Menu

Category Archives: Security

Articles about security

The php packages are updated to version 7.3.27 to fix a Null Dereference in SoapClient (SOAP). (CVE-2021-21702). Note also php packages version 7.4.15-1.mga7 are available in backports/updates.

A vulnerability was discovered in how wpa_supplicant processing P2P (Wi-Fi Direct) group information from active group owners. The actual parsing of that information validates field lengths appropriately, but processing of the parsed information misses a length check when storing a copy of the secondary device types. This can result in writing

phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, database.php does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in administrator to visit a malicious page with a CSRF exploit and execute […]

Report: Adoption of passwordless security takes off amid COVID-19
CrowdSec: An Innovative Open-Source Massively Multiplayer Firewall for Linux>
The Linux Flaw you can’t afford to Ignore (CVE-2021-3156)>
LibreOffice 7.1 Open-Source Office Suite Officially Released, This Is What’s New>
The future of work: Coming sooner than you think

An update that fixes three vulnerabilities is now available.

CVE-2020-0256 In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This

Red Hat OpenShift Container Platform release 4.6.16 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes 6 vulnerabilities is now available.

Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge

Multiple vulnerabilites were discovered in privoxy, a privacy enhancing HTTP proxy, like memory leaks, dereference of a NULL-pointer, et al.

Security fix for [PUT CVEs HERE]

Security fix for CVE-2020-26418, CVE-2020-26419, CVE-2020-26420, CVE-2020-26421 Update to version 3.4.2 Fix %post script on Silverblue

Update to jasper-2.0.24, see https://github.com/jasper- software/jasper/releases/tag/version-2.0.24 for details. Backport fix for CVE-2021-3272.

security fix for CVE-2021-0326 see also: https://w1.fi/security/2020-2/

Industrial Networks See Sharp Uptick in Hackable Security Holes
Unpatched WordPress Plugin Code-Injection Bug Afflicts 50K Sites

Update to 3.10.0a5. Security fix for CVE-2021-3177.

**PHP version 7.4.15** (04 Feb 2021) **Core:** * Fixed bug php#80523 (bogus parse error on >4GB source code). (Nikita) * Fixed bug php#80384 (filter buffers entire read until file closed). (Adam Seitz, cmb) **Curl:** * Fixed bug php#80595 (Resetting POSTFIELDS to empty array breaks request). (cmb) **Date:** * Fixed bug php#80376 (last day of the […]

Security fix for CVE-2021-20197

Backport patches for CVE-2020-14409, CVE-2020-14410.

CVE-2020-8695 Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to

SitePoint hacked: Hashed, salted passwords pinched from web dev learning site via GitHub tool pwnage

An update that fixes two vulnerabilities is now available.

Facebook etiquette: Behaviors you should avoid

Sharing your thoughts or photos for the world to see is now as easy as pushing a button, but even a seemingly harmless post may come back to haunt you The post Facebook etiquette: Behaviors you should avoid appeared first on WeLiveSecurity

New VS Code release hits stable channel for everyone who’s not on Apple Silicon after last-minute bug found
Google Chrome Zero-Day Afflicts Windows, Mac Users
Ransomware Attacks Hit Major Utilities
Chrome zero-day bug that is actively being abused by bad folks affects Edge, Vivaldi, and other Chromium-tinged browsers

flatpak: sandbox escape via spawn portal (CVE-2021-21261) SL7 x86_64 flatpak-1.0.9-10.el7_9.x86_64.rpm flatpak-debuginfo-1.0.9-10.el7_9.x86_64.rpm flatpak-libs-1.0.9-10.el7_9.x86_64.rpm flatpak-builder-1.0.0-10.el7_9.x86_64.rpm flatpak-devel-1.0.9-10.el7_9.x86_64.rpm – Scientific Linux Development Team

Fake WhatsApp app may have been built to spy on iPhone users – what you need to know

It was discovered that Mutt incorrectly handled certain email messages. An attacker could possibly use this issue to cause a denial of service because rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators […]

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part […]

It was discovered that there was an issue in nodejs-ini, where an application could be exploited by a malicious input file. This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be […]

The Linux box that runs the exec carpark gate is down! A chance for PostgreSQL Man to show his quality
Cisco reveals critical bug in small biz VPN routers when half the world is stuck working at home
Vote machine biz Smartmatic sues Fox News and Trump chums for $2.7bn over bogus claims of rigged 2020 election
Android Devices Prone to Botnet’s DDoS Onslaught

# New in release OpenJDK 11.0.10 (2021-01-19): Live versions of these release notes can be found at: * https://bitly.com/openjdk11010 * https://builds.shipilev.net/backports-monitor/release-notes-11.0.10.txt ## Security fixes * JDK-8247619: Improve Direct Buffering of Characters ## Other changes * [JDK-8213821](https://bugs.openjdk.java.net/browse/JDK-8213821):

The 5.10.12 stable kernel update contains a number of important fixes across the tree.

