Menu

Category Archives: All

Everything

Europol announces two more ransomware busts in Ukraine
Telegraph newspaper bares 10TB of subscriber data and server logs to world+dog

Update to 8.6.0.

Squid could be made to crash or expose sensitive information over the network.

DevSecOps tools, culture and misconceptions: Advice from Red Hatters

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated samba packages that fix several bugs with added enhancement are now available for Red Hat Gluster Storage 3.5 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Updated samba packages that fix several bugs with added enhancement are now available for Red Hat Gluster Storage 3.5 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Update to 8.6.0.

Facebook Outage Drags Down Instagram, WhatsApp, Messenger, Oculus VR
Encrypted & Fileless Malware Sees Big Growth
Lawsuit claims hospital ransomware infection cost baby her life
UK’s £5bn National Cyber Force HQ to be sited in Lancashire beside Defence Secretary’s constituency
Transnational Fraud Ring Bilks U.S. Military Service Members Out of Millions
Ukrainian cops cuff two over $150m ransomware gang allegations, seize $1.3m in cryptocurrency

Imlib2 could be made to denial of service and possibly execute arbitrary code.

€70 million ransomware gang busted in Ukraine
The Pandora Papers is the Panama Papers turned up to 11
Cybersecurity Awareness Month: #BeCyberSmart
Leveraging the “Power of the Crowd” to Fight Cybercrime with a Unique, Collaborative Intrusion Prevention System>

An update that fixes 9 vulnerabilities is now available.

Python could allow unintended access to network services.

Sir Tim Berners-Lee and the BBC stage a very British coup to rescue our data from Facebook and friends
Firewalls? Pfft – it’s no match for my mighty spares-bin PC

Multiple security vulnerabilities have been discovered in fig2dev, utilities for converting XFig figure files. Buffer overflows, out-of-bounds reads and NULL pointer dereferences could lead to a denial-of-service or other unspecified impact.

– Update cranelift crates to version 0.77.0. – Update the wast crate to version 38.0.0. – Update the wat crate to version 1.0.40. – Update the wasmparser crate to version 0.80.1. – Update wasmtime crates to version 0.30.0. – Update the backtrace crate to version 0.3.61. – Update the addr2line crate to version 0.16.0. – […]

– Update cranelift crates to version 0.77.0. – Update the wast crate to version 38.0.0. – Update the wat crate to version 1.0.40. – Update the wasmparser crate to version 0.80.1. – Update wasmtime crates to version 0.30.0. – Update the backtrace crate to version 0.3.61. – Update the addr2line crate to version 0.16.0. – […]

An update that contains security fixes can now be installed.

Update to 94.0.4606.61. Fixes a big pile of security issues: CVE-2021-30542 CVE-2021-30543 CVE-2021-30558 CVE-2021-30625 CVE-2021-30626 CVE-2021-30627 CVE-2021-30628 CVE-2021-30629 CVE-2021-30630 CVE-2021-30631 CVE-2021-30632 CVE-2021-30633 CVE-2021-37972 CVE-2021-37956 CVE-2021-37957 CVE-2021-37958 CVE-2021-37959 CVE-2021-37960 CVE-2021-37961 CVE-2021-37962 CVE-2021-37963

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

Security fix for [PUT CVEs HERE]

One security issue has been discovered in plib. Integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.

2020 was a year of immense change. One thing is for certain – the world collectively witnessed the increase of digital interconnectivity. We began even more to rely on the internet as a conduit to the world. The rise of remote access to businesses, entertainment and interpersonal connections surged. The death of distance accelerated. The […]

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

Security fix for [PUT CVEs HERE]

– CVE-2021-22947 – STARTTLS protocol injection via MITM – CVE-2021-22946 – protocol downgrade required TLS bypassed – CVE-2021-22945 – use-after-free and double-free in MQTT sending

MFA Glitch Leads to 6K+ Coinbase Customers Getting Robbed
Internet Archive’s 2046 Wayforward Machine says Google will cease to exist

An issue has been found in openssl1.0, a Secure Sockets Layer library. The issue is related to read buffer overruns while processing ASN.1 strings.

Two issues have been found in curl, a command line tool and an easy-to-use client-side library for transferring data with URL syntax.

Sure, you can do Kubernetes at scale. But can you do it securely too?
3.1M Neiman Marcus Customer Card Details Breached
Hackers could force locked iPhones to make contactless payments

Flaws in Apple Pay and Visa could allow criminals to make arbitrary contactless payments – no authentication needed, research finds The post Hackers could force locked iPhones to make contactless payments appeared first on WeLiveSecurity

ESET Threat Report T2 2021

A view of the T2 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T2 2021 appeared first on WeLiveSecurity

That ‘anti-NSO Pegasus spyware’ download is actually a Trojan – so don’t touch it
Gift card fraud: four suspects hit with money laundering charges
Flubot Malware Targets Androids With Fake Security Updates
IKEA: Cameras were hidden in the ceiling above warehouse toilets for ‘health and safety’
New APT ChamelGang Targets Russian Energy, Aviation Orgs
Runtime Analysis in the Red Hat DevSecOps framework
2FA? More like 2F-in-the-way: It seems no one wants me to pay for their services after all
Revealed: How to steal money from victims’ contactless Apple Pay wallets
Google Emergency Update Fixes Two Chrome Zero Days

Fix for CVE-2021-20208 Update to 6.13 cifs.upcall: fix regression in kerberos mount mount.cifs: fix crash when mount point does not exist —- Fix for CVE-2021-20208: cifs.upcall kerberos auth leak in container

Fix for CVE-2021-20208 Update to 6.13 cifs.upcall: fix regression in kerberos mount mount.cifs: fix crash when mount point does not exist —- Fix for CVE-2021-20208: cifs.upcall kerberos auth leak in container

Several problems were corrected in TagLib, a library for reading and editing audio meta data. CVE-2017-12678

Military’s RFID Tracking of Guns May Endanger Troops

Several vulnerabilities were fixed in MIT Kerberos, a system for authenticating users and services on a network. CVE-2018-5729

Ransomware crim: Yeah, what I do is bad. No, I don’t care. Yes, infosec bods are all mouth and no trousers
Tips & Tricks for Unmasking Ghoulish API Behavior
Baby’s Death Alleged to Be Linked to Ransomware
Innovative Proxy Phantom ATO Fraud Ring Haunts eCommerce Accounts
CISA and NSA release guidance for securing VPNs

What your organization should consider when it comes to choosing a VPN solution and hardening it against attacks The post CISA and NSA release guidance for securing VPNs appeared first on WeLiveSecurity

How to steal money via Apple Pay using the “Express Transit” feature
S3 Ep52: Let’s Encrypt, Outlook leak, and VMware exploit [Podcast]
Which? survey finds people would actually pay the online giants not to take their data
Apple Pay with Visa Hacked to Make Payments via Locked iPhones
Beware poisoned Apple AirTags that exploit unpatched “Lost Mode” flaw
Secret backdoor allegedly lets the REvil ransomware gang scam its own affiliates
US cryptocurrency expert pleads guilty to helping North Korea evade sanctions

An update for the virt:av and virt-devel:av modules is now available for Red Hat Enterprise Linux Advanced Virtualization 8.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The Top Ransomware Threats Aren’t Who You Think
Thousands of University Wi-Fi Networks Expose Log-In Credentials

Several vulnerabilities were fixed in the chat client WeeChat. CVE-2020-8955

UK MoD data strategy calls for social media surveillance on behalf of ‘local authorities’
How to prevent CSRF attacks in ASP.NET Core
Attacks against Remote Desktop Protocol endpoints have exploded this year, warns ESET’s latest Threat Report

Red Hat AMQ Broker 7.9.0 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

The container sles-15-sp3-chost-byos-v20210927 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20210927-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20210927-gen2 was updated. The following patches have been included in this update:

Anonymous: We’ve leaked disk images stolen from far-right-friendly web host Epik
Keep Attackers Out of VPNs: Feds Offer Guidance
Smashing Security podcast #245: The Julian Assange assassination plot, and IoT toilets
Don’t look a GriftHorse in the mouth: Trojan trampled 10 million Android devices
Apple AirTag Zero-Day Weaponizes Trackers
Unpatched flaw ‘weaponises’ Apple AirTags to turn them into the phisherman’s friend
GriftHorse Money-Stealing Trojan Takes 10M Android Users for a Ride
Akamai beefs up cybersecurity portfolio with ransomware-tastic Guardicore acquisition
Conti Ransomware Expands Ability to Blow Up Backups
Kaspersky links new Tomiris malware to Nobelium group
SAS 2021: ‘Tomiris’ Backdoor Linked to SolarWinds Malware
Threat Actors Weaponize Telegram Bots to Compromise PayPal Accounts

An update that fixes one vulnerability is now available.

The Migration Toolkit for Containers (MTC) 1.6.0 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Red Hat OpenShift Container Platform release 4.7.32 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.