Menu

Category Archives: Security

Articles about security

RansomEXX trojan variant is being deployed against Linux systems, warns Kaspersky
Microsoft Exchange Attack Exposes New xHunt Backdoors
Somebody’s Russian to meddle with UK coronavirus vaccine efforts, but GCHQ won’t take it lying down
Millions of Hotel Guests Worldwide Caught Up in Mass Data Leak
Campari staggers to its feet following $15 million Ragnar Locker ransomware attack

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

It was discovered that Docker could be made to expose sensitive information when processing URLs in container image manifests. A remote attacker could use this to trick the user and obtain the user’s registry credentials (CVE-2020-15157).

An update that solves 18 vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has 35 fixes is now available.

Chinese hacking competition cracks Chrome, ESXi, Windows 10, iOS 14, Galaxy 20, Qemu, and more
Hackers work 24 hours a day – when will you schedule your security training?

SFD_GetFontMetaData() insufficient CVE-2020-5395 backport. (CVE-2020-25690) References: – https://bugs.mageia.org/show_bug.cgi?id=27563 – https://access.redhat.com/errata/RHSA-2020:4844

The latest release of mariadb fixes some undisclosed easily exploitable vulnerabilities. (CVE-2020-14765, CVE-2020-14776, CVE-2020-14789 and CVE-2020-14812). Additionally some bugs are fixed:

It was discovered that junit contained a local information disclosure vulnerability. On Unix like systems, the system’s temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users on that same system. This vulnerability does not […]

Vaisha Bernard discovered that blueman did not properly sanitize input on the D-Bus interface to blueman-mechanism. A local attacker could possibly use this issue to escalate privileges and run arbitrary code or cause a denial of service (CVE-2020-15238).

The suricata package has been updated to version 4.1.9, which fixes security issues and other bugs. See the upstream announcements for details. References: – https://bugs.mageia.org/show_bug.cgi?id=27475

An XSS Vulnerability exists in Webmin 1.941 and earlier affecting the Cluster Shell Commands Endpoint. A user may enter any XSS Payload into the Command field and execute it. Then, after revisiting the Cluster Shell Commands Menu, the XSS Payload will be rendered and executed. (CVE-2020-8820)

security update

In libexif/exif-entry.c, through libexif 0.6.21-2+deb9u4, compiler optimization could remove a buffer overflow check, making a buffer overflow possible with some EXIF tags.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that solves three vulnerabilities and has 7 fixes is now available.

It was discovered that raptor2, an RDF parser library, is prone to heap-based buffer overflow flaws, which could result in denial of service, or potentially the execution of arbitrary code, if a specially crafted file is processed.

security update

Let’s Encrypt warns about a third of Android devices will from next year stumble over sites that use its certs
WordPress Sites Open to Code Injection Attacks via Welcart e-Commerce Bug
Feds Seize $1B in Bitcoin from Silk Road
Campari Site Suffers Ransomware Hangover
Gitpaste-12 Worm Targets Linux Servers, IoT Devices
Ransomware crims read our bank balance and demanded the lot, reveals Scotland’s Dundee and Angus College
Gaming company Capcom hit by cyberattack

The developer of popular video game franchises took swift action to prevent the attack from spreading further across its systems The post Gaming company Capcom hit by cyberattack appeared first on WeLiveSecurity

Business VOIP phone systems are being hacked for profit worldwide. Is yours secure?
Sodinokibi/REvil ransomware gang pwns British housing biz via suspected phishing attack

Reading Time: ~ 2 min. Maze Ransomware Group Ends Operations A press release issued this week announced the end of the Maze ransomware group’s data theft operations. In the release, the Maze authors revealed their motives behind one of the most successful ransomware campaigns to date, and why they chose to finally shut down their […]

Apple Patches Bugs Tied to Previously Identified Zero-Days
Snap-crappy: 183 Brit local authorities operate 80,000 CCTV cams between them, says surveillance watchdog

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to run insecure deserialization, embed spam, perform various Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) attacks, escalate privileges, run arbitrary

netqmail could be made to crash if it received specially crafted input.

