Menu

Category Archives: Security

Articles about security

Florida Water Plant Hack: Leaked Credentials Found in Breach Database
Footfallcam kerfuffle: Firm apologises, promises to fix product after viral Twitter thread, infoseccer backlash

Several security vulnerabilities have been corrected in unbound, a validating, recursive, caching DNS resolver. Support for the unbound DNS server has been resumed, the sources can be found in the unbound1.9 source package.

After hackers blackmailed their clients, Finnish therapy firm declares bankruptcy
“Microosft”. Patch Tuesday goof points users to typo-bait website

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

The package helm before version 3.5.2-1 is vulnerable to insufficient validation.

The package privoxy before version 3.0.31-1 is vulnerable to denial of service.

The package python2-jinja before version 2.11.3-1 is vulnerable to denial of service.

Apple iOS 14.5 will hide Safari users’ IP addresses from Google’s Safe Browsing

In today’s rapidly evolving cybersecurity landscape, the battle for privacy and security is relentless. Cybercriminals are masters at using technology and psychology to exploit basic human trust and compromise businesses of all sizes. What’s more, they often hide in plain sight, using both covert and overt tactics to cause disruption, steal money and data, and […]

Pre-Valentine’s Day Malware Attack Mimics Flower, Lingerie Stores
Phishing awareness gone wrong: Facebook tries to seize websites set up for staff security training

While we can all rejoice that 2020 is over, cybersecurity experts agree we haven’t seen the last of the pandemic-related rise in cyberattacks. Throughout the last year, we’ve seen huge spikes in phishing, malicious domains, malware and more, and we don’t expect that to slow down. As employees around the world continue to work from […]

Celeb SIM-Swap Crime Ring Stole $100M from U.S. Victims
How Email Attacks are Evolving in 2021
Various Malware Lurks in Discord App to Target Gamers
Creeped-out dev spins up an Ubuntu VM on Azure only to be immediately approached by a Canonical sales rep
Eight men arrested following celebrity SIM-swapping attacks
Military, Nuclear Entities Under Target By Novel Android Malware
Smashing Security podcast #214: Lockdown love scams, SolarWinds, and a data deletion bungle

An update for openvswitch2.13 is now available for Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Open Source Vulnerabilities database: Nice idea but too many Google-shaped hoops to jump through at present

Red Hat JBoss Web Server 5.4.1 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 and Windows. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Updated Red Hat JBoss Web Server 5.4.1 packages are now available for Red Hat Enterprise Linux 7, and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Web Server 3.1, for RHEL 7 and Windows. Red Hat Product Security has rated this release as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Web Server 3.1 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for rh-nodejs12-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

This scumbag stole and traded victims’ nude pics and vids after guessing their passwords, security answers
No joy for Julian Assange as Uncle Sam confirms it will keep pushing for WikiLeaker’s extradition to America
SAP Commerce Critical Security Bug Allows RCE
Hacker Sets Alleged Auction for Witcher 3 Source Code

security update

security update

security update

Hybrid, Older Users Most-Targeted by Gmail Attackers
Microsoft patches actively exploited Windows kernel flaw

This month’s relatively humble bundle of security updates fixes 56 vulnerabilities, including a zero-day bug and 11 flaws rated as critical The post Microsoft patches actively exploited Windows kernel flaw appeared first on WeLiveSecurity

8 Brits arrested after probe into SIM-swapping scam targeting US celebs
Intel Squashes High-Severity Graphics Driver Flaws
The time for Insider Risk Management is now: Code42 2021 Data Exposure Report Reveals a Perfect Storm
Supply-Chain Hack Breaches 35 Companies, Including PayPal, Microsoft, Apple

An update for .NET 5.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for .NET Core 2.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

All grown up: Raspberry Pis running Ubuntu added to IoT patching service KernelCare

An update for rh-dotnet50-dotnet is now available for .NET on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-dotnet31-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-dotnet21-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Understanding Multipath TCP: High availability for endpoints and the networking highway of the future
No phish for the likes of you, thank you very much! Google finds email villains are picky about demographics, country
North Korean attacks on crypto exchanges reportedly netted $316m in two years

security update

Actively Exploited Windows Kernel EoP Bug Allows Takeover
Google Play Boots Barcode Scanner App After Ad Explosion
Microsoft Patch Tuesday gaffe leads netizens to ‘Microosft’ typo-squatting domain

