Menu

Category Archives: Security

Articles about security

Hacker Sets Alleged Auction for Witcher 3 Source Code

security update

security update

security update

Hybrid, Older Users Most-Targeted by Gmail Attackers
Microsoft patches actively exploited Windows kernel flaw

This month’s relatively humble bundle of security updates fixes 56 vulnerabilities, including a zero-day bug and 11 flaws rated as critical The post Microsoft patches actively exploited Windows kernel flaw appeared first on WeLiveSecurity

8 Brits arrested after probe into SIM-swapping scam targeting US celebs
Intel Squashes High-Severity Graphics Driver Flaws
The time for Insider Risk Management is now: Code42 2021 Data Exposure Report Reveals a Perfect Storm
Supply-Chain Hack Breaches 35 Companies, Including PayPal, Microsoft, Apple

An update for .NET 5.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for .NET Core 2.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

All grown up: Raspberry Pis running Ubuntu added to IoT patching service KernelCare

An update for rh-dotnet50-dotnet is now available for .NET on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-dotnet31-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-dotnet21-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Understanding Multipath TCP: High availability for endpoints and the networking highway of the future
No phish for the likes of you, thank you very much! Google finds email villains are picky about demographics, country
North Korean attacks on crypto exchanges reportedly netted $316m in two years

security update

Actively Exploited Windows Kernel EoP Bug Allows Takeover
Google Play Boots Barcode Scanner App After Ad Explosion
Microsoft Patch Tuesday gaffe leads netizens to ‘Microosft’ typo-squatting domain

The supply chain attack that Trojanized a SolarWinds update to infect and spy on the IT management platform’s customer base continues to be analyzed. Early reports have called the methods highly sophisticated and the actors highly trained. We do know that IP addresses, a command and control server and a malicious product update file were […]

Attackers Exploit Critical Adobe Flaw to Target Windows Users
Hacker attempts to poison Florida city’s water supply

While the incursion was thwarted in time, cyberattacks targeting critical infrastructure are a major cause for concern The post Hacker attempts to poison Florida city’s water supply appeared first on WeLiveSecurity

ESET Threat Report Q4 2020

A view of the Q4 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report Q4 2020 appeared first on WeLiveSecurity

Android Devices Hunted by LodaRAT Windows Malware
Cyberpunk 2077 Publisher Hit with Hack, Threats and Ransomware
Just 2020 things: Miscreants hit remote desktops 700% harder as world’s IT teams try to support locked-down staff
Hacker Tries to Poison Water Supply of Florida Town
CD Projekt Red ‘EPICALLY pwned’: Cyberpunk 2077 dev publishes ransom note after company systems encrypted
Hackers publish patient data stolen from two US hospital chains
DISA Has Released the Red Hat Enterprise Linux 8 STIG
How To Secure the Linux Kernel >

Upstream details at : https://access.redhat.com/errata/RHSA-2021:0411

An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 and Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenShift Container Platform release 4.5.31 is now available with updates to packages and images that fix several bugs. This release also includes a security update for Red Hat OpenShift Container Platform 4.5.

Ignore that ransomware demand and restore from backup – well… if only it were that easy
‘Quad’ nations sign up for meta think-tank to advance ‘Techno-Democratic Statecraft’

Various overflow errors were identified and fixed. CVE-2020-27814

The container caasp/v4.5/cilium-operator was updated. The following patches have been included in this update:

The container caasp/v4.5/cilium was updated. The following patches have been included in this update:

Someone tried to poison a Florida city by hijacking its water treatment plant via TeamViewer, says sheriff
A hacker tried to poison Florida city’s water supply
Barcode scan app amassed millions of downloads before weird update starting popping open webpages…
Billions of Passwords Offered for $2 in Cyber-Underground
Critical WordPress Plugin Flaw Allows Site Takeover
Ransomware Demands Spike 320%, Payments Rise

security update

Fake Forcepoint Google Chrome Extension Hacks Windows Users
Thanks for finding a critical bug. Have a $1.5 million bounty, and our CTO will get a tattoo of anything you like
WestRock Ransomware Attack Hinders Packaging Production
EncroChat hack case: RAM, bam… what? Data in transit is data at rest, rules UK Court of Appeal
Private messages between Mensa forum members are leaked onto the internet

The php packages are updated to version 7.3.27 to fix a Null Dereference in SoapClient (SOAP). (CVE-2021-21702). Note also php packages version 7.4.15-1.mga7 are available in backports/updates.

