Menu

Category Archives: Security

Articles about security

Vishing: What is it and how do I avoid getting scammed?

How do vishing scams work, how do they impact businesses and individuals, and how can you protect yourself, your family and your business? The post Vishing: What is it and how do I avoid getting scammed? appeared first on WeLiveSecurity

Microsoft Disrupts Large-Scale, Cloud-Based BEC Campaign
NCSC chief: Ransomware is more of a threat to Britain than hostile nations’ spies
Insider Risks In the Work-From-Home World
SASE & Zero Trust: The Dream Team

kernel: Integer overflow in Intel(R) Graphics Drivers (CVE-2020-12362) * kernel: Use after free via PI futex state (CVE-2021-3347) * kernel: use-after-free in n_tty_receive_buf_common function in drivers/tty/n_tty.c (CVE-2020-8648) * kernel: Improper input validation in some Intel(R) Graphics Drivers (CVE-2020-12363) * kernel: Null pointer dereference in some Intel(R) Graphics Drivers (CVE [More…]

TimeCache aims to block side-channel cache attacks – without hurting performance

An update for ceph, ceph-ansible, ceph-iscsi, python-waitress, and tcmu-runner is now available for Red Hat Ceph Storage 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Microsoft Gets Second Shot at Banning hiQ from Scraping LinkedIn User Data
Brit IT firms wound up by court order after fooling folk into paying for ‘support’ over fake computer errors
Apple Hurries Patches for Safari Bugs Under Active Attack
The latest REvil ransomware victim? Sol Oriens. Oh, a US nuclear weapons contractor

Open Liberty 21.0.0.6 Runtime is now available from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in ImageMagick.

gupnp: allows DNS rebinding which could result in tricking browser into triggering actions against local UPnP services (CVE-2021-33516) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_ [More…]

When security gets physical: Mossad boss hints at less-than-subtle Stuxnet followup
NATO summit communiqué compares repeat cyberattacks to armed attacks – and stops short of saying ‘one-in, all-in’ rule will always apply

Red Hat OpenShift Container Platform release 4.7.16 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

G7 nations call out Russia for harbouring ransomware crims ahead of Biden-Putin powwow
Utilities ‘Concerningly’ at Risk from Active Exploits
Ex-NSA leaker Reality Winner released from prison early for ‘exemplary’ behavior
Microsoft Teams: Very Bad Tabs Could Have Led to BEC
Moobot Milks Tenda Router Bugs for Propagation
Volkswagen Vendor Exposed Data of 3.3m Drivers
Norton dodges UK courts after telling Brit watchdog it will be nicer to consumers
Ransomware is the biggest threat, says GCHQ cybersecurity chief
Meat supplier JBS probed after paying $11 million ransom to attackers

Openshift Logging Bug Fix Release (5.0.5) This release includes a security update. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

An update for dhcp is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

dhcp: stack-based buffer overflow when parsing statements with colon- separated hex digits in config or lease files in dhcpd and dhclient (CVE-2021-25217) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 dhclient-4.2.5-83.el7_9.1.x86_64.rpm dhcp-4.2.5-83.el7_9.1.x86_64.rpm dhcp [More…]

hw: vt-d related privilege escalation (CVE-2020-24489) * hw: improper isolation of shared resources in some Intel Processors (CVE-2020-24511) * hw: observable timing discrepancy in some Intel Processors (CVE-2020-24512) * hw: information disclosure on some Intel Atom processors (CVE-2020-24513) Bug Fix(es) and Enhancement(s): * Update Intel CPU microcode to microcode-20210525 release — [More…]

The great cloud computing surge
We’ve been shown time and again that strong encryption puts crims behind bars, so why do politicos hate it?

Several vulnerabilities were discovered in Squid, a proxy caching server. CVE-2021-28651

An update for postgresql is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The AN0M fake secure chat app may have been too clever for its own good

The container suse-sles-15-sp2-chost-byos-v20210610-gen2 was updated. The following patches have been included in this update:

Add proposed patches for CVE-2021-29338 and a heap buffer overflow.

Add proposed patches for CVE-2021-29338 and a heap buffer overflow.

Add proposed patches for CVE-2021-29338 and a heap buffer overflow.

Add proposed patches for CVE-2021-29338 and a heap buffer overflow.

