Menu

Monthly Archives: October 2021

Microsoft Oct. Patch Tuesday Squashes 4 Zero-Day Bugs

security update

Microsoft Patch Tuesday bug harvest festival comes to town
User locked out of Microsoft account by MFA bug, complains of customer-hostile support
Windows Zero-Day Actively Exploited in Widespread Espionage Campaign
Office 365 Spy Campaign Targets US Military Defense
Apple patches ‘actively exploited’ iPhone zero-day with iOS 15.0.2 update
Apple Releases Urgent iOS Updates to Patch New Zero-Day Bug

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes 25 vulnerabilities is now available.

An update for libxml2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openssl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Schools email marketing company told us to go away when we told them of exposed database creds, say infoseccers
Bank of America employee indicted for email scam that targeted businesses
Google gives away 10,000 free security keys to high-risk users
What’s missing from most ICS cybersecurity training? The ICS itself…
Apple quietly patches yet another iPhone 0-day – check you have 15.0.2
Zero-day hunters seek laws to prevent vendors suing them for helping out and doing their jobs
Ransomware cost US companies almost $21 billion in downtime in 2020

The victims lost an average of nine days to downtime and two-and-a-half months to investigations, an analysis of disclosed attacks shows The post Ransomware cost US companies almost $21 billion in downtime in 2020 appeared first on WeLiveSecurity

Russia-based criminals are still the UK’s number 1 cyber-foe, NSO Group’s wares a ‘red flag’ says NCSC chief
Cybersecurity awareness month: Fight the phish!
Man charged with hack which shared COVID-19 test details in protest against vaccine pass
An appearance on the IntoSecurity Chats podcast

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Brewdog might make an OK pint but its security sucks: Flaw opened door to free beers for anyone

An update that fixes 21 vulnerabilities is now available.

When criminals go corporate: Ransomware-as-a-service, bulk discounts and more
Gripped by cybersec career indecision? Don’t give up. Level up

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for httpd24-httpd is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

US nuke sub plans leaked on SD card hidden in peanut butter sandwich, claims FBI

security update

– New upstream update (93.0) – Fixed NSS package dependency (NSS 3.70) —- – New upstream release (93.0)

Two security issues were found in TIFF, a widely used format for storing image data, as follows: CVE-2020-19131

Update to f13cbcf (dr_wav 0.13.2) Fix a possible buffer overflow. —- Update to 8900af1 with dr_mp3 0.6.31 Fix a bug in dr_mp3 when loading from memory.

Upgrade Grafana to upstream version 7.5.10 —- rebuild to resolve CVE-2021-34558

Update to f13cbcf (dr_wav 0.13.2) Fixes a possible buffer overflow. —- Update to 8900af1 with dr_mp3 0.6.31 Fix a bug in dr_mp3 when loading from memory.

An update that solves three vulnerabilities and has one errata is now available.

The container caasp/v4/kured was updated. The following patches have been included in this update:

The container caasp/v4/kucero was updated. The following patches have been included in this update:

The container caasp/v4/kubernetes-client was updated. The following patches have been included in this update:

The container caasp/v4/hyperkube was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

security update

FontOnLake: Previously unknown malware family targeting Linux

ESET researchers discover a malware family with tools that show signs they’re used in targeted attacks The post FontOnLake: Previously unknown malware family targeting Linux appeared first on WeLiveSecurity

Apache patch proves patchy – now you need to patch the patch
Never mind Russia: Turkey and Vietnam are Microsoft’s new state-backed hacker threats du jour
Air gaps have been ‘shattered’, says new Indian policy on power sector security

Due to a data race in the crossbeam-deque in the crossbeam crate, one or more tasks in the worker queue could have been be popped twice instead of other tasks that are forgotten and never popped. If tasks are allocated on the heap, this could have caused a double free and a memory leak (CVE-2021-32810).

New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Navy Warship’s Facebook Page Hacked to Stream ‘Age of Empires’ Gaming
Twitch Leak Included Emails, Passwords in Clear Text: Researcher

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Russian spies reportedly used SolarWinds hack to steal US counterintelligence details
You know what ransomware attackers really, really like? Yes, your backups…
4 Key Questions for Zero-Trust Success
Google to turn on 2FA by default for 150 million users, 2 million YouTubers

Two-factor authentication is a simple way to greatly enhance the security of your account The post Google to turn on 2FA by default for 150 million users, 2 million YouTubers appeared first on WeLiveSecurity

To the moon and hack: Fake SafeMoon app drops malware to spy on you

Cryptocurrencies rise and fall, but one thing stays the same – cybercriminals attempt to cash in on the craze The post To the moon and hack: Fake SafeMoon app drops malware to spy on you appeared first on WeLiveSecurity

S3 Ep53: Apple Pay, giftcards, cybermonth, and ransomware busts [Podcast]
NSO Group’s Pegasus malware was used to spy on Dubai princess’s lawyers during child custody dispute
Ransom disclosure law would give firms 48 hours to disclose payments to ransomware gangs

Several security issues were fixed in MySQL.

Rebase to libssh-0.9.6 Fix CVE-2021-3634

Cherie Blair and the Dubai ruler who spied on his ex-wife’s phone with Pegasus spyware
3 focus areas for DevSecOps success

Updated container images that fix various bugs are now available for Red Hat OpenShift Container Storage 3.11 Update 8 in the Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact

Updated packages that provide Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 9, and fix an important security issue, are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 9 zip release for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows is available. Red Hat Product Security has rated this update as having a security impact

Bottle could be made to cache malicious requests if it received a specially crafted input.

State-sponsored Chinese crims targeted India with tax and COVID phishing
Smashing Security podcast #246: Facebook has fallen
Canopy Parental Control App Wide Open to Unpatched XSS Bugs
VMware ESXi Servers Encrypted by Lightning-Fast Python Script
Are you making good progress with Kubernetes? Cybercriminals are progressing faster
ESPecter Bootkit Malware Haunts Victims with Persistent Espionage
Apache web server zero-day bug is easy to exploit – patch now!
UEFI threats moving to the ESP: Introducing ESPecter bootkit

ESET research discovers a previously undocumented UEFI bootkit with roots going back all the way to at least 2012 The post UEFI threats moving to the ESP: Introducing ESPecter bootkit appeared first on WeLiveSecurity

Running a recent Apache web server version? You probably need to patch it. Now
Twitch Gets Gutted: All Source Code Leaked
Recorded Future’s intelligence summit, Predict 21, is happening next week – and you’re invited!
Things that are not PogChamp: Twitch has its source code, streamer payout data leaked

The updated packages fix a security vulnerabilities: While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Element celebrates The Great Facebook Outage with a Signal bridge for Matrix

Red Hat JBoss Web Server 5.5.1 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated Red Hat JBoss Web Server 5.5.1 packages are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Google to auto-enroll 150m users, 2m YouTubers with two-factor authentication

New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

IP Surveillance Bugs in Axis Gear Allow RCE, Data Theft

security update

security update

Apache Web Server Zero-Day Exposes Sensitive Data
How to Build an Incident-Response Plan, Before Security Disaster Strikes
Facebook Blames Outage on Faulty Router Configuration
Oops! Compound DeFi Platform Gives Out $90M, Would Like it Back, Please