Menu

Category Archives: Security

Articles about security

Hackers disrupt Chicago police radios with anti-cop songs
Enterprise Mobile Phishing Attacks Skyrocket Amidst Pandemic
Coincheck cryptocurrency exchange targeted by hackers, customer emails exposed

An update that solves three vulnerabilities and has 18 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Tor soups up onion sites with bountiful browser bump: No more tears trying to find the secure sites you want
Joomla Resources Directory Users Exposed in Leaky AWS Bucket
Office supplies biz owned by UK council snubs ransomware demand for 102 Bitcoin
Two Critical Android Bugs Open Door to RCE
Bug in ‘Sign in with Apple’ could have allowed account hijacking

The tech giant rewards the bug bounty hunter who found the severe flaw in its login mechanism with US$100,000 The post Bug in ‘Sign in with Apple’ could have allowed account hijacking appeared first on WeLiveSecurity

3 things to discuss with your kids before they join social media

What are some of the key things your children should know about before they make their first foray into social media? The post 3 things to discuss with your kids before they join social media appeared first on WeLiveSecurity

Severe Cisco DoS Flaw Can Cripple Nexus Switches
Octopus Scanner Sinks Tentacles into GitHub Repositories
Hackers use Github bot to steal $1,200 in ETH within 100 seconds
What the NHS Test and Trace scheme could learn from banks about stopping scams

An update that solves one vulnerability and has one errata is now available.

Apple Jailbreak Zero-Day Gets a Patch
Podcast: Why Identity Access Management is the New Perimeter

An update for openshift-istio-kiali-rhel7-operator-container is now available for Openshift Service Mesh 1.0 and 1.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

8Belts exposes personal data of 100,000 e-learners globally
‘Beyond stupid’: Linus Torvalds trashes 5.8 Linux kernel patch over opt-in Intel CPU bug mitigation

Reading Time: ~ 3 min. Working from home is no longer something some of us can get away with some of the time. It’s become essential for our health and safety. So, what does the future of work look like in a post-COVID world? We asked some of our cybersecurity and tech experts for their […]

An update for jaeger, kiali, and servicemesh-grafana is now available for OpenShift Service Mesh 1.0. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 7 vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 13 vulnerabilities is now available.

Contact-tracer spoofing is already happening – and it’s dangerously simple to do
Had a bad weekend? Probably, if you’re a Sectigo customer, after root cert expires and online chaos ensues
Get rich quick! Work from home! Earn $100,000 easy – just find a critical flaw in Apple’s sign-in system
Cisco hacked: Six backend servers used by customer VIRL-PE deployments compromised via SaltStack
Remember when Republicans said Dems hacked voting systems to rig Georgia’s election? There were no hacks
Database of dark web host with 7600 websites leaked by KingNull

In httplib2, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts

Apple Pays $100K Bounty for Critical ‘Sign in With Apple’ Flaw
REvil ransomware gang publishes ‘Elexon staff’s passports’ after UK electrical middleman shrugs off attack
Minneapolis Police Department Hack Likely Fake, Says Researcher
Hosting Provider’s Database of Crooked Customers Leaked
Mobile payment app BHIM leaked financial data of 7 million Indians

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2344

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2337

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2334

Flask could be made to consume a large amount of memory if it received a specially crafted input.

Joomla suffers security breach exposing user records

An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

UK.gov dangles £400k over makers of IoT Things: Go on, let’s see how you’d make a security cert scheme
The inevitable coronavirus-inspired cyber-attacks are stepping up. Are you ready?

The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

Gollem, as used in Horde Groupware Webmail Edition and other products, had been affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting

The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

An update that solves one vulnerability and has one errata is now available.

New upstream release with bug and security fixes. Also, consolidates duplicate pakages marked and nodejs-marked. I tested upgrades from both, but may have missed some wonky situation.

New version 3.2.4, enabled build with androiddump.

Fake mobile version of Valorant game spreading malware

Two memory management issues were found in the asfdemux element of the GStreamer “ugly” plugin collection, which can be triggered via a maliciously crafted file.

