Menu

Monthly Archives: January 2022

Ukrainian cops nab husband and wife suspected to be part of $1m ransomware operation
S3 Ep65: Supply chain conniption, NetUSB hole, Honda flashback, FTC muscle [Podcast + Transcript]
New GootLoader Campaign Targets Accounting, Law Firms
Hackers are posting out malicious USB drives to businesses
Austrian watchdog rules German company’s use of Google Analytics breached GDPR by sending data to US
Admins report Hyper-V and domain controller issues after first Patch Tuesday of 2022

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

This update upgrades Thunderbird to version 91.5.0. * Mozilla: Iframe sandbox bypass with XSLT (CVE-2021-4140) * Mozilla: Race condition when playing audio files (CVE-2022-22737) * Mozilla: Heap-buffer-overflow in blendGaussianBlur (CVE-2022-22738) * Mozilla: Use-after-free of ChannelEventQueue::mOwner (CVE-2022-22740) * Mozilla: Browser window spoof using fullscreen mode (CVE-2022-22741) [More…]

This update upgrades Firefox to version 91.5.0 ESR. * Mozilla: Iframe sandbox bypass with XSLT (CVE-2021-4140) * Mozilla: Race condition when playing audio files (CVE-2022-22737) * Mozilla: Heap-buffer-overflow in blendGaussianBlur (CVE-2022-22738) * Mozilla: Use-after-free of ChannelEventQueue::mOwner (CVE-2022-22740) * Mozilla: Browser window spoof using fullscreen mode (CVE-2022-22741) [More…]

Several security issues were fixed in Pillow.

Several security issues were fixed in Ghostscript.

Volunteer Dutch flaw finders bag $100k to forward national bug bounty goal

Apache Log4j 1.2 could be made to crash or run programs if it received specially crafted input.

Smashing Security podcast #257: Pokemon-hunting cops and the Spine Collector scammer
Ransomware puts New Mexico prison in lockdown: Cameras, doors go offline
Widespread, Easily Exploitable Windows RDP Bug Opens Users to Data Theft
Amazon, Azure Clouds Host RAT-ty Trio in Infostealing Campaign

security update

security update

Stolen TikTok Videos, Bent on Fraud, Invade YouTube Shorts
New York AG Warns 17 Firms of Credential Attacks
Ransomware demands… a new approach to security
CES 2022: Wireless power for all

We don’t need no stinkin’ wall power as CES shows off the power and promise of usable long-range wireless charging The post CES 2022: Wireless power for all appeared first on WeLiveSecurity

Signed kernel drivers – Unguarded gateway to Windows’ core

ESET researchers look at malware that abuses vulnerabilities in kernel drivers and outline mitigation techniques against this type of exploitation The post Signed kernel drivers – Unguarded gateway to Windows’ core appeared first on WeLiveSecurity

Wormable Windows HTTP hole – what you need to know
Hackers raided Panasonic server for months, stealing personal data of job seekers
Phishers Rip Off High-Profile EA Gamers

It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not properly sanitize HTML messages. This would allow an attacker to perform Cross-Site Scripting (XSS) attacks.

Info-saturated techie builds bug alert service that phones you to warn of new vulns

An update that fixes two vulnerabilities is now available.

lxml could be made to execute arbitrary code if it received a specially crafted XML or HTML file.

Several security issues were fixed in Ghostscript.

Two issues were found in GDAL, a geospatial library, that could lead to denial of service via application crash or possibly the execution of arbitrary code if maliciously crafted data was parsed.

openssl: Read buffer overruns processing ASN.1 strings (CVE-2021-3712) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 openssl-1.0.2k-23.el7_9.x86_64.rpm openssl-debuginfo-1.0.2k-23.el7_9.i686.rpm openssl-debuginfo-1.0.2k-23.el7_9.x86_64.rpm openssl-libs-1.0.2k-23.e [More…]

Microsoft starts 2022 with big bundle fixes for 96 security bugs in its software
Make sure you’re up-to-date with Sonicwall SMA 100 VPN box patches – security hole exploit info is now out
Here’s REALLY How to Do Zero-Trust Security
Microsoft Faces Wormable, Critical RCE Bug & 6 Zero-Days
MacOS Bug Could Let Creeps Snoop On You
WordPress Bugs Exploded in 2021, Most Exploitable
Home routers with NetUSB support could have critical kernel hole
FIN7 Mails Malicious USB Sticks to Drop Ransomware
CES 2022 – the “anyone can make an electric car” edition

But as we learned in mashing up other technologies, the security devil is in the details The post CES 2022 – the “anyone can make an electric car” edition appeared first on WeLiveSecurity

‘Fully Undetected’ SysJoker Backdoor Malware Targets Windows, Linux & macOS
Critical SonicWall NAC Vulnerability Stems from Apache Mods
Hacking group accidentally infects itself with Remote Access Trojan horse
Millions of Routers Exposed to RCE by USB Kernel Bug
EU data watchdog to Europol: You’ve helped yourself to too much data

An update that solves two vulnerabilities, contains one feature and has 13 fixes is now available.

