Menu

Category Archives: Security

Articles about security

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Talk about the fox guarding the hen house. Comcast to handle DNS-over-HTTPS for Firefox-using subscribers
US govt: Julian Assange tried to recruit hacker to steal hush-hush dirt and we should know – the hacker was an informant
“I think you appear in this video” phishing scam hijacks Facebook accounts
Nationwide Facial Recognition Ban Proposed By Lawmakers
Golang Worm Widens Scope to Windows, Adds Payload Capacity
Maze Ransomware operators hack LG Electronics stealing critical data
Honeypot behind sold-off IP subnet shows Cyberbunker biz hosted all kinds of filth, says SANS Institute
US indicts WikiLeaks’ Julian Assange for hiring Anonymous & LulzSec
Nvidia Warns Windows Gamers of Serious Graphics Driver Bugs
Find a Playstation 4 vulnerability and earn over $50,000

An update that fixes one vulnerability is now available.

Office 365 Users Targeted By ‘Coronavirus Employee Training’ Phish

An update for nghttp2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The inside story of the Maersk NotPetya ransomware attack, from someone who was there

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has 9 fixes is now available.

Reading Time: ~ 3 min. It didn’t take long for COVID-19 to completely alter the way we work. Businesses that succeed in this rapidly changing environment will be the ones that adapt with the same velocity. In our second installment from The Future of Work series, you’ll hear from Webroot Product Marketing Director George Anderson, […]

Red Hat AMQ Broker 7.7 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

There are DDoS attacks, then there’s this 809 million packet-per-second tsunami Akamai says it just caught
Smashing Security podcast #184: Vanity Bitcoin wallets, BlueLeaks, and a Coronavirus app conspiracy
After huffing and puffing for years, US senators unveil law to blow the encryption house down with police backdoors
‘Safe Documents’ tool in Office 365 will automatically detect malware
Emerging Ransomware Targets Photos, Videos on Android Devices
Self-Propagating Lucifer Malware Targets Windows Systems
Ransomware crims to sell off ‘scandalous’ files swiped from Mariah Carey, Nicki Minaj, Puff Daddy’s legal eagles

**horde 5.2.23** * [mjr] SECURITY: Fix javascript injection vulnerability in mobile login page. * [mjr] Fix broken cloud search in portal block.

security update

Fake govt COVID-19 contact tracking app spreads Android ransomware
DDoSecrets thrown off Twitter after distributing 269GB BlueLeaks data dump
Laws on police facial recognition aren’t tough enough, UK data watchdog barrister tells Court of Appeal
HEY pulls feature which could expose email threads without participants’ knowledge
Clop ransomware operators leak 4.75 GB data on Indiabulls conglomerate
Former UK Labour deputy leader wants to know how the NHS’s contact-tracing app will ensure user privacy
New Bill Targeting ‘Warrant-Proof’ Encryption Draws Ire
Experts Denounce Racial Bias of Crime-Predictive Facial-Recognition AI
Maze ransomware gang threatens to publish sensitive stolen data after US aerospace biz sensibly refuses to pay
EncroChat encrypted communication provider quits after malware attack

An update that fixes three vulnerabilities is now available.

An update for candlepin and satellite is now available for Red Hat Satellite 6.5 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Carbon-based vuln hunters will always be better at infosec than AI, insist puny humans

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Three words you do not want to hear regarding a ‘secure browser’ called SafePay… Remote. Code. Execution
Verizon FiOS Router and Security Issues
The state of OpenPGP key servers: Kristian, can you renew my certificate? A month later: Kristian? Ten days later: Too late, it’s expired
Here’s a headline we never thought we’d write 20 years ago: Microsoft readies antivirus for Linux, Android
New ransomware posing as COVID‑19 tracing app targets Canada; ESET offers decryptor

ESET researchers dissect an Android app that masquerades as an official COVID-19 contact-tracing app and encrypts files on the victim’s device The post New ransomware posing as COVID‑19 tracing app targets Canada; ESET offers decryptor appeared first on WeLiveSecurity

Sodinokibi Ransomware Now Scans Networks For PoS Systems
Stalker Online data breach: Over 1.2m player records sold on dark web
Majority of new remote employees use their personal laptops for work

And many of them didn’t receive any new security training or tools from their employer to properly secure the devices, a study finds The post Majority of new remote employees use their personal laptops for work appeared first on WeLiveSecurity

Work From Home Opens New Remote Insider Threats
None shall pass: Yet another layer to protect hapless users, employers from dodgy docs added to Microsoft 365

Reading Time: ~ 3 min. Most major tech blogs have run some variation of the following headline in recent months: Is it worth paying for an antivirus solution anymore? The insinuation, of course, is that built in antivirus solutions for Mac and Windows machines have progressed to such a point that it’s no longer worth […]

Scam uses Elon Musk’s name to trick people out of US$2 million in bitcoin

The giveaway scheme uses the tech titan’s name as part of Bitcoin addresses for extra credibility The post Scam uses Elon Musk’s name to trick people out of US$2 million in bitcoin appeared first on WeLiveSecurity

UK police’s face recognition tech breaks human rights laws. Outlaw it, civil rights group urges Court of Appeal
Hakbit Ransomware Attack Uses GuLoader, Malicious Microsoft Excel Attachments
Attackers steal payment information through Google Analytics

