Menu

Monthly Archives: May 2022

Cops’ Killer Bee stings credential-stealing scammer

security update

What You Need to Know About Open-Source Software Security
Microsoft’s identity services huddle under Entra umbrella

Several integer overflows have been discovered in TurboJPEG, a JPEG image library, which can lead to a denial of service (application crash) if someone attempts to compress or decompress gigapixel images with the TurboJPEG API.

CIOs largely believe their software supply chain is vulnerable
EnemyBot Malware Targets Web Servers, CMS Tools and Android OS

– Update to 1.1.2. Fixes rhbz#2085287. – Mitigate CVE-2022-29162 / GHSA-f3fp- gc8g-vw66.

Update to pcre2-10.40, see https://github.com/PCRE2Project/pcre2/blob/pcre2-10.40/NEWS for details.

ChromeLoader Browser Hijacker Provides Gateway to Bigger Threats

Several security issues were fixed in CUPS.

Red Hat Compliance service and the Red Hat Insights API
A Complete Guide to Torrenting Safely in 2022

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Hacker steals Verizon employee database after tricking worker into granting remote access
Australian digital driving licenses can be defaced in minutes
Mysterious “Follina” zero-day hole in Office – here’s what to do!

security update

security update

Zero-day vuln in Microsoft Office: ‘Follina’ will work even when macros are disabled
Beware the Smish! Home delivery scams with a professional feel…
Zero-Day ‘Follina’ Bug Lays Microsoft Office Open to Attack
Follina. Unpatched Microsoft Office zero-day vulnerability exploited in the wild

A malicious source package could write files outside the unpack directory.

That critical vulnerability might not be the first you should patch

An update for the maven:3.5 module is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Extended Update Support, and Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact

An update for the postgresql:10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for postgresql is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for rsyslog is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for rsyslog is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Keeping it real: Don’t fall for lies about the war

Falsehoods about the war in Ukraine come in all shapes and sizes – here are a few examples of what’s in the fake news The post Keeping it real: Don’t fall for lies about the war appeared first on WeLiveSecurity

Indian authorities issue conflicting advice about biometric ID card security

security update

Global tech industry objects to India’s new infosec reporting regime
Ransomware attack sends US county back to 1977

An update that fixes 10 vulnerabilities is now available.

Peter Agten discovered that several modules for TCP syslog reception in rsyslog, a system and kernel logging daemon, have buffer overflow flaws when octet-counted framing is used, which could result in denial of service or potentially the execution of arbitrary code.

Smarty3 is a template engine for PHP. It was found that template authors could inject PHP code by choosing a malicious {block} name or {include} file name. For Debian 9 stretch, this problem has been fixed in version

A flaw was found in the check_chunk_name() function of pngcheck, a tool to verify the integrity of PNG, JNG and MNG files. This flaw allows an attacker who can pass a malicious file to be processed by pngcheck to cause a temporary denial of service.

Several security vulnerabilities have been discovered in smarty3, the compiling PHP template engine. Template authors are able to run restricted static php methods or even arbitrary PHP code by crafting a malicious math string or by choosing an invalid {block} or {include} file name. If a math string was passed

security update

This kernel-linus update is based on upstream 5.15.43 and fixes at least the following security issues: A race condition in the perf subsystem allows for a local privilege escalation. NOTE: Mageia kernels by default has disabled the perf usage

This kernel update is based on upstream 5.15.43 and fixes at least the following security issues: A race condition in the perf subsystem allows for a local privilege escalation. NOTE: Mageia kernels by default has disabled the perf usage

The chromium-browser-stable package has been updated to the 102.0.5005.61 version, fixing many bugs and 32 CVE. Some of them are listed below: CVE-2022-1853: Use after free in Indexed DB. CVE-2022-1854: Use after free in ANGLE. CVE-2022-1855: Use after free in Messaging.

