Menu

Monthly Archives: December 2021

Of course a Bluetooth-using home COVID test was cracked to fake results
Java Code Repository Riddled with Hidden Log4j Bugs; Here’s Where to Look
How to tackle hybrid cloud security and DevSecOps
Half-Billion Compromised Credentials Lurking on Open Cloud Server
Why SBOM management is no longer optional
Apache’s other product: Critical bugs in ‘httpd’ web server, patch now!
Don’t forget to unplug your devices before you leave for the holidays!

As you down tools for the holiday season, be sure to also switch off the standby lights – it’s both cost effective and better for the environment The post Don’t forget to unplug your devices before you leave for the holidays! appeared first on WeLiveSecurity

Two Active Directory Bugs Lead to Easy Windows Domain Takeover
FBI: Another Zoho ManageEngine Zero-Day Under Active Attack
Belgian defence ministry admits attackers accessed its computer network by exploiting Log4j vulnerability

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the postgresql:13 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openssl is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

UK National Crime Agency finds 225 million previously unexposed passwords
US bags Russian accused of stealing millions after stealing pre-release financial filings
Conti Ransomware Gang Has Full Log4Shell Attack Chain

security update

Robocalls More Than Doubled in 2021, Cost Victims $30B
Third Log4J Bug Can Trigger DoS; Apache Issues Patch
Police National Computer not pwned by Clop ransomware crims, insists Home Office
Log4Shell: The Movie… a short, safe visual tour for work and home

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update for log4j is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.6 Advanced Update Support, Red

How to keep on top of cloud security best practices
VMware 2FA flaw can divulge that vital second credential to malicious actors
Bad things come in threes: Apache reveals another Log4J bug

security update

security update

An update that fixes one vulnerability is now available.

Updated olm packages fix security vulnerability: The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is

Updated privoxy packages fix security vulnerabilities: A security issue has been found in Privoxy before version 3.0.33. get_url_spec_param() did not free memory of compiled pattern spec before bailing (CVE-2021-44540).

Updated watchdog packages fixes an issue with a memory leak when verbose mode is on. References: – https://bugs.mageia.org/show_bug.cgi?id=29576

Log4j: Everything You Need to Know>

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.

Updated mediawiki packages fix security vulnerabilities: == Security fixes == * (T292763. CVE-2021-44854) REST API incorrectly publicly caches autocomplete search results from private wikis.

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property (CVE-2021-44225).

security update

US distrust of Huawei linked in part to malicious software update in 2012

An update that fixes one vulnerability is now available.

It was discovered that modsecurity-apache, an Apache module to tighten the Web application security, does not properly handles excessively nested JSON objects, which could result in denial of service. The update introduces a new ‘SecRequestBodyJsonDepthLimit’ option to limit the

CISA issues emergency directive to fix Log4j vulnerability

security update

xwayland 21.1.4 Security fix for CVE-2021-4008, CVE-2021-4009, CVE-2021-4010, CVE-2021-4011 Store EGLcontext to avoid superfluous eglMakeCurrent() calls Prefer EGLStream with NVIDIA proprietary driver if both GBM and EGLstream are available

Update log4j to 2.16.0 – Disables JNDI by default

Fix out of bounds read issue in *larrv functions (CVE-2021-4048)

– Update the libsqlite3-sys crate to version 0.23.2. – Update the rusqlite crate to version 0.26.3. This update also contains a fix for RUSTSEC-2021-0128.

Facebook Bans Spy-for-Hire Firms for Targeting 50K People
Spider-Man Movie Release Frenzy Bites Fans with Credit-Card Harvesting
Malicious Joker App Scores Half-Million Downloads on Google Play
Serious Security: OpenSSL fixes “error conflation” bugs – how mixing up mistakes can lead to trouble
Brand-New Log4Shell Attack Vector Threatens Local Hosts
Convergence Ahoy: Get Ready for Cloud-Based Ransomware
RAF shoots down ‘terrorist drone’ over US-owned special ops base in Syria
Conti Gang Suspected of Ransomware Attack on McMenamins
Over Log4j? VMware has another critical flaw for you to patch
Facebook locks out 1,500 fake accounts used by cyber-spy firms to snoop on people, alerts 50k potential targets

security update

‘Tropic Trooper’ Reemerges to Target Transportation Outfits

Managed service providers (MSPs) deliver critical operational support for businesses around the world. As third-party providers of remote management, MSPs are typically contracted by small and medium-sized businesses (SMBs), government agencies and non-profit organizations to perform daily maintenance of information technology (IT) systems. Similar to an MSP, managed security service providers (MSSPs) offer comparable organizations […]

‘PseudoManuscrypt’ Mass Spyware Campaign Targets 35K Systems
Why ransomware attacks happen out of hours or during the holidays
S3 Ep63: Log4Shell (what else?) and Apple kernel bugs [Podcast+Transcript]
The dirty dozen of Latin America: From Amavaldo to Zumanek

The grand finale of our series dedicated to demystifying Latin American banking trojans The post The dirty dozen of Latin America: From Amavaldo to Zumanek appeared first on WeLiveSecurity

Free eBook! Ransomware – how to stop it, and how to survive an attack
East Londoners nicked under Computer Misuse Act after NHS vaccine passport app sprouted clump of fake entries
How developers scrambled to secure the Log4j vulnerability
The DHS is inviting hackers to break into its systems, but there are rules of engagement
‘DarkWatchman’ RAT Shows Evolution in Fileless Malware
Move fast, break security: Why CISOs must push back against Agile IT
National Cyber Strategy will lead to BritChip for mobile devices by 2025, claims UK.gov
Japan draws a LINE: web giants must reveal where they store user data
Facebook expands bug bounty program to include scraping attacks, two years after it was scraped – hard
Smashing Security podcast #256: Virgin Media just won’t take no for an answer, NFT apes, and bad optics
As CISA tells US govt agencies to squash Log4j bug by Dec 24, fingers start pointing at China, Iran, others
Relentless Log4j Attacks Include State Actors, Possible Worm
US lawmakers want to put NSO Group, 3 other spyware makers out of business with fresh severe sanctions
Malicious Exchange Server Module Hoovers Up Outlook Credentials
SAP Kicks Log4Shell Vulnerability Out of 20 Apps
What every business leader needs to know about Log4Shell

Hundreds of thousands of attempts to exploit the vulnerability are under way The post What every business leader needs to know about Log4Shell appeared first on WeLiveSecurity

5 warning signs your identity has been stolen

By spotting these early warning signs of identity theft, you can minimize the impact on you and your family The post 5 warning signs your identity has been stolen appeared first on WeLiveSecurity

Pen Test Partners: Anyone could view Gumtree users’ GPS location by pressing F12
Apache’s Fix for Log4Shell Can Lead to DoS Attacks
Gathering security data for container images using the Pyxis API
Securing the Kubernetes software supply chain
Microsoft closes installer hole abused by Emotet malware, Google splats Chrome bug exploited in the wild
In 2022, Expect More Supply Chain Pain and Changing Security Roles
Apache takes off, nukes insecure feature at the heart of Log4j from orbit with v2.16
Apple iOS Update Fixes Cringey iPhone 13 Jailbreak Exploit
Actively Exploited Microsoft Zero-Day Allows App Spoofing, Malware Delivery
400 Banks’ Customers Targeted with Anubis Trojan
You may have cracked serverless development, but it’s almost certain you haven’t solved serverless security
What the Log4Shell Bug Means for SMBs: Experts Weigh In
How to Buy Precious Patching Time as Log4j Exploits Fly
Popular password manager LastPass to be spun out from LogMeIn