Menu

Category Archives: Security

Articles about security

EU data watchdog to Europol: You’ve helped yourself to too much data

An update that solves two vulnerabilities, contains one feature and has 13 fixes is now available.

An update that fixes one vulnerability is now available.

Secure boot for UK electric car chargers isn’t mandatory until 2023 – but why the delay?

Introduced regression Exiv2.

Four million outdated Log4j downloads were served from Apache Maven Central alone despite vuln publicity blitz

An update that solves one vulnerability and has two fixes is now available.

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform SQL injection, run unchecked SQL queries, bypass hardening, or perform Cross-Site Scripting (XSS) attacks.

Use-after-free in sampled_data_sample (called from sampled_data_continue and interp). (CVE-2021-45944) Heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp). (CVE-2021-45949)

Signal CEO Moxie Marlinspike resigns, leaves WhatsApp co-founder to run things until a successor is named

security update

Avira also mines imaginary internet money on customers’ PCs
URL Parsing Bugs Allow DoS, RCE, Spoofing & More
Cyber-Spike: Orgs Suffer 925 Attacks per Week, an All-Time High
China puts Walmart in the naughty corner, citing 19 alleged cybersecurity ‘violations’

Version 0.102 of ClamAV, an anti-virus toolkit, is end-of-life. ClamAV has been updated to version 0.103 to be able to receive virus signature updates.

GCHQ was rebuked for ignoring spy law safeguards as pandemic hit Britain
Free guide: “A Journey to Zero Trust With Zero Passwords”

The container suse/sles/15.3/virt-operator was updated. The following patches have been included in this update:

The container suse/sles/15.3/libguestfs-tools was updated. The following patches have been included in this update:

The container suse/sles/15.3/virt-handler was updated. The following patches have been included in this update:

The container suse/sles/15.3/virt-controller was updated. The following patches have been included in this update:

The container suse/sles/15.3/virt-api was updated. The following patches have been included in this update:

No defence for outdated defenders as consumer AV nears RIP
WebSpec, a formal framework for browser security analysis, reveals new cookie attack

Multiple security issues were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which could result in denial of service and potentially the execution of arbitrary code if malformed document files are processed.

It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not properly sanitize HTML messages. This would allow an attacker to perform Cross-Side Scripting (XSS) attacks.

security update

EoL Systems Stonewalling Log4j Fixes for Fed Agencies
Cyberattackers Hit Data of 80K Fertility Patients

security update

Security fix for CVE-2021-45463

https://www.mediawiki.org/wiki/Release_notes/1.36#MediaWiki_1.36.3

3.7M FlexBooker Records Dumped on Hacker Forum

These updated packages fix a buffer overflow in the faces reader.

An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

It was discovered that sphinxsearch, a fast standalone full-text SQL search engine, could allow arbitrary files to be read by abusing a configuration option.

The Spine Collector: Man arrested for using fake email addresses to steal hundreds of unpublished manuscripts

2020 may have been the year of establishing remote connectivity and addressing the cybersecurity skills gap, but 2021 presented security experts, government officials and businesses with a series of unpresented challenges. The increased reliance on decentralized connection and the continued rapid expansion of digital transformation by enterprises, small to medium-sized businesses (SMBs) and individuals, provided […]

QNAP: Get NAS Devices Off the Internet Now
Attack misuses Google Docs comments to spew out “massive wave” of malicious links
Log4J-Related RCE Flaw in H2 Database Earns Critical Rating
Salesforce mandates MFA by default

Security fix for CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021-4186

Add wayland detection and pass flags to improve experience when wayland is used. —- Update to 96.0.4664.110. You know the drill, lots of security bugs fixed, update if you like security, hit that like and subscribe button. CVE-2021-4052 CVE-2021-4053 CVE-2021-4054 CVE-2021-4055 CVE-2021-4056 CVE-2021-4057 CVE-2021-4058 CVE-2021-4059 CVE-2021-4061 CVE-2021-4062 CVE-2021-4063

Activision Files Unusual Lawsuit over Call of Duty Cheat Codes
Your backups can save you from ransomware. But how do you protect your backups?
Google Voice Authentication Scam Leaves Victims on the Hook
CES 2022: More sensors than people

A sea of sensors will soon influence almost everything in your world The post CES 2022: More sensors than people appeared first on WeLiveSecurity

5 ways hackers steal passwords (and how to stop them)

From social engineering to looking over your shoulder, here are some of the most common tricks that bad guys use to steal passwords The post 5 ways hackers steal passwords (and how to stop them) appeared first on WeLiveSecurity

Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover
Apple iPhone Malware Tactic Causes Fake Shutdowns to Enable Spying
‘Malsmoke’ Exploits Microsoft’s E-Signature Verification
Attackers Exploit Flaw in Google Docs’ Comments Feature

Several security issues were fixed in WebKitGTK.

