Menu

Category Archives: All

Everything

eterm, an enlightened terminal emulator, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q).

Red Hat OpenShift Container Platform release 3.11.452 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 3.11.

DarkSide Pwned Colonial With Old VPN Password
Intel’s latest patch set plugs some serious holes in CPU, Bluetooth, server, and – ironically – security lines

An update that fixes three vulnerabilities is now available.

Identity and access in the DevSecOps life cycle

Several security issues were fixed in Intel Microcode.

Security researcher says attacks on Russian government have Chinese fingerprints – and typos, too
Extra urgency in June’s Patch Tuesday: Microsoft warns six more bugs are being exploited
FBI paid renegade developer $180k for backdoored AN0M chat app that brought down drug underworld
Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws
Lewd Phishing Lures Aimed at Business Explode
TrickBot Coder Faces Decades in Prison
Google Patches Critical Android RCE Bug
Hundreds of suspected criminals arrested after being tricked into using FBI‑run chat app

Law enforcement around the world used a messaging app called AN0M to monitor the communications of alleged criminals The post Hundreds of suspected criminals arrested after being tricked into using FBI‑run chat app appeared first on WeLiveSecurity

‘An0m’ Encrypted-Chat Sting Leads to Arrest of 800
Cryptography whizz Phil Zimmermann looks back at 30 years of Pretty Good Privacy
Siloscape malware targets Windows containers, breaks through to the underlying Kubernetes cluster
DoS vulns in 3 open-source MQTT message brokers could leave users literally locked out of their homes or offices
Billions of Compromised Records and Counting: Why the Application Layer is Still the Front Door for Data Breaches

Memory safety bugs fixed in Firefox 89 and Firefox ESR 78.11 Mozilla developers Gabriele Svelto, Anny Gakhokidze, Alexandru Michis, Christian Holler reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been […]

Fixed format string vulnerability allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file (CVE-2021-30145). References: – https://bugs.mageia.org/show_bug.cgi?id=29058 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QVXB4F67QODLPKYBZX7SBXTE7ESGKGOD/

This update patches the vendored `smallvec` Rust crate in librsvg to fix a security vulnerability: The Iterator implementation mishandles destructors, leading to a double free (CVE-2021-25900). References:

A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability (CVE-2021-20193). References: – https://bugs.mageia.org/show_bug.cgi?id=29049 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XRDSUUE3LUKBDRLPB7GTT5QZRPV5J7O4/

Exponential entity expansion attack bypasses all existing protection mechanisms. (CVE-2021-3541). References: – https://bugs.mageia.org/show_bug.cgi?id=29039 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/NYSYJVWYEQHFG2TBIQJRJ5COUR5LNFJJ/

A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmasq, only needs to guess the random transmission ID to forge a […]

Evil Corp Impersonates PayloadBin Group to Avoid Federal Sanctions
Criminal networks smashed after using “secure” chat app secretly run by cops
I think therefore IAM: It’s not cool, it’s not sexy, but it’s one of the most important and difficult areas in modern IT
Uncle Sam recovers 63.7 of 75 Bitcoins Colonial Pipeline paid to ransomware crew
Australian cops, FBI created backdoored chat app, told crims it was secure – then snooped on 9,000 users’ plots
FBI drops subpoena to identify readers of USA Today article about shootout with agents
Everything Apple announced: Tor-ish Safari anonymization. Cloaked iCloud addresses. Cloud CI/CD. And more
Google, Facebook, Chaos Computer Club join forces to oppose German state spyware
FBI Claws Back Millions of DarkSide’s Ransom Profits
US House Rep on cyber committees tweets Gmail password, PIN in Capitol riot lawsuit outrage
Bad Apple: App Store Rife with Fraud, Fleeceware
Novel ‘Victory’ Backdoor Spotted in Chinese APT Campaign
Windows Container Malware Targets Kubernetes Clusters
Latvian woman charged with writing malware for the Trickbot Group
Remember Anonymous? It/they might be back, and it/they are angry with Elon Musk

USN-4937-1 introduced a regression in GNOME Autoar.

