Menu

Category Archives: Security

Articles about security

An issue has been found in libsndfile, a library for reading/writing audio files. A crafted WAV file can trigger a heap buffer overflow and might allow exectution of arbitrary code.

Leading cybersecurity agencies reveal list of most exploited vulnerabilities of the past 2 years

There are 30 vulnerabilities listed in total; organizations would do well to patch their systems if they haven’t done so yet The post Leading cybersecurity agencies reveal list of most exploited vulnerabilities of the past 2 years appeared first on WeLiveSecurity

Booking your next holiday? Watch out for these Airbnb scams

With vacations in full swing, cybercriminals will be looking to scam vacationers looking for that perfect accommodation. The post Booking your next holiday? Watch out for these Airbnb scams appeared first on WeLiveSecurity

Israeli Government Agencies Visit NSO Group Offices
Spam is Chipotle’s secret ingredient: Marketing email hijacked to dish up malware
Upcoming Android privacy changes include ability to blank advertising ID, and ‘safety section’ in Play store

PEAR could be made to overwrite files as the administrator.

Several security issues were fixed in QPDF.

libsndfile could be made to crash or run programs as your login if it opened a specially crafted file.

Smashing Security podcast #238: Fashion captain, fraud family, and DEF CON. D’oh!

An update that solves one vulnerability, contains two features and has two fixes is now available.

libsndfile could be made to crash or run programs as your login if it opened a specially crafted file.

Israeli authorities investigate NSO Group over Pegasus spyware abuse claims
Here’s a list of the flaws Russia, China, Iran and pals exploit most often, say Five Eyes infosec agencies
‘Woefully insufficient’: Biden administration’s assessment of critical infrastructure infosec protection
Over 100 Taiwanese political figures’ messages leaked outta LINE app

* Properly set the cookies settings after a network process crash. * Fix accessibility tree after a cross site navigation with PSON enabled. * Ensure WebKitScriptWorld::window-object-cleared signal is always emitted. * Fix several crashes and rendering issues. * Security fixes: CVE-2021-21775, CVE-2021-21779, CVE-2021-30663, CVE-2021-30665, CVE-2021-30689, CVE-2021-30720,

Security breaches where working from home is involved are costlier, claims IBM report
Most Twitter users haven’t enabled 2FA yet, report reveals

Twitter’s transparency report revealed that users aren’t quick to adopt 2FA and once they do enable it, they choose the least secure option The post Most Twitter users haven’t enabled 2FA yet, report reveals appeared first on WeLiveSecurity

BlackMatter & Haron: Evil Ransomware Newborns or Rebirths
Reboot of PunkSpider Tool at DEF CON Stirs Debate
Iranian state-backed hackers posed as flirty Scouser called Marcy to target workers in defence and aerospace

Several security issues were fixed in WebKitGTK.

Podcast: Why Securing Active Directory Is a Nightmare
UK’s National Cyber Security Centre needs its posh Westminster digs, says Cabinet Office, because of WannaCry
Google revamps bug bounty program
Biden warns ‘real shooting war’ will be sparked by severe cyber attack

An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for rh-nodejs12-nodejs and rh-nodejs12-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Tencent suspends signups to WeChat, citing ‘security upgrade’ and need to comply with Chinese laws
eBay ex-security boss sent down for 18 months for cyber-stalking, witness tampering

* Update to go1.16.6 * Security fix for CVE-2021-34558

No More Ransom Saves Victims Nearly €1 billion Over 5 Years
Misconfigured Azure Blob at Raven Hengelsport exposed records of 246,000 anglers – and took months to tackle, claim infosec researchers
Scam-baiting YouTube channel Tech Support Scams taken offline by tech support scam

Red Hat OpenShift Container Platform release 4.8.2 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.8.

Red Hat OpenShift Container Platform release 4.8.2 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.8.

Tech biz must tell us about more security breaches, says UK.gov as it ponders lowering report thresholds

OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) (CVE-2021-2388) * OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341) * OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369) For more details about the security issue(s), including the [More…]

OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) (CVE-2021-2388) * OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341) * OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369) For more details about the security issue(s), including the [More…]

Apple releases patch for zero‑day flaw in iOS, iPadOS and macOS

The vulnerability is under active exploitation by unknown attackers and affects a wide range of Apple’s products. The post Apple releases patch for zero‑day flaw in iOS, iPadOS and macOS appeared first on WeLiveSecurity

Zimbra Server Bugs Could Lead to Email Plundering
Despite all the advice, 97.7% of Twitter users have still not enabled two-factor authentication
Three Zero-Day Bugs Plague Kaseya Unitrends Backup Servers
Apple Patches Actively Exploited Zero-Day in iOS, MacOS
Compsci student walks off with $50,000 after bug bounty report blows gaping hole in Shopify software repos
Data controls in the DevSecOps life cycle

An update that fixes 8 vulnerabilities is now available.

Patch your iPhones and Macs against “actively exploited” zero-day right now
It takes intuition and skill to find hidden evidence and hunt for elusive threats
SSD belonging to Euro-cloud Scaleway was stolen from back of a truck, then turned up on YouTube

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Apple patches zero-day vulnerability in iOS, iPadOS, macOS under active attack
Black Hat USA & DEFCON 2021 Coverage on LinuxSecurity: What You Need to Know>
Podcast: IoT Piranhas Are Swarming Industrial Controls
Babuk Ransomware Gang Ransomed, New Forum Stuffed With Porn

* Update to upstream 20210716 release * update NXP 8897/8997 firmware images * rtlwifi: de-dupe rtl8723b/rtl8192e SDIO/USB WiFi firmware * Mediatek: update WiFi/bluetooth chip (MT7921) * Mediatek: update MT7915 firmware to 20201105 * Mellanox: Add new mlxsw_spectrum firmware xx.2008.2946 * cxgb4: Update firmware to revision 1.26.0.0 * firmware/i915/guc: Add HuC v7.9.3 for TGL & DG1 […]

You, too, can be a Windows domain controller and do whatever you like, with this one weird WONTFIX trick
Microsoft Rushes Fix for ‘PetitPotam’ Attack PoC

This update upgrades Thunderbird to version 78.12.0. * Mozilla: IMAP server responses sent by a MITM prior to STARTTLS could be processed (CVE-2021-29969) * Mozilla: Use-after-free in accessibility features of a document (CVE-2021-29970) * Mozilla: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 (CVE-2021-29976) * chromium-browser: Out of bounds write in ANGLE […]

Who us??? Kaseya says it hasn’t paid anybody for its ransomware decryption key
Average ransomware payments decline… but that’s not good news
No More Ransom website celebrates five years of providing free ransomware recovery tools and advice
Malware Makers Using ‘Exotic’ Programming Languages
Good news! I’m getting a salary increase!
The True Impact of Ransomware Attacks

Aspell could be made to execute arbitrary code or cause a crash if it received a specially crafted input.

An update is now available for Red Hat OpenShift Container Platform 4.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Stay sharp this summer with security tips from the experts – sign up to 1Password’s Security Summer School today

Several security issues were fixed in MySQL.

Vikings hack Instagram account of SBS News in Australia

This update ships updated CPU microcode for some types of Intel CPUs and provides mitigations for security vulnerabilities which could result in privilege escalation in combination with VT-d and various side channel attacks.

Several security issues were fixed in the kernel.

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Somebody is destined for somewhere hot, and definitely not Coventry
DEF CON offers beginner-level Spot the Fed this year: He’ll be on stage giving a keynote

An integer overflow bug in Redis version 6.0 or newer could be exploited using the `STRALGO LCS` command to corrupt the heap and potentially result with remote code execution (CVE-2021-29477). An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt

This affects the package y18n before 3.2.2, 4.0.1 and 5.0.5. PoC by po6ix: const y18n = require(‘y18n’)(); y18n.setLocale(‘__proto__’); y18n.updateLocale({polluted: true}); console.log(polluted); // true (CVE-2020-7774).

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository (CVE-2021-3572). The bundled python-urllib3 was also vulnerable to:

In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream (CVE-2021-21341).

It was discovered that the previous upload of the package rabbitmq-server versioned 3.6.6-1+deb9u1 introduced a regression in function fmt_strip_tags. Big thanks to Christoph Haas for the reporting an issue and for testing the update.

encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method (CVE-2021-27918).

security update

The container suse-sles-15-sp2-chost-byos-v20210722-gen2 was updated. The following patches have been included in this update:

An update that solves one vulnerability and has one errata is now available.

Multiple vulnerabilities have been found in libsdl2, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been found in libyang, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been found in Leptonica, the worst of which could result in a Denial of Service condition.

Discord CDN and API Abuses Drive Wave of Malware Detections

At Carbonite + Webroot, we’re always preaching about the importance of layering security solutions. Because here’s the truth: data’s always at risk. Whether from cybercriminals, everyday mishaps or mother nature, businesses can put up all the defenses they want but disaster only has to successfully strike once. The global pandemic means more work is being […]

Security fix for CVE-2021-3602 bump podman to v3.2.3 include podman-machine- cni in podman-plugins subpackage bump crun to 0.20.1 —- Fix `secrets` definition in /usr/share/containers/containers.conf

5 Steps to Improving Ransomware Resiliency
Popular Wi‑Fi routers still using default passwords making them susceptible to attacks

To mitigate the chances of their Wi-Fi home routers being compromised, users would do well to change the manufacturer’s default access credentials The post Popular Wi‑Fi routers still using default passwords making them susceptible to attacks appeared first on WeLiveSecurity

FIN7’s Liquor Lure Compromises Law Firm with Backdoor
Fraud Family cybercrime ring under the spotlight as arrests made in the Netherlands
Kaseya Obtains Universal Decryptor for REvil Ransomware
Hole blasted in Guntrader: UK firearms sales website’s CRM database breached, 111,000 users’ info spilled online
Kaseya offers universal decryptor to customers following ransomware attack

The container sles-15-sp2-chost-byos-v20210722 was updated. The following patches have been included in this update:

The container suse-sles-15-sp2-chost-byos-v20210722-hvm-ssd-x86_64 was updated. The following patches have been included in this update: