Menu

Monthly Archives: October 2021

A Guide to Doing Cyberintelligence on a Restricted Budget
Feds Warn BlackMatter Ransomware Gang is Poised to Strike

Update to upstream stable release 2.9.4, includes a fix for CVE-2021-3802 (#2003650, #2003649)

Several security issues were fixed in strongSwan.

Free BlackByte decryptor released, after researchers say they found flaw in ransomware code
3 things to add to your 2022 cloud to-do list

An update for the redis:5 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

TA505 Gang Is Back With Newly Polished FlawedGrace RAT

An update is now available for Red Hat Quay 3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in strongSwan.

Reg scribe spends week being watched by government Bluetooth wristband, emerges to more surveillance

The container suse/sle15 was updated. The following patches have been included in this update:

Japanese messaging giant Line admits it mishandled user data, promises to do better

What do the terms artificial intelligence and machine learning mean to you? If what comes to mind initially involves robot butlers or rogue computer programs, you’re not alone. Even IT pros at large enterprise organizations can’t escape pop culture visions fed by films and TV. But today, as cyberattacks against businesses and individuals continue to […]

Time to Build Accountability Back into Cybersecurity
Podcast: Could the Zoho Flaw Trigger SolarWinds 2.0?
Sinclair Confirms Ransomware Attack That Disrupted TV Stations
TikTok Serves Up Fresh Gamer Targets via Fake Among Us, Steam Offerings
Microsoft called out as big malware hoster – thanks to OneDrive and Office 365 abuse
Twitter Suspends Accounts Used to Snare Security Researchers

Red Hat OpenShift Container Platform release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenShift Container Platform release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Cybersecurity Awareness Month: Building your career

An update that fixes one vulnerability is now available.

Ardour could be made to crash or possibly arbitrary code execute if it received a specially crafted XML file.

A security issue was fixed in nginx.

DLA-2743-1 was issued for CVE-2017-5715, affecting amd64-microcode, processor microcode firmware for AMD CPUs. However, the binaries for the resulting upload weren’t built and published, thereby preventing the users to upgrade to a fixed version.

Chinese tech minister says he’s ‘dealt with’ 73,000 sites that breached the law
Whatever sort of disaster we’re talking about, if your backups are fried, you’re not going to recover
US gov claims ransomware ‘earned’ $590m in the first half of 2021 alone – mostly in Bitcoin

security update

https://lib.openmpt.org/libopenmpt/2021/10/04/security- updates-0.5.12-0.4.24-0.3.33/

The newest upstream commit Security fix for CVE-2021-3796 Security fix for CVE-2021-3778

https://lib.openmpt.org/libopenmpt/2021/10/04/security- updates-0.5.12-0.4.24-0.3.33/

Two security issues have been discovered in LibreOffice’s support for digital signatures in ODF documents, which could result in incorrect signature indicators/timestamps being presented.

NFTs not annoying enough? Now they come with wallet-emptying malware

Two security issue have been discovered in nghttp2: server, proxy and client implementing HTTP/2. CVE-2018-1000168

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 20 vulnerabilities is now available.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Amazon textbook rental service scammed for $1.5m

security update

security update

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

TrickBot Gang Enters Cybercrime Elite with Fresh Affiliates
Missouri Vows to Prosecute ‘Hacker’ Who Informed State About Data Leak
LANtenna hack spies on your data from across the room! (Sort of)
Employee offboarding: Why companies must close a crucial gap in their security strategy

There are various ways a departing employee could put your organization at risk of a data breach. How do you offboard employees the right way and ensure your data remains safe? The post Employee offboarding: Why companies must close a crucial gap in their security strategy appeared first on WeLiveSecurity

Acer hacked (for the second time this year)
Disrupt adversaries and prevent identity fraud with Recorded Future Identity Intelligence

Richard Weinberger reported that unsquashfs in squashfs-tools, the tools to create and extract Squashfs filesystems, does not check for duplicate filenames within a directory. An attacker can take advantage of this flaw for writing to arbitrary files to the filesystem if a malformed

An update that solves 6 vulnerabilities and has 44 fixes is now available.

