Menu

Category Archives: All

Everything

Oil & Gas Targeted in Year-Long Cyber-Espionage Campaign
US offers Julian Assange time in Australian prison instead of American supermax if he loses London extradition fight

Cybersecurity analysts are charting both a rise in ransomware incidents and in amounts cybercriminals are demanding from businesses to restore their data. That’s bad news in itself, but what’s often overlooked are the additional ways – beyond payments victims may or may not choose to make– victims pay for these attacks. Our latest threat report […]

Coursera Flunks API Security Test in Researchers’ Exam
Bandidos at large: A spying campaign in Latin America

ESET Research uncovers an active malicious campaign that uses new versions of old malware, Bandook, to spy on its victims The post Bandidos at large: A spying campaign in Latin America appeared first on WeLiveSecurity

S3 Ep40: Kaseya breach, PrintNightmare 0-day, and hacking versus the law [Podcast]
How Fake Accounts and Sneaker-Bots Took Over the Internet
Lazarus gang targets engineers with job offers using poisoned emails
ICO survey on data flouters: 50% say they receive more unwanted calls than before pandemic

Several vulnerabilities have been found in the Apache HTTP server, which could result in denial of service. In addition the implementation of the MergeSlashes option could result in unexpected behaviour.

Criminals prefer to WFH too: Singapore infosec agency says 43% of all crimes in the city-state happened online in 2020
In conversation with Gene Hoffman, co-creator of the internet’s first ad blocker
India under attack by rapidly-evolving advanced persistent threat actor SideCopy, says Cisco Talos
White hats reported key Kaseya VSA flaw months ago. Ransomware outran the patch

The container ses/7/rook/ceph was updated. The following patches have been included in this update:

An inefficient regular expression could be exploited to cause a Denial of Service condition.

You’ve patched that critical Sage X3 ERP security hole, yeah? Not exposing the suite to the internet, either, yeah?

A buffer overflow in BladeEnc might allow arbitrary code execution.

A file named by an attacker being utilized by Mechanize could result in arbitrary code execution.

Multiple vulnerabilities have been found in Privoxy, the worst of which could result in Denial of Service.

Bogus Kaseya VSA patches circulate, booby-trapped with remote-access tool
Smashing Security podcast #235: REvil returns, TikTok grows, and Gettr defaced
Critical Sage X3 RCE Bug Allows Full System Takeovers
British Airways data breach lawsuit settled: Airline coughs up potentially millions to make sueball bounce away
Microsoft struggles to wake from its PrintNightmare: Latest print spooler patch can be bypassed, researchers say
MacOS Targeted in WildPressure APT Malware Campaign
Suspected ‘Dr HeX’ Hacker Busted for 9 Years of Phishing
Report shines light on REvil’s depressingly simple tactics: Phishing, credential-stuffing RDP servers… the usual
Fake Kaseya VSA Security Update Drops Cobalt Strike
Why I Love (Breaking Into) Your Security Appliances
Join over 45,000 others, and get FREE threat intelligence on hackers and exploits with the Recorded Future Cyber Daily
PrintNightmare official patch is out – update now!
UK’s data watchdog probes use of private email to discuss government business at the Department of Health
Cloud Cryptomining Swindle in Google Play Rakes in Cash
How Developers Can Protect Linux From Vulnerabilities>

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Microsoft Releases Emergency Patch for PrintNightmare Bugs
Malware campaign targets companies waiting for Kaseya security patch

linuxptp: missing length check of forwarded messages (CVE-2021-3570) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 – linuxptp-2.0-2.el7_9.1.x86_64.rpm – linuxptp-debuginfo-2.0-2.el7_9.1.x86_64.rpm – Scientific Linux Development Team

Several security issues were fixed in PHP.

libuv could be made to crash or expose sensitive information if it received a specially crafted input.

Mega-distie SYNNEX attacked and Microsoft cloud accounts it tends tampered
Microsoft patches PrintNightmare – even on Windows 7 – but the terror isn’t over

A bug in TCG TPM2 Software Stack may result in information disclosure to a local attacker.

Pro-Trump ‘Gettr’ Social Platform Hacked On Day One
Kaseya’s VSA SaaS restart fails, service restoration delayed by at least ten hours
Kaspersky Password Manager’s random password generator was about as random as your wall clock

security update

security update

Android Apps in Google Play Harvest Facebook Credentials
Ransomware-hit law firm gets court order asking crooks not to publish the data they stole
Western Digital Users Face Another RCE
Kaseya Patches Imminent After Zero-Day Exploits, 1,500 Impacted
British Airways data breach lawsuit settled: Airline coughs up around £30m to make sueball bounce away

An update for linuxptp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for linuxptp is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for linuxptp is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for linuxptp is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Quantum Key Distribution: Is it as secure as claimed and what can it offer the enterprise?

Red Hat OpenShift Container Platform release 4.7.19 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

DARPA nails cash to project ‘FENCE’ — a smart camera that only sends pics when pixels change

An update that fixes three vulnerabilities is now available.

Kaseya says it’s seen no sign of supply chain attack, sets SaaS restoration target of Tuesday afternoon, on-prem fix to follow
The cost of cyber insurance increased 32 per cent last year and shows no signs of easing
Kaseya Attack Fallout: CISA, FBI Offer Guidance
The wheels come off Formula 1’s notification service as fans plied with attacker’s messages
Kaseya ransomware attackers say: “Pay $70 million and we’ll set everyone free”
S3 Ep 39.5: A conversation with Eva Galperin [Podcast]
What’s this about a lawyer looking for an heir? City of London Police seek IT crew to help crack down on fraud
REvil ransomware rampages following Kaseya supply-chain attack
Ransomware Defense: Top 5 Things to Do Right Now

An update that contains security fixes can now be installed.

DjVuLibre could be made to crash or execute arbitrary code if it opened a specially crafted file.

DiDi, China’s Uber analog, booted from local app stores for data naughtiness
IT for service providers biz Kaseya defers decision about SaaS restoration following supply chain attack
Aled Jones says he was hacked, after rude picture posted on Twitter

* CVE-2021-29157: Dovecot does not correctly escape kid and azp fields in JWT tokens. This may be used to supply attacker controlled keys to validate tokens, if attacker has local access. * CVE-2021-33515: On-path attacker could have injected plaintext commands before STARTTLS negotiation that would be executed after STARTTLS finished with the

* CVE-2021-29157: Dovecot does not correctly escape kid and azp fields in JWT tokens. This may be used to supply attacker controlled keys to validate tokens, if attacker has local access. * CVE-2021-33515: On-path attacker could have injected plaintext commands before STARTTLS negotiation that would be executed after STARTTLS finished with the

The ieee-data package, which provides the OUI and IAB listings of identifiers assigned by IEEE Standards Association, ships a script (update-ieee-data) which queries ieee.org to download the most recent dataset and save it to /var/lib/ieee-data/.

Updated live packages fix security vulnerabilities: Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and Matroska

Updated PHP packages fix security vulnerabilities: – Fixed bug #81122: SSRF bypass in FILTER_VALIDATE_URL. (CVE-2021-21705) PDO_Firebird: – Fixed bug #76448: Stack buffer overflow in firebird_info_cb.

Updated file-roller package fixes security vulnerability: A path traversal vulnerability was found in file-roller due to an incomplete fix for CVE-2020-11736. It may still be possible to extract files outside of the intended directory in case of malicious archives

Updated busybox packages fix security vulnerability: decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data (CVE-2021-28831).

A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability. (CVE-2021-20297)

Kaseya supply‑chain attack: What we know so far

As news breaks about the supply-chain ransomware attack against Kaseya’s IT management software, here’s what we know so far The post Kaseya supply‑chain attack: What we know so far appeared first on WeLiveSecurity

IT management biz Kaseya pwned by miscreants to infect businesses with ransomware

Cyber resilience refers to a business’s ability to mitigate damage to its systems, processes and even its reputation. It’s based on the principle that, in the real (and really connected) world, adverse events occur. This could be in the form of a user enabling a breach by providing sensitive information during a phishing attack, through […]

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Digital rights org claims cyberattacks against Filipino media outlets come from government and army
Microsoft warns of serious vulnerabilities in Netgear’s DGN2200v1 router
Cyber insurance model is broken, consider banning ransomware payments, says think tank
Microsoft tells US lawmakers cloud has changed the game on data privacy, gets 10 info demands a day from cops

An update that solves four vulnerabilities and has one errata is now available.

TrickBot Spruces Up Its Banking Trojan Module
Widespread Brute-Force Attacks Tied to Russia’s APT28
Why Healthcare Keeps Falling Prey to Ransomware and Other Cyberattacks
US email hacker gets his “computer trespass” conviction reversed
The PrintNightmare continues: Microsoft confirms presence of vulnerable code in all versions of Windows