Several security issues were fixed in Apache HTTP Server.

Several security issues were fixed in the kernel.

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/minimal was updated. The following patches have been included in this update:

1.1M Compromised Accounts Found at 17 Major Companies

Each year, as online shopping ramps up in the weeks before the holidays, so do online scams targeting the elderly. This season – in many ways unprecedented – is no different in this regard. In fact, COVID-19, Zoom meetings, vaccination recommendations and travel warnings all provide ample and unique precedent for social engineering attacks. Not […]

You better have patched those Log4j holes or we’ll see what a judge has to say – FTC
‘Elephant Beetle’ Lurks for Months in Networks
Broward Breach Highlights Healthcare Supply-Chain Problems
Uber Bug, Ignored for Years, Casts Doubt on Official Uber Emails

security update

US Army journal’s top paper from 2021 says Taiwan should destroy TSMC if China invades
FTC to Go After Companies that Ignore Log4j

The following updated rpms for Oracle Linux 7 have been uploaded to the Unb= reakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Instagram and teens: A quick guide for parents to keep their kids safe

How can you help your kids navigate Instagram safely? Here are a few tips to help you protect their privacy on the app. The post Instagram and teens: A quick guide for parents to keep their kids safe appeared first on WeLiveSecurity

Remember Norton 360’s bundled cryptominer? Irritated folk realise Ethereum crafter is tricky to delete
What You Need to Know About the Predator-OS 20.04 LTS Release>
US police warn of parking meters with phishing QR codes
Windows giant seeks Pluton-ic relationship with chip maker: AMD first out of the gates with Microsoft’s security processor

Several security issues were fixed in Django.

How ransomware gangs went pro

The container sles-15-sp3-chost-byos-v20220103 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220103-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220103-gen2 was updated. The following patches have been included in this update:

Microsoft Sees Rampant Log4j Exploit Attempts, Testing
SEGA’s Sloppy Security Confession: Exposed AWS S3 Bucket Offers Up Steam API Access & More
Data Skimmer Hits 100+ Sotheby’s Real-Estate Websites
SlimPay fined €180k after 12 million customers’ bank data publicly accessible for 5 years
Israeli newspapers targeted by hackers on anniversary of Iranian general’s assassination
Purple Fox Rootkit Dropped by Malicious Telegram Installers
Breaking the habit: Top 10 bad cybersecurity habits to shed in 2022

Be alert, be proactive and break these 10 bad habits to improve your cyber-hygiene in 2022 The post Breaking the habit: Top 10 bad cybersecurity habits to shed in 2022 appeared first on WeLiveSecurity

McMenamins Data Breach Affects 12 Years of Employee Info
John Edwards takes the reins at the UK’s data protection watchdog
Portugal Media Giant Impresa Crippled by Ransomware Attack

Two vulnerabilities have been discovered in the Apache HTTP server: CVE-2021-44224

2022: The year of software supply chain security

An update for the idm:DL1 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for samba is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for telnet is now available for Red Hat Enterprise Linux 7.6 Advanced Update Support, Red Hat Enterprise Linux 7.6 Telco Extended Update Support, and Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions.

xorg-x11-server: SProcRenderCompositeGlyphs out-of-bounds access (CVE-2021-4008) * xorg-x11-server: SProcXFixesCreatePointerBarrier out-of-bounds access (CVE-2021-4009) * xorg-x11-server: SProcScreenSaverSuspend out-of-bounds access (CVE-2021-4010) * xorg-x11-server: SwapCreateRegister out-of-bounds access (CVE-2021-4011) For more details about the security issue(s), including the impact, [More…]

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code, spoofing, information disclosure, downgrade attacks on SMTP STARTTLS connections or misleading display of OpenPGP/MIME signatures.

security update

An update for xorg-x11-server is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,