Menu

Category Archives: Security

Articles about security

Top CVEs Trending with Cybercriminals
Instagram Security Check hopes to make life harder for account hackers
You’ll want to shut down the Windows Print Spooler service (yes, again): Another privilege escalation bug found
The Evolving Role of the CISO
Critical Juniper Bug Allows DoS, RCE Against Carrier Networks
Sports events and online streaming: prepare your cybersecurity

If you’ll be watching Sports Streaming events on your SmartTV, laptop, tablet or cell phone, learn the tips to keep you and your personal data safe. The post Sports events and online streaming: prepare your cybersecurity appeared first on WeLiveSecurity

Wanted: State-backed bandits planning cyberattacks on US infrastructure. Reward: $10m
Windows 0-Days Used Against Dissidents in Israeli Broker’s Spyware
Irish hospital sued by cancer patient after ransomware attack

The package vivaldi before version 4.0.2312.41-1 is vulnerable to arbitrary code execution.

The package chromium before version 91.0.4472.164-1 is vulnerable to arbitrary code execution.

The package systemd before version 249-2 is vulnerable to denial of service.

The package varnish before version 6.6.1-1 is vulnerable to url request injection.

The package mbedtls before version 2.26.0-1 is vulnerable to information disclosure.

The package python-pillow before version 8.3.0-1 is vulnerable to arbitrary code execution.

The Matt Hancock CCTV footage leak – why it’s right for the ICO to investigate
Microsoft: New Unpatched Bug in Windows Print Spooler           
Microsoft, Google, Citizen Lab blow lid off zero-day bug-exploiting spyware sold to governments

It’s not just that they’re making headlines more often. Ransomware rates really are rising. Given the recent spate of high-profile attacks, it’s worth remembering the difference between standard backup and high-availability replication. Our research suggests that the costs of ransomware for businesses can amount to much more than an extortion payment. They include lost hours […]

Zero-Day Attacks on Critical WooCommerce Bug Threaten Databases

security update

Microsoft Patch Tuesday fixes 13 critical flaws, including 4 under active attack

The latest Patch Tuesday brings a new batch of security updates addressing a total of 117 vulnerabilities The post Microsoft Patch Tuesday fixes 13 critical flaws, including 4 under active attack appeared first on WeLiveSecurity

Fake Zoom App Dropped by New APT ‘LuminousMoth’
This is the data watchdog! Surrender your Matt Hancock smoochy-kiss pics right now!
SonicWall Warns Secure VPN Hardware Bugs Under Attack
US offers $10 million reward in hunt for state-sponsored ransomware attackers
Regulating facial recognition technology? It’s the ‘Wild West out there,’ says US law boffin

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

This advisory resolves CVE issues filed against XP2 releases that have been fixed in the underlying EAP 7.3.x base. There are no changes to the EAP XP2 code base. NOTE: This advisory is informational only. There are no code changes

Smashing Security podcast #236: Stingrays, soccer, and smart homes
Safari Zero-Day Used in Malicious LinkedIn Campaign

Several vulnerabilities were discovered in php5, a server-side, HTML-embedded scripting language. An attacker could cause denial of service (DoS), memory corruption and potentially execution of arbitrary code, and server-side request forgery (SSRF) bypass.

NortonLifeLock sniffs around Avast, announces ‘advanced discussions’ for acquisition
Report sheds light on ‘cocky’ but ‘creative’ Mespinoza ransomware group
Restoring your privacy costs money, which makes it a marker of class

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

So nice of China to put all of its network zero-day vulns in one giant database no one will think to break into

security update

Cryptominer Farm Rigged with 3,800 PS4s Busted in Ukraine
Facial-recognition technology gets a smack in the chops from civil rights campaigners
Choosing your MSP: What the Kaseya incident tells us about third‑party cyber risk

Lessons to learn from the Kaseya cyberincident to protect your business’ data when doing business with a MSP. The post Choosing your MSP: What the Kaseya incident tells us about third‑party cyber risk appeared first on WeLiveSecurity

The hybrid workplace: What does it mean for cybersecurity?

