Menu

Monthly Archives: November 2022

Sirius XM flaw unlocks so-called smart cars thanks to code flaw
San Francisco lawmakers approve lethal robots, but they can’t carry guns
AWS’ Inspector offers vulnerability management for Lambda serverless functions
Serious Security: MD5 considered harmful – to the tune of $600,000
Twitter isn’t going to stop people posting COVID-19 misinformation anymore
TikTok NSFW if you work for the South Dakota government
Who’s swimming in South Korean waters? Meet ScarCruft’s Dolphin

ESET researchers uncover Dolphin, a sophisticated backdoor extending the arsenal of the ScarCruft APT group The post Who’s swimming in South Korean waters? Meet ScarCruft’s Dolphin appeared first on WeLiveSecurity

Flaw allowed man to access private information of other Brinks Home Security customers

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

The container trento/trento-web was updated. The following patches have been included in this update:

The container trento/trento-web was updated. The following patches have been included in this update:

The container trento/trento-runner was updated. The following patches have been included in this update:

The container trento/trento-runner was updated. The following patches have been included in this update:

Cloudflare finds a way through China’s network defences

security update

Criminals use trending TikTok challenge to make data-stealing malware invisible
TikTok “Invisible Challenge” porn malware puts us all at risk
Lockheed Martin’s Army cyber training platform goes civilian

The end of year holidays mark the busiest time of the year for online shoppers. We’re all rushing around trying to find the right gift that doesn’t break the budget. Throw in family time and stress can get out of hand. Sadly, this time also marks one of the busiest times of year for online […]

RansomBoggs: New ransomware targeting Ukraine

ESET researchers spot a new ransomware campaign that goes after Ukrainian organizations and has Sandworm’s fingerprints all over it The post RansomBoggs: New ransomware targeting Ukraine appeared first on WeLiveSecurity

The five cyber attack techniques of the apocalypse

USN-5745-1 introduced a regression in shadow.

Sysstat could be made to crash or run programs if it processed specially crafted data.

Sysstat could be made to crash or run programs if it processed specially crafted data.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Sandworm gang launches Monster ransomware attacks on Ukraine
International cops arrest hundreds of fraudsters, money launderers and cocaine kingpins
Blockchain couldn’t stop TXT spam in India, regulator now trying AI

security update

AWS releases Wickr, its encrypted messaging service for enterprises
Windows Server domain controllers may stop, restart after recent updates
Want to boost your cyber security skills by playing games this Christmas?
An Enterprises Guide To Strengthening Linux Cloud Security

It was discovered that twisted, a framework for internet applications written in Python, was prone to an HTML injection when displaying the HTTP Host header in an error page.

It was discovered that twisted, a framework for internet applications written in Python, was prone to an HTML injection when displaying the HTTP Host header in an error page.

An update that fixes 8 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Chrome fixes 8th zero-day of 2022 – check your version now

security update

US bans Chinese telecoms imports – won’t even consider authorizing them
Spyware posing as VPN apps – Week in security with Tony Anscombe

The Bahamut APT group distributes at least eight malicious apps that pilfer victims’ data and monitor their messages and conversations The post Spyware posing as VPN apps – Week in security with Tony Anscombe appeared first on WeLiveSecurity

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

security update

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

10 tips to avoid Black Friday and Cyber Monday scams

It pays not to let your guard down during the shopping bonanza – watch out for some of the most common scams doing the rounds this holiday shopping season The post 10 tips to avoid Black Friday and Cyber Monday scams appeared first on WeLiveSecurity

Voice-scamming site “iSpoof” seized, 100s arrested in massive crackdown

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Several security vulnerabilities were discovered in inetutils, a collection of common network programs. CVE-2019-0053

Several security vulnerabilities were discovered in inetutils, a collection of common network programs. CVE-2019-0053

It was discovered that a buffer overflow in GraphicsMagick, a collection of image processing tools, could potentially result in the execution of arbitrary code when processing a malformed MIFF image.

It was discovered that a buffer overflow in GraphicsMagick, a collection of image processing tools, could potentially result in the execution of arbitrary code when processing a malformed MIFF image.

How advances in email encryption bring all-out security success
Know your payment options: How to shop and pay safely this holiday season

‘Tis the season for shopping and if you too are scouting for bargains, make sure to keep your money safe when snapping up those deals The post Know your payment options: How to shop and pay safely this holiday season appeared first on WeLiveSecurity

Guess the most common password. Hint: We just told you
Elon Musk to abused Twitter users: Your tormentors are coming back
UK bans Chinese CCTV cameras on ‘sensitive’ government sites
Red Hat OpenShift: How to create and integrate a private registry with stronger security capabilities
S3 Ep110: Spotlight on cyberthreats – an expert speaks [Audio + Text]
Bahamut cybermercenary group targets Android users with fake VPN apps

Malicious apps used in this active campaign exfiltrate contacts, SMS messages, recorded phone calls, and even chat messages from apps such as Signal, Viber, and Telegram The post Bahamut cybermercenary group targets Android users with fake VPN apps appeared first on WeLiveSecurity

Operation Elaborate – UK police text 70,000 people thought to have fallen victim to iSpoof bank fraudsters

JBIG-KIT could be made to crash if it opened a specially crafted file.

Meta links US military to fake social media influence campaigns

Exim could be made to crash or run programs if it processed specially crafted regular expressions.

Exim could be made to crash or run programs if it processed specially crafted regular expressions.

Several security issues were fixed in ImageMagick.

Several security issues were fixed in ImageMagick.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

European Parliament Putin things back together after cyber attack

The risk of becoming a victim of identity theft has never been greater We are increasingly living our lives in the digital realm. Whether we’re banking, purchasing or browsing, our daily activities are most likely taking place online. Not only has this sped up our efficiency, but it has also expanded our exposure to a […]

Smashing Security podcast #299: EV charging risks, FTX, and an ancient apocalypse

security update

Still using a discontinued Boa web server? Microsoft warns of supply chain attacks
Hive ransomware has extorted $100 million in 18 months, FBI warns
CryptoRom “pig butchering” scam sites seized, suspects arrested in US
Security fatigue is real: Here’s how to overcome it

Do your employees take more risks with valuable data because they’ve become desensitized to security guidance? Spot the symptoms before it’s too late. The post Security fatigue is real: Here’s how to overcome it appeared first on WeLiveSecurity

Several security issues were fixed in MariaDB.

Expat could be made to crash or execute arbitrary code.

Expat could be made to crash or execute arbitrary code.

APR-util could be made to crash or leak sensitive information if it opened a specially crafted SDBM file.

APR-util could be made to crash or leak sensitive information if it opened a specially crafted SDBM file.

Understanding open source software supply chain risks

An update that fixes one vulnerability is now available.

‘Pig butchering’ romance scam domains seized and slaughtered by the Feds
For two years security experts have been secretly decrypting systems for Zeppelin ransomware victims
DraftKings gamblers lose $300,000 to credential stuffing attack
AWS fixes ‘confused deputy’ vulnerability in AppSync
How to hack an unpatched Exchange server with rogue PowerShell code