Menu

Monthly Archives: December 2021

MPs charged with analysing Online Safety Bill say end-to-end encryption should be called out as ‘specific risk factor’
‘Seedworm’ Attackers Target Telcos in Asia, Middle East
Apple security updates are out – and not a Log4Shell mention in sight
Log4Shell: The race is on to fix millions of systems and internet-connected devices
Kronos Ransomware Outage Drives Widespread Payroll Chaos
Log4j RCE latest: In case you hadn’t noticed, this is Really Very Bad, exploited in the wild, needs urgent patching
Log4Shell vulnerability: What we know so far

The critical flaw in the ubiquitous Log4j utility has sent shockwaves far beyond the security industry – here’s what we know so far The post Log4Shell vulnerability: What we know so far appeared first on WeLiveSecurity

Where the Latest Log4Shell Attacks Are Coming From
Malicious PyPI Code Packages Rack Up Thousands of Downloads
Log4Shell Is Spawning Even Nastier Mutations
When disaster strikes, data recovery really is a race against time
Is VPOTUS Bluetooth-phobic or sensible? The answer’s pretty clear
Timekeeping biz Kronos hit by ransomware and warns customers to engage biz continuity plans
Ooh, an update. Let’s install it. What could possibly go wro-
Log4Shell explained – how it works, why you need to know, and how to fix it

security update

Chen Zhaojun of Alibaba Cloud Security Team discovered a critical security vulnerability in Apache Log4j, a popular Logging Framework for Java. JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker

The container suse/sle15 was updated. The following patches have been included in this update:

An update that fixes 7 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

security update

How to detect the Log4j vulnerability in your applications
Irish Health Service ransomware attack happened after one staffer opened malware-ridden email

Apache Log4j2

– Update to latest upstream (95.0)

**MariaDB 10.5.13** Release notes: https://mariadb.com/kb/en/mariadb-10513-release-notes/ Maintainer notes: This update contains – conditionally only on F>=35 – patch for OpenSSL 3 This update enables LTO – Link Time Optimization This update disables DTRACE on ARMv7hl architecture as a temporary workaround for BZ #2026600

**MariaDB 10.5.13** Release notes: https://mariadb.com/kb/en/mariadb-10513-release-notes/ Maintainer notes: This update contains – conditionally only on F>=35 – patch for OpenSSL 3 This update enables LTO – Link Time Optimization This update disables DTRACE on ARMv7hl architecture as a temporary workaround for BZ #2026600

security update

Next-Gen Maldocs & How to Solve the Human Vulnerability

An update that contains security fixes can now be installed.

‘Appalling’ Riot Games Job Fraud Takes Aim at Wallets

CVE-2021-4052: Use after free in web apps. CVE-2021-4053: Use after free in UI. CVE-2021-4079: Out of bounds write in WebRTC. CVE-2021-4054: Incorrect security UI in autofill. CVE-2021-4078: Type confusion in V8.

Zero Day in Ubiquitous Apache Log4j Tool Under Active Attack
SnapHack: Watch out for those who can hack into anyone’s Snapchat!

Oh snap! This is how easy it may be for somebody to hijack your Snapchat account – all they need to do is peer over your shoulder. The post SnapHack: Watch out for those who can hack into anyone’s Snapchat! appeared first on WeLiveSecurity

“Log4Shell” Java vulnerability – how to safeguard your servers
Sprawling Active Attack Aims to Take Over 1.6M WordPress Sites
Log4j RCE: Emergency patch issued to plug critical auth-free code execution hole in widely-used logging utility
Revealed: Remember the Sony rootkit rumpus? It was almost oh so much worse
‘Karakurt’ Extortion Threat Emerges, But Says No to Ransomware
Gathering security data using the Red Hat Security Data API

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Ransomwared payroll provider leaks data on 38,000 Australian government workers

The container suse/sle15 was updated. The following patches have been included in this update:

An update for python-django20 is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for etcd is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Canadian Ransomware Arrest Is a Meaningful Flex, Experts Say
Fueled by Pandemic Realities, Grinchbots Aggressively Surge in Activity
A third of you slackers out there still aren’t using HTTPS by default
S3 Ep62: The S in IoT stands for security (and much more) [Podcast+Transcript]
How MikroTik Routers Became a Cybercriminal Target
Resistance is … cheap? Cloudflare, Mandiant, and pals form incident response ‘n’ cyber insurance borg
Smashing Security podcast #255: Revolting receipts, a Twitter fandango, and shopkeeper cyber tips

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the virt:8.2 and virt-devel:8.2 modules is now available for Advanced Virtualization for RHEL 8.2.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Ransomware giving you sleepless nights? Here’s how to insure a good night’s sleep
Oz Feds reveal distribution model behind backdoored ‘An0m’ chat app spread by crims
Malicious npm Code Packages Built for Hijacking Discord Servers
Moobot Botnet Chews Up Hikvision Surveillance Systems
Not with a Bang but a Whisper: The Shift to Stealthy C2
Critical SonicWall VPN Bugs Allow Complete Appliance Takeover
Canadian charged with running ransomware attack on US state of Alaska
AWS Among 12 Cloud Services Affected by Flaws in Eltima SDK
Not all tech disasters are ‘all hands’ events. But how do you tell which is which?
5 common gift card scams and how to spot them

It often pays to look a gift horse in the mouth – recognizing these types of gift card fraud will go a long way toward helping you stay safe from this growing threat not just this holiday season The post 5 common gift card scams and how to spot them appeared first on WeLiveSecurity

Virgin Media fined £50,000 after spamming 451,000 who didn’t want marketing emails
Emotet’s Behavior & Spread Are Omens of Ransomware Attacks
20 years of Red Hat Product Security: The rise of branded exploits (Part 2)

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

An update for firefox is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

What’s the right amount of trust to build into your network? Less than Zero
Microsoft extends Secured-core concept to servers
Windows 10 Drive-By RCE Triggered by Default URI Handler
When Scammers Get Scammed, They Take It to Cybercrime Court
Leaked Downing Street video footage exposes staff laughing about party
Ransomware hits Spar supermarkets and petrol stations
Firefox update brings a whole new sort of security sandbox
Google Takes Down Glupteba Botnet; Files Lawsuit Against Operators
What are buffer overflow attacks and how are they thwarted?

Ever since the Morris worm, buffer overflows have become notorious fare in the world of vulnerabilities The post What are buffer overflow attacks and how are they thwarted? appeared first on WeLiveSecurity

Cryptominers aren’t just a headache – they’re a big neon sign that Bad Things are on your network
Foreign Office IT chaos: Shocking testimony reveals poor tech support hindered Afghan evac attempts
SolarWinds Attackers Spotted Using New Tactics, Malware
Integrate security into CI/CD with the Trivy scanner

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

An update for rpm is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.

An update is now available for Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in BusyBox.

Django could be made to expose sensitive information.

An update that fixes 7 vulnerabilities is now available.

Microsoft wins court approval to take over sites run by Chinese crime gang
LINE Pay leaks around 133,000 users’ data to GitHub, of all places