Menu

Category Archives: Security

Articles about security

FluBot malware warning after 70,000 attacks launched over SMS
1Password 8 for Windows – improved productivity, and enhanced security & privacy
Jumping the air gap: 15 years of nation‑state effort

ESET researchers studied all the malicious frameworks ever reported publicly that have been used to attack air-gapped networks and are releasing a side-by-side comparison of their most important TTPs The post Jumping the air gap: 15 years of nation‑state effort appeared first on WeLiveSecurity

NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP […]

A NULL pointer dereference in Busybox’s hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input. (CVE-2021-42376)

BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be […]

The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both “manifests” and “layers” fields could be

In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability. References:

New UK product security law won’t be undercut by rogue traders upping and vanishing, government boasts
European Cybercrime Centre confident it’s kicked credit card crims – again
Three key ransomware actors changed jobs on October 18 – the same day REvil went dark
Smashing Security podcast #254: A dead hamster, a brass pen, and The Beatles
Rewriting your disaster recovery plan might just save your company…and could transform it
80K Retail WooCommerce Sites Exposed by Plugin XSS Bug
Stealthy ‘WIRTE’ Gang Targets Middle Eastern Governments
Singapore and UK ink digital trade agreements at Future Tech Forum in London

Thunderbird could be made to crash or run programs if it verified a specially crafted signature.

NSS could be made to crash or run programs if it verified a specially crafted signature.

Widespread ‘Smishing’ Campaign Defrauds Iranian Android Users
20 Years of Red Hat Product Security: From inception to customer experience (Part 1)
U.S. Government issues directive to prioritize fixing exploited CVEs: How Red Hat Insights can help

Red Hat OpenShift Container Platform release 4.7.38 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

UK watchdog’s punishment for Blackbaud, Easyjet, other big privacy lawbreakers was slap on the wrist in private
UK intel chief says MI6 must outsource innovation – and James Bond’s in-house ‘Q’ is nonsense
How Decryption of Network Traffic Can Improve Security
Lloyd’s Carves Out Cyber-Insurance Exclusions for State-Sponsored Attacks

Two heap overflows were fixed in the rsyslog logging daemon. CVE-2019-17041

Out-of-bounds read for an incomplete URI with an IPv6 address containing an embedded IPv4 address has been fixed in uriparser, a library to parse Uniform Resource Identifiers (URIs).

guests may exceed their designated memory limit [XSA-385, CVE-2021-28706] PoD operations on misaligned GFNs [XSA-388, CVE-2021-28704, CVE-2021-28707 CVE-2021-28708] issues with partially successful P2M updates on x86 [XSA-389, CVE-2021-28705, CVE-2021-28709] certain VT-d IOMMUs may not work in shared page table mode [XSA-390, CVE-2021-28710]

It’s the flu season – FluBot, that is: Surge of info-stealing Android malware detected
Finland Faces Blizzard of Flubot-Spreading Text Messages
Panasonic’s Data Breach Leaves Open Questions
Visiting a booby-trapped webpage could give attackers code execution privileges on HP network printers
Leaked footage shows British F-35B falling off HMS Queen Elizabeth and pilot’s death-defying ejection
Lloyd’s of London suggests insurers should not cover ‘retaliatory cyber operations’ between nation states
Yanluowang Ransomware Tied to Thieflock Threat Actor

An update that fixes 16 vulnerabilities is now available.

Red Hat AMQ Broker 7.9.1 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Red Hat OpenShift Container Platform release 4.8.22 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Winter is coming … with a blizzard of live and virtual SANS Institute events

Andrew Bartlett discovered that Samba, a SMB/CIFS file, print, and login server for Unix, may map domain users to local users in an undesired way. This could allow a user in an AD domain to potentially become root on domain members.

Several security issues were fixed in ImageMagick.

Panasonic admits intruders were inside its servers for months

security update

IKEA Hit by Email Reply-Chain Cyberattack
Researchers Flag 300K Banking Trojan Infections from Google Play in 4 Months

security update

The 5.15.5 stable kernel update contains a number of important fixes across the tree.

ScarCruft APT Mounts Desktop/Mobile Double-Pronged Spy Attacks
Unpatched Windows Zero-Day Allows Privileged File Access
More than 1,000 arrested in global crackdown on online fraud

The INTERPOL-led operation involved law enforcement from 20 countries and led to the seizure of millions of dollars in illicit gains The post More than 1,000 arrested in global crackdown on online fraud appeared first on WeLiveSecurity

Shape-Shifting ‘Tardigrade’ Malware Hits Vaccine Makers
Wind turbine maker Vestas confirms recent security incident was ransomware
Social media firms will be forced to unmask online trolls, says Australia

An update for samba is now available for Red Hat Gluster Storage 3.5 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat OpenShift Container Storage 4.8.5 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for samba is now available for Red Hat Gluster Storage 3.5 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Container Platform release 4.9.9 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.9.

Several vulnerabilities were fixed in the OpenSC smart card utilities. CVE-2019-15945

Australia will force social networks to identify trolls, so they can be sued for defamation

Release of stargz snapshotter v0.10.1. This release contains the mitigation for CVE-2021-41190. Please see the release note for details. https://github.com/containerd/stargz-snapshotter/releases/tag/v0.10.1 —- Update to v0.10.0. See changes at https://github.com/containerd/stargz- snapshotter/releases/tag/v0.10.0

Rongxin Wu discovered a use-after-free vulnerability in the International Components for Unicode (ICU) library which could result in denial of service or potentially the execution of arbitrary code.

An infinite loop when –sparse is used with file shrinkage during read access was fixed in the GNU tar archiving utility. For Debian 9 stretch, this problem has been fixed in version

Update to 7.12.1

This is a security update to address CVE-2021-35063 and other misc bugs.

Update to 7.12.1

An out-of-bounds buffer read on truncated key frames in vp8_decode_frame has been fixed in libvpx, a popular library for the VP8 and VP9 video codecs. For Debian 9 stretch, this problem has been fixed in version

Several vulnerabilities were discovered in BlueZ, the Linux Bluetooth protocol stack. An attacker could cause a denial-of-service (DoS) or leak information.

It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not properly sanitize requests and mail messages. This would allow an attacker to perform Cross-Side Scripting (XSS) or SQL injection attacks.

security update

Couple arrested for secretly installing cryptomining software on department store PCs

The 5.15.4 stable kernel rebase contains improved hardware support, new features, and a number of important fixes across the tree.

The 5.15.4 stable kernel rebase contains improved hardware support, new features, and a number of important fixes across the tree.

The 5.15.4 stable kernel rebase contains improved hardware support, new features, and a number of important fixes across the tree.

– Update to 21.08.4. – Closes security issue CVE-2021-43337.

The triangle of holiday shopping: Scams, social media and supply chain woes

‘Tis the season to avoid getting played by scammers hijacking Twitter accounts and promoting fake offers for PlayStation 5 consoles and other red-hot products The post The triangle of holiday shopping: Scams, social media and supply chain woes appeared first on WeLiveSecurity

EU needs more cybersecurity graduates, says ENISA infosec agency – pointing at growing list of master’s degree courses
Privacy Sandbox saga continues: UK watchdog extracts more commitments from Google over ad tech

The following updated rpms for Oracle Linux 8 have been uploaded to the Unb= reakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unb= reakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unb= reakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unb= reakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Government-favoured child safety app warned it could violate the UK’s Investigatory Powers Act with message-scanning tech
If you want to see off next year’s cyber-threats, the time to prepare is … now
Microsoft Defender for Endpoint laid low. Not by malware, but by another buggy Windows patch
Try out 1Password 8 for Windows, where security meets productivity
It’s about the survival of the fittest – CISOs must be brave enough to throw away their security playbook, or suffer the consequences
Avoiding the shopping blues: How to shop online safely this holiday season

With the holiday shopping bonanza right around the corner, here’s how to make sure your online spending spree is hacker-free The post Avoiding the shopping blues: How to shop online safely this holiday season appeared first on WeLiveSecurity

Sophisticated Tardigrade malware launches attacks on vaccine manufacturing infrastructure
New Twists on Gift-Card Scams Flourish on Black Friday
Smashing Security podcast #253: Cybercrime unicorns, HVAC hacks, and NFT piracy – with Mikko Hyppönen
New UK IoT law means huge fines and a ban on default passwords
Veeam Ransomware Protection with Red Hat Enterprise Linux as the Immutable Repository
UK.gov emits draft IoT and smartphone security law for Parliamentary scrutiny

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685. (CVE-2019-7282)

Integer-overflow in Imf_3_1::bytesPerDeepLineTable. (CVE-2021-3933) Divide-by-zero in Imf_3_1::RGBtoXYZ. (CVE-2021-3941) References: – https://bugs.mageia.org/show_bug.cgi?id=29657

Server processes unencrypted bytes from man-in-the-middle. (CVE-2021-23214) libpq processes unencrypted bytes from man-in-the-middle. (CVE-2021-23222) References: