Menu

Category Archives: Security

Articles about security

US Customs has one heck of a false positive over “counterfeit Apple AirPods”

An update for librepo is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the mysql:8.0 module is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Update to version 0.9.5 * https://www.libssh.org/2020/09/10/libssh-0-9-5/ * Fixes CVE-2020-16135

QEMU: usb: out-of-bounds r/w access issue [XSA-335, CVE-2020-14364] (#1871850)

Apache Log4j could be made to remotely execute arbitrary code if it received specially crafted log data.

MFA Bypass Bugs Opened Microsoft 365 to Attack
Have hackers, cybercrims worked their way into your corporate net while you’ve been working from home?
Chinese database detailing 2.4 million influential people, their kids, their addresses, and how to press their buttons revealed
Infosec big names rally against US voting app maker’s bid to outlaw unsanctioned bug hunting via T&Cs
What do F5, Citrix, Pulse Secure all have in common? China exploiting their flaws to hack govt, biz – Feds
Feds Warn Nation-State Hackers are Actively Exploiting Unpatched Microsoft Exchange, F5, VPN Bugs
Court hearing on election security is zoombombed on 9/11 anniversary with porn, swastikas, pics of WTC attacks
Take your pick: ‘Hack-proof’ blockchain-powered padlock defeated by Bluetooth replay attack or 1kg lump hammer
Cloud Leak Exposes 320M Dating-Site Records
Personal data from Experian on 40% of South Africa’s population has been bundled onto a file-sharing website
TikTok Fixes Flaws That Opened Android App to Compromise

Reading Time: ~ 3 min. Women of Webroot and Carbonite talk about what drew them to the field and their advice for others looking to break into STEM. The lack of representative diversity in tech has been long acknowledged and well-studied.  Organizations and non-profit groups like National Center for Women & Information Technology (NCWIT), Girls […]

Magecart Attack Impacts More Than 10K Online Shoppers
Sorry we shut you out, says Tutanota: Encrypted email service weathers latest of ongoing DDoS storms

An update that solves 8 vulnerabilities and has 17 fixes is now available.

An update that solves 8 vulnerabilities and has 17 fixes is now available.

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3617

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3631

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3643

Another month, another cryptocurrency exchange hacked and ‘millions of dollars’ stolen by miscreants

An update that fixes one vulnerability is now available.

New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

– https://www.drupal.org/project/drupal/releases/7.72 – [Drupal core – Critical – Cross Site Request Forgery – SA- CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 – https://www.drupal.org/project/drupal/releases/7.71 – https://www.drupal.org/project/drupal/releases/7.70 – [Drupal core –

https://lists.gnupg.org/pipermail/gnutls-help/2020-September/004669.html

– https://www.drupal.org/project/drupal/releases/7.72 – [Drupal core – Critical – Cross Site Request Forgery – SA- CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 – https://www.drupal.org/project/drupal/releases/7.71 – https://www.drupal.org/project/drupal/releases/7.70 – [Drupal core –

An update that fixes one vulnerability is now available.

Update to upstream bugfix and security release 2.9.13.

update to 2.2.16, CVE-2020-24583, CVE-2020-24584

New F31 selinux-policy build

Update to .NET Core SDK 3.1.107 and Runtime 3.1.7. This fixes CVE-2020-1597 – Release Notes: https://github.com/dotnet/core/blob/master/release- notes/3.1/3.1.7/3.1.7.md

Update to .NET Core SDK 3.1.107 and Runtime 3.1.7. This fixes CVE-2020-1597 – Release Notes: https://github.com/dotnet/core/blob/master/release- notes/3.1/3.1.7/3.1.7.md

Don’t pay the ransom, mate. Don’t even fix a price, say Australia’s cyber security bods
APT28 Mounts Rapid, Large-Scale Theft of Office 365 Logins
Office 365 Phishing Attack Leverages Real-Time Active Directory Validation
It’s No ‘Giggle’: Managing Expectations for Vulnerability Disclosure
Who is calling? CDRThief targets Linux VoIP softswitches

ESET researchers have discovered and analyzed malware that targets Voice over IP (VoIP) softswitches. The post Who is calling? CDRThief targets Linux VoIP softswitches appeared first on WeLiveSecurity

WordPress Plugin Flaw Allows Attackers to Forge Emails
What an IDORable Giggle: AI-powered ‘female only’ app gets in Twitter kerfuffle over breach notification
“Yourefired” was Donald Trump’s Twitter password, claim hackers