How can organizations mitigate the risk of damaging cyberattacks while juggling the constantly changing mix of office and off-site workers? The post The hybrid workplace: What does it mean for cybersecurity? appeared first on WeLiveSecurity

Linux-Focused Cryptojacking Gang Tracked to Romania
Apps Built Better: Why DevSecOps is Your Security Team’s Silver Bullet
Trickbot Malware Rebounds with Virtual-Desktop Espionage Module
Updated Joker Malware Floods into Android Apps
Windows Hello Bypass Fools Biometrics Safeguards in PCs
Hong Kong working to share its digital IDs with mainland China
What follows Patch Tuesday? Exploit Wednesday. Grab this bumper batch of security updates from Microsoft
Cybercriminals took advantage of WFH to target financial services companies, say financial bods
Microsoft names Chinese group as source of new attack on SolarWinds

Red Hat OpenShift Container Platform release 4.6.38 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.6.

Outrun the cyber-crooks with information security training from SANS Institute

Multiple vulnerabilities have been found in Pillow, the worst of which could result in a Denial of Service condition.

An update that solves 14 vulnerabilities, contains one feature and has 5 fixes is now available.

Multiple vulnerabilities have been found in Apache Thrift, the worst of which could result in a Denial of Service condition.

Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service (CVE-2021-3200).

This update provides ffmpeg version 4.3.2, which fixes several security vulnerabilities and other bugs which were corrected upstream. References: – https://bugs.mageia.org/show_bug.cgi?id=28433

Microsoft Crushes 116 Bugs, Three Actively Exploited
Ransomware Giant REvil’s Sites Disappear
Guess Fashion Brand Deals With Data Loss After Ransomware Attack
Unpatched Critical RCE Bug Allows Industrial, Utility Takeovers
REvil ransomware gang’s websites vanish soon after Kaseya fiasco, Uncle Sam threatens retaliation
Adobe Patches 11 Critical Bugs in Popular Acrobat PDF Reader
The State of Vulnerability Management and Patching in The Enterprise Environment>
UK govt draws a blank over vaccine certification app – no really, the report is half-empty
‘Charming Kitten’ APT Siphons Intel From Mid-East Scholars
Is Remote Desktop Protocol Secure? It Can Be
You’ll never Guess whose data has been nicked as US fashion firm confirms systems breach
New CISA Director Confirmed, White House Gains Cyber-Director
SolarWinds Issues Hotfix for Zero-Day Flaw Under Active Attack

Release of OpenShift Serverless Client kn 1.16.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Microsoft to beef up security portfolio with reported half-billion-dollar RiskIQ buyout

An update that fixes one vulnerability is now available.

Complete Guide to Installing Security Updates in Debian & Ubuntu>
Researchers warn of unpatched remote code execution flaws in Schneider Electric industrial gear
We’re terrified of sharing information, but the benefits of talking about IT and infosec outweigh the negatives

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

FBI warns hackers are targeting cryptocurrency wallets and exchanges
Kaseya restores SaaS, then ‘performance issues’ force a do-over
With a straight face, Putin agrees to do something about ransomware coming out of Russia, apparently
BIOPASS RAT Uses Live Streaming Steal Victims’ Data
WordPress File Management Plugin Riddled with Critical Bugs
SolarWinds issues software update – one it wrote for a change – to patch hole exploited in the wild
Critical RCE Vulnerability in ForgeRock OpenAM Under Active Attack
Kaseya Patches Zero-Days Used in REvil Attacks
Looking for some up close and personal cybersecurity training? Well, look to London

XStream: remote command execution attack by manipulating the processed input stream (CVE-2021-29505) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 noarch – xstream-1.3.1-14.el7_9.noarch.rpm – xstream-javadoc-1.3.1-14.el7_9.noarch.rpm – Scientific Linux Development Team

Spreadshop hacked. T-shirt lovers warned of “considerably vicious” data breach

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Red Hat AMQ Broker 7.8.2 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that fixes one vulnerability is now available.

Kaseya claims SaaS restoration going swimmingly