Menu

Category Archives: All

Everything

Black Hat 2020: Using Botnets to Manipulate Energy Markets for Big Profits

ppp could be made to load arbitrary kernel modules and possibly run programs.

U.S. Offers Reward of $10M for Info Leading to Discovery of Election Meddling

An update that solves one vulnerability and has one errata is now available.

National Crime Agency says Brit teen accused of Twitter hack has not been arrested
USA decides to cleanse local networks of anything Chinese under new five-point national data security plan
Canon not firing on all cylinders: Fledgling cloud loses people’s pics’n’vids, then ‘Maze ransomware’ hits
US voting hardware maker’s shock discovery: Security improves when you actually work with the community
Ever wonder how a pentest turns into felony charges? Coalfire duo explain Iowa courthouse arrest debacle
Black Hat 2020: Linux Spyware Stack Ties Together 5 Chinese APTs
Black Hat 2020: In a Turnaround, Voting Machine Vendor Embraces Ethical Hackers
Twitter Fixes High-Severity Flaw Affecting Android Users
America was getting on top of its electronic voting machine security – then suddenly… A wild pandemic appears
Black Hat 2020: Scaling Mail-In Voting Spawns Broad Challenges
Black Hat 2020: Open-Source AI to Spur Wave of ‘Synthetic Media’ Attacks
FBI warns of surge in online shopping scams

In one scheme, shoppers ordering gadgets or gym equipment are in for a rude surprise – they receive disposable face masks instead The post FBI warns of surge in online shopping scams appeared first on WeLiveSecurity

High-Severity Android RCE Flaw Fixed in August Security Update
Microsoft Teams Patch Bypass Allows RCE
A Cyber ‘Vigilante’ is Sabotaging Emotet’s Return
UK data watchdog having a hard time making GDPR fines stick: Marriott scores another extension, BA prepares to pay 11% of original £183m penalty

An update that fixes 10 vulnerabilities is now available.

An update that fixes 26 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Red Hat Ansible Tower 3.7.2-1 – RHEL7 Container 2. Description: * Updated Named URLs to allow for testing the presence or absence of objects (CVE-2020-14337)

Red Hat Ansible Tower 3.6.5-1 – RHEL7 Container 2. Description: * Removed reports option for Satellite inventory script * Fixed Tower Server Side Request Forgery on Credentials (CVE-2020-14327)

OPA: A general-purpose policy engine for cloud-native

USN-4441-1 introduced a regression in MySQL

NSA warns that mobile device location services constantly compromise snoops and soldiers
China slams President Trump’s TikTok banned-or-be-bought plan in the US
Chinese debt collectors jailed for cyberbullying under ‘soft violence’ laws
Microsoft forked out $13.7m in bug bounties. The reward program’s architect thinks the money could be better spent
NetWalker Ransomware Rakes in $29M Since March

security update

As the world descends into madness, it’s good to see some things never change: Monthly Android patches
Newsletter WordPress Plugin Opens Door to Site Takeover
They say the tooth will set you free… so Brit dentist trade union tells members: ‘Bad news; we’ve been hacked’
Twitter Could Face $250M FTC Fine Over Improper Data Use

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Uncle Sam blames best pal China as Taidoor crew’s dirty RAT takes aim at Western orgs, but others are less sure

libssh could be made to crash if it received a specially crafted request.

Apple Knocked Off Perch as Most Imitated Brand for Phishing Attacks
Podcast: Learning to ‘Speak the Language’ of OT Security Teams
GandCrab ransomware hacker arrested in Belgium

Reading Time: ~ 5 min. Don’t expect cybercriminals to go easy during a hurricane. Quite the opposite, in fact. Just like they’ve used the coronavirus pandemic to launch COVID-related malware scams, hackers will capitalize on the names and news coverage of hurricanes to disguise attacks. That’s why now is a good time to review your […]

postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML (CVE-2020-13692) SL6 noarch postgresql-jdbc-8.4.704-4.el6_10.noarch.rpm – Scientific Linux Development Team

Updated ovirt-engine packages that fix several bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML (CVE-2020-13692) SL7 noarch postgresql-jdbc-9.2.1002-8.el7_8.noarch.rpm postgresql-jdbc-javadoc-9.2.1002-8.el7_8.noarch.rpm – Scientific Linux Development Team

Doctor, doctor, got some sad news, there’s been a bad case of hacking you: UK govt investigates email fail
Leaky AWS S3 buckets are so common, they’re being found by the thousands now – with lots of buried secrets
Days after President Trump suggests pausing election over security, US House passes $500m for states to shore up election security

security update

Google Updates Ad Policies to Counter Influence Campaigns, Extortion
How much is your personal data worth on the dark web?

