Menu

Category Archives: Security

Articles about security

An update that fixes one vulnerability is now available.

Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification (CVE-2020-13802). References: – https://bugs.mageia.org/show_bug.cgi?id=27511

Smart tech gifts: How to keep your kids and family safe

Cyberthreats can take the fun out of connected gadgets – here’s how to make sure your children enjoy the tech without putting themselves or their family at risk The post Smart tech gifts: How to keep your kids and family safe appeared first on WeLiveSecurity

The update for python-apt released as 2488-1 introduced a regression by causing a segmentation fault, which is now fixed with this update. For Debian 9 stretch, this problem has been fixed in version

An update that solves 7 vulnerabilities and has two fixes is now available.

New version 1.4.3. Security fix for CVE-2020-28241.

New version 1.4.3. Security fix for CVE-2020-28241.

An update that fixes 8 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

security update

xenstore watch notifications lacking permission checks [XSA-115, CVE-2020-29480] (#1908091) Xenstore: new domains inheriting existing node permissions [XSA-322, CVE-2020-29481] (#1908095) Xenstore: wrong path length check [XSA-323, CVE-2020-29482] (#1908096) Xenstore: guests can crash xenstored via watchs [XSA-324, CVE-2020-29484] (#1908088) Xenstore: guests can disturb domain cleanup

xenstore watch notifications lacking permission checks [XSA-115, CVE-2020-29480] (#1908091) Xenstore: new domains inheriting existing node permissions [XSA-322, CVE-2020-29481] (#1908095) Xenstore: wrong path length check [XSA-323, CVE-2020-29482] (#1908096) Xenstore: guests can crash xenstored via watchs [XSA-324, CVE-2020-29484] (#1908088) Xenstore: guests can disturb domain cleanup

Several vulnerabilities were discovered in Sympa, a mailing list manager, which could result in local privilege escalation, denial of service or unauthorized access via the SOAP API.

A vulnerability in NSS might allow remote attackers to cause a Denial of Service condition.

7 ways malware can get into your device

You know that malware is bad, but are you also aware of the various common ways in which it can infiltrate your devices? The post 7 ways malware can get into your device appeared first on WeLiveSecurity

Windows Zero-Day Still Circulating After Faulty Fix

Multiple vulnerabilities have been found in Samba, the worst of which could result in a Denial of Service condition.

A vulnerability has been discovered in Apache Tomcat that allows for the disclosure of sensitive information.

A buffer overflow in HAProxy might allow an attacker to execute arbitrary code.

Lazarus Group Hits COVID-19 Vaccine-Maker in Espionage Attack

It was found that spip, a website engine for publishing, did not correctly validate its input (couleur, display, display_navigation, display_outils, imessage, and spip_ecran) allowing authenticated users to execute arbitrary code.

Third-Party APIs: How to Prevent Enumeration Attacks
Hey Alexa, Who Am I Messaging?
Emotet Returns to Hit 100K Mailboxes Per Day
Police bring down “bulletproof” VPN services beloved by cybercriminals

It was discovered that Awstats, a web server log analyzer, was vulnerable to path traversal attacks. A remote unauthenticated attacker could leverage that to perform arbitrary code execution. The previous fix did not fully address the issue when the default

How to bring zero-trust security to microservices

The container ses/7/ceph/ceph was updated. The following patches have been included in this update:

US Department of Homeland Security warns American business not to use Chinese tech or let data behind the Great Firewall
Holiday Puppy Swindle Has Consumers Howling

Previous fix for buffer overrun printing the contents of the sPLT chunk in certain malformed inputs (RHBZ#1905775) was incomplete; it should be properly fixed now. —- Security fix for multiple buffer overflows from crafted file input (RHBZ#1902786,1902806,1902810: no CVE yet assigned), and for buffer overrun printing the contents of the sPLT chunk in certain malformed […]

Update to 2.16.9 Release notes: https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.9

Previous fix for buffer overrun printing the contents of the sPLT chunk in certain malformed inputs (RHBZ#1905775) was incomplete; it should be properly fixed now. —- Security fix for multiple buffer overflows from crafted file input (RHBZ#1902786,1902806,1902810: no CVE yet assigned), and for buffer overrun printing the contents of the sPLT chunk in certain malformed […]

An update that fixes 8 vulnerabilities is now available.

Cybersecurity Advent calendar: Stay aware, stay safe!

When it comes to holiday gifts, surprise and wonder are always welcome. When it comes to protecting your security, however, you don’t want to leave anything to chance. The post Cybersecurity Advent calendar: Stay aware, stay safe! appeared first on WeLiveSecurity

Tech Giants Lend WhatsApp Support in Spyware Case Against NSO Group
UK cryptocurrency exchange EXMO suffers breach, funds stolen
Joker’s Stash Carding Site Taken Down
Patrick Wardle on Hackers Leveraging ‘Powerful’ iOS Bugs in High-Level Attacks
UK firm NOW: Pensions tells some customers a ‘service partner’ leaked their data all over ‘public software forum’

Security awareness training is one of the most straightforward ways to improve a business’ overall resilience against cyberattacks. That is, when you get it just right. Thanks to the disruptions to “normal” work routines that COVID-19 has brought, launching a company-wide training program to teach end users how to avoid phishing scams and online risks […]

An update that fixes one vulnerability is now available.

An update that solves 7 vulnerabilities and has two fixes is now available.

A few issues have been found in the OpenJDK 8u272 update, including LDAP connection failures and application crash. For Debian 9 stretch, this problem has been fixed in version

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the postgresql:10 module is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for mariadb-connector-c is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Nosy Ex-Partners Armed with Instagram Passwords Pose a Serious Threat
Smart Doorbell Disaster: Many Brands Vulnerable to Attack
Defending Against State and State-Sponsored Threat Actors
Zero-Click Apple Zero-Day Uncovered in Pegasus Spy Attack
Simplifying Proactive Defense With Threat Playbooks
Dark Web Pricing Skyrockets for Microsoft RDP Servers, Payment-Card Data
Critical Bugs in Dell Wyse Thin Clients Allow Code Execution, Client Takeovers
Dell Wyse Thin Client scores two perfect 10 security flaws
Hacker Dumps Crypto Wallet Customer Data; Active Attacks Follow
Hacker publishes stolen email and mailing addresses of 270,000 Ledger cryptocurrency wallet users
Business and enterprise anti-virus products put through a long-term test – which performed the best?
SolarWinds releases known attack timeline but new data suggests hackers may have done a dummy run last year
Modernize Your Intrusion Detection Strategy with an AI-Powered, Open-Source NIDS>
Telemed Poll Uncovers Biggest Risks and Best Practices
‘Best tech employer of the year’ threatened trainee with £15k penalty fee for quitting to look after his sick mum

It was discovered that there was an issue in node-ini, a .ini format parser and serializer for Node.js, where an application could be exploited by a malicious input file.

Well, on the bright side, the SolarWinds Sunburst attack will spur the cybersecurity field to evolve all over again

An update for thunderbird is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Container Platform release 4.6.9 is now available with updates to packages and images that fix several bugs and add enhancements. This release also includes a security update for Red Hat OpenShift Container Platform 4.6.

An update for openssl is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes 5 vulnerabilities is now available.

Trump administration says Russia behind SolarWinds hack. Trump himself begs to differ

A heap-buffer overwrites error was discovered in lib/openjp2/mqc.c in OpenJPEG 2.3.1. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution (CVE-2020-27814). A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass

An issue has been found in influxdb, a scalable datastore for metrics, events, and real-time analytics. By using a JWT token with an empty shared secret, one is able to bypass

An update that solves one vulnerability and has one errata is now available.

SCAP Security Guide: helping you to achieve security policy compliance

An update that fixes two vulnerabilities is now available.

Two vulnerabilities were discovered in the PEAR Archive_Tar package for handling tar files in PHP, potentially allowing a remote attacker to execute arbitrary code or overwrite files.

The update for lxml released as 4810-1 introduced a regression when running under Python 2. Updated lxml packages are now available to correct this issue.

security update

Cloud is King: 9 Software Security Trends to Watch in 2021

– Update to Firefox 84 – Built with system nss Please give karma to nss packages which are needed for this update: https://bodhi.fedoraproject.org/updates/FEDORA-2020-c489b93b18 https://bodhi.fedoraproject.org/updates/FEDORA-2020-d04a8e97b3 —- – New upstream version (Firefox 84) – Enabled WebRender by default on Gnome Wayland

Update to latest upstream version.

This update backports a patch for CVE-2020-27828.

Sunburst’s C2 Secrets Reveal Second-Stage SolarWinds Victims
Operation SignSight: Supply‑chain attack against a certification authority in Southeast Asia

ESET researchers have uncovered a supply-chain attack on the website of a government in Southeast Asia. The post Operation SignSight: Supply‑chain attack against a certification authority in Southeast Asia appeared first on WeLiveSecurity

Microsoft Caught Up in SolarWinds Spy Effort, Joining Federal Agencies
Cyberpunk 2077 Headaches Grow: New Spyware Found in Fake Android Download
Insider Threats: What Are They, Really?
Unsecured Azure blob exposed 500,000+ highly confidential docs from UK firm’s CRM customers
Ransomware attackers are making threatening phone calls to their victims, warns FBI

Trickbot spreading through Subway company emails Customers of Subway U.K. have been receiving confirmation emails for recent orders that instead contain malicious links for initiating Trickbot malware downloads. Subway has since disclosed that it discovered unauthorized access to several of its servers, which then launched the campaign. Users who do click on the malicious link […]

The container caasp/v4/nginx-ingress-controller was updated. The following patches have been included in this update:

‘Long-standing vulns’ in 5G protocols open the door for attacks on smartphone users

Several vulnerabilities have been discovered in the Linux kernel that may lead to the execution of arbitrary code, privilege escalation, denial of service or information leaks.

Updated images are now available for Red Hat OpenShift Container Storage 4.6.0 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 14 vulnerabilities is now available.

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting or the disclosure of hidden users.

US nuke agency hacked by suspected Russian SolarWinds spies, Microsoft also installed backdoor

security update

How to Increase Your Security Posture with Fewer Resources