Menu

Category Archives: All

Everything

Ring Adds End-to-End Encryption to Quell Security Uproar

Release of OpenShift Serverless 1.12.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each

LibreOffice slideshow aborts with stack smashing in cairo’s composite_boxes (CVE-2020-35492). References: – https://bugs.mageia.org/show_bug.cgi?id=28084

Use-after-free write when handling a malicious COOKIE-ECHO SCTP chunk. (CVE-2020-16044) See upstream releasenotes for other changes. References:

NVIDIA GPU Display Driver Linux contains a vulnerability in the kernel mode layer (nvidia.ko) IOCTL in which user-mode clients can access legacy privileged APIs, which may lead to denial of service, escalation of privileges, and information disclosure (CVE”2021”1052).

FILTER_VALIDATE_URL accepts URLs with invalid userinfo (CVE-2020-7071). stream_get_contents() fails with maxlength=-1 or default. See upstream releasenotes for other changes.

It was discovered that Awstats was vulnerable to path traversal attacks. A remote unauthenticated attacker could leverage that to perform arbitrary code execution. The previous fix did not fully address the issue when the default /etc/awstats/awstats.conf is not present (CVE-2020-29600).

Orca Security public cloud security report reveals how most large cloud breaches happen
Smashing Security podcast #210: DC rioters ID’d, Energydots, and ransomware gets you in a pickle
Is a remote workforce making your organisation less secure?
Hackers leak stolen COVID‑19 vaccine documents

The documents related to COVID-19 vaccine and medications were stolen from the EU’s medicines agency last month The post Hackers leak stolen COVID‑19 vaccine documents appeared first on WeLiveSecurity

TikTok Takes Teen Accounts Private
High-Severity Cisco Flaw Found in CMX Software For Retailers

Top gaming companies positioned to be next major cyberattack target After healthcare and higher education emerged as lucrative targets for cyberattacks in 2020, researchers have identified the video gaming industry as another key target. By scouring the dark web for stolen data belonging to any of the top 25 largest gaming firms, over a million […]

Microsoft patches anti-virus bug that allowed boobytrapped files to run malicious code when scanned

“It’s definitely dead,” says Tyler Moffitt, security analyst at Carbonite + Webroot, OpenText companies. “At least,” he amends, “for now.” Maze ransomware, which made our top 10 list for Nastiest Malware of 2020 (not to mention numerous headlines throughout the last year), was officially shut down in November of 2020. The ransomware group behind it […]

Critical WordPress-Plugin Bug Found in ‘Orbit Fox’ Allows Site Takeover
Hackers Leak Stolen Pfizer-BioNTech COVID-19 Vaccine Data
Sophisticated Hacks Against Android, Windows Reveal Zero-Day Trove
Operation Spalax: Targeted malware attacks in Colombia

ESET researchers uncover attacks targeting Colombian government institutions and private companies, especially from the energy and metallurgical industries The post Operation Spalax: Targeted malware attacks in Colombia appeared first on WeLiveSecurity

Home schooling – how to stay secure
Post-Backlash, WhatsApp Spells Out Privacy Policy Updates
CISOs Prep For COVID-19 Exposure Notification in the Workplace

Red Hat OpenShift Container Platform release 4.4.32 is now available with updates to packages and images that fix several bugs and add enhancements. This release also includes a security update for Red Hat OpenShift Container Platform 4.4.

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for .NET 5.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for rh-dotnet50-dotnet is now available for .NET on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

World’s largest dark-web marketplace shuttered after Euro cybercops cuff Aussie
Critical Microsoft Defender Bug Actively Exploited; Patch Tuesday Offers 83 Fixes
Microsoft emits 83 security fixes – and miscreants are already exploiting one of the vulns in Windows Defender
SolarWinds malware was sneaked out of the firm’s Orion build environment 6 months before anyone realised it was there – report
Data Breach at ‘Resident Evil’ Gaming Company Widens
Mimecast Certificate Hacked in Microsoft Email Supply-Chain Attack
BumbleBee Opens Exchange Servers in xHunt Spy Campaign

OpenShift Serverless 1.9.0 release and security update is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Adobe Fixes 7 Critical Flaws, Blocks Flash Player Content
5 common scams and how to avoid them

Fraudsters are quick to exploit current events for their own gain, but many schemes do the rounds regardless of what’s making the news. Here are 5 common scams you should look out for. The post 5 common scams and how to avoid them appeared first on WeLiveSecurity

Europol Reveals Dismantling of ‘Largest’ Underground Marketplace
Ethical Hackers Breach U.N., Access 100,000 Private Records

Several security vulnerabilities were found in ImageMagick, a suite of image manipulation programs. An attacker could cause denial of service and execution of arbitrary code when a crafted image file is processed.

Microsoft’s beefed-up take on Linux server security has hit general availability
Ubiquiti users told to change their passwords following security breach

An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For

An update is now available for Red Hat Ceph Storage 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat Ceph Storage 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Kaspersky Lab autopsies evidence on SolarWinds hack
How I found a bug in YouTube that let me watch private videos I wasn’t allowed to, says compsci student

An update for kernel is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Ubiquiti iniquity: Wi-Fi box slinger warns hackers may have peeked at customers’ personal information
That’s it. It’s over. It’s really over. From today, Adobe Flash Player no longer works. We’re free. We can just leave
Russia-linked postcard was “sent to FireEye’s CEO after cybersecurity firm uncovered hack”
Donald Trump’s presidency ended today, claims altered US State Department website
Aliens and UFOs: A Final Frontier for Social Engineers
Millions of Social Profiles Leaked by Chinese Data-Scrapers
Researcher Builds Parler Archive Amid Amazon Suspension
SolarWinds Hack Potentially Linked to Turla APT
Thou shalt not hack indiscriminately, High Court of England tells Britain’s spy agencies
Unauthorised RAC staffer harvested customer details then sold them to accident claims management company
Google Titan security keys hacked by French researchers

An update that fixes 13 vulnerabilities is now available.

An update that fixes 13 vulnerabilities is now available.

SolarWinds takes a leaf out of Zoom’s book, hires A-Team of Stamos and Krebs to sort out its security woes

This update upgrades Firefox to version 78.6.1 ESR. * Mozilla: Use-after-free write when handling a malicious COOKIE-ECHO SCTP chunk (CVE-2020-16044) SL7 x86_64 firefox-78.6.1-1.el7_9.x86_64.rpm firefox-debuginfo-78.6.1-1.el7_9.x86_64.rpm firefox-78.6.1-1.el7_9.i686.rpm – Scientific Linux Development Team

Ransomware gangs scavenge for sensitive data by targeting top executives

An update that solves 6 vulnerabilities and has 58 fixes is now available.

A flaw was discovered in coturn, a TURN and STUN server for VoIP. By default coturn does not allow peers on the loopback addresses (127.x.x.x and ::1). A remote attacker can bypass the protection via a specially crafted request using a peer address of ‘0.0.0.0’ and trick

An update that contains security fixes can now be installed.

security update

A Linux Admin’s Getting Started Guide to Improving PHP Security>

An update that fixes 13 vulnerabilities is now available.

An update that fixes 13 vulnerabilities is now available.

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code.

A use-after-free in Mozilla Firefox’s SCTP handling may allow remote code execution.

A buffer overflow in ipmitool might allow remote attacker(s) to execute arbitrary code.

Multiple vulnerabilities have been found in Firejail, the worst of which could result in the arbitrary execution of code.

Malicious Software Infrastructure Easier to Get and Deploy Than Ever
A Look Ahead at 2021: SolarWinds Fallout and Shifting CISO Budgets

security update

security update

Ryuk Rakes in $150M in Ransom Payments

New Firefox version (84.0.2) which fixes security / stability issues.

US courts system fears SolarWinds snafu could have let state hackers poke about in sealed case documents
SolarWinds Hires Chris Krebs, Alex Stamos in Wake of Hack
Red Hat snaps up Kubernetes security specialist StackRox
FBI Warns of Egregor Attacks on Businesses Worldwide

A malicious peer could have modified a COOKIE-ECHO chunk in a SCTP packet in a way that potentially resulted in a use-after-free. We presume that with enough effort it could have been exploited to run arbitrary code. (CVE-2020-16044).

It was discovered that mingw-binutils and binutils suffered from two vulnerabilites which might lead to DoS. Null Pointer Dereference in debug_get_real_type could result in DoS (CVE-2020-16598).

XSS was discovered in SquirrelMail through 1.4.22. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element ().

Busybox contains a Missing SSL certificate validation vulnerability in The “busybox wget” applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using “busybox wget https://compromised-domain.com/important-file”. ().

The container suse/sle15 was updated. The following patches have been included in this update:

It was discovered that Dovecot incorrectly handled certain imap hibernation commands. A remote authenticated attacker could possibly use this issue to access other users’ email (CVE-2020-24386). Innokentii Sennovskiy discovered that Dovecot incorrectly handled MIME

How good are you at scoring security vulnerabilities, really? Boffins seek infosec pros to take rating skill survey
Bugs in Firefox, Chrome, Edge Allow Remote System Hijacking
Biden to Appoint Cybersecurity Advisor to NSC – Report
Nvidia Warns Windows Gamers of High-Severity Graphics Driver Flaws

security update

Fired Healthcare Exec Stalls Critical PPE Shipment for Months
Threatpost Poll: Weigh in on Ransomware Security