The going prices are lower than you probably think – your credit card details, for example, can sell for a few bucks The post How much is your personal data worth on the dark web? appeared first on WeLiveSecurity

Netgear Won’t Patch 45 Router Models Vulnerable to Serious Flaw
UK Defence Committee chair muses treating TikTok like Huawei: So eyeball its code then ban it from the country?
Garmin Pays Up to Evil Corp After Ransomware Attack — Reports
Linux Foundation rolls bunch of overlapping groups into one to tackle growing number of open-source security vulns
Black Hat USA 2020: Critical Meetup.com Flaws Reveal Common AppSec Holes

An update that fixes one vulnerability is now available.

‘We stopped ransomware’ boasts Blackbaud CEO. And by ‘stopped’ he means ‘got insurance to pay off crooks’

An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Meetup Critical Flaws Allow ‘Group’ Takeover, Payment Theft

An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

libvncserver: websocket decoding buffer overflow (CVE-2017-18922) SL7 x86_64 libvncserver-0.9.9-14.el7_8.1.i686.rpm libvncserver-0.9.9-14.el7_8.1.x86_64.rpm libvncserver-debuginfo-0.9.9-14.el7_8.1.i686.rpm libvncserver-debuginfo-0.9.9-14.el7_8.1.x86_64.rpm libvncserver-devel-0.9.9-14.el7_8.1.i686.rpm libvncserver-devel-0.9.9-14.el7_8.1.x86_64.rpm – Scientific Linux [More…]

Oh cool, more Cisco patches to apply. Happy Monday
IoT Security Vulnerabilities are Ubiquitous: How To Secure Your Router and Your Linux System Now>

An update that fixes one vulnerability is now available.

Multiple security issues have been found in Thunderbird which could result in denial of service or potentially the execution of arbitrary code.

It was discovered that there was an escaping issue in libphp-phpmailer, an email generation utility class for the PHP programming language.

Multiple vulnerabilities have been found in Python, the worst of which could result in a Denial of Service condition.

In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in

Security fix for CVE-2020-15917 (STARTTLS protocol violation).

security update

Fix insufficient output escaping bug in file attachment names (CVE-2020-13625). References: – https://bugs.mageia.org/show_bug.cgi?id=26760

Twitter hack – three suspects charged in the US
Who was behind that stunning Twitter hack? State spies? Probably this Florida kid, say US prosecutors

An integer overflow in the getnum function in lua_struct.c CVE-2020-14147 References: – https://bugs.mageia.org/show_bug.cgi?id=26978

Multiple security vulnerabilites in virtualbox allow unauthorized access to critical data or takeover of Oracle VM VirtualBox. See CVE references for details. References:

Updated dnsmasq package fix insecure default configuration potentially making it an open resolver (CVE-2020-14312). In its default configuration, dnsmasq listen and answer query from any address even outside of the local subnet. Thus, it may inadvertently

Bypass of boundary checks in nio.Buffer via concurrent access. (CVE-2020-14583) Incomplete bounds checks in Affine Transformations. (CVE-2020-14593)

The CBC padding operations were not constant time and as a result would leak the length of the plaintext values which were being padded to an attacker running a side channel attack via shared resources such as cache or branch predictor. No information about the contents was leaked, but the length alone might be used […]

Travel company CWT avoids ransomware derailment by paying $4.5m blackmail demand
4 Unpatched Bugs Plague Grandstream ATAs for VoIP Users
Authorities Arrest Alleged 17-Year-Old ‘Mastermind’ Behind Twitter Hack
CWT Travel Agency Faces $4.5M Ransom in Cyberattack, Report
Anti-NATO Disinformation Campaign Leveraged CMS Compromises

An update that fixes 10 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

A flaw in PyCrypto allow remote attackers to obtain sensitive information.

Multiple vulnerabilities have been found in SNMP Trap Translator, the worst of which could allow attackers to execute arbitrary shell code.

Multiple vulnerabilities have been found in WebKitGTK+, the worst of which could result in the arbitrary execution of code.

Twitter: Epic Account Hack Caused by Mobile Spearphishing
First rule of Ransomware Club is do not pay the ransom, but it looks like Carlson Wagonlit Travel didn’t get the memo
Black Hat USA 2020 Preview: Election Security, COVID Disinformation and More

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Burn baby burn, plastic inferno! Infosec researchers turn 3D printers into self-immolating suicide machines
In the market for a second-hand phone? Check it’s still supported by the vendor – almost a third sold are not