Unpatched Bugs Found Lurking in Provisioning Platform Used with Cisco UC

security update

Baby Clothes Giant Carter’s Leaks 410K Customer Records
REvil Hits US Nuclear Weapons Contractor: Report
Google fixes actively exploited Chrome zero‑day

The latest Chrome update patches a bumper crop of security flaws across the browser’s desktop versions The post Google fixes actively exploited Chrome zero‑day appeared first on WeLiveSecurity

BackdoorDiplomacy: Upgrading from Quarian to Turian

ESET researchers discover a new campaign that evolved from the Quarian backdoor The post BackdoorDiplomacy: Upgrading from Quarian to Turian appeared first on WeLiveSecurity

UK tells UN that nation-states should retaliate against cyber badness with no warning
Cyberpunk 2077 Hacked Data Circulating Online
Monumental Supply-Chain Attack on Airlines Traced to State Actor

The package wireshark-cli before version 3.4.6-1 is vulnerable to denial of service.

The package kube-apiserver before version 1.21.1-1 is vulnerable to insufficient validation.

The package nettle before version 3.7.3-1 is vulnerable to denial of service.

The package isync before version 1.4.2-1 is vulnerable to arbitrary code execution.

The package python-websockets before version 9.1-1 is vulnerable to private key recovery.

The package python-urllib3 before version 1.26.5-1 is vulnerable to denial of service.

Police Grab Slilpp, Biggest Stolen-Logins Market
EA Games looted by intruders: Publisher says ‘no player data accessed’ after reported theft of FIFA 21, Frostbite source
Hackers Steal FIFA 21 Source Code, Tools in EA Breach
Complexity is the biggest threat to cloud success and security
Smashing Security podcast #231: Sexy snaps and encrypted chat traps
Seven-year-old make-me-root bug in Linux service polkit patched
China arrests over 1000 for using cryptocurrency to help launder proceeds of phone scams
‘Fancy Lazarus’ Cyberattackers Ramp up Ransom DDoS Efforts

security update

security update

Chrome Browser Bug Under Active Attack
STEM Audio Table Rife with Business-Threatening Bugs
Gelsemium: When threat actors go gardening

ESET researchers shed light on new campaigns from the quiet Gelsemium group The post Gelsemium: When threat actors go gardening appeared first on WeLiveSecurity

Microsoft: Big Cryptomining Attacks Hit Kubeflow
Steam Gaming Platform Hosting Malware
JBS Paid $11M to REvil Gang Even After Restoring Operations

An update for servicemesh-operator is now available for OpenShift Service Mesh 2.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Student Loans Company splashes out on 20,000 cybersecurity training courses – for just 3,300 employees

libwebp could be made to crash or run programs as your login if it opened a specially crafted file.

An update for the postgresql:13 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

South Korea’s data watchdog barks warnings at Microsoft and five local firms

An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Ransomware-skewered meat producer JBS confesses to paying $11m for its freedom

An update for the container-tools:3.0 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

ALPACA gnaws through TLS protection to snarf cookies and steal data
Huawei flings open the doors of its third privacy and security transparency centre
Risk and reward: Nefilim ransomware gang mainly targets fewer, richer companies and that strategy is paying off, warns Trend Micro
PrivacyMic looks to keep your home smart without Google, Alexa, Siri and pals listening in
Mysterious Custom Malware Collects Billions of Stolen Data Points
‘I put the interests of the country first’: Colonial Pipeline CEO on why oil biz paid off ransomware crooks
Intel Plugs 29 Holes in CPUs, Bluetooth, Security
Mysterious Gelsemium APT was behind February compromise of NoxPlayer, says ESET

rxvt, VT102 terminal emulator for the X Window System, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q).

mrxvt, lightweight multi-tabbed X terminal emulator, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q).

eterm, an enlightened terminal emulator, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q).

Red Hat OpenShift Container Platform release 3.11.452 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 3.11.

DarkSide Pwned Colonial With Old VPN Password
Intel’s latest patch set plugs some serious holes in CPU, Bluetooth, server, and – ironically – security lines

An update that fixes three vulnerabilities is now available.

Identity and access in the DevSecOps life cycle

Several security issues were fixed in Intel Microcode.

Security researcher says attacks on Russian government have Chinese fingerprints – and typos, too
Extra urgency in June’s Patch Tuesday: Microsoft warns six more bugs are being exploited