Menu

Category Archives: All

Everything

An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes 5 vulnerabilities is now available.

Trump administration says Russia behind SolarWinds hack. Trump himself begs to differ

A heap-buffer overwrites error was discovered in lib/openjp2/mqc.c in OpenJPEG 2.3.1. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution (CVE-2020-27814). A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass

An issue has been found in influxdb, a scalable datastore for metrics, events, and real-time analytics. By using a JWT token with an empty shared secret, one is able to bypass

An update that solves one vulnerability and has one errata is now available.

SCAP Security Guide: helping you to achieve security policy compliance

An update that fixes two vulnerabilities is now available.

Two vulnerabilities were discovered in the PEAR Archive_Tar package for handling tar files in PHP, potentially allowing a remote attacker to execute arbitrary code or overwrite files.

The update for lxml released as 4810-1 introduced a regression when running under Python 2. Updated lxml packages are now available to correct this issue.

security update

Cloud is King: 9 Software Security Trends to Watch in 2021

– Update to Firefox 84 – Built with system nss Please give karma to nss packages which are needed for this update: https://bodhi.fedoraproject.org/updates/FEDORA-2020-c489b93b18 https://bodhi.fedoraproject.org/updates/FEDORA-2020-d04a8e97b3 —- – New upstream version (Firefox 84) – Enabled WebRender by default on Gnome Wayland

Update to latest upstream version.

This update backports a patch for CVE-2020-27828.

Sunburst’s C2 Secrets Reveal Second-Stage SolarWinds Victims
Operation SignSight: Supply‑chain attack against a certification authority in Southeast Asia

ESET researchers have uncovered a supply-chain attack on the website of a government in Southeast Asia. The post Operation SignSight: Supply‑chain attack against a certification authority in Southeast Asia appeared first on WeLiveSecurity

Microsoft Caught Up in SolarWinds Spy Effort, Joining Federal Agencies
Cyberpunk 2077 Headaches Grow: New Spyware Found in Fake Android Download
Insider Threats: What Are They, Really?
Unsecured Azure blob exposed 500,000+ highly confidential docs from UK firm’s CRM customers
Ransomware attackers are making threatening phone calls to their victims, warns FBI

Trickbot spreading through Subway company emails Customers of Subway U.K. have been receiving confirmation emails for recent orders that instead contain malicious links for initiating Trickbot malware downloads. Subway has since disclosed that it discovered unauthorized access to several of its servers, which then launched the campaign. Users who do click on the malicious link […]

The container caasp/v4/nginx-ingress-controller was updated. The following patches have been included in this update:

‘Long-standing vulns’ in 5G protocols open the door for attacks on smartphone users

Several vulnerabilities have been discovered in the Linux kernel that may lead to the execution of arbitrary code, privilege escalation, denial of service or information leaks.

Updated images are now available for Red Hat OpenShift Container Storage 4.6.0 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 14 vulnerabilities is now available.

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting or the disclosure of hidden users.

US nuke agency hacked by suspected Russian SolarWinds spies, Microsoft also installed backdoor
“Is it you in the video?” – don’t fall for this Messenger scam

security update

How to Increase Your Security Posture with Fewer Resources
Nuclear Weapons Agency Hacked in Widening Cyberattack – Report
5M WordPress Sites Running ‘Contact Form 7’ Plugin Open to Attack
Ethical power supplier People’s Energy hacked, 250,000 customers’ personal info accessed

security update

Update to 2.16.9 Release notes: https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.9

Police Vouch for Hacker Who Guessed Trump’s Twitter Password
Google, Qualcomm team up to make long-term Android updates easier on Snapdragon
Air-Gap Attack Turns Memory Modules into Wi-Fi Radios
RubyGems Packages Laced with Bitcoin-Stealing Malware
Cryptologists Crack Zodiac Killer’s 340 Cipher
3M Users Targeted by Malicious Facebook, Insta Browser Add-Ons
Cybersecurity Advent calendar: Stay close to one another… Safely!

This year, many of us will be celebrating Christmas with our loved ones virtually, however we shouldn’t underestimate the value of securing our online communication. The post Cybersecurity Advent calendar: Stay close to one another… Safely! appeared first on WeLiveSecurity

Code42 Incydr Series: Bringing Shadow IT into the light with Code42 Incydr
When zombie malware leads to big-money ransomware attacks
Whistleblowers have come to us alleging spy agency wrongdoing, says UK auditor IPCO

An update for openssl is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

How cyber-attackers are coming after you in 2021
Smashing Security podcast #209: Vengeful ex-staff, bad Santas, and iOS app nutrition facts

An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the postgresql:9.6 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

UK Home Office chucks US firm Leidos £30m for help snooping on comms data
Passwords begone: GitHub will ban them next year for authenticating Git operations
Dutch officials say Donald Trump really did protect his Twitter account with MAGA2020! password

security update

security update

SolarWinds’ shares drop 22 per cent. But what’s this? $286m in stock sales just before hack announced?

security update

security update

Log right in, the water’s fine, whispers Microsoft as it adds autofill to Authenticator app
Ryuk, Egregor Ransomware Attacks Leverage SystemBC Backdoor

It was discovered that Apache Tomcat from 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an

The SolarWinds Perfect Storm: Default Password, Access Sales and More
Sextortionist Campaign Targets iOS, Android Users with New Spyware
UK proposes new powers for comms regulator to legally unleash avenging hordes on security-breached telcos

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openssl is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Your ship comms app is ‘secured’ with a Flash interface, doesn’t sanitise SQL inputs and leaks user data, you say?

An update for python-XStatic-Bootstrap-SCSS is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for python-XStatic-jQuery is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

How to leak data via Wi-Fi when there’s no Wi-Fi chip: Boffin turns memory bus into covert data transmitter
We’re not saying this is how SolarWinds was backdoored, but its FTP password ‘leaked on GitHub in plaintext’
Subway Sandwich Loyalty-Card Users Suffer Ham-Handed Phishing Scam
Easy WP SMTP Security Bug Can Reveal Admin Credentials
Gitpaste-12 Worm Widens Set of Exploits in New Attacks
Firefox Patches Critical Mystery Bug, Also Impacting Google Chrome
Medical scans of millions of patients exposed online

Other leaked data included a range of personal information such as names, addresses and personal healthcare information. The post Medical scans of millions of patients exposed online appeared first on WeLiveSecurity

Twitter scores a first for big tech after being fined €450,000 by Ireland’s data watchdog for violating the EU’s GDPR
45 Million Medical Images Left Exposed Online
How scammers target PayPal users and how you can stay safe

What are some common ploys targeting PayPal users? Here’s what you should watch out for when using the popular payment service. The post How scammers target PayPal users and how you can stay safe appeared first on WeLiveSecurity

Agent Tesla Keylogger Gets Data Theft and Targeting Update
Millions of Unpatched IoT, OT Devices Threaten Critical Infrastructure
Phishing tricks that really work – and how to avoid them
Ransomware and IP Theft: Top COVID-19 Healthcare Security Scares

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Cruise line operator Hurtigruten crippled in ransomware attack

An update for the nginx:1.16 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

New Red Hat Single Sign-On 7.4.4 packages are now available for Red Hat Enterprise Linux 8. 2. Relevant releases/architectures: Red Hat Single Sign-On 7.4 for RHEL 8 – noarch

A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

New Red Hat Single Sign-On 7.4.4 packages are now available for Red Hat Enterprise Linux 7. 2. Relevant releases/architectures: Red Hat Single Sign-On 7.4 for RHEL 7 Server – noarch

45 million medical scans from hospitals all over the world left exposed online for anyone to view – some servers were laced with malware
Up to 18,000 SolarWinds customers installed poisoned update that could allow state-sponsored attack
SolarWinds: Hey, only as many as 18,000 customers installed backdoored software linked to US govt hacks