Menu

Category Archives: Security

Articles about security

Connected Farms Easy Pickings for Global Food Supply-Chain Hack

Security fix for CVE-2021-34558

Actively Exploited Windows Zero-Day Gets a Patch

Security fix for CVE-2021-34558

$600m in cryptocurrencies swiped from Poly Network servers after security snafu

security update

Microsoft Patch Tuesday bug drought: No, it’s not climate change or unexpected code quality improvements

The issue at the heart of ransomware insurance will be familiar to most parents of young children: rewarding bad behavior only invites more of the same, so it’s generally not a good idea. But critics of the ransomware insurance industry argue that’s exactly what the practice does. Ransomware insurance has by now long been suspected […]

eCh0raix Ransomware Variant Targets QNAP, Synology NAS Devices
Deepfakes – the bot made me do it

As fraud involving highly believable synthetic media soars, what can you do to avoid getting scammed? The post Deepfakes – the bot made me do it appeared first on WeLiveSecurity

DEF CON 29: Satellite hacking 101

How peering into the innards of a future satellite can make cybersecurity in space more palatable The post DEF CON 29: Satellite hacking 101 appeared first on WeLiveSecurity

IISpy: A complex server‑side backdoor with anti‑forensic features

The second in our series on IIS threats dissects a malicious IIS extension that employs nifty tricks in an attempt to secure long-term espionage on the compromised servers The post IISpy: A complex server‑side backdoor with anti‑forensic features appeared first on WeLiveSecurity

Chaos Malware Walks Line Between Ransomware and Wiper
Fuzz Off: How to Shake Up Code to Get It Right – Podcast
Learn how to build a culture of security with 1Password
Cutting Through the Noise from Daily Alerts
1M Stolen Credit Cards Hit Dark Web for Free

Red Hat OpenShift Virtualization release 2.6.6 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Tails 4.21 Is Out – Here’s What’s New & How To Get Started>

An update that fixes 27 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that solves 7 vulnerabilities and has 58 fixes is now available.

An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Solving authorization for software developers
We’ll drop SBOMs on UK.gov to solve Telecoms Security Bill’s technical demands, beams Cisco
Splunk spots malware targeting Windows Server on AWS to mine Monero

security update

security update

Apple responds to critics of CSAM scan plan with FAQs – says it’d block governments subverting its system
‘Glowworm’ Attack Turns Power Light Flickers into Audio
Black Hat: Scaling Automated Disinformation for Misery and Profit
Auth Bypass Bug Exploited, Affecting Millions of Routers
Android Malware ‘FlyTrap’ Hijacks Facebook Accounts

Perl could be made to run arbitrary programs.

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3028

Upstream details at : https://access.redhat.com/errata/RHSA-2021:1002

Black Hat USA 2021 & DEF CON 29 Highlights & Key Takeaways>

An update that fixes one vulnerability is now available.

This update provides a new upstream version.

An update for microcode_ctl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Black Hat security conference returns to Las Vegas – complete with hacks to quiet the hotel guest from hell

security update

Several vulnerabilities were discovered in Bluez, the Linux Bluetooth protocol stack. CVE-2020-26558 / CVE-2021-0129

– Resolves: rhbz#1985153 – mod_auth_openidc-2.4.9 is available – Resolves: rhbz#1986103 – CVE-2021-32786 mod_auth_openidc: open redirect in oidc_validate_redirect_url() – Resolves: rhbz#1986396 – CVE-2021-32791 mod_auth_openidc: hardcoded static IV and AAD with a reused key in AES GCM encryption – Resolves:

This kernel-linus update is based on upstream 5.10.56 and fixes atleast the following security issues: In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store

This kernel update is based on upstream 5.10.56 and fixes atleast the following security issues: In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Several vulnerabilities have been found in Ansible, a configuration management, deployment and task execution system, which could result in information disclosure or argument injection. In addition a race condition in become_user was fixed.

security update

Golang Cryptomining Worm Offers 15% Speed Boost
All your DNS were belong to us: AWS and Google Cloud shut down spying vulnerability
Amazon Kindle Vulnerable to Malicious EBooks

A cyber resilience strategy “I have used a lot of different security products over the years, and I get approached by a lot of vendors,” says Pedro Nuñez. As president and CEO of New England based MSP IT Management Solutions, Nuñez is always on the lookout for products that go beyond just a traditional security […]

A Global Challenge The steady stream of cyberattacks seen throughout 2019 turned into a torrent over the last year – ransomware, phishing scams and data breaches are now at an all-time high. Of course, the growing cybersecurity threat isn’t contained to just one country. The effects are being felt the world over. The National Cybersecurity […]

Is your personal information being abused?

Drowning in spam? A study presented at Black Hat USA 2021 examines if sharing your personal information with major companies contributes to the deluge of nuisance emails, texts and phone calls. The post Is your personal information being abused? appeared first on WeLiveSecurity

Why cloud security is the key to unlocking value from hybrid working

How can companies and employees who start to adapt to hybrid working practices protect themselves against cloud security threats? The post Why cloud security is the key to unlocking value from hybrid working appeared first on WeLiveSecurity

Critical Cisco Bug in VPN Routers Allows Remote Takeover
Scanning for Child Sexual Abuse Material (CSAM) on iPhones
Zoom Settlement: An $85M Business Case for Security Investment  
Angry Affiliate Leaks Conti Ransomware Gang Playbook

An update that fixes two vulnerabilities is now available.

Updated exiv2 packages fix security vulnerability: A heap-based buffer overflow vulnerability in jp2image.cpp of Exiv2 0.27.3 allows attackers to cause a denial of service (DOS) via crafted metadata (CVE-2021-31291).

Updated bluez packages fix security vulnerability: Adapter incorrectly restores Discoverable state after powered down (CVE-2021-3658).

Updated nodejs packages fix security vulnerability: Node.js is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior (CVE-2021-22930)

Updated php-pear packages fix security vulnerability: In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive (CVE-2021-32610).

Updated libsndfile packages fix security vulnerability: A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file (CVE-2021-3246).

South Korea to test grenade-launching drones
Microsoft wonders if disabling just-in-time compilation of JavaScript improves browser security
America enlists Big Tech to help it develop and execute cyber security plans

Webroot put forward another strong performance in its latest round of independent third-party testing, besting all competitors and taking home the highest overall score. In taking the highest score in the category for 2021, Webroot beat out competitors including BitDefender, McAfee® and ESET® endpoint security solutions. In the report, the company conducted objective testing of […]

US ‘dropped the ball’ on security by going it alone claims Huawei US CSO
Black Hat: New CISA Head Woos Crowd With Public-Private Task Force

In March of 2020 schools throughout the United Kingdom closed their doors to try to stem the spread of the coronavirus. In addition to disruptions to the lives of students and their families, the pandemic put unprecedented pressure on IT departments across the UK and wider world. Notoriously strapped for resources, many schools’ IT departments […]

Apple is about to start scanning iPhone users’ devices for banned content, warns professor
Auditors: Feds’ Cybersecurity Gets the Dunce Cap

security update

Black Hat 2021 – non‑virtual edition

How is Black Hat USA 2021 different from the past editions of the conference and what kinds of themes may steal the show this year? The post Black Hat 2021 – non‑virtual edition appeared first on WeLiveSecurity

MacOS Flaw in Telegram Retrieves Deleted Messages
Black Hat: Microsoft’s Patch for Windows Hello Bypass Bug is Faulty, Researchers Say
Black Hat: Charming Kitten Leaves More Paw Prints
Got a cheap Cisco router in your home office? If it’s one of these, there’s an exposed RCE hole you need to plug

An update that fixes four vulnerabilities is now available.

This update provides a new upstream version.

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes 6 vulnerabilities is now available.

An update that solves four vulnerabilities and has two fixes is now available.

Das tut mir leid! Germany’s ruling party sorry for calling cops on researcher after she outed canvassing app flaws
Security tips from the experts – sign up to 1Password’s free Security Summer School today
Not all authentication is created equal – and that’s a good thing
‘I’m Calling About Your Car Warranty’, aka PII Hijinx
Black Hat: Security Bugs Allow Takeover of Capsule Hotel Rooms
Black Hat: Let’s All Help Cyber-Immunize Each Other
Worried your data protection strategy is dated? Don’t let a ransomware infection prove you right
SolarWinds urges US judge to toss out crap infosec sueball: We got pwned by actual Russia, give us a break
Phishing Campaign Dangles SharePoint File-Shares

openCryptoki could be made to allow invalid curve attacks if it received a specially crafted key.