Menu

Category Archives: All

Everything

Cash-flashing rapper charged with money laundering for BTC-e
Firefox to tell you if sites are shortening your passwords
EasyJet hacked in a sophisticated attack; 9 million customers affected
Clever Phishing Attack Bypasses MFA to Nab Microsoft Office 365 Credentials
Easyjet hacked: 9 million people’s data accessed plus 2,200 folks’ credit card details grabbed

Reading Time: ~ 3 min. There’s a pretty common misconception among small businesses and medium-sized businesses (SMBs) that hackers only target large organizations. Unfortunately, this belief couldn’t be further from the truth. In fact, according to the most recent Verizon Data Breach Investigations Report, more than 70% of cyberattacks target small businesses. Additionally, many attacks […]

Open letter from digital rights groups to UK health secretary questions big tech’s role in NHS COVID-19 data store
EasyJet hack impacts nine million passengers
FBI warns hackers are planting card skimmers on online stores running a vulnerable Magento plugin
AT&T tracked its own sales bods using GPS, secretly charged them $135 a month to do so, lawsuit claims
GDPR what? European Parliament breach exposes data of 1000s of people
Magecart malware merrily sipped card details, evaded security scans on UK e-tailer Páramo for almost 8 months
Get your live, GIAC-certified, online cybersecurity training from SANS – available now
Verizon Data Breach Report: DoS Skyrockets, Espionage Dips
Insider threat? Pffft. Hackers on the outside are the ones mostly making off with your private biz data, says Verizon
With millions upon millions out of work in the US, here come the scammers claiming victims’ unemployment money using stolen info

This package fixes a security issue that allowed for _method query parameters to be used with GET requests. The fix is backported from Mojolicious v8.42.

This package fixes a security issue that allowed for _method query parameters to be used with GET requests. The fix is backported from Mojolicious v8.42.

Update to 8.10 release (CVE-2020-12823)

**PHP version 7.4.6** (14 May 2020) **Core:** * Fixed bug php#78434 (Generator yields no items after valid() call). (Nikita) * Fixed bug php#79477 (casting object into array creates references). (Nikita) * Fixed bug php#79514 (Memory leaks while including unexistent file). (cmb, Nikita) * Fixed bug php#79470 (PHP incompatible with 3rd party file system on demand). […]

This package fixes a security issue that allowed for _method query parameters to be used with GET requests. The fix is backported from Mojolicious v8.42.

Attorney General: We didn’t need Apple to crack terrorist’s iPhones – tho we still want iGiant to do it in future
Ransomware Gang Arrested for Spreading Locky to Hospitals
Apple’s MagicPairing for Bluetooth fails to enchant after mischief-making bugs found hiding in the stack
ProLock Ransomware Teams Up With QakBot Trojan to Infect Victims

Several security issues were fixed in the Linux kernel.

db8151dd breach- Contact management firm leaks 22 million emails
Microsoft gives Office 365 admins the heads-up: Some internal queries over weekend might have returned results from completely different orgs
The RATicate gang – implanting malware in an industry near you
Edison Mail iOS Bug Exposes Emails to Strangers
Senate renews warrantless collection of web histories
Hackers compromise Supercomputers across Europe with cryptominers
The ProLock ransomware doesn’t tell you one important thing about decrypting your files
Edison Mail bug exposed iPhone users’ email accounts to complete strangers
Shiny new Azure login attracts shiny new phishing attacks
Kali Linux 2020.2 Released, Download Now!!!>
The US Senate just voted to let the FBI access your browser history without a warrant>

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves 7 vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes three vulnerabilities is now available.

