Menu

Monthly Archives: December 2021

Crypto-Exchange BitMart to Pay Users for $200M Theft
Are You Guilty of These 8 Network-Security Bad Practices?
Cyber Command Publicly Joins Fight Against Ransomware Groups  

security update

Spar shops across northern UK shut after cyber attack hits payment processing abilities
Cuba Ransomware Gang Hauls in $44M in Payouts
Miscreants make off with $150m of digital assets in BitMart security breach
Pegasus Spyware Infects U.S. State Department iPhones
Apache Kafka Cloud Clusters Expose Sensitive Data for Large Companies
Cryptocurrency startup fails to subtract before adding, loses $31m
Cuba ransomware gang scores almost $44m in ransom payments across 49 orgs, say Feds

A security issue was fixed in MariaDB

Upstream details at : https://access.redhat.com/errata/RHSA-2021:4904

Ransomware – how to stop it, and how to survive an attack. Free eBook by Recorded Future

libmodbus could be made to crash if it received specially crafted input.

Several security issues were fixed in uriparser.

Several security issues were fixed in Long Range ZIP.

USN-5142-1 introduced regressions in Samba.

Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in privilege escalation, denial of service or information leaks.

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp3 was updated. The following patches have been included in this update:

The container sles-15-sp3-chost-byos-v20211202 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20211202-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20211202-gen2 was updated. The following patches have been included in this update:

American diplomats’ iPhones reportedly compromised by NSO Group intrusion software
Utility biz Delta-Montrose Electric Association loses billing capability and two decades of records after cyber attack
Feds charge two men with claiming ownership of others’ songs to steal YouTube royalty payments

NSS rebase to 3.73, includes fix for CVE-2021-43527

Pandemic-Influenced Car Shopping: Just Use the Manufacturer API
Omicron Phishing Scam Already Spotted in UK
Protecting your critical infrastructure is one thing…protecting your backups is the same thing
Mozilla patches critical “BigSig” cryptographic bug: Here’s how to track it down and fix it
What Are Your Top Cloud Security Challenges? Threatpost Poll
Netgear router flaws exploitable with authentication … like the default creds on Netgear’s website
Launching ESET Research Podcast: A peek behind the scenes of ESET discoveries

Press play for the first episode as host Aryeh Goretsky is joined by Zuzana Hromcová to discuss native IIS malware The post Launching ESET Research Podcast: A peek behind the scenes of ESET discoveries appeared first on WeLiveSecurity

UK Government fined £500,000 after revealing home addresses in New Year honours data breach
Threat Group Takes Aim Again at Cloud Platform Provider Zoho
OpenShift Security Hardening for the healthcare industry

An update that contains security fixes can now be installed.

Man charged with Ubiquiti data breach and extortion was employee assigned to investigate hack

Several vulnerabilities were discovered in LibreCAD, an application for computer aided design (CAD) in two dimensions. An attacker could trigger code execution through malicious .dwg and .dxf files.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

BadgerDAO DeFi defunded as hackers apparently nab millions in crypto tokens

security update

‘Double-Extortion’ Ransomware Damage Skyrockets 935%
Planned Parenthood Breach Opens Patients to Follow-On Attacks
S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness [Podcast]
AT&T Takes Steps to Mitigate Botnet Found Inside Its Network 
IoT devices must “protect consumers from cyberharm”, says UK government
FluBot malware warning after 70,000 attacks launched over SMS
1Password 8 for Windows – improved productivity, and enhanced security & privacy
Jumping the air gap: 15 years of nation‑state effort

ESET researchers studied all the malicious frameworks ever reported publicly that have been used to attack air-gapped networks and are releasing a side-by-side comparison of their most important TTPs The post Jumping the air gap: 15 years of nation‑state effort appeared first on WeLiveSecurity

NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP […]

A NULL pointer dereference in Busybox’s hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input. (CVE-2021-42376)

BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be […]

The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both “manifests” and “layers” fields could be

In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability. References:

New UK product security law won’t be undercut by rogue traders upping and vanishing, government boasts
European Cybercrime Centre confident it’s kicked credit card crims – again
Three key ransomware actors changed jobs on October 18 – the same day REvil went dark
Smashing Security podcast #254: A dead hamster, a brass pen, and The Beatles
Rewriting your disaster recovery plan might just save your company…and could transform it
80K Retail WooCommerce Sites Exposed by Plugin XSS Bug
Stealthy ‘WIRTE’ Gang Targets Middle Eastern Governments
Singapore and UK ink digital trade agreements at Future Tech Forum in London

Thunderbird could be made to crash or run programs if it verified a specially crafted signature.

NSS could be made to crash or run programs if it verified a specially crafted signature.

Widespread ‘Smishing’ Campaign Defrauds Iranian Android Users
20 Years of Red Hat Product Security: From inception to customer experience (Part 1)
U.S. Government issues directive to prioritize fixing exploited CVEs: How Red Hat Insights can help

Red Hat OpenShift Container Platform release 4.7.38 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

UK watchdog’s punishment for Blackbaud, Easyjet, other big privacy lawbreakers was slap on the wrist in private
UK intel chief says MI6 must outsource innovation – and James Bond’s in-house ‘Q’ is nonsense