Menu

Category Archives: Security

Articles about security

How to Increase Your Security Posture with Fewer Resources
Nuclear Weapons Agency Hacked in Widening Cyberattack – Report
5M WordPress Sites Running ‘Contact Form 7’ Plugin Open to Attack
Ethical power supplier People’s Energy hacked, 250,000 customers’ personal info accessed

security update

Update to 2.16.9 Release notes: https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.9

Police Vouch for Hacker Who Guessed Trump’s Twitter Password
Google, Qualcomm team up to make long-term Android updates easier on Snapdragon
Air-Gap Attack Turns Memory Modules into Wi-Fi Radios
RubyGems Packages Laced with Bitcoin-Stealing Malware
Cryptologists Crack Zodiac Killer’s 340 Cipher
3M Users Targeted by Malicious Facebook, Insta Browser Add-Ons
Cybersecurity Advent calendar: Stay close to one another… Safely!

This year, many of us will be celebrating Christmas with our loved ones virtually, however we shouldn’t underestimate the value of securing our online communication. The post Cybersecurity Advent calendar: Stay close to one another… Safely! appeared first on WeLiveSecurity

Code42 Incydr Series: Bringing Shadow IT into the light with Code42 Incydr
Whistleblowers have come to us alleging spy agency wrongdoing, says UK auditor IPCO

An update for openssl is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

How cyber-attackers are coming after you in 2021
Smashing Security podcast #209: Vengeful ex-staff, bad Santas, and iOS app nutrition facts

An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the postgresql:9.6 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

UK Home Office chucks US firm Leidos £30m for help snooping on comms data
Passwords begone: GitHub will ban them next year for authenticating Git operations
Dutch officials say Donald Trump really did protect his Twitter account with MAGA2020! password

security update

security update

SolarWinds’ shares drop 22 per cent. But what’s this? $286m in stock sales just before hack announced?

security update

security update

Log right in, the water’s fine, whispers Microsoft as it adds autofill to Authenticator app
Ryuk, Egregor Ransomware Attacks Leverage SystemBC Backdoor

It was discovered that Apache Tomcat from 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an

The SolarWinds Perfect Storm: Default Password, Access Sales and More
Sextortionist Campaign Targets iOS, Android Users with New Spyware
UK proposes new powers for comms regulator to legally unleash avenging hordes on security-breached telcos

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openssl is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Your ship comms app is ‘secured’ with a Flash interface, doesn’t sanitise SQL inputs and leaks user data, you say?

An update for python-XStatic-Bootstrap-SCSS is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for python-XStatic-jQuery is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

How to leak data via Wi-Fi when there’s no Wi-Fi chip: Boffin turns memory bus into covert data transmitter
We’re not saying this is how SolarWinds was backdoored, but its FTP password ‘leaked on GitHub in plaintext’
Subway Sandwich Loyalty-Card Users Suffer Ham-Handed Phishing Scam
Easy WP SMTP Security Bug Can Reveal Admin Credentials
Gitpaste-12 Worm Widens Set of Exploits in New Attacks
Firefox Patches Critical Mystery Bug, Also Impacting Google Chrome
Medical scans of millions of patients exposed online

Other leaked data included a range of personal information such as names, addresses and personal healthcare information. The post Medical scans of millions of patients exposed online appeared first on WeLiveSecurity

Twitter scores a first for big tech after being fined €450,000 by Ireland’s data watchdog for violating the EU’s GDPR
45 Million Medical Images Left Exposed Online
How scammers target PayPal users and how you can stay safe

What are some common ploys targeting PayPal users? Here’s what you should watch out for when using the popular payment service. The post How scammers target PayPal users and how you can stay safe appeared first on WeLiveSecurity

Agent Tesla Keylogger Gets Data Theft and Targeting Update
Millions of Unpatched IoT, OT Devices Threaten Critical Infrastructure
Ransomware and IP Theft: Top COVID-19 Healthcare Security Scares

