Menu

Monthly Archives: August 2022

security update

URGENT! Apple quietly slips out zero-day update for older iPhones
Student Loan Breach Exposes 2.5M Records
Chrome patches 24 security holes, enables “Sanitizer” safety system
Decisions on health data sharing should not be taken by politicians, citizen juries find
China-linked APT40 gang targets wind farms, Australian government
Find a security hole in Google’s open source and you could bag a $31,337 reward

security update

JavaScript bugs aplenty in Node.js ecosystem – found automatically
Watering Hole Attacks Push ScanBox Keylogger
Boots lets down its customers, by only offering SMS-based 2FA
Blackhat USA 2022: Return to Sender – Detecting Kernel Exploits with eBPF
That ‘clean’ Google Translate app is actually Windows crypto-mining malware
Automation is the ultimate cloud security tip
TikShock: Don’t get caught out by these 5 TikTok scams

Are you aware of the perils of the world’s no. 1 social media? Do you know how to avoid scams and stay safe on TikTok? The post TikShock: Don’t get caught out by these 5 TikTok scams appeared first on WeLiveSecurity

Google Play to ban Android VPN apps from interfering with ads
Critical hole in Atlassian Bitbucket allows any miscreant to hijack servers
LastPass source code breach – do we still recommend password managers?
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms

security update

security update

French hospital crippled by cyberattack – Week in security with Tony Anscombe

As another hospital falls victim to ransomware, Tony weighs in on the much-debated issue of banning ransomware payouts The post French hospital crippled by cyberattack – Week in security with Tony Anscombe appeared first on WeLiveSecurity

77% of security leaders fear we’re in perpetual cyberwar from now on

security update

PyPI warns of first-ever phishing campaign against its users
What is doxing and how to protect yourself

Doxing can happen to anyone – here’s how you can reduce the odds that your personal information will be weaponized against you The post What is doxing and how to protect yourself appeared first on WeLiveSecurity

Ransomware Attacks are on the Rise
Now Oktapus gets access to some DoorDash customer info via phishing attack
Firefox 104 is out – no critical bugs, but update anyway
LastPass hackers steal source code, no evidence of users’ passwords compromised
Twilio, Cloudflare just two of 135 orgs targeted by Oktapus phishing campaign
LastPass source code, blueprints stolen by intruder

security update

security update

Cybercriminals Are Selling Access to Chinese Surveillance Cameras

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or spoofing.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

Updated images that include numerous enhancements, security, and bug fixes are now available for Red Hat OpenShift Data Foundation 4.11.0 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

An update for systemd is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for curl is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Crooks target top execs on Office 365 with MFA-bypass scheme
S3 Ep97: Did your iPhone get pwned? How would you know? [Audio + Text]
Twitter, Meta kill hundreds of pro-Western troll accounts
Ever present danger
How RavenDB Has Earned the Trust of Hundreds of Companies
Shout-out to whoever went to Black Hat and had North Korean malware on their PC
Block sued after ex-staffer siphons customer data

With social engineering now the #1 cause of cyberattacks, it’s imperative for you to learn how to stop social engineering attacks against your business. Your first step in stopping them is to learn what they are and how they work. After that, you need to learn how combining security layers like Endpoint Protection and Email […]

80,000 internet-connected cameras still vulnerable after critical patch offered
Breaching airgap security: using your phone’s compass as a microphone!
Is your personal data all over the internet? 7 steps to cleaning up your online presence

You may not be able to disappear completely from the internet, but you can minimize your digital footprint with a few simple steps The post Is your personal data all over the internet? 7 steps to cleaning up your online presence appeared first on WeLiveSecurity

VMware confirms Carbon Black causing BSODs, boot loops on Windows
Twitter Whistleblower Complaint: The TL;DR Version
Attacker snags account details from streaming service Plex

open-vm-tools could be made to run programs as an administrator.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Lloyd’s to exclude certain nation-state attacks from cyber insurance policies

security update

Twitter savaged by former security boss Mudge in whistleblower complaint
Smartphone gyroscopes threaten air-gapped systems, researcher finds
Hackers demand $10 million from Paris hospital after ransomware attack
Bitcoin ATMs leeched by attackers who created fake admin accounts
Firewall Bug Under Active Attack Triggers CISA Warning
Getting started with Red Hat Insights malware detection
Black Hat USA 2022 & DEF CON 30: Highlights, Key Findings & Notable Trends

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

patchlevel 213 Security fixes for CVE-2022-2819, CVE-2022-2816, CVE-2022-2817

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

Microsoft finds critical hole in operating system that for once isn’t Windows
If you haven’t patched Zimbra holes by now, assume you’re toast
Novant Health admits leak of 1.3m patients’ info to Facebook
Hiding a phishing attack behind the AWS cloud

security update

Warning over Java libraries and deserialization security weaknesses
LockBit gang hit by DDoS attack after threatening to leak Entrust ransomware data
Laptop denial-of-service via music: the 1980s R&B song with a CVE!
Fake Reservation Links Prey on Weary Travelers
Mac users urged to update Zoom, after security patch released for previously-flawed security patch

An update that solves one vulnerability and has two fixes is now available.

Several security issues were fixed in Libxslt.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Security is hard and won’t get much easier
Zoom patches make-me-root security flaw, patches patch
NSO Group CEO steps down, 100 employees let go too

New vim packages are available for Slackware 15.0 and -current to fix a security issue.

Multiple vulnerabilities have been discovered in Apache Tomcat, the worst of which could result in denial of service.

Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution.

A vulnerability has been found in libcroco which could result in denial of service.

Google and Apple both release patches against zero‑day vulnerabilities – Week in security with Tony Anscombe

Zero-day vulnerabilities are super active and Google and Apple are acting to patch these vulnerabilities, some of which seen on-the-wild. The post Google and Apple both release patches against zero‑day vulnerabilities – Week in security with Tony Anscombe appeared first on WeLiveSecurity