Menu

Category Archives: All

Everything

Banking Attacks Surge Along with Post-COVID Economy
Ahem, Huawei, your USB LTE stick has a vuln. I SAID AHEM, Huawei, are you listening?
JBS Foods ransomware gang: White House ‘engaging directly’ with Russia about attack on massive meat producer
REvil Ransomware Ground Down JBS: Sources
UK Special Forces soldiers’ personal data was floating around WhatsApp in a leaked Army spreadsheet
Babuk ransomware gang says it’s no longer interested in encrypting data, would rather kidnap it instead
DoJ Charges Rhode Island Woman in Phishing Scheme Against Politicians

An update for glib2 is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Amazon Sidewalk Poised to Sweep You Into Its Mesh
OpenPGP library RNP updates after Thunderbird decrypt-no-recrypt bug squashed

An update for openvswitch is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This advisory resolves CVE issues filed against XP1 releases that have been fixed in the underlying EAP 7.3.x base. There are no changes to the EAP XP1 code base. NOTE: This advisory is informational only. There are no code changes

Dnsmasq could be exposed to cache poisoning.

Several security issues were fixed in Django.

Network-Bound Disk Encryption improvements in RHEL 8
Feds seize two domains used by SolarWinds intruders for malware spear-phishing op
“Have I Been Pwned” breach site partners with… the FBI!

Applications using Lasso could be made to allow unintended access.

Cyber-Insurance Fuels Ransomware Payment Surge

In a previous post, we talked a bit about what pen testing is and how to use the organizations that provide them to your benefit. But, what about when one of them hands a client a failing grade? Consider this, you’re an MSP and you get a letter or email from one of your customers […]

An update for rh-python36-python-jinja2 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Where Bug Bounty Programs Fall Flat
There’s a lesson here for us all: A third of healthcare orgs in Sophos survey ‘hit with ransomware in 2020’
Remember those wacky cyberpunk costumes in Hackers? They’re on display in London this week
How Mobile Ad Fraud has Evolved in the Year of the Pandemic
Cyberattack Forces Meat Producer to Shut Down Operations in U.S., Australia
World’s biggest meat supplier, JBS, suffers cyber attack
5 common scams targeting teens – and how to stay safe

From knock-off designer products to too-good-to-be-true job offers, here are five common schemes fraudsters use to trick teenagers out of their money and sensitive data The post 5 common scams targeting teens – and how to stay safe appeared first on WeLiveSecurity

Increase confidence in public cloud security: Integrate Intel SGX, says G-Core Labs Cloud
Have I Been Pwned goes open source, bags help from FBI

security update

US Army tells remote workers to switch off their IoT devices (and then withdraws advice)
On the Taxonomy and Evolution of Ransomware
Don’t feed the trolls and other tips for avoiding online drama

You may not be able to escape internet trolls, but you have a choice about how you will deal with them – here’s how you can handle trolls without losing your cool The post Don’t feed the trolls and other tips for avoiding online drama appeared first on WeLiveSecurity

Amir Sarabadani and Kunal Mehta discovered that the import functionality of Hyperkitty, the web user interface to access Mailman 3 archives, did not restrict the visibility of private archives during the import, i.e. that during the import of a private Mailman 2 archive the archive was

security update

8u292 update

8u292 update

Security fix for CVE-2021-30465

**Version 4.4.24** (2021-05-19) * security **CVE-2021-21424** [SecurityCore] Fix user enumeration via response body on invalid credentials (chalasr) * bug #41230 [FrameworkBundle][Validator] Fix deprecations from Doctrine Annotations+Cache (derrabus) * bug #41240 Fixed deprecation warnings about passing null as parameter (derrabus) * bug #41241 [Finder] Fix gitignore regex

**Version 3.4.49** (2021-05-19) * security **CVE-2021-21424** [SecurityCore] Fix user enumeration via response body on invalid credentials (chalasr) —- **Version 3.4.48** (2021-05-12) * security **CVE-2021-21424** [Security][Guard] Prevent user enumeration (chalasr)

Hackers Exploit Post-COVID Return to Offices
US nuclear weapon bunker security secrets spill from online flashcards since 2013
HPE Fixes Critical Zero-Day in Server Management Software
Let’s talk ransomware with the experts from Acronis
Nobelium Phishing Campaign Poses as USAID
Building Multilayered Security for Modern Threats
Most cloud security problems breathe

Luis Merino, Markus Vervier and Eric Sesterhenn discovered an off-by-one in Nginx, a high-performance web and reverse proxy server, which could result in denial of service and potentially the execution of arbitrary code.

