Menu

Category Archives: Security

Articles about security

An update that fixes 12 vulnerabilities is now available.

UK reveals new ‘National Cyber Force’, announces Space Command and mysterious AI agency
You can protect the company from hackers, but can you protect the company from the CEO?
VMware reveals critical hypervisor bugs found at Chinese white hat hacking comp. One lets guests run code on hosts
In 2016 Australia’s online census failed. Preparations for the 2021 edition have been rated ‘partly effective’
Robot Vacuums Suck Up Sensitive Audio in ‘LidarPhone’ Hack
German COVID-19 Contact-Tracing Vulnerability Allowed RCE
US Senate approves deepfake bill to defend against manipulated media

security update

GO SMS Pro Android App Exposes Private Photos, Videos and Messages
Tis’ the Season for Online Holiday Shopping; and Phishing
AWS includes open-source Suricata for stateful inspection with Network Firewall service
Code42 Incydr Series: Protect IP with Code42 Incydr
Get the free Security Intelligence Handbook from Recorded Future
Food-Supply Giant Americold Admits Cyberattack
IoT Cybersecurity Improvement Act Passed, Heads to President’s Desk
Cyberup campaign: 80% of infosec pros fear they might fall foul of UK’s outdated Computer Misuse Act
APT Exploits Microsoft Zerologon Bug: Targets Japanese Companies
Cybercriminals Batter Automakers With Ransomware, IP Theft Cyberattacks
Egregor ransomware attack hijacks printers to spit out ransom notes

An update that solves one vulnerability and has two fixes is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that solves one vulnerability, contains one feature and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

In any other year, many of us would be gearing up for airline travel, big family dinners, cocktail hours or potlucks with friends, and much more. But with all the challenges this year has brought in terms of how we work and connect during a global pandemic, I’m guessing all our plans look a little […]

How security and compliance automation can help achieve a more secure hybrid cloud
Anti-adversarial machine learning defenses start to take root
Compsci guru wants ‘right to be forgotten’ for old email, urges Google and friends to expire, reveal crypto-keys
China-linked hacking gang ‘APT10’ named as probable actor behind extended attacks on Japanese companies

It’s common for savvy online shoppers to check third-party reviews before making an online purchasing decision. That’s smart, but testing the efficacy of security software can be a bit more difficult than determining if a restaurant had decent service or if clothing brand’s products are true to size. So, with the arguably more significant consequences […]

Smashing Security podcast #205: Zoom password pinching and Parler problems
Reeling from ransomware attack, Managed.com takes down its entire web hosting infrastructure
Widespread Scans Underway for RCE Bugs in WordPress Websites
Cryptocurrency exchange Liquid suffers security breach, user data exposed

security update

LAPD Bans Facial Recognition, Citing Privacy Concerns
Cisco Webex ‘Ghost’ Flaw Opens Meetings to Snooping
Heads up: A new strain of card-skimming Grelos malware is on the loose

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

How AI Is powering a new generation of cyber-attacks
Bumble bugs could have exposed personal data of all users

The information at risk of theft due to API flaws included people’s pictures, locations, dating preferences and Facebook data The post Bumble bugs could have exposed personal data of all users appeared first on WeLiveSecurity

Google Chrome 87 Closes High-Severity ‘NAT Slipstreaming’ Hole
The ones who brought you Let’s Encrypt, bring you: Tools for gathering anonymized app usage metrics from netizens
Firing of CISA Chief Christopher Krebs Widely Condemned
Test and Trace chief Dido Harding prompted to self-isolate by NHS COVID-19 app
You call that DevSecOps? Why your DevSecOps practice may be falling short
Hackers steal 46 million Animal Jam account records, dating back 10 years

Release of OpenShift Serverless 1.11.0 2. Description: Red Hat OpenShift Serverless 1.11.0 is a generally available release of the OpenShift Serverless Operator. This version of the OpenShift Serverless

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

No, the creator of cURL didn’t morph into Elon Musk and give away Bitcoins. But his hijacked Twitter page tried to
Trump fires cybersecurity boss Chris Krebs for doing his job: Securing the election and telling the truth about it
Israeli spyware maker NSO channels Hollywood spy thrillers in appeal for legal immunity in WhatsApp battle
Multiple Industrial Control System Vendors Warn of Critical Bugs
Defining Security Policies to Manage Remote Insider Threats
ThreatList: Pharma Mobile Phishing Attacks Turn to Malware
COVID-19 Antigen Firm Hit by Malware Attack
Microsoft brings Trusted Platform Module functionality directly to CPUs under securo-silicon architecture Pluton
A visit to a crafted webpage would have been enough for a bad guy to munch all your Firefox for Android cookies
Zoom Takes on Zoom-Bombers Following FTC Settlement
Lazarus supply‑chain attack in South Korea

ESET researchers uncover a novel Lazarus supply-chain attack leveraging WIZVERA VeraPort software The post Lazarus supply‑chain attack in South Korea appeared first on WeLiveSecurity

Cisco Patches Critical Flaw After PoC Exploit Code Release
Legendary hacker and L0pht member Peiter Zatko joins Twitter as security chief
Some Apple Apps on macOS Big Sur Bypass Content Filters, VPNs

An update that fixes one vulnerability is now available.

An update that fixes 29 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Kerberos could be made to consume unlimited resources if it received specially crafted ASN.1.

Apple’s privacy pledges: We sent dev checks over plain HTTP, logged IP addresses. We bypass firewall apps
End the year as you mean to go on… with world-class cyber-security training
Micropayments company Coil distributes new privacy policy with email that puts users’ addresses in the ‘To:’ field
Dating Site Bumble Leaves Swipes Unsecured for 100M Users
Attackers Target Porn Site Goers in ‘Malsmoke’ Zloader Attack
Citrix SD-WAN Bugs Allow Remote Code Execution
Hacked Security Software Used in Novel South Korean Supply-Chain Attack
Exposed Database Reveals 100K+ Compromised Facebook Accounts
Street Fighter maker says soz after ransomware hadoukens servers leaving 350,000 folks’ data at risk of compromise
Up to 350,000 people at risk after Capcom ransomware attack
Cybercrime Moves to the Cloud to Accelerate Attacks Amid Data Glut

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

International infosec rules delivered to make nations and non-state actors behave themselves online
This year’s biggest innovators? Hackers and cybercriminals. Again

An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the virt:8.2 and virt-devel:8.2 modules is now available for Advanced Virtualization for RHEL 8.2.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Australia to track Coronavirus encounters with payment card records

Apache Ant uses various insecure temporary files possibly allowing local code execution.

A vulnerability in MIT Kerberos 5 could lead to a Denial of Service condition.

A vulnerability in libmaxminddb could lead to a Denial of Service condition.

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation. (CVE-2020-0452)

The Kleopatra component before 20.07.80 for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary library. (CVE-2020-24972).

A flaw was found in Go standard library packages. Both the net/http/cgi and net/http/fcgi packages use a default Content-Type response header value of “text/html”, rather than “text/plain”. An attacker could exploit this in applications using these packages by uploading crafted files, allowing for a cross-site scripting attack (XSS) (CVE-2020-24553).

A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick was too tolerant against an invalid Transfer-Encoding header. This may lead to inconsistent interpretation between WEBrick and some HTTP proxy servers, which may allow the attacker to ”smuggle” a request (CVE-2020-25613).

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-8694) Observable discrepancy in the RAPL interface for some Intel(R) Processors may

Scams Ramp Up Ahead of Black Friday Cybercriminal Craze
Stick a fork in SGX, it’s done: Intel’s cloud-server security defeated by $30 chip and electrical shenanigans