We’re right behind Computer Misuse Act reforms for busting ransomware gangs, says UK infosec industry

USN-4969-1 introduced a regression in DHCP.

Go fuzz to catch hard-to-find bugs in Go
Hacking space: How to pwn a satellite

Hacking an orbiting satellite is not light years away – here’s how things can go wrong in outer space The post Hacking space: How to pwn a satellite appeared first on WeLiveSecurity

Military infosec SNAFUs: What WhatsApp and bears in the woods can teach us

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libwebp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

Multiple security issues have been discovered in libwebp CVE-2018-25009

An update that solves 12 vulnerabilities and has 23 fixes is now available.

An update that fixes 21 vulnerabilities is now available.

Several security issues were fixed in the Linux kernel.

security update

New version 3.4.5, Fix for CVE-2021-22207.

Fix for CVE-2021-25217

New version 3.4.5, Fix for CVE-2021-22207.

security update

Cyberattack Suspected in Cox TV and Radio Outages
Biden expands Chinese tech and military blocklist to 59 companies

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. In adddition two security issues were addressed in the OpenPGP support.

Zero‑day in popular WordPress plugin exploited to take over websites

Websites using Fancy Product Designer are susceptible to remote code execution attacks even if the plugin is deactivated The post Zero‑day in popular WordPress plugin exploited to take over websites appeared first on WeLiveSecurity

Good news for pentesters and network admins: US issues ransomware guidance asking biz to skill up security teams
Supreme Court Limits Scope of Controversial Hacking Law
How to hack into 5500 accounts… just using “credential stuffing”
REvil Ransomware Gang Spill Details on US Attacks
Android banking malware sharply increased in the first chunk of 2021, reckons ESET

An update that fixes one vulnerability is now available.

Is it possible to automate all of cloud operations?
The policy of truth: As ransomware claims rise, what’s a cyber insurer to do?
Brit retailer Furniture Village confirms ‘cyber-attack’ as systems outage rolls into Day 7
How to use Google’s new dependency mapping tool to find security flaws buried in your projects
‘Battle for the Galaxy’ Mobile Game Leaks 6M Gamer Profiles

Apply fix for CVE-2021-3500. —- Apply fix for CVE-2021-32490, CVE-2021-32491, CVE-2021-32492, CVE-2021-32493

Backport fixes for CVE-2021-32617, CVE-2021-29623.

Upgrade to upstream security release 3.7.4

Apply fix for CVE-2021-3500. —- Apply fix for CVE-2021-32490, CVE-2021-32491, CVE-2021-32492, CVE-2021-32493

Backport fixes for CVE-2021-32617, CVE-2021-29623.

Supreme Court narrows Computer Fraud and Abuse Act: Misusing access not quite the same as breaking in

security update

Google PPC Ads Used to Deliver Infostealers
Cryptocurrency hacks wanted – $100,000 prize fund offered in contest run by cybercrime forum
Backup appliance firm pays out $2.6 million ransom to attackers
FireEye sold to McAfee’s new owners for $1.2bn as Mandiant split into standalone firm again
Exchange Servers Targeted by ‘Epsilon Red’ Malware
S3 Ep35: Apple chip flaw, Have I Been Pwned, and Covid tracker trouble [Podcast]
Then and Now: Securing Privileged Access Within Healthcare Orgs
Kubernetes architecture and what it means for security
It’s time to get serious about enterprise password management – download this 1Password white paper now
Smashing Security podcast #230: Flash card f-up and energy pipe pilfering
ESET Threat Report T1 2021

A view of the T1 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T1 2021 appeared first on WeLiveSecurity

European Parliament’s data adequacy objection: Doubts cast on UK’s commitment to privacy protection
Antivirus that mines Ethereum sounds a bit wrong, right? Norton has started selling it
Deadline draws near to avoid auto-joining Amazon’s mesh network Sidewalk
Podcast: The State of Ransomware
Effective Adoption of SASE in 2021

security update