Multiple vulnerabilities were discovered in WordPress, a popular content management framework. CVE-2019-17670

Adtech’s bogeymen are tracking everything – even your web visits to mental health charities, claim campaigners

Reading Time: ~ 3 min. This year more than others, for many of us, it’s gaming that’s gotten us through. Lockdowns, uncertainty, and some pretty darn good releases have kept our computers and consoles switched on in 2020. GamesIndustry.biz, a website tracking the gaming sector, reported a record number of concurrent users on the gaming […]

Secure your Zoom account with Two-Factor Authentication

An update that solves 8 vulnerabilities and has 12 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Stop unauthorized applications with RHEL 8’s File Access Policy Daemon

Update built with the new CMake settings Number of files which should have been owned by the testsuite subpackage are now owned by it Started building MeCab plugin

8u265 update, disable LTO

Three middle-aged Dutch hackers slipped into Donald Trump’s Twitter account days before 2016 US election
Billions of Bluetooth gadgets bothered by ‘BLURtooth’ miscreant-in-the-middle bug
China, Russia and Iran all attacking US elections and using some nasty new tactics, says Microsoft

Reading Time: ~ 4 min. Today’s work-from-home environment has created an abundance of opportunities for offering new cybersecurity services in addition to your existing business. With cyberattacks increasing in frequency and sophistication, business owners and managers need protection now more than ever. MSPs are ideally positioned to deliver the solutions businesses need in order to […]

Microsoft Warns of Cyberattacks on Trump, Biden Election Campaigns
Razer Gaming Fans Caught Up in Data Leak
Portland passes the strictest facial recognition technology ban in the US yet 

Oregon’s largest city aims to be a trailblazer when it comes to facial recognition legislation . The post Portland passes the strictest facial recognition technology ban in the US yet  appeared first on WeLiveSecurity

How to talk vulnerability management with the C-suite – and make them care
Bluetooth Bug Opens Devices to Man-in-the-Middle Attacks
Ransomware And Zoom-Bombing: Cyberattacks Disrupt Back-to-School Plans
Pension scheme cold caller fined £130,000 by UK data watchdog
Govt.-Backed Contact-Tracing Apps Raise Privacy Hackles

libX11 1.6.12 (CVE-2020-14363, CVE 2020-14344)

QEMU: usb: out-of-bounds r/w access issue [XSA-335, CVE-2020-14364] (#1871850)

The 5.8.7 stable kernel update contains a number of important fixes across the tree.

Product Overview: Cynet Takes Cyber Threat Protection Automation to the Next Level with Incident Engine
Cryptocurrency exchange Eterbase hacked, $5.4 million worth of funds stolen
Ireland unfriends Facebook: Oh Zucky Boy, the pipes, the pipes are closing…from glen to US, and through the EU-side

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

CDRThief Malware Targets VoIP Gear in Carrier Networks

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dovecot is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

China’s UK embassy calls for probe into ‘hack of Ambassador’s Twitter account’
Now that’s a somewhat unexpected insider threat: Zoombombings mostly blamed on rogue participants, unique solution offered
Don’t be BlindSided: Watch speculative memory probing bypass kernel defenses, give malware root control
Smashing Security podcast #195: Selene Delgado Lopez is not your friend
UK University suffers cyberattack, ransomware gang claims responsibility 

The cyber incident has taken most of Newcastle University’s systems offline and officials estimates it will take weeks to recover.  The post UK University suffers cyberattack, ransomware gang claims responsibility  appeared first on WeLiveSecurity

Fake Facebook email invites you to tell 39 strangers you were duped
Zeppelin Ransomware Returns with New Trojan on Board
Google Squashes Critical Android Media Framework Bug
Lead‑offering business booming as usual!

…but there are no conferences or exhibitions??? The post Lead‑offering business booming as usual! appeared first on WeLiveSecurity

I can ‘proceed without you’, judge tells Julian Assange after courtroom outburst
TeamTNT Gains Full Remote Takeover of Cloud Instances
Critical Flaws in 3rd-Party Code Allow Takeover of Industrial Control Systems

An update that fixes one vulnerability is now available.

Several security issues were fixed in X.Org X Server.

Remember the Titans: Yubico jangles new NFC and USB-C touting security key
Spyware Labeled ‘TikTok Pro’ Exploits Fears of US Ban

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Using OPA to safeguard Kubernetes

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 6 fixes is now available.

Enjoyed the US Labor Day weekend? Because it’s September 2020 and Exchange Server can be pwned via email