Menu

Monthly Archives: June 2022

Google: How we tackled this iPhone, Android spyware

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Beijing-backed attackers use ransomware as a decoy while they conduct espionage
NSO claims ‘more than 5’ EU states use Pegasus spyware

security update

security update

$6b mega contract electronics vendor Sanmina jumps into zero trust
Amazon thinks it’s really cool that Alexa can mimic your dead grandma’s voice
NHS warns of scam COVID-19 text messages
Smashing Security podcast #280: Hot tub hijinx, and a sentient AI
Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug
Web App Vs. Progressive Web App: How Are They Different?

An update that fixes 11 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

S3 Ep88: Phone scammers, hacking bust, and data breach fines [Podcast + Transcript]
Virtual private networks: 5 common questions about VPNs answered

(Almost) everything you always wanted to know about virtual private networks, but were afraid to ask The post Virtual private networks: 5 common questions about VPNs answered appeared first on WeLiveSecurity

Halfords suffers a puncture in the customer details department

An update is now available for Red Hat build of Eclipse Vert.x. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For

Don’t ditch PowerShell to improve security, say infosec agencies from UK, US, and NZ

USN-5487-1 introduced a regression in Apache.

Europol arrests nine suspected of stealing ‘several million’ euros via phishing
Mega’s unbreakable encryption proves to be anything but
Cisco warns of security holes in its security appliances
Israeli air raid sirens triggered in possible cyberattack
Phishing awareness training: Help your employees avoid the hook

Educating employees about how to spot phishing attacks can strike a much-needed blow for network defenders The post Phishing awareness training: Help your employees avoid the hook appeared first on WeLiveSecurity

DARPA study challenges assumptions about distributed ledger (and Bitcoin) security
Gamification of Ethical Hacking and Hacking Esports
Discovery of 56 OT Device Flaws Blamed on Lackluster Security Culture
Elusive ToddyCat APT Targets Microsoft Exchange Servers

Squid could be made to crash if it received specially crafted network traffic.

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

postgresql: Autovacuum, REINDEX, and others omit “security restricted operation” sandbox (CVE-2022-1552) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 postgresql-debuginfo-9.2.24-8.el7_9.i686.rpm postgresql-debuginfo-9.2.24-8.el7_9.x86_64.rpm postgresql-libs-9.2.24-8. [More…]

Yodel becomes the latest victim of a cyber ‘incident’

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

Okta says Lapsus$ incident was actually a brilliant zero trust demonstration
Israeli military personnel spied on via Strava fitness-tracking app
Info on 1.5m people stolen from US bank in cyberattack
Voicemail-themed phishing attacks target organisations
Crypto mixers: What are they and how are they used?

How crypto mixers, also known as crypto tumblers, are used to obscure the trail of digital money The post Crypto mixers: What are they and how are they used? appeared first on WeLiveSecurity

Don’t react, prevent
Capital One identity theft hacker finally gets convicted
1Password’s Insights tool to help admins monitor users’ security practices

Several vulnerabilities were discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of these flaws for local root privilege escalation.

Kazakh Govt. Used Spyware Against Protesters
Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware Attack

Several security issues were fixed in QEMU.

OpenSSL could be made to crash or run programs when the c_rehash script is used.

A great day for non-robots: iOS 16 will bypass CAPTCHAs
Voicemail Scam Steals Microsoft Credentials
Interview with Guardian Digital CEO Dave Wreski: Open Source Utilization in Email Security Solutions & More
Email Security FAQs Answered by Guardian Digital

An update that fixes one vulnerability is now available.

Several security issues were fixed in Apache HTTP Server.

This update includes the latest changes to the leap second list, including an update to its expiry date, which was set for the end of June.

Legacy systems are the new attack vectors for hackers
How refactoring code in Safari’s WebKit resurrected ‘zombie’ security bug
CISA and friends raise alarm on critical flaws in industrial equipment, infrastructure
Voicemail phishing emails steal Microsoft credentials

security update

Interpol busts 2000 suspects in phone scamming takedown
Five Things You Need To Know about Linux Container Security
Akamai Warns Of “Panchan” Linux Botnet That Leverages Golang Concurrency, Systemd
Capital One: Convicted techie got in via ‘misconfigured’ AWS buckets
How to get Fortune 500 cybersecurity without the hefty price tag
There are 24.6 billion sets of credentials up for sale on the dark web

Brief introduction CVE-2017-13755

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 17 vulnerabilities and has 26 fixes is now available.

Are you ready to automate continuous deployment in CI/CD?
You don’t need another hero…you need an automated incident response process
Indian government issues confidential infosec guidance to staff – who leak it

security update

security update

It was discovered that exo, a support library for the Xfce desktop environment, would allow executing remote .desktop files. In some scenario, an attacker could use this vulnerability to trick an user an execute arbitrary code on the platform with the privileges of that user.

Security fix for CVE-2015-20107

Security fix for CVE-2015-20107

Update to version 2.1.1 CVE-2022-24065

New version 2.8.5 is released. This new version address the security issue CVE-2022-31033 related to header information leak.

Security fix for CVE-2015-20107

How to spot malicious spam – Week in security with Tony Anscombe

As the risk of receiving a malware-laden email increases, take a moment to consider how to spot attacks involving malicious spam The post How to spot malicious spam – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Common Security Advisory Framework (CSAF) beta files now available
DeadBolt ransomware takes another shot at QNAP storage

The 5.18.5 stable kernel update contains mitigation for the processor MMIO stale-data vulnerabilities. These are covered by CVE-2022-21166 CVE-2022-21125 and CVE-2022-21123

Update to 2.36.3: * Support capturing already encoded video streams, which takes advantage of encoding done in hardware by devices which support this feature. * Avoid using experimental GStreamer elements for video demuxing. * Avoid using the legacy GStreamer VA-API decoding plug-ins, which often cause rendering issues and are not much maintained. Their usage can […]

Inverse Finance stung for $1.2 million via flash loan attack

Rebuild for ntfs-3g CVE

US senators seek ban on sale of health location data
International operation takes down Russian RSOCKS botnet
How Emotet is changing tactics in response to Microsoft’s tightening of Office macro security

Emotet malware is back with ferocious vigor, according to ESET telemetry in the first four months of 2022. Will it survive the ever-tightening controls on macro-enabled documents? The post How Emotet is changing tactics in response to Microsoft’s tightening of Office macro security appeared first on WeLiveSecurity

Microsoft Defender goes cross-platform for the masses
QNAP warns of new DeadBolt ransomware attack locking up NAS devices
China-linked APT Flew Under Radar for Decade
Cookie consent crumbles under fresh UK data law proposals