Kernel: vfio: access to disabled MMIO space of some devices may lead to DoS scenario (CVE-2020-12888) SL7 x86_64 bpftool-3.10.0-1127.13.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1127.13.1.el7.x86_64.rpm kernel-3.10.0-1127.13.1.el7.x86_64.rpm kernel-debug-3.10.0-1127.13.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1127.13.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1 [More…]

ntp: ntpd using highly predictable transmit timestamps could result in time change or DoS (CVE-2020-13817) * ntp: DoS on client ntpd using server mode packet (CVE-2020-11868) SL7 x86_64 ntp-4.2.6p5-29.el7_8.2.x86_64.rpm ntp-debuginfo-4.2.6p5-29.el7_8.2.x86_64.rpm ntpdate-4.2.6p5-29.el7_8.2.x86_64.rpm sntp-4.2.6p5-29.el7_8.2.x86_64.rpm noarch ntp-doc-4.2.6p5-29.el7_8.2 [More…]

An update that solves two vulnerabilities and has 10 fixes is now available.

Remote Workers Pose New Security Risks

An update that solves two vulnerabilities and has 10 fixes is now available.

An update that fixes three vulnerabilities is now available.

Updated microcode_ctl packages that fix several security bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact

What did it take for stubborn IBM to fix flaws in its Data Risk Manager security software? Someone dropping zero-days
Step on it, I’ve got the police on my hack: Anon swipes, leaks online 269GB of crime intel docs from cops, Feds
Report: ‘BlueLeaks’ Exposes Sensitive Data From Police Departments

security update

Adobe Prompts Users to Uninstall Flash Player As EOL Date Looms
We were already secure enough for mass remote working before COVID-19, boast IT pros
Hackers leak 296 GB worth of data from US Police & Fusion centers
AMD: Fixes For High-Severity SMM Callout Flaws Upcoming
Hackers manipulating Google searches to spread nasty Mac malware
Stalker Online hacked! Over one million gamers’ passwords made available for download
VMware and Office for Mac need patching, Microsoft can scan your firmware, and Anonymous takes credit for Atlanta police hacks

Several security issues were fixed in Mutt.

nfs-utils could be made to overwrite files as the administrator.

unbound: amplification of an incoming query into a large number of queries directed to a target (CVE-2020-12662) * unbound: infinite loop via malformed DNS answers received from upstream servers (CVE-2020-12663) SL6 x86_64 unbound-debuginfo-1.4.20-29.el6_10.1.i686.rpm unbound-debuginfo-1.4.20-29.el6_10.1.x86_64.rpm unbound-libs-1.4.20-29.el6_10.1.i686.rpm unbound-libs-1.4.2 [More…]

unbound: incomplete fix for CVE-2020-12662 in RHEL7 (CVE-2020-10772) SL7 x86_64 unbound-1.6.6-5.el7_8.x86_64.rpm unbound-debuginfo-1.6.6-5.el7_8.i686.rpm unbound-debuginfo-1.6.6-5.el7_8.x86_64.rpm unbound-libs-1.6.6-5.el7_8.i686.rpm unbound-libs-1.6.6-5.el7_8.x86_64.rpm unbound-devel-1.6.6-5.el7_8.i686.rpm unbound-devel-1.6.6-5.el7_8.x86_64.rpm unbound-python [More…]

Mozilla: Security downgrade with IMAP STARTTLS leads to information leakage (CVE-2020-12398) * Mozilla: Use-after-free in SharedWorkerService (CVE-2020-12405) * Mozilla: JavaScript Type confusion with NativeTypes (CVE-2020-12406) * Mozilla: Memory safety bugs fixed in Firefox 77 and Firefox ESR 68.9 (CVE-2020-12410) SL7 x86_64 thunderbird-68.9.0-1.el7_8.x86_64.rpm thunderbird-deb [More…]

An update that solves 5 vulnerabilities and has 22 fixes is now available.

If a Cyber Security Report Falls in a Forest, Is Anyone Listening?
What You Need to Know About Linux Rootkits [Updated]>

It was discovered that there was an out-of-bounds access vulnerability in the server-server protocol in the ngircd Internet Relay Chat (IRC) server.

Updated gnutls packages fix security vulnerability: It was found that GnuTLS 3.6.4 introduced a regression in the TLS protocol implementation. This caused the TLS server to not securely construct a session ticket encryption key considering the application

security update

Damian Poddebniak and Fabian Ising discovered two security issues in the STARTTLS handling of the Mutt mail client, which could enable MITM attacks.

IT guy from FEMA hacked medical center, sold data on dark web
Hey NYPD, when you’re done tear-gassing and running over protesters, can you tell us about your spy gear?
Former DIA Analyst Sentenced to Prison Over Data Leak

security update

Australia’s Lion brewery hit by second cyber attack as nation staggers under suspected Chinese digital assault
Digging up InvisiMole’s hidden arsenal

ESET researchers reveal the modus operandi of the elusive InvisiMole group, including newly discovered ties with the Gamaredon group The post Digging up InvisiMole’s hidden arsenal appeared first on WeLiveSecurity

News Wrap: Malicious Chrome Extensions Removed, CIA ‘Woefully Lax’ Security Policies Bashed
70 malicious Chrome extensions found spying on 32 million+ users