I know what you leased last summer: Asset database leak hits Capita, Rolls-Royce, Tesco (every little helps, eh?)
A real loch mess: Navy larks sunk by a truculent torpedo
Dutch spies helped Britain’s GCHQ break Argentine crypto during Falklands War
New Report: Severe Flaws in Cyberoam’s Firewall and VPN Technology Left At Least 86,000 Networks Vulnerable to Exploit>
Know The Enemy: Upgrade Your Threat Detection Strategy with Honeynets>

8u252 update

Update to latest upstream 8.8.8

Are you ready, kids? I said, are you ready? Whoooooo has another update for you to see? Google Chromium! For browsing and tweeting (but not FTP) Google Chromium! If improved security be something you wish Google Chromium! Then run dnf while you flop like a fish! Google Chromium! Google Chromium! Google Chromium! Google Chromium! Ahem. […]

Update to 4.9.0

REvil hackers leaks email conversation on Trump amid ransom demand

Update to latest upstream 8.8.8

Are you ready, kids? I said, are you ready? Whoooooo has another update for you to see? Google Chromium! For browsing and tweeting (but not FTP) Google Chromium! If improved security be something you wish Google Chromium! Then run dnf while you flop like a fish! Google Chromium! Google Chromium! Google Chromium! Google Chromium! Ahem. […]

Authorities bust hacker group planning to hit hospitals with ransomware
Flaws in cyber security firm’s firewall & VPN tech exposed 100k+ devices

It was discovered that exim4, a mail transport agent, suffers from a authentication bypass vulnerability in the spa authentication driver. The spa authentication driver is not enabled by default.

Cybercrime marketplace MagBo selling access to 43,000 hacked websites

OpenConnect, a VPN software, had a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.

Version update + security fix

security update

security update

Version update + security fix

Update to OpenEXR-2.4.1, see https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.4.1 for details.

Update to OpenEXR-2.4.1, see https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.4.1 for details.

Hoaxcalls Botnet Exploits Symantec Secure Web Gateways
Mandrake Android malware stealing Facebook, crypto data since 2016
News Wrap: Ransomware Extortion Tactics, Contact-Tracing App Security Worries
Zero-day attacks are potent cyber threats that require serious response
Mikroceen: Spying backdoor leveraged in high‑profile networks in Central Asia

ESET researchers dissect a backdoor deployed in attacks against multiple government agencies and major organizations operating in two critical infrastructure sectors in Asia The post Mikroceen: Spying backdoor leveraged in high‑profile networks in Central Asia appeared first on WeLiveSecurity

Pay $42m or Trump’s ‘dirty laundry’ goes online – REvil ransomware hackers
Cyber attack against UK power grid middleman Elexon sparks in-house IT recovery efforts
RATicate Group Hits Industrial Firms With Revolving Payloads
An outbreak of Coronavirus trojans and scams
You can’t have it both ways: Anti-coronavirus masks may thwart our creepy face-recog cameras, London cops admit

Updated libreswan packages fix security vulnerability: An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan. An unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange

Updated suricata packages fix security vulnerabilities: The suricata package has been updated to version 4.1.8, which fixes security issues and other bugs. See the upstream announcements for details.

Updated jbig2dec packages fix security vulnerability: jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow (CVE-2020-12268).

The updated packages fix security vulnerabilities including: ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled

Updated netkit-telnetd packages fix security vulnerability: A vulnerability was found where incorrect bounds checks in the telnet server’s (telnetd) handling of short writes and urgent data, could lead to information disclosure and corruption of heap data. An unauthenticated

8 best dark web search engines for 2020
Paying Ransomware Crooks Doubles Clean-up Costs, Report
How scammers abuse Google Search’s open redirect feature
Security flaws mitigated by compiler optimizations

An update that fixes one vulnerability is now available.

Top 10 most exploited vulnerabilities list released by FBI, DHS CISA
Microsoft joins encrypted DNS club with Windows 10 option
Vint Cerf suggests GDPR could hurt coronavirus vaccine development
Brit defense contractor hacked, up to 100,000 past and present employees’ details siphoned off – report
Innovative Spy Trojan Targets European Diplomatic Targets

security update

TikTok Violated Children’s Privacy Law, FTC Complaint Says
Stolen database trading site WeLeakData hacked; data leaked
Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks

ESET researchers uncover several instances of malware that uses various attack vectors to target systems isolated by an air gap The post Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks appeared first on WeLiveSecurity

PrintDemon – patch this ancient Windows printer bug!
Microsoft Adds DNS-Over-HTTPS Support for Windows 10 Insiders
The most-targeted security vulnerabilities – despite patches having been available for years

An update that solves two vulnerabilities and has four fixes is now available.

An update that fixes one vulnerability is now available.