Russian gang behind SolarWinds hack returns with phishing attack disguised as mail from US aid agency
Hong Kong recorded phishing surge in 2020 as scum sought to cash in on viral worries

The container caasp/v4.5/velero-restic-restore-helper was updated. The following patches have been included in this update:

The container caasp/v4.5/velero-plugin-for-microsoft-azure was updated. The following patches have been included in this update:

The container caasp/v4.5/velero-plugin-for-gcp was updated. The following patches have been included in this update:

The container caasp/v4.5/velero-plugin-for-aws was updated. The following patches have been included in this update:

The container caasp/v4.5/velero was updated. The following patches have been included in this update:

security update

You’ve likely heard of software-as-a-service (SaaS), infrastructure-as-a-service (IaaS), and numerous other “as-a-service” platforms that help support the modern business world. What you may not know is that cybercriminals often use the same business concepts and service models in their own organizations as regular, non-criminal enterprises; i.e., the same practices the majority of their intended victims […]

Targeted AnyDesk Ads on Google Served Up Weaponized App
Fujitsu SaaS Hack Sends Govt. of Japan Scrambling
Cryptocurrency scam attack on Twitter reminds users to check their app connections
“Unpatchable” vuln in Apple’s new Mac chip – what you need to know
Fujitsu pulls ProjectWEB tool offline after apparent supply chain attack sees Japanese infosec agency data stolen
Biden’s Cybersecurity Executive Order Puts Emphasis on the Wrong Issues
Security automation for digital transformation
I hacked my friend’s website after a SIM swap attack

Here’s how easily your phone number could be stolen, why a successful SIM swap scam is only the beginning of your problems, and how you can avoid becoming a victim of the attack The post I hacked my friend’s website after a SIM swap attack appeared first on WeLiveSecurity

Unfixable Apple M1 chip bug enables cross-process chatter, breaking OS security model
Smashing Security podcast #229: Dating leaks, right to repair, and a stinky bishop

Patch for CVE-2020-24119.

CVE-2021-3480: invalid BIND DN crash

Patch for CVE-2020-24119.

CVE-2021-3480: invalid BIND DN crash

An update that fixes one vulnerability is now available.

PDF Feature ‘Certified’ Widely Vulnerable to Attack
VMware Sounds Ransomware Alarm Over Critical Severity Bug
Bluetooth bugs could allow attackers to impersonate devices

Patches to remedy the vulnerabilities should be released over the coming weeks The post Bluetooth bugs could allow attackers to impersonate devices appeared first on WeLiveSecurity

Multiple vulnerabilities have been found in Ceph, the worst of which could result in privilege escalation.

BazaLoader Masquerades as Movie-Streaming Service
S3 Ep34: Apple bugs, scammers busted, and how crooks bypass 2FA [Podcast]
‘Privateer’ Threat Actors Emerge from Cybercrime Swamp
A Peek Inside the Underground Ransomware Economy
What to do about open source vulnerabilities? Move fast, says Linux Foundation expert

nginx could be made to crash or run programs if it received specially crafted network traffic.

A vulnerability in Nextcloud Desktop Client could allow a remote attacker to execute arbitrary commands.

Actionable threat intelligence for publicly known exploits for RHEL

Multiple vulnerabilities have been found in cURL, the worst of which could result in the arbitrary execution of code.

Computer Misuse Act: Tell the Home Office infosec needs a public interest defence in law, says CyberUp campaign

Multiple vulnerabilities have been found in OpenSSH, the worst of which could allow a remote attacker to execute arbitrary code.

The package thunderbird before version 78.10.2-1 is vulnerable to multiple issues including content spoofing and information disclosure.

The package hivex before version 1.3.20-1 is vulnerable to denial of service.

In-person cybersec training? Yes, it’s back on the agenda this year
Contract killer: Certified PDFs can be secretly tampered with during the signing process, boffins find
VMware reveals critical vCenter hole it says ‘needs to be considered at once’

If you’re an admin, service provider, security executive, or are otherwise affiliated with the world of IT solutions, then you know that one of the biggest challenges to overcome is efficacy. Especially in terms of cybersecurity, efficacy is something of an amorphous term; everyone wants it to be better, but what exactly does that mean? […]

Threat Actor ‘Agrius’ Emerges to Launch Wiper Attacks Against Israeli Targets

An update that fixes one vulnerability is now available.

Red Hat OpenShift Container Platform release 4.7.12 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

Red Hat OpenShift Container Platform release 4.7.12 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.7.12.

Red Hat OpenShift Container Platform release 4.7.12 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.7.12.