Menu

Category Archives: Security

Articles about security

The package firefox before version 77.0-1 is vulnerable to multiple issues including arbitrary code execution, denial of service, private key recovery and content spoofing.

Hospital-busting hacker crew may be behind ransomware attack that made Honda halt car factories, say researchers
Adobe Warns of Critical Flaws in Flash Player, Framemaker
Brave soz about coding snafu that sent search queries to affiliate links but insists practice is ‘industry-standard’
Dark Basin Hack-For-Hire Group Targeted Thousands Over 7 Years

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Can Governments Defeat Nation-State Attacks on Critical Infrastructures?

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2414

An information disclosure vulnerability in GnuTLS allow remote attackers to obtain sensitive information.

Reading Time: ~ 3 min. Nestled within our chapter on malware in the 2020 Webroot Threat Report is a comparison of infection rates between business and personal devices. The finding that personal devices are about twice as likely as business devices to become infected was always significant, if not surprising. But the advent of the […]

Singapore to distribute wearable contact-tracing device and won’t rule out making it compulsory
Because things aren’t bad enough already: COVID-19 is going to mess up election security assumptions too
Singapore’s Contact Tracing Wearable Causes Privacy Backlash

security update

Your “smart” household appliance might have a short lifespan
SMBGhost RCE Exploit Threatens Corporate Networks
Phishing Attack Hits German Coronavirus Task Force
Huawei launches UK charm offensive: We’ve provided 2G, 3G and 4G for 20 years, and you’re worried about 5G?
No prison for cyber criminal duo behind vDOS DDoS for hire service

An update that fixes three vulnerabilities is now available.

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

DDoS-for-hire gang escape with light community service sentence

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that fixes one vulnerability is now available.

Why would someone want to hack Germany’s PPE supply chain? We’re glad you masked
Smart fridges are cool, but after a few short years you could be stuck with a big frosty brick in the kitchen
Tycoon malware rages through US schools, LG’s boot problem, and QNAP admins had better get busy

The following CVE(s) were reported against src:cups. CVE-2019-8842

A vulnerability was discovered in graphicsmagick, a collection of image processing tools, that results in a heap buffer overwrite when magnifying MNG images.

Top US aerospace services provider suffers breach, loses 1.5 TB of data

GnuTLS could be made to expose sensitive information.

How to use Signal messenger face blur tool on Android & iOS

A flaw was reported in the TLS session ticket key construction in GnuTLS, a library implementing the TLS and SSL protocols. The flaw caused the TLS server to not securely construct a session ticket encryption key considering the application supplied secret, allowing a

Two vulnerabilities were discovered in Node.js, which could result in denial of service and potentially the execution of arbitrary code. For the stable distribution (buster), these problems have been fixed in

security update

Reading Time: ~ 2 min. TrickBot Silently Targets Servers Knowing that many domain controller servers are rarely shutdown or rebooted, the authors of TrickBot have made some changes to allow the infection to run from memory. While this can be detrimental to the payload, as a reboot could easily remove it, the stealth approach could […]

Scammers using voicemail email phishing scam to steal data
British Army pulls up its SOC: New regiment to do infosec work even civvies will recognise
FTC Slams Children’s App Developer for COPPA Violations
Cyberattacks targeting BLM movement see widespread increase
Electrolux, Others Conned Out of Big Money by BEC Scammer
Kind of goes without saying, but fix your admin passwords or risk getting borged by this brute-forcing botnet
News Wrap: Fake Minneapolis Police Breach, Zoom End-To-End Encryption Debate
Mozilla fixes high‑risk Firefox flaws, bug in DoH feature

The browser maker rolls out updates on back-to-back days, including a patch to avoid unintentionally overloading DNS providers The post Mozilla fixes high‑risk Firefox flaws, bug in DoH feature appeared first on WeLiveSecurity

WhatsApp Phone Numbers Pop Up in Google Search Results — But is it a Bug?
UK govt publishes contracts granting Amazon, Microsoft, Google and AI firms access to COVID-19 health data
Hackers using malicious CV files to infect PCs with banking trojan

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Signal goes Gaussian to take privacy to the next level: All your faces don’t belong to us
OK Windows 10, we get it: You really do not want us to install this unsigned application. But 7 steps borders on ridiculous
Facebook to save US users from ads bought by foreign state-controlled media
VMware beefs up security chops with Lastline acquisition, reportedly drops 40 per cent of staff

– Updated to latest upstream (77.0.1) —- – New upstream version (77.0) —- – Updated VA-API patches for Wayland backend – Use dmabuf WebGL backend by default on Wayland

– Update to 1.2.12 Release notes: https://www.cacti.net/release_notes.php?version=1.2.12

– Update to 1.2.12 Release notes: https://www.cacti.net/release_notes.php?version=1.2.12

– Update to 2.16.6 Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.16.6-and-2.7.15-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2020-04

Significant increase in demand of stolen YouTube credentials on dark web
Tycoon Ransomware Banks on Unusual Image File Tactic

security update

Trump, Biden Campaign Staffers Targeted By APT Phishing Emails
New malware tool can steal files from airgapped PCs using USBs

There were several CVE bugs reported against src:netqmail. CVE-2005-1513

Have I Been Pwned breach report email pwned entire firm’s helldesk ticket system
Understanding the Payload-Less Email Attacks Evading Your Security Team
Facebook now lets you delete old posts in bulk

Dealing with skeletons lurking in your Facebook closet has never been easier The post Facebook now lets you delete old posts in bulk appeared first on WeLiveSecurity

Zoom Restricts End-to-End Encryption to Paid Users
U.S. Nuclear Contractor Hit with Maze Ransomware, Data Leaked
MAZE hackers hit US Nuclear contractor; steal sensitive documents
Goodbye Naked Security?

An update that fixes one vulnerability is now available.

An update that solves 7 vulnerabilities and has one errata is now available.

Legal complaint lodged with UK data watchdog over claims coronavirus Test and Trace programme flouts GDPR
The scammer who tried to launder over $500,000 through Business Email Compromise
Sophos puts 100 at risk of redundancy as future of Naked Security blog hangs in balance
Google Faces Privacy Lawsuit Over Tracking Users in Incognito Mode

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2383

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2378

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2381

ZLoader-Laced Emails Masquerade As CVs From Job-Seekers
Creeps give away money to harass recipients with abusive transaction descriptions on bank statements
Why updating your PC fleet lowers TCO, bolsters security – and makes life easier for your IT admins
Update Firefox: Mozilla just patched three hijack-me holes and a bunch of other flaws
Anatomy of a business email scam: FBI dossier details how fraudster pocketed $500k+ by redirecting payments
Smashing Security podcast #181: Anti-cybercrime ads, tricky tracing, and a 5G Bioshield
Sophisticated Info-Stealer Targets Air-Gapped Devices via USB
Attackers Target 1M+ WordPress Sites To Harvest Database Credentials
$5bn+ sueball bounces into Google’s court over claims it continues to track netizens in ‘private browsing mode’
Google adds Nest devices to Advanced Protection Program

You can now shore up your smart home security by leveraging Google’s top security offering The post Google adds Nest devices to Advanced Protection Program appeared first on WeLiveSecurity

TrickBot Adds BazarBackdoor to Malware Arsenal
Critical SAP ASE Flaws Allow Complete Control of Databases

Reading Time: ~ 2 min. Bank of America Breach Reveals PPP Information After processing over 300,000 Paycheck Protection Program applications, Bank of America has revealed that a data breach occurred within the U.S. Small Business Administration’s program that allowed all other SBA-authorized lenders to view highly sensitive data. The data includes tax information and social […]

Defending critical national infrastructure… hmm. Does Zoom count as critical now?

An update that fixes one vulnerability is now available.

Hackers disrupt Chicago police radios with anti-cop songs
Enterprise Mobile Phishing Attacks Skyrocket Amidst Pandemic
Coincheck cryptocurrency exchange targeted by hackers, customer emails exposed