The supply chain attack that Trojanized a SolarWinds update to infect and spy on the IT management platform’s customer base continues to be analyzed. Early reports have called the methods highly sophisticated and the actors highly trained. We do know that IP addresses, a command and control server and a malicious product update file were […]

Attackers Exploit Critical Adobe Flaw to Target Windows Users
Hacker attempts to poison Florida city’s water supply

While the incursion was thwarted in time, cyberattacks targeting critical infrastructure are a major cause for concern The post Hacker attempts to poison Florida city’s water supply appeared first on WeLiveSecurity

ESET Threat Report Q4 2020

A view of the Q4 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report Q4 2020 appeared first on WeLiveSecurity

Android Devices Hunted by LodaRAT Windows Malware
Cyberpunk 2077 Publisher Hit with Hack, Threats and Ransomware
Just 2020 things: Miscreants hit remote desktops 700% harder as world’s IT teams try to support locked-down staff
Hacker Tries to Poison Water Supply of Florida Town
CD Projekt Red ‘EPICALLY pwned’: Cyberpunk 2077 dev publishes ransom note after company systems encrypted
Hackers publish patient data stolen from two US hospital chains
DISA Has Released the Red Hat Enterprise Linux 8 STIG
How To Secure the Linux Kernel >

Upstream details at : https://access.redhat.com/errata/RHSA-2021:0411

An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 and Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenShift Container Platform release 4.5.31 is now available with updates to packages and images that fix several bugs. This release also includes a security update for Red Hat OpenShift Container Platform 4.5.

Ignore that ransomware demand and restore from backup – well… if only it were that easy
‘Quad’ nations sign up for meta think-tank to advance ‘Techno-Democratic Statecraft’

Various overflow errors were identified and fixed. CVE-2020-27814

The container caasp/v4.5/cilium-operator was updated. The following patches have been included in this update:

The container caasp/v4.5/cilium was updated. The following patches have been included in this update:

Someone tried to poison a Florida city by hijacking its water treatment plant via TeamViewer, says sheriff
A hacker tried to poison Florida city’s water supply
Barcode scan app amassed millions of downloads before weird update starting popping open webpages…
Billions of Passwords Offered for $2 in Cyber-Underground
Critical WordPress Plugin Flaw Allows Site Takeover
Ransomware Demands Spike 320%, Payments Rise

security update

Fake Forcepoint Google Chrome Extension Hacks Windows Users
Thanks for finding a critical bug. Have a $1.5 million bounty, and our CTO will get a tattoo of anything you like
WestRock Ransomware Attack Hinders Packaging Production
EncroChat hack case: RAM, bam… what? Data in transit is data at rest, rules UK Court of Appeal
Private messages between Mensa forum members are leaked onto the internet

The php packages are updated to version 7.3.27 to fix a Null Dereference in SoapClient (SOAP). (CVE-2021-21702). Note also php packages version 7.4.15-1.mga7 are available in backports/updates.

A vulnerability was discovered in how wpa_supplicant processing P2P (Wi-Fi Direct) group information from active group owners. The actual parsing of that information validates field lengths appropriately, but processing of the parsed information misses a length check when storing a copy of the secondary device types. This can result in writing

phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, database.php does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in administrator to visit a malicious page with a CSRF exploit and execute […]

Report: Adoption of passwordless security takes off amid COVID-19
CrowdSec: An Innovative Open-Source Massively Multiplayer Firewall for Linux>
The Linux Flaw you can’t afford to Ignore (CVE-2021-3156)>
LibreOffice 7.1 Open-Source Office Suite Officially Released, This Is What’s New>
The future of work: Coming sooner than you think

An update that fixes three vulnerabilities is now available.

CVE-2020-0256 In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This

Red Hat OpenShift Container Platform release 4.6.16 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes 6 vulnerabilities is now available.