A vulnerability was discovered in how wpa_supplicant processing P2P (Wi-Fi Direct) group information from active group owners. The actual parsing of that information validates field lengths appropriately, but processing of the parsed information misses a length check when storing a copy of the secondary device types. This can result in writing

phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, database.php does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in administrator to visit a malicious page with a CSRF exploit and execute […]

Report: Adoption of passwordless security takes off amid COVID-19
CrowdSec: An Innovative Open-Source Massively Multiplayer Firewall for Linux>
The Linux Flaw you can’t afford to Ignore (CVE-2021-3156)>
LibreOffice 7.1 Open-Source Office Suite Officially Released, This Is What’s New>
The future of work: Coming sooner than you think

An update that fixes three vulnerabilities is now available.

CVE-2020-0256 In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This

Red Hat OpenShift Container Platform release 4.6.16 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes 6 vulnerabilities is now available.

Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge

Multiple vulnerabilites were discovered in privoxy, a privacy enhancing HTTP proxy, like memory leaks, dereference of a NULL-pointer, et al.

Security fix for [PUT CVEs HERE]

Security fix for CVE-2020-26418, CVE-2020-26419, CVE-2020-26420, CVE-2020-26421 Update to version 3.4.2 Fix %post script on Silverblue

Update to jasper-2.0.24, see https://github.com/jasper- software/jasper/releases/tag/version-2.0.24 for details. Backport fix for CVE-2021-3272.

security fix for CVE-2021-0326 see also: https://w1.fi/security/2020-2/

Industrial Networks See Sharp Uptick in Hackable Security Holes
Unpatched WordPress Plugin Code-Injection Bug Afflicts 50K Sites

Update to 3.10.0a5. Security fix for CVE-2021-3177.

**PHP version 7.4.15** (04 Feb 2021) **Core:** * Fixed bug php#80523 (bogus parse error on >4GB source code). (Nikita) * Fixed bug php#80384 (filter buffers entire read until file closed). (Adam Seitz, cmb) **Curl:** * Fixed bug php#80595 (Resetting POSTFIELDS to empty array breaks request). (cmb) **Date:** * Fixed bug php#80376 (last day of the […]

Security fix for CVE-2021-20197

Backport patches for CVE-2020-14409, CVE-2020-14410.

CVE-2020-8695 Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to

SitePoint hacked: Hashed, salted passwords pinched from web dev learning site via GitHub tool pwnage

An update that fixes two vulnerabilities is now available.

Facebook etiquette: Behaviors you should avoid

Sharing your thoughts or photos for the world to see is now as easy as pushing a button, but even a seemingly harmless post may come back to haunt you The post Facebook etiquette: Behaviors you should avoid appeared first on WeLiveSecurity

New VS Code release hits stable channel for everyone who’s not on Apple Silicon after last-minute bug found
Google Chrome Zero-Day Afflicts Windows, Mac Users
Ransomware Attacks Hit Major Utilities
Chrome zero-day bug that is actively being abused by bad folks affects Edge, Vivaldi, and other Chromium-tinged browsers

flatpak: sandbox escape via spawn portal (CVE-2021-21261) SL7 x86_64 flatpak-1.0.9-10.el7_9.x86_64.rpm flatpak-debuginfo-1.0.9-10.el7_9.x86_64.rpm flatpak-libs-1.0.9-10.el7_9.x86_64.rpm flatpak-builder-1.0.0-10.el7_9.x86_64.rpm flatpak-devel-1.0.9-10.el7_9.x86_64.rpm – Scientific Linux Development Team

Fake WhatsApp app may have been built to spy on iPhone users – what you need to know

It was discovered that Mutt incorrectly handled certain email messages. An attacker could possibly use this issue to cause a denial of service because rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators […]

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part […]

It was discovered that there was an issue in nodejs-ini, where an application could be exploited by a malicious input file. This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be […]

The Linux box that runs the exec carpark gate is down! A chance for PostgreSQL Man to show his quality
Cisco reveals critical bug in small biz VPN routers when half the world is stuck working at home
Vote machine biz Smartmatic sues Fox News and Trump chums for $2.7bn over bogus claims of rigged 2020 election
Android Devices Prone to Botnet’s DDoS Onslaught

# New in release OpenJDK 11.0.10 (2021-01-19): Live versions of these release notes can be found at: * https://bitly.com/openjdk11010 * https://builds.shipilev.net/backports-monitor/release-notes-11.0.10.txt ## Security fixes * JDK-8247619: Improve Direct Buffering of Characters ## Other changes * [JDK-8213821](https://bugs.openjdk.java.net/browse/JDK-8213821):

The 5.10.12 stable kernel update contains a number of important fixes across the tree.

How do you fix a problem like open-source security? Google has an idea, though constraints may not go down well