Menu

Category Archives: All

Everything

GDPR Compliance Site Leaks Git Data, Passwords

security update

A GIF image could have let hackers hijack Microsoft Teams at your firm
Microsoft Teams flaw could let attackers hijack accounts

Microsoft plugs a security hole that could have enabled attackers to weaponize a GIF in order to hijack Teams accounts and steal data The post Microsoft Teams flaw could let attackers hijack accounts appeared first on WeLiveSecurity

Hackers Mount Zero-Day Attacks on Sophos Firewalls
U.S. Universities Hit With ‘Adult Dating’ Spear-Phishing Attack
5 common mistakes that lead to ransomware
Eight Common OT / Industrial Firewall Mistakes
Chinese COVID-19 detection firm hacked; source code sold on dark web

An update that solves 11 vulnerabilities and has 96 fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves 12 vulnerabilities and has 139 fixes is now available.

Web shell warning issued by US and Australia
Don’t vote for me and Smashing Security in the EU Security awards

Several security issues were fixed in OpenEXR.

We could have pwned Microsoft Teams with a GIF, claims Israeli infosec outfit
Apple and Google tweak key bits of contact-tracing privacy plan
Single Malicious GIF Opened Microsoft Teams to Nasty Attack
Rabobank security cert expires and gives its Australian Android app a case of internet-blindness

Update to latest upstream OpenVPN 2.4.9 release. It contains a security fix for CVE-2020-11810. This security issue is quite hard to abuse, requiring a fairly precise timing attack combined with guessing a just assigned peer-id reference. If successful, only a single client just initiating a new connection will experience a denial of service situation. This […]

6.2.6

Australia’s contact-tracing app regulation avoids ‘woolly’ principles in comparable cyber-laws, say lawyers
Exclusive: Scammers using fake WHO Bitcoin wallet to steal donation

Three issues have been found in php5, a server-side, HTML-embedded scripting language.

Sophos XG firewalls hacked, hotfix ready. Texts wreck Apple iThings. Yup, business as usual in infosec world
Hackers’ malicious script skimmed credit card details off Robert Dyas website

Hanno Boeck discovered that it was possible to create a cross site scripting attack on the webarchives of the Mailman mailing list manager, by sending a special type of attachement.

Called to an urgent Zoom meeting with HR? It might be a phishing attack

Update to WebKitGTK 2.28.1: * Fix position of default option element popup windows under Wayland. * Fix rendering after a cross site navigation with PSON enabled and hardware acceleration forced. * Fix a crash in nested wayland compositor when closing a tab with PSON enabled. * Update Chrome and Firefox versions in user agent quirks. […]

Security fix for CVE-2020-5260 From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.5.txt): > With a crafted URL that contains a newline or empty host, or lacks > a scheme, the credential helper machinery can be fooled into > providing credential information that is not appropriate for the > protocol in use and host being

Update to WebKitGTK 2.28.1: * Fix position of default option element popup windows under Wayland. * Update Chrome and Firefox versions in user agent quirks. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-11793

Update to version 1.26. Resolves CVE-2017-18640.

Dark web hackers selling 400,000 South Korean & US payment card data

security update

Hackers deface church service on Zoom with child abuse content
VictoryGate cryptominer infected 35,000 devices via USB drives
Open Source Intelligence, Security Hacking, and Security Blogger Dancho Danchev>

It was discovered that python-reportlab, a Python library to create PDF documents, is prone to a code injection vulnerability while parsing a color attribute. An attacker can take advantage of this flaw to execute arbitrary code if a specially crafted document is processed.

security update

This update fixes the following security vulnerabilities: CVE-2018-20536, CVE-2018-20537, CVE-2018-20539, CVE-2018-20540

**PHP version 7.3.17** (16 Apr 2020) **Core:** * Fixed bug php#79364 (When copy empty array, next key is unspecified). (cmb) * Fixed bug php#78210 (Invalid pointer address). (cmb, Nikita) **CURL:** * Fixed bug php#79199 (curl_copy_handle() memory leak). (cmb) **Date:** * Fixed bug php#79396 (DateTime hour incorrect during DST jump forward). (Nate Brunette) **Iconv:**

3.2.3 —- New version 3.2.2 Security fix for CVE-2020-7044, CVE-2020-9428, CVE-2020-9430, CVE-2020-9431

Fix mistakes in Wayland wrapper change —- Fixes Wayland issue when running from terminal —- Update sound touch library, fixes some known security issues.

Security fix for CVE-2015-9541

Spyware maker NSO can’t claim immunity, Facebook lawyers insist – it’s time to face the music
SAS@home Virtual Summit Showcases New Threat Intel, Industry Changes
Latest Apple Text-Bomb Crashes iPhones via Message Notifications
Hackers set up fake NHS website to spread malware

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

Following ESET’s discovery, a Monero mining botnet is disrupted

ESET researchers discover, and play a key role in the disruption of, a 35,000-strong botnet spreading in Latin America via infected USB drives The post Following ESET’s discovery, a Monero mining botnet is disrupted appeared first on WeLiveSecurity

News Wrap: Nintendo Account Hacks, Apple Zero Days, NFL Security
Nintendo accounts hacked: 160,000 accounts accessed by hackers
Latest iOS Text Bomb Bug Crashing iPhones with Sindhi Characters
Nintendo Confirms Breach of 160,000 Accounts
Apple Pushes Back Against Zero-Day Exploit Claims

Reading Time: ~ 2 min. Los Angeles Suburb Hit with Ransomware Last month, the City of Torrance, California fell victim to a ransomware attack that shut down many of their internal systems and demanded 100 Bitcoins to not publish the stolen data. Along with the roughly 200GB of data it stole from the city, the […]

Patch now! Microsoft issues unexpected Office fix
Shadow Broker leaked NSA files point to unknown APT group
Text ‘bomb’ crashes iPhones, iPads, Macs and Apple Watches – what you need to know
AI helps experts find thousands of child sexual abuse imagery keywords

Several vulnerabilities have been discovered in the OpenJDK Java runtime, resulting in denial of service, insecure TLS handshakes, bypass of sandbox restrictions or HTTP response splitting attacks.

Canada’s .ca overlord rolls out free privacy-protecting DNS-over-HTTPS service for folks in Great White North

Reading Time: ~ 4 min. Did you know there are three primary types of hacker—white hats, black hats, and grey hats—and that there are subcategories within each one? Despite what you may have heard, not all hackers have intrinsically evil goals in mind. In fact, there are at least 300,000 hackers throughout the world who […]

New Zoom vulnerability lets hackers record any meeting anonymously
iOS Mail app flaws may have left iPhone users vulnerable for years

A pair of vulnerabilities in the default email app on iOS devices is believed to have been exploited against high-profile targets The post iOS Mail app flaws may have left iPhone users vulnerable for years appeared first on WeLiveSecurity

Valve Confirms CS:GO, Team Fortress 2 Source-Code Leak
Buying a secondhand device? Here’s what to keep in mind

If you’re trying to be responsible towards the planet, also be responsible to yourself and take these steps so that the device doesn’t end up costing you more than you’ve saved The post Buying a secondhand device? Here’s what to keep in mind appeared first on WeLiveSecurity

Serious flaws found in multiple smart home hubs: Is your device among them?

In worst-case scenarios, some vulnerabilities could even allow attackers to take control over the central units and all peripheral devices connected to them The post Serious flaws found in multiple smart home hubs: Is your device among them? appeared first on WeLiveSecurity

iPhone zero day – don’t panic! Here’s what you need to know
Public Sector Ransomware Attacks Rage On: Can Your Organization Repel Them?
WHO, CDC and Bill and Melinda Gates Foundation Victims of Credential Dump, Report
A Dozen Nation-Backed APTs Tap COVID-19 to Cover Spy Attacks
Skype Phishing Attack Targets Remote Workers’ Passwords
Trove of RubyGems malware highlights software supply chain issues
iOS exploit lets attackers access default iPhone mail app
Fake Skype, Signal Apps Used to Spread Surveillanceware

Multiple vulnerabilities have been found in Git which might all allow attackers to access sensitive information.

Password-free database of exercise app Kinomap leaks 42m user records
Maze ransomware – what you need to know

The package lib32-openssl before version 1.1.1.g-1 is vulnerable to denial of service.

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More…]

Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities were found in OpenSSL, the worst of which could allow remote attackers to cause a Denial of Service condition.

python-twisted: HTTP request smuggling when presented with two Content-Length headers (CVE-2020-10108) * python-twisted: HTTP request smuggling when presented with a Content-Length and a chunked Transfer-Encoding header (CVE-2020-10109) SL7 x86_64 python-twisted-web-12.1.0-7.el7_8.x86_64.rpm – Scientific Linux Development Team

GCC 10 gets security bug trap. And look what just fell into it: OpenSSL and a prod-of-death flaw in servers and apps
Smashing Security #175: Zoom deepfakes, Zardoz, and ‘Rona tracing
Why should the UK pensions watchdog be able to spy on your internet activities? Same reason as the Environment Agency and many more
Get your free work-from-home IT security awareness training kit, courtesy of SANS
Vietnam alleged to have hacked Chinese organisations in charge of COVID-19 response
Zero-click, zero-day flaws in iOS Mail ‘exploited to hijack’ VIP smartphones. Apple rushes out beta patch
CS:GO & Team Fortress 2 source code leaked – Virus alert for TF2
Stripe is absolutely logging your mouse movements on websites’ payment pages – for your own good, says CEO
Fast-Moving DDoS Botnet Exploits Unpatched ZyXel RCE Bug
After intense scrutiny, Zoom tightens up security with version 5. New features include not, er, spilling video calls to network snoops
This Zoom trick would have spared swearing politician’s blushes
Apple Patches Two iOS Zero-Days Abused for Years