Menu

Monthly Archives: October 2021

There’s a wave of ransomware coming down the pipeline. What can you do about it?
Ransomware criminals have feelings too: BlackMatter abuse caused crims to shut down negotiation portal
Cybersecurity Awareness Month: Listen up – CYBER­SECURITY FIRST!
Listen up 2 – CYBERSECURITY FIRST! How to protect yourself from supply chain attacks
Listen up 3 – CYBERSECURITY FIRST! Cyberinsurance, help or hindrance?
Listen up 4 – CYBERSECURITY FIRST! Purple teaming – learning to think like your adversaries

Google Chromebook devices could rightly be called a game-changer for education. These low-cost laptops are within financial reach for far more families than their more expensive competitors, a fact that proved crucial with the outbreak of the COVID-19 pandemic at the beginning of last year. During that period, Google donated more than 4,000 Chromebook devices […]

CISA Urges Sites to Patch Critical RCE in Discourse

An update for redis is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This kernel-linus update is based on upstream 5.10.75 and fixes atleast the following security issues: A memory leak in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ ccp/ccp-ops.c in the Linux kernel allows malicious users to cause a

This kernel update is based on upstream 5.10.75 and fixes atleast the following security issues: A memory leak in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ ccp/ccp-ops.c in the Linux kernel allows malicious users to cause a

SolarWinds attacker on the move: Russia’s Nobelium crew has trebled attacks targeting MSPs, cloud resellers, says Microsoft
Sharpen your security knowledge with 1Password University

Several security issues were fixed in GNU binutils.

HIV Scotland fined £10,000 for BCC email blunder identifying names of virus-carriers’ patient-advocates

Several security issues were fixed in MySQL.

An update that solves 6 vulnerabilities and has four fixes is now available.

Online harms don’t need dangerous legislation, they need a spot of naval action
Facebook sues scraper who sold 178 million phone numbers and user IDs
Cleanup on aisle C: Tesco app back online after attack led to shopping app outages

This update provides the upstream 6.1.28 maintenance release that fixes atleast the following security vulnerabilities: Vulnerability in the Oracle VM VirtualBox prior to 6.1.28 contains an easily exploitable vulnerability that allows high privileged attacker with

Several issues have been found in faad2, a freeware Advanced Audio Decoder player. They are related to heap buffer overflows or null pointer dereferences, which both might allow an attacker to execute code by

security update

Do not include params in exception when a call to set_options fails. Additionally, block the exception that is returned from being displayed to stdout. (CVE-2021-3620) References:

Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the Flatpak app as though it was an ordinary, non-sandboxed host-OS process, by manipulating the VFS using recent mount-related syscalls that are not blocked by Flatpak’s denylist seccomp

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. (CVE-2021-30640) Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66

A bug was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky.

Security fix for CVE-2021-39360

## 2021-10-12, Version 14.18.1 ‘Fermium’ (LTS), @danielleadams This is a security release. ### Notable changes * **CVE-2021-22959**: HTTP Request Smuggling due to spaced in headers (Medium) * The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS). More details will […]

Remote access has helped us become more interconnected than ever before. In the United States alone, two months into the pandemic, approximately 35% of the workforce was teleworking. The growth of remote access allowed individuals to work with organizations and teams they don’t physically see or meet. However, the demand for remote access has critical […]

FIN7 Lures Unwitting Security Pros to Carry Out Ransomware Attacks

The package nodejs-lts-erbium before version 12.22.7-1 is vulnerable to multiple issues including arbitrary code execution, url request injection and certificate verification bypass.

The package nodejs-lts-fermium before version 14.18.1-1 is vulnerable to multiple issues including arbitrary code execution, url request injection and certificate verification bypass.

The package nodejs before version 16.11.1-1 is vulnerable to url request injection.

Better late than never: Microsoft rolls out a public preview of E2EE in Teams calls
REvil Servers Shoved Offline by Governments – But They’ll Be Back, Researchers Say
Cybersecurity careers: What to know and how to get started

Want to help make technology safer for everyone? Love solving puzzles? Looking for a rewarding career? Break into cybersecurity! Insights from ESET researchers Aryeh Goretsky and Cameron Camp will put you on the right track. The post Cybersecurity careers: What to know and how to get started appeared first on WeLiveSecurity

Recycled Cobalt Strike key pairs show many crooks are using same cloned installation
Donald Trump’s Truth Social account posts a picture of a pig defecating
Cisco SD-WAN Security Bug Allows Root Code Execution
REvil ransomware gang allegedly forced offline by law enforcement counterattacks
Recorded Future Identity Intelligence prevents identity fraud and disrupts attackers – learn more now
Romance scam suspects rounded up in South Africa after 100 women targeted
Threat Actors Abuse Discord to Push Malware
Unhappy customers and their own tricks used against them, REvil ransomware gang reportedly pulled offline by ‘multi-country’ operations
How your phone, laptop, or watch can be tracked by their Bluetooth transmissions
YouTubers fell for shady ‘sponsors’ who seized, then sold, accounts

Several security issues were fixed in Mailman.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

U.S. Ban on Sales of Cyberattack Tools Is Anemic, Experts Warn
TA551 Shifts Tactics to Install Sliver Red-Teaming Tool
Gigabyte Allegedly Hit by AvosLocker Ransomware
US Government warns of BlackMatter ransomware attacks against critical infrastructure
We regret to inform you there’s an RCE vuln in old version of WinRAR. Yes, the file decompression utility
S3 Ep55: Live malware, global encryption, dating scams, and secret emanations [Podcasts]
Why is Cybersecurity Failing Against Ransomware?

fix memory leak when verbose mode is on

Security fix for CVE-2021-3618

Ransomware Sinks Teeth into Candy-Corn Maker Ahead of Halloween

libcaca could be made to crash if it received a specially crafted image.

Research finds consumer-grade IoT devices showing up… on corporate networks

Tenable discovered that in Babel, a set of tools for internationalizing Python applications, Babel.Locale allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution. This

What is self-learning AI and how does it tackle ransomware?

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Smashing Security podcast #248: Press F12 to hack
Uncle Sam to clip wings of Pegasus-like spyware – sorry, ‘intrusion software’ – with proposed export controls
Brave browser replaces Google with its own search engine

Brave Search will become the default search option for new users in the US, UK, Canada, Germany and France, with more countries to follow soon The post Brave browser replaces Google with its own search engine appeared first on WeLiveSecurity

security update

Google Crushes YouTube Cookie-Stealing Channel Hijackers
We don’t want to be critical, but humans alone aren’t enough to protect your ICS
VPN Exposes Data for 1M Users, Leading to Researcher Questioning
A recipe for failure: Predictably poor passwords

Security professionals advise to never use ‘beef stew’ as a password. It just isn’t stroganoff. The post A recipe for failure: Predictably poor passwords appeared first on WeLiveSecurity

“To the moon!” Cryptocurrency hamster Mr Goxx trades online 24/7
Geriatric Microsoft Bug Exploited by APT Using Commodity RATs
Not just deprecated, but deleted: Google finally strips File Transfer Protocol code from Chrome browser
NHS Digital exposes hundreds of email addresses after BCC blunder copies in entire invite list to ‘Let’s talk cyber’ event

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

How security has changed in the era of cloud computing

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the redis:6 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The security update of smarty3, the compiling PHP template engine, issued as DLA 2618-1 introduced a regression in the smarty_security class when secure directories are evaluated. Updated smarty3 packages are now available to correct this issue.

An update for the redis:5 module is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Centre for Computing History apologises to customers for ’embarrassing’ breach
When it comes to ransomware, every second hurts
Crims target telcos’ Linux and Solaris boxes, which don’t get enough infosec love
Acer servers cracked in India and Taiwan – including systems with customer data
You’ve heard of HTTPS. Now get a load of HTTPA: Web services in verified remote trusted environments?
Squirrel Bug Lets Attackers Execute Code in Games, Cloud Services

security update

Fresh APT Harvester Reaps Telco, Government Data
BlackMatter ransomware gang will target agriculture for its next harvest – Uncle Sam
$5.2 billion worth of Bitcoin transactions possibly tied to ransomware

Threat actors are increasingly using advanced tactics to obfuscate and launder their illicit gains, a report by the US Government finds The post $5.2 billion worth of Bitcoin transactions possibly tied to ransomware appeared first on WeLiveSecurity

Scrambling to counter a ransomware attack could leave you with egg on your face
Lyceum APT Returns, This Time Targeting Tunisian Firms
Email phishing crapcannon operators TA505 are back from the dead, researchers warn
UK competition watchdog unveils principles to make a kinder antivirus business

Earlier this year, the National Institute for Standards and Technology (NIST) published updated recommendations for phishing simulations in security awareness training programs. We discussed it on our Community page soon after the updated standards were released, but the substance of the change bears repeating. “Practical exercises include no-notice social engineering attempts to collect information, gain […]