Two memory handling issues were found in gst-plugins-good0.10, a collection of GStreamer plugins from the “good” set:

It was discovered that there was both an invalid memory and heap overflow vulnerability in dosfstools, a collection of utilities for making and checking MS-DOS FAT filesystems.

New AWS phishing scam steals credentials via fake AWS notification

Several vulnerabilities were discovered in package salt, a configuration management and infrastructure automation software.

New version 3.2.4, enabled build with androiddump.

An update that fixes one vulnerability is now available.

Famous video apps with 157M+ installations operating as spyware
Steganography Anchors Pinpoint Attacks on Industrial Targets
Minted confirms data breach as Shiny Hunters sell its database
People know reusing passwords is risky – then do it anyway

And most people don’t change their password even after hearing about a breach, a survey finds The post People know reusing passwords is risky – then do it anyway appeared first on WeLiveSecurity

NTT Communications Data Breach Affects Customers, Threatens Supply Chain
NSA Warns of Sandworm Backdoor Attacks on Mail Servers
OPSEC fail! “Super-hacker” accidentally outs himself through careless clues left on social media
‘Hack-For-Hire’ Firms Spoof WHO To Target Google Credentials
ACLU Sues Clearview AI Over Faceprint Collection, Sale
The Increasing Need For Application Security During COVID-19

An update that solves one vulnerability and has two fixes is now available.

Great news. Patch load drops 20% for the first time in 10 years. Bad news: Well, you’ve heard about coronavirus?

git: Crafted URL containing new lines, empty host or lacks a scheme can cause credential leak (CVE-2020-11008) SL7 x86_64 git-1.8.3.1-23.el7_8.x86_64.rpm git-daemon-1.8.3.1-23.el7_8.x86_64.rpm git-debuginfo-1.8.3.1-23.el7_8.x86_64.rpm git-gnome-keyring-1.8.3.1-23.el7_8.x86_64.rpm git-svn-1.8.3.1-23.el7_8.x86_64.rpm noarch emacs-git-1.8.3.1-23.el7_8.noarch.rpm [More…]

It’s not every day the NSA publicly warns of attacks by Kremlin hackers – so take this critical Exim flaw seriously
NTT warns its Singapore cloud was hacked, Japanese customer data compromised

## Python 3.8.3 This is the third maintenance release of Python 3.8. See [the c hangelog](https://docs.python.org/release/3.8.3/whatsnew/changelog.html#changelo g) for details. Contains the security fix for CVE-2020-8492.

Authorities arrest active dark web child abuser in Italy
Inside the Hoaxcalls Botnet: Both Success and Failure
Got $50k spare? Then you can crack SHA-1 – so OpenSSH is deprecating flawed hashing algo in a ‘near-future release’
Hackers Compromise Cisco Servers Via SaltStack Flaws

An update that fixes three vulnerabilities is now available.

Cybercrooks tend to prefer Google-branded phishing to Microsoft-flavoured lures

USN-4369-1 introduced a regression in the Linux kernel.

USN-4367-1 introduced a regression in the Linux kernel.

The Bank of America is the latest victim of a data breach
Critical Android flaw lets attackers hijack almost any app, steal data

Left unpatched, the vulnerability could expose almost all Android users to the risk of having their personal data intercepted by attackers The post Critical Android flaw lets attackers hijack almost any app, steal data appeared first on WeLiveSecurity

Google Location Tracking Lambasted in Arizona Lawsuit
Microsoft warns of PonyFinal ransomware attacks
PonyFinal Ransomware Targets Enterprise Servers Then Bides Its Time

Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine.

You, Apple Mac fan. Put down the homemade oat-milk latte, you need to patch a load of security bugs, too
NetWalker ransomware – what you need to know
Alleged data of 47.5 million Truecaller Indian users sold online
Valak Loader Revamped to Rob Microsoft Exchange Servers

An update for freerdp is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for freerdp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Various minor vulnerabilities have been addredd in libexif, a library to parse EXIF metadata files.