How do you fix a problem like open-source security? Google has an idea, though constraints may not go down well
Spotify Suffers Second Credential-Stuffing Cyberattack in 3 Months
Google: Better patching could have prevented 1 in 4 zero‑days last year

Vendors should fix the root cause of a vulnerability, rather than block just one path to triggering it, says Google The post Google: Better patching could have prevented 1 in 4 zero‑days last year appeared first on WeLiveSecurity

Test Amber Alert accidentally sent out warning of Chucky from the Child’s Play horror movies
Critical Cisco Flaws Open VPN Routers Up to RCE Attacks
Microsoft Office 365 Attacks Sparked from Google Firebase
Sloppy vendor patches are a breeding ground for zero-day exploits, says Google
Cybersecurity firm Stormshield hacked. Data (including source code) stolen
Orca’s “State of Public Cloud Security” report reveals how most cloud security breaches happen
Clearview Facial-Recognition Technology Ruled Illegal in Canada

An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

STIG Security Profile in Red Hat Enterprise Linux 7

Red Hat Quay 3.4.0 is now available with bug fixes and various enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

In KDE KMail, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to […]

Cross-origin information leakage via redirected PDF requests. (CVE-2021-23953) Type confusion when using logical assignment operators in JavaScript switch statements. (CVE-2021-23954)

A flaw was found in python. A stack-based buffer overflow was discovered in the ctypes module provided within Python. Applications that use ctypes without carefully validating the input passed to it may be vulnerable to this flaw, which would allow an attacker to overflow a buffer on the stack and crash the application. The highest […]

A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby’s `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input as the filename (CVE-2019-5477).

Is there a widening gulf between you and your remote workers? Yes – and it’s security shaped
Nespresso smart cards hacked to provide infinite coffee after someone wasn’t too perky about security
Smashing Security podcast #213: No security smarts at Mensa, long-term identity theft, and GameStop’s share frenzy
Myanmar’s new military government bans Facebook
Emotet’s Takedown: Have We Seen the Last of the Malware?
More patches for SolarWinds Orion after researchers find flaw allowing low-priv users to execute code, among others
Second SolarWinds Attack Group Breaks into USDA Payroll — Report
New Malware Hijacks Kubernetes Clusters to Mine Monero

We’ve been doing our homework, and two things seem to be true about cybersecurity awareness training simultaneously: It can be very effective at protecting businesses from one of the most common security threats they face (the majority, according to the Ponemon Institute). Namely, phishing. MSPs, often the single most reliable source of cybersecurity for small […]

A video Q&A session
Identity theft spikes amid pandemic

The US Federal Trade Commission received 1.4 million reports of identity theft last year, double the number from 2019 The post Identity theft spikes amid pandemic appeared first on WeLiveSecurity

Dairy farm group faces $30 million ransom The Dairy Farm Group, one of the largest retailers in Asia, has suffered a ransomware attack by the REvil group, which has demanded a roughly $30 million ransom. The attack is still ongoing nearly nine days after being first identified. The attackers still have full control over the […]

Kobalos – A complex Linux threat to high performance computing infrastructure

ESET researchers publish a white paper about unique multiplatform malware they’ve named Kobalos The post Kobalos – A complex Linux threat to high performance computing infrastructure appeared first on WeLiveSecurity

Five Critical Android Bugs Patched, Part of Feb. Security Bulletin

CVE-2020-8020 An improper neutralization of input during web page generation vulnerability in open-build-service allows remote attackers to

Tiny Kobalos malware seen backdooring SSH tools, menacing supercomputers, an ISP, and more – ESET

An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

SolarWinds Orion Bug Allows Easy Remote-Code Execution and Takeover

Several vulnerabilities were discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. An unauthenticated remote attacker can take advantage of these flaws to cause a denial of service (slapd daemon crash, infinite loops) via

Location tracking report: X-Mode SDK use much more widespread than first thought
Rubbish software security patches responsible for a quarter of zero-days last year

An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Container Platform release 4.4.33 is now available with updates to packages and images that fix several bugs and add enhancements. This release also includes a security update for Red Hat OpenShift Container Platform 4.4.

security update

TrickBot Continues Resurgence with Port-Scanning Module

security update

Crypto Crook Hired Steven Seagal to Promote Scam, Now Faces Charges
Tiny Kobalos Malware Bedevils Supercomputers to Steal Logins
Magento Web Skimmers Piggyback in Ongoing Costway Website Compromise
Operation NightScout: Supply‑chain attack targets online gaming in Asia

ESET researchers uncover a supply-chain attack used in a cyberespionage operation targeting online‑gaming communities in Asia The post Operation NightScout: Supply‑chain attack targets online gaming in Asia appeared first on WeLiveSecurity

Agent Tesla Trojan ‘Kneecaps’ Microsoft’s Anti-Malware Interface

Today, the average enterprise uses over 2000 cloud applications and services, and we expect this number will continue to grow as more businesses realize the efficiency, flexibility and collaboration benefits these services bring. But the use of cloud-based applications also comes with a few caveats; for example, the apps themselves may pose potential security vulnerabilities, […]

Identity Theft Spikes Due to COVID-19 Relief

An update that contains security fixes can now be installed.

kernel: use-after-free in fs/block_dev.c (CVE-2020-15436) * kernel: Nfsd failure to clear umask after processing an open or create (CVE-2020-35513) Bug Fix(es): * double free issue in filelayout_alloc_commit_info * Regression: Plantronics Device SHS2355-11 PTT button does not work after update to 7.7 * Openstack network node reports unregister_netdevice: waiting for qr- 3cec0c92-9a to bec [More…]

An update that fixes one vulnerability is now available.

An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated ovirt-engine packages that fix several bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Updated ovirt-engine packages that fix several bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which