flipping dating apps, and crypto rewards for criminals
Fired credit union employee admits: I wiped 21GB of files from company’s shared drive in retaliation

security update

Relax, says NSA: There’s no such thing as a quantum computer that’ll crack current encryption algos
Gutenberg Template Library & Redux Framework Bugs Plague WordPress Sites
Vaccine passports: Is your personal data in safe hands?

Vaccination passports may facilitate the return to normalcy, but there are also concerns about what kinds of personal data they collect and how well they protect it. Here’s what you should know. The post Vaccine passports: Is your personal data in safe hands? appeared first on WeLiveSecurity

LockBit Jumps Its Own Countdown, Publishes Bangkok Air Files
BEC Scammers Seek Native English Speakers on Underground
Feds Warn of Ransomware Attacks Ahead of Labor Day
Network Controls in the DevSecOps life cycle
Best Linux Backup Solutions to Prevent Data Loss in A Ransomware Attack>

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3338

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3336

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3325

Upstream details at : https://access.redhat.com/errata/RHSA-2020:1021

Upstream details at : https://access.redhat.com/errata/RHSA-2018:3140

Indonesian authorities probe million-record leak from national COVID app
Singapore adds a third bug bounty program – this time to fortify government digital services