An update that fixes one vulnerability is now available.

Secure boot for UK electric car chargers isn’t mandatory until 2023 – but why the delay?

Introduced regression Exiv2.

Four million outdated Log4j downloads were served from Apache Maven Central alone despite vuln publicity blitz

An update that solves one vulnerability and has two fixes is now available.

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform SQL injection, run unchecked SQL queries, bypass hardening, or perform Cross-Site Scripting (XSS) attacks.

Use-after-free in sampled_data_sample (called from sampled_data_continue and interp). (CVE-2021-45944) Heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp). (CVE-2021-45949)

Signal CEO Moxie Marlinspike resigns, leaves WhatsApp co-founder to run things until a successor is named
JavaScript developer destroys own projects in supply chain “lesson”

security update

Avira also mines imaginary internet money on customers’ PCs
URL Parsing Bugs Allow DoS, RCE, Spoofing & More
Cyber-Spike: Orgs Suffer 925 Attacks per Week, an All-Time High
China puts Walmart in the naughty corner, citing 19 alleged cybersecurity ‘violations’

Version 0.102 of ClamAV, an anti-virus toolkit, is end-of-life. ClamAV has been updated to version 0.103 to be able to receive virus signature updates.

GCHQ was rebuked for ignoring spy law safeguards as pandemic hit Britain
Free guide: “A Journey to Zero Trust With Zero Passwords”

The container suse/sles/15.3/virt-operator was updated. The following patches have been included in this update:

The container suse/sles/15.3/libguestfs-tools was updated. The following patches have been included in this update:

The container suse/sles/15.3/virt-handler was updated. The following patches have been included in this update:

The container suse/sles/15.3/virt-controller was updated. The following patches have been included in this update:

The container suse/sles/15.3/virt-api was updated. The following patches have been included in this update:

No defence for outdated defenders as consumer AV nears RIP
WebSpec, a formal framework for browser security analysis, reveals new cookie attack

Multiple security issues were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which could result in denial of service and potentially the execution of arbitrary code if malformed document files are processed.

It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not properly sanitize HTML messages. This would allow an attacker to perform Cross-Side Scripting (XSS) attacks.

Honda cars in flashback to 2002 – “Can’t Get You Out Of My Head”

security update

EoL Systems Stonewalling Log4j Fixes for Fed Agencies
Cyberattackers Hit Data of 80K Fertility Patients

security update

Security fix for CVE-2021-45463

https://www.mediawiki.org/wiki/Release_notes/1.36#MediaWiki_1.36.3

3.7M FlexBooker Records Dumped on Hacker Forum

These updated packages fix a buffer overflow in the faces reader.

An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

It was discovered that sphinxsearch, a fast standalone full-text SQL search engine, could allow arbitrary files to be read by abusing a configuration option.

The Spine Collector: Man arrested for using fake email addresses to steal hundreds of unpublished manuscripts

2020 may have been the year of establishing remote connectivity and addressing the cybersecurity skills gap, but 2021 presented security experts, government officials and businesses with a series of unpresented challenges. The increased reliance on decentralized connection and the continued rapid expansion of digital transformation by enterprises, small to medium-sized businesses (SMBs) and individuals, provided […]

Log4Shell-like security hole found in popular Java SQL database engine H2
QNAP: Get NAS Devices Off the Internet Now
Attack misuses Google Docs comments to spew out “massive wave” of malicious links
Log4J-Related RCE Flaw in H2 Database Earns Critical Rating
Salesforce mandates MFA by default

Security fix for CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021-4186

Add wayland detection and pass flags to improve experience when wayland is used. —- Update to 96.0.4664.110. You know the drill, lots of security bugs fixed, update if you like security, hit that like and subscribe button. CVE-2021-4052 CVE-2021-4053 CVE-2021-4054 CVE-2021-4055 CVE-2021-4056 CVE-2021-4057 CVE-2021-4058 CVE-2021-4059 CVE-2021-4061 CVE-2021-4062 CVE-2021-4063

Activision Files Unusual Lawsuit over Call of Duty Cheat Codes
Your backups can save you from ransomware. But how do you protect your backups?
Google Voice Authentication Scam Leaves Victims on the Hook
CES 2022: More sensors than people

A sea of sensors will soon influence almost everything in your world The post CES 2022: More sensors than people appeared first on WeLiveSecurity

5 ways hackers steal passwords (and how to stop them)

From social engineering to looking over your shoulder, here are some of the most common tricks that bad guys use to steal passwords The post 5 ways hackers steal passwords (and how to stop them) appeared first on WeLiveSecurity