The syscall.Faccessat function checks whether the calling process can access a file. Faccessat contains a bug where it checks a file’s group permission bits if the process’s user is a member of the process’s group rather than a member of the file’s group. (CVE-2022-29526)

ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a. (CVE-2018-25033) References:

MITM vulnerability when DNSSEC wasn’t used (CVE-2022-26491) References: – https://bugs.mageia.org/show_bug.cgi?id=30438 – https://lists.suse.com/pipermail/sle-security-updates/2022-May/011017.html

Stolen university credentials up for sale by Russian crooks, FBI warns
Cloud security unicorn cuts 20% of staff after raising $1.3b
Talos names eight deadly sins in widely used industrial software
Scams targeting NFT investors – Week in security with Tony Anscombe

As with everything digital, there’s someone, somewhere devising a method to steal the assets away from their rightful owners The post Scams targeting NFT investors – Week in security with Tony Anscombe appeared first on WeLiveSecurity

GitHub saved plaintext passwords of npm users in log files, post mortem reveals
This Windows malware uses PowerShell to inject malicious extension into Chrome

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

S3 Ep84: Government demand, Mozilla velocity, and Clearview fine [Podcast]
Critical Flaws in Popular ICS Platform Can Trigger RCE

An update for thunderbird is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Cybersecurity: A global problem that requires a global answer

New and exacerbated cyber-risks following Russia’s invasion of Ukraine are fueling a new urgency towards enhancing resilience The post Cybersecurity: A global problem that requires a global answer appeared first on WeLiveSecurity

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

Let’s play everyone’s favorite game: REvil? Or Not REvil?
China offering ten nations help to run their cyber-defenses and networks
How to reprogram Apple AirTags, play custom sounds
Ransomware encrypts files, demands three good deeds to restore data
Cheers ransomware hits VMware ESXi systems

security update

security update

Campaigners warn of legal challenge against Privacy Shield enhancements
Ransomware demands acts of kindness to get your files back
Using 2FA phone numbers for targeted advertising. One of the dumbest ways ever for a company to abuse its users’ trust. Take a bow, Twitter. And have a $150 million fine too.
Who’s watching your webcam? The Screencastify Chrome extension story…
ESET Research Podcast: UEFI in crosshairs of ESPecter bootkit

Listen to Aryeh Goretsky, Martin Smolár, and Jean-Ian Boutin discuss what UEFI threats are capable of and what the ESPecter bootkit tells us about their evolution The post ESET Research Podcast: UEFI in crosshairs of ESPecter bootkit appeared first on WeLiveSecurity

It was discovered that the previous upload to neutron to Debian 9 “Stretch” (ie. version 2:9.1.1-3+deb9u2) was incomplete and did not actually apply the fix for CVE-2021-40085.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Several security issues were fixed in OpenSSL.

Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious ‘fzsftp’ binary in the user’s home directory.

Several security issues were fixed in subversion.

Cybergang Claims REvil is Back, Executes DDoS Attacks
Verizon: Ransomware sees biggest jump in five years
Suspected phishing email crime boss cuffed in Nigeria
Ex-spymaster and fellow Brexiteers’ emails leaked by suspected Russian op
Ransomware grounds some flights at Indian budget airline SpiceJet
Millions of people’s info stolen from MGM Resorts dumped on Telegram for free
Smashing Security podcast #276: Webcam extortion, Michael Fish, and food foul-ups

security update

security update

In record year for vulnerabilities, Microsoft actually had fewer
Vehicle owner data exposed in GM credential-stuffing attack
Airline passengers left stranded after ransomware attack
Link Found Connecting Chaos, Onyx and Yashma Ransomware
Zoom Patches ‘Zero-Click’ RCE Bug
Verizon Report: Ransomware, Human Error Among Top Security Risks

Max Justicz reported a directory traversal vulnerability in Dpkg::Source::Archive in dpkg, the Debian package management system. This affects extracting untrusted source packages in the v2 and v3 source package formats that include a debian.tar.

Max Justicz reported a directory traversal vulnerability in Dpkg::Source::Archive in dpkg, the Debian package management system. This affects extracting untrusted source packages in the v2 and v3 source package formats that include a debian.tar.

An update that fixes one vulnerability is now available.

An update that fixes 15 vulnerabilities is now available.