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Cruise line operator Hurtigruten crippled in ransomware attack

An update for the nginx:1.16 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

New Red Hat Single Sign-On 7.4.4 packages are now available for Red Hat Enterprise Linux 8. 2. Relevant releases/architectures: Red Hat Single Sign-On 7.4 for RHEL 8 – noarch

A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

New Red Hat Single Sign-On 7.4.4 packages are now available for Red Hat Enterprise Linux 7. 2. Relevant releases/architectures: Red Hat Single Sign-On 7.4 for RHEL 7 Server – noarch

45 million medical scans from hospitals all over the world left exposed online for anyone to view – some servers were laced with malware
Up to 18,000 SolarWinds customers installed poisoned update that could allow state-sponsored attack
SolarWinds: Hey, only as many as 18,000 customers installed backdoored software linked to US govt hacks
Spotify Changes Passwords After Another Data Breach

security update

Ransomware masterminds claim to have nabbed 53GB of data from Intel’s Habana Labs
House purchases in Hackney fall through following cyber attack against council
Ex-Cisco Employee Convicted for Deleting 16K Webex Accounts
DHS Among Those Hit in Sophisticated Cyberattack by Foreign Adversaries – Report
SolarWinds’ ‘breached by nation state spies’ software is in wide use throughout the British public sector
Microsoft Office 365 Credentials Under Attack By Fax ‘Alert’ Emails

The cybersecurity industry and end-of-year predictions go together like Fall and football or champagne and the New Year. But on the heels of an unprecedented year, where a viral outbreak changed the landscape of the global workforce practically overnight, portending what’s in store for the year ahead is even trickier than usual.   One thing […]

New Windows Trojan Steals Browser Credentials, Outlook Files
You’re invited to the “Smashing Security” Christmas party!
Anatomy of a Linux Ransomware Attack>

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for xorg-x11-server is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Ad blocking made Google throw its toys out of the pram – and now even more control is being taken from us

Red Hat OpenShift Container Platform release 4.6.8 is now available with updates to packages and images that fix several bugs. This release includes a security update for openshift-enterprise-builder-container for Red Hat OpenShift Container

An update for libexif is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Red Hat OpenShift Container Platform release 4.6.8 is now available with updates to packages and images that fix several bugs. An update for ironic-images, openshift, openshift-ansible, openshift-clients, and python-eventlet, cri-o, openshift-kuryr,

An update for libpq is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

US Treasury, Dept of Commerce hacks linked to SolarWinds IT monitoring software supply-chain attack

Yaniv Nizry discovered that the clean module of lxml, Python bindings for libxml2 and libxslt could be bypassed. For the stable distribution (buster), this problem has been fixed in

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Ruild with hardening flags enabled; also, add -doc subpackage, fix .so version symlinking, make -devel dependency on main package strict (arched), and other minor improvements

New version 3.4.0. Security fix for CVE-2020-26575, CVE-2020-28030.

Rogue ex-Cisco employee who crippled WebEx conferences and cost Cisco millions gets two years in US prison

The container caasp/v4.5/velero-restic-restore-helper was updated. The following patches have been included in this update:

The container caasp/v4.5/velero-plugin-for-microsoft-azure was updated. The following patches have been included in this update:

The container caasp/v4.5/velero-plugin-for-gcp was updated. The following patches have been included in this update:

The container caasp/v4.5/velero-plugin-for-aws was updated. The following patches have been included in this update:

The container caasp/v4.5/velero was updated. The following patches have been included in this update:

The container caasp/v4.5/skuba-tooling was updated. The following patches have been included in this update:

Hackers, never at a loss for creative deception, have engineered new tactics for exploiting the weakest links in the cybersecurity chain: ourselves! Social engineering and business email compromise (BEC) are two related cyberattack vectors that rely on human error to bypass the technology defenses businesses deploy to deter malware. Social Engineering Social Engineering is when […]