Menu

Monthly Archives: November 2021

Phishing Scam Aims to Hijack TikTok ‘Influencer’ Accounts
UK government publishes guidance on security rules for tech takeovers
Red Hat Global Customer Tech Outlook 2022: Hybrid and multicloud strategies lead the way as funding priorities hold steady
You wanna use GCHQ offshoot NCSC’s threat intel feeds? Why not, say bosses
The race to secure Kubernetes at run time

An update that fixes 10 vulnerabilities is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3801

Upstream details at : https://access.redhat.com/errata/RHSA-2021:4619

Upstream details at : https://access.redhat.com/errata/RHSA-2021:4044

Upstream details at : https://access.redhat.com/errata/RHSA-2021:4033

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3889

South Korean privacy watchdog apologises for violating privacy while mediating privacy lawsuit
FBI Email Hoaxer ID’ed by the Guy He Allegedly Loves to Torment
The inside story of ransomware repeatedly masquerading as a popular JS library for Roblox gamers
Rooting Malware Is Back for Mobile. Here’s What to Look Out For.
200M Adult Cam Model, User Records Exposed in Stripchat Breach

security update

Lock up your Office macros: Emotet botnet back from the dead with Trickbot links
MosesStaff Locks Up Targets, with No Ransom Demand, No Decryption
GitHub fixes authorisation vulnerability in the NPM JavaScript package registry
The self-driving smart suitcase… that the person behind you can hijack!
Mozilla sprinkles Firefox Relay with Premium fairy dust
1Password 8 for Windows: Security, meet productivity
Not only MSPs: All cloudy firms are in line for UK security law crackdown
Emotet malware: “The report of my death was an exaggeration”
Emotet Resurfaces on the Back of TrickBot After Nearly a Year

Security fix for CVE-2021-40529

An update that contains security fixes and contains one feature can now be installed.

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rust-toolset-1.54-rust is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Intel’s recent Atom, Celeron, Pentium chips can be lulled into a debug mode, potentially revealing system secrets
If cybercriminals can’t see data because it’s encrypted, they have nothing to steal
China Telecom’s US arm sues in last-ditch bid to retain license
Chinese Communist Party official expelled for mining cryptocurrency
The Best Ransomware Response, According to the Data 
When the world ends, all that will be left are cockroaches and new Rowhammer attacks: RAM defenses broken again
High-Severity Intel Processor Bug Exposes Encryption Keys
America, when you’re done hitting us with the ban hammer, see these on-prem Zoom vulns, says Positive
Cybercriminals Target Alibaba Cloud for Cryptomining, Malware
FBI systems compromised to send out fake attack alerts

Hackers break into the Bureau’s email systems to send out at least 100,000 emails warning recipients of imminent cyberattacks The post FBI systems compromised to send out fake attack alerts appeared first on WeLiveSecurity

Email encryption should be a no-brainer, not a brain melter
FBI Says Its System Was Exploited to Email Fake Cyberattack Alert
As ransomware attacks rise, US government advice to protect K-12 schools is “vastly outdated”
There’s something to be said for delayed gratification when Windows 11 is this full of bugs

Several security issues were fixed in Vim.

Apache Santuario – XML Security for Java is vulnerable to an issue where the “secureValidation” property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

3 reasons devops must integrate agile and ITSM tools

An update that solves 14 vulnerabilities, contains four features and has 5 fixes is now available.

An update that fixes one vulnerability is now available.

An update for gcc-toolset-10-binutils is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

FBI spams thousands with fake infosec advice after ‘software misconfiguration’

The 5.14.17 stable kernel update contains a number of important fixes across the tree.

The 5.14.17 stable kernel update contains a number of important fixes across the tree.

The 5.14.17 stable kernel update contains a number of important fixes across the tree.

DHS warning about hackers in your network? Don’t panic!

security update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

Threat from Organized Cybercrime Syndicates Is Rising
Costco Confirms: A Data Skimmer’s Been Ripping Off Customers

security update

security update

security update

security update

security update

Top 10 Cybersecurity Best Practices to Combat Ransomware

Security and compatibility fixes

Security and compatibility fixes

Windows 10 Privilege-Escalation Zero-Day Gets an Unofficial Fix
ChaosDB: Infosec bods could pull anyone’s plaintext Azure Cosmos DB keys at will from Microsoft admin tools
Mac Zero Day Targets Apple Devices in Hong Kong
Samba update patches plaintext passwork plundering problem
When the alarms go off: 10 key steps to take after a data breach

It’s often said that data breaches are no longer a matter of ‘if’, but ‘when’ – here’s what your organization should do, and avoid doing, in the case of a security breach The post When the alarms go off: 10 key steps to take after a data breach appeared first on WeLiveSecurity

Millions of Routers, IoT Devices at Risk from New Open-Source Malware
Instagram, tricked into thinking its boss was dead, locked him out of his own account

Apache Tomcat, the servlet and JSP engine, did not properly release an HTTP upgrade connection for WebSocket connections once the WebSocket connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

Jacob Champion discovered two vulnerabilities in the PostgreSQL database system, which could result in man-in-the-middle attacks. For Debian 9 stretch, these problems have been fixed in version

AMD reveals an EPYC 50 flaws – 23 of them rated High severity. Intel has 25 problems, too
Philippines gov takes down passport application website amid privacy leak fears
Invest in These 3 Key Security Technologies to Fight Ransomware
Dutch newspaper accuses US spy agencies of orchestrating 2016 Booking.com breach
Back-to-Back PlayStation 5 Hacks Hit on the Same Day

The binary got built with Fedora mandatory compiler flags.

ImageMagick is updated 6.9.12.28 , soname bump , many security fixes —- Add scraper2vdr_serienposter_statt_banner.diff

ImageMagick is updated 6.9.12.28 , soname bump , many security fixes —- Add scraper2vdr_serienposter_statt_banner.diff

ImageMagick is updated 6.9.12.28 , soname bump , many security fixes —- Add scraper2vdr_serienposter_statt_banner.diff

Cyber-Mercenary Group Void Balaur Attacks High-Profile Targets for Cash
If even tech leaders struggle with email encryption, are we all doomed?
Congress Mulls Ban on Big Ransom Payouts Unless Victims Get Official Say-So
S3 Ep58: Faces on Facebook, scams that pose as complaints, and a Kaseya bust [Podcast]
Palo Alto Networks patches 9.8 severity CVE in popular GlobalProtect product
Tiny Font Size Fools Email Filters in BEC Phishing

OpenEXR could be made to crash or execute arbitrary code if it received a specially crafted EXR file.

Openafs packages have been updated to 1.9.1 for various bugfixes, and added a fix for security vulnerability: There exist in the wild AFS3 clients that improperly construct access control lists which are then stored to directories via RXAFS_StoreACL

This kernel-linus update is based on upstream 5.10.78 and fixes atleast the following security issues: A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, and system availability (CVE-2021-3760).