An update that contains security fixes can now be installed.

When it comes to ransomware, your fightback should start long before you’re attacked
White House ransomware summit calls for virtual asset crackdown, without mentioning cryptocurrency

An update that fixes one vulnerability is now available.

Client-side content scanning as an unworkable, insecure disaster for democracy

security update

USN-5091-1 introduced a regression in the Linux kernel for Microsoft Azure cloud systems.

Rickroll Grad Prank Exposes Exterity IPTV Bug

security update

WhatsApp’s got your back(ups) with encryption for stored messages
Google’s VirusTotal reports that 95% of ransomware spotted targets Windows

Red Hat Advanced Cluster Management for Kubernetes 2.2.9 General Availability release images, which provide security updates, one or more container updates, and bug fixes. Red Hat Product Security has rated this update as having a security impact

Verizon’s Visible Wireless Carrier Confirms Credential-Stuffing Attack

Fix CVE-2021-29063 regular expression denial of service References: – https://bugs.mageia.org/show_bug.cgi?id=29537 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3M5O55E7VUDMXCPQR6MQTOIFDKHP36AA/

Don’t get phished! How to be the one that got away

If it looks like a duck, swims like a duck, and quacks like a duck, then it’s probably a duck. Now, how do you apply the duck test to defense against phishing? The post Don’t get phished! How to be the one that got away appeared first on WeLiveSecurity

3D printing site Thingiverse suffers breach of 228,000 email addresses amid sluggish disclosure
Analysis of 80 million ransomware samples reveals a world under attack
CryptoRom Scam Rakes in $1.4M by Exploiting Apple Enterprise Features
Podcast: 67% of Orgs Have Been Hit by Ransomware at Least Once
S3 Ep54: Another 0-day, double Apache patch, and Fight The Phish [Podcast]

Security fix for CVE-2021-41617

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform Cross-Site Scripting (XSS) attacks or impersonate other users.

US invites friends to multilateral cybersecurity meetings – Russia and China strangely absent

An update for httpd is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.6 Advanced Update Support, Red Hat

The container suse/sles12sp4 was updated. The following patches have been included in this update:

Ad-blocking browser extension actually adds ads, say Imperva researchers

Red Hat 3scale API Management 2.11.0 Release – Container Images A security update for Red Hat 3scale API Management is now available from the Red Hat Container Catalog. Red Hat Product Security has rated this update as having a security impact

Smashing Security podcast #247: Rickrolling submarine secrets

The Rise of Ransomware Ransomware attacks dominate news coverage of the cybersecurity industry. And it’s no wonder – with million-dollar payouts, infrastructure attacks and international manhunts, ransomware makes for exciting headlines. But its recent domination of the airwaves has been a long time coming.   “The first types of ransomware have existed for quite some […]

FreakOut Botnet Turns DVRs Into Monero Cryptominers
Romance scams with a cryptocurrency twist – new research from SophosLabs
Microsoft thwarts record‑breaking DDoS attack

The attack, which clocked in at 2.4 Tbps, targeted one of Azure customers based in Europe The post Microsoft thwarts record‑breaking DDoS attack appeared first on WeLiveSecurity

Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers

Malware leaps from the darkness to envelop our lives in a cloak of stolen information, lost data and worse. But to know your enemy is to defeat your enemy. So we peered over the ledge leading to the dark web and leapt. The forces we sought are disruptors – without warning, they disturb our businesses […]

Incident Response: 5 Principles to Boost the Infosec/Legal Relationship
Ex-camera biz Olympus investigating ‘suspicious’ network activity again a month after ransomware hit
Mandating a Zero-Trust Approach for Software Supply Chains
OpenSea ‘Free Gift’ NFTs Drain Cryptowallet Balances
30 Mins or Less: Rapid Attacks Extort Orgs Without Ransomware

Squashfs-Tools could be made to overwrite files.

Microsoft says Azure fended off what might just be the world’s biggest-ever DDoS attack

The container suse/sle15 was updated. The following patches have been included in this update:

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability