Menu

Category Archives: All

Everything

Revamped Qbot Trojan Packs New Punch: Hijacks Email Threads
‘My wife tried to order some clothes tonight. When she logged in, she was in someone else’s account … Now someone’s charged her card’
DDoS downs New Zealand stock exchange for third consecutive day

security update

Smashing Security podcast #193: Hacking the CIA, Bridgefy, and college lockdowns
Forget your space-age IT security systems. It might just take a $1m bribe and a willing employee to be pwned
North Korean hacking gang targets banks worldwide, US Government warns

security update

Cisco Patches ‘High-Severity’ Bugs Impacting Switches, Fibre Storage
Here’s a neat exploit to trick someone into inadvertently emailing their files to you from their Mac, iPhone via Safari
“Chrome considered harmful” – the Law of Unintended Consequences
Researchers shine light on hackers-for-hire op that hit estate agent with malicious plugin for Autodesk 3ds Max
Hackers Exploit Autodesk Flaw in Recent Cyberespionage Attack
Disinformation Spurs a Thriving Industry as U.S. Election Looms

An update that fixes one vulnerability is now available.

Medical Data Leaked on GitHub Due to Developer Errors
US election 2020: The disinfo operations have evolved, but so have state governments

It was reported that the Lua module for Nginx, a high-performance web and reverse proxy server, is prone to a HTTP request smuggling vulnerability.

Mozilla: Attacker-induced prompt for extension installation (CVE-2020-15664) * Mozilla: Use-After-Free when aborting an operation (CVE-2020-15669) SL6 x86_64 firefox-68.12.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.12.0-1.el6_10.x86_64.rpm firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm i386 firefox-68.12.0-1.el6_10.i686.rpm firefox-d [More…]

How to Write a Cybersecurity Playbook During a Pandemic

Several security issues were fixed in libmysofa.

An update that fixes three vulnerabilities is now available.

– New upstream version (80.0)

security update

Four More Bugs Patched in Microsoft’s Azure Sphere IoT Platform
FBI, CISA warn of spike in vishing attacks

Cybercriminals increasingly take aim at teleworkers, setting up malicious duplicates of companies’ internal VPN login pages The post FBI, CISA warn of spike in vishing attacks appeared first on WeLiveSecurity

Cyber attacks: Several Canadian government services disrupted

Several services from the Canadian government, including the national revenue agency, had to be shut down following a series of credential stuffing cyberattacks. The post Cyber attacks: Several Canadian government services disrupted appeared first on WeLiveSecurity

How to secure your TikTok account

From keeping your account safe to curating who can view your liked content, we look at how you can increase your security and privacy on TikTok The post How to secure your TikTok account appeared first on WeLiveSecurity

Impersonating users of ‘protest’ app Bridgefy was as simple as sniffing Bluetooth handshakes for identifiers
Safari Bug Revealed After Apple Takes Nearly a Year to Patch
Lazarus Group Targets Cryptocurrency Firms Via LinkedIn Messages
Be very afraid! British Army might scrap battle tanks for keyboard warriors – report

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

Shoring Up the 2020 Election: Secure Vote Tallies Aren’t the Problem
North Korean hackers pwned cryptocurrency sysadmin with GDPR-themed LinkedIn lure, says F-Secure
The Viking Snowden: Denmark spy chief ‘relieved of duty’ after whistleblower reveals illegal snooping on citizens
Google Fixes High-Severity Chrome Browser Code Execution Bug

security update

Iran-Linked ‘Newbie’ Hackers Spread Dharma Ransomware Via RDP Ports

An update that fixes 21 vulnerabilities is now available.

Several security issues were fixed in Net-SNMP.

APIs Are the Next Frontier in Cybercrime

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update for openshift-enterprise-hyperkube-container is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for jenkins and openshift is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Canadian shipping company Canpar gets an unwanted delivery – ransomware
Bletchley Park Trust can’t crack COVID-caused revenue slump without losing staff

Chrony’s method of opening its PID file could allow a compromised chrony user account to overwrite files in certain parts of the filesystem with chrony’s PID, using a symlink attack (CVE-2020-14367). References:

Reading Time: ~ 2 min. Ransomware Attack Targets Major Cruise Line Officials for Carnival Cruises have confirmed that a portion of their IT systems were encrypted following a cyberattack identified over the weekend. The company also revealed that sensitive information for both employees and customers was illicitly accessed, though they did not admit to what […]

Security fix for CVE-2020-14367

Several vulnerabilities have been discovered in sqlite3, a C library that implements an SQL database engine. CVE-2018-8740

Several memory leaks were discovered in proftpd-dfsg, a versatile, virtual-hosting FTP daemon, when mod_facl or mod_sftp is used which could lead to memory exhaustion and a denial-of-service.

Jason A. Donenfeld found an ansi escape sequence injection into software-properties, a manager for apt repository sources. An attacker could manipulate the screen of a user prompted to install an additional repository (PPA).

News Wrap: AWS Cryptojacking Worm, IBM Privacy Lawsuit and More

Multiple vulnerabilities were discovered in Python2.7, an interactive high-level object-oriented language.

Tim Starling discovered two vulnerabilities in firejail, a sandbox program to restrict the running environment of untrusted applications.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Utes gotta be kidding me… University of Utah handed $457K to ransomware creeps
Appearing on the Easy Prey podcast
Outlook “mail issues” phishing – don’t fall for this scam!
University of Utah Pays $457K After Ransomware Attack
CREST exam cheat-sheet scandal: New temp chairman at UK infosec body as lawyers and ex-copper get involved

An update that solves one vulnerability and has 22 fixes is now available.

An update that solves one vulnerability and has 19 fixes is now available.

Researchers Sound Alarm Over Malicious AWS Community AMIs
Using AI to fight hand-crafted Business Email Compromise
Shared memory vulnerability in IBM’s Db2 database could let nefarious insiders wreak havoc – so get patching
Former Uber CSO Charged With Paying ‘Hush Money’ in 2016 Breach Cover-Up

Several security issues were fixed in Bind.

Physical locks are less hackable than digital locks, right? Maybe not: Boffins break in with a microphone

An update that solves 7 vulnerabilities and has 109 fixes is now available.

Ex-Uber chief security officer charged, accused of covering up theft of personal info from databases by hackers

The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function. (CVE-2020-14148) References:

– fix expired pointer dereference via multi API with `CURLOPT_CONNECT_ONLY` option set (CVE-2020-8231)

IBM Settles Lawsuit Over Weather Channel App Data Privacy
How to prepare and protect your digital legacy

It’s never too soon to plan for what will happen to your digital presence after you pass away The post How to prepare and protect your digital legacy appeared first on WeLiveSecurity

Transparent Tribe Mounts Ongoing Spy Campaign on Military, Government
Microsoft Out-of-Band Security Update Fixes Windows Remote Access Flaws
Experian says it recovered and deleted data on 24 million South Africans after giving it to random ‘marketing’ person

Multiple vulnerabilities were found in ghostscript, an interpreter for the PostScript language and for PDF, allowing an attacker to escalate privileges and cause denial of service via crafted PS/EPS/PDF files.

An update that solves two vulnerabilities and has 6 fixes is now available.

Senate Bill Would Expand Facial-Recognition Restrictions Nationwide
Cisco Critical Flaw Patched in WAN Software Solution
Warehouse management software biz SnapFulfil hit by ransomware: It’s not just the big dogs getting KO’d
IBM AI-Powered Data Management Software Subject to Simple Exploit
Sloppy string sanitization sabotages system security of millions of Java-powered 3G IoT kit: Patch me if you can

curl could be made to expose sensitive information over the network.

Thanks for the memories… now pay up or else: Maze ransomware crew claims to have hacked SK hynix, leaks ‘5% of stolen files’
Smashing Security podcast #192: Ritz and robocalls with Rory

Rebased to version 3.33.0

Update to v0.3.4 release

A security flaw was found on ruby kramdown which may lead to unintended code execution. This vulnerability is now assigned as CVE-2020-14001 . This new rpm should fix this issue.

Researchers Warn of Flaw Affecting Millions of IoT Devices