Ransomware attack shutters Brazilian courts. But did attackers breach the virtual machine divide?
Tech support scammer dialed random number and Australian Police’s cybercrime squad answered
Apple emits iOS, iPadOS, watchOS, macOS patches to fix three hijack-my-device flaws exploited in the wild
Gaming Giant Capcom Hit By Ragnar Locker Ransomware: Report
Zoom Snooping: How Body Language Can Spill Your Password

Update to CVE release 3001.3-1 for Python3 Includes fixes for CVE-2020-16846, CVE-2020-17490, CVE-2020-25592

Fix executable hardening (PIC/PIE)

Update to v2.1.4. Contains security fix for CVE-2020-15238.

Update to Chromium 86. A few big things here: 1. Upstream has made hardware accelerated video support (VAAPI) for Linux possible without patches. One key difference is that the patchset used previously in Fedora enabled it by default and upstream’s approach disables it by default. To enable Hardware accelerated video in chromium, open this link […]

Following Ubisoft cyber attack, hackers claim to leak Watch Dogs: Legion code online
After Cummings’ Barnard Castle trip, cheeky Britons started using the word ‘vision’ in their passwords
Cisco Zero-Day in AnyConnect Secure Mobility Client Remains Unpatched

An update that fixes 5 vulnerabilities is now available.

An update that solves three vulnerabilities and has 6 fixes is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Malspam Campaign Milks Election Uncertainty
Data protection scofflaws failed to pay £2m in fines from UK watchdog – and 68% of penalties are still outstanding
Capcom hacked. Resident Evil game developer discloses cyber attack
USBGuard improvements in Red Hat Enterprise Linux 8.3
Smashing Security podcast #203: Testing times, naming names, and the bald truth about AI
Deloitte’s ‘Test your Hacker IQ’ site fails itself after exposing database user name, password in config file
No, GitHub’s source code wasn’t hacked and posted on GitHub, says GitHub CEO
Proofpoint survey: IT security leaders worry about and are ill-prepared to defeat cyber-attacks
Criticalstudies.org sounds pretty important, right? Wrong: USA says it’s an Iranian fake news front

Reading Time: ~ 2 min. Adobe Flash Being Uninstalled on Windows Systems Following its September announcement, Microsoft has released an update that removes Adobe Flash from Windows 10 systems and prevents reinstallation. It should be noted that this update only removes the version of Adobe Flash that comes bundled with Windows 10. Internet browser extensions […]

Revamped DLL side-load attack hits Myanmar

security update

Feds throw book at eBay execs who deny they had anything to do with cyberstalking of site’s critics
Mysterious APT Leaves Curious ‘KilllSomeOne’ Clue
GrowDiaries Exposes Emails, Passwords of 1.4M Cannabis Growers
Google Forms Abused to Phish AT&T Credentials
You can be a security intelligence expert, with these free tools from Recorded Future
If you’re an update laggard, buck up: Chrome zero-days are being exploited in the wild
A career in cybersecurity: Is it for you?

There’s no shortage of opportunities for cybersecurity professionals and people looking to break into this field of endeavor. Could this also be the right career path for you? The post A career in cybersecurity: Is it for you? appeared first on WeLiveSecurity

Toymaker Mattel Hit by Ransomware Attack
VMware Issues Updated Fix For Critical ESXi Flaw
Code42 Incydr Series: Why Most Companies Can’t Stop Departing Employee Data Theft
Police to Livestream Ring Camera Footage of Mississippi Residents

An update that solves three vulnerabilities and has 6 fixes is now available.

WireGuard Brings Speed and Simplicity to VPN Technology>

Reading Time: ~ 3 min. Mobile devices have become an indispensable part of our lives. By the time we’re teenagers, we’re already tethered to technology that lives in our pockets and connects us to a network far larger than we ever imagined possible. Because of the way we interact with our phones, it knows our […]

An update for xorg-x11-server is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Using OPA for cloud-native app authorization
IBM adds code risk analyzer to cloud-based CI/CD

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes two vulnerabilities is now available.

An update that fixes 16 vulnerabilities is now available.

Was that November’s Patch Tuesday? Already? Oh, no, it’s just Adobe issuing 14 emergency security fixes
Automation software slinger SaltStack warns of stop-watching-the-election-and-patch-now bugs
Oracle Solaris Zero-Day Attack Revealed
APT Groups Finding Success with Mix of Old and New Tools
34M Records from 17 Companies Up for Sale in Cybercrime Forum
The death of the email attack ‘campaign’
Two Chrome Browser Updates Plug Holes Actively Targeted by Exploits
None of our apps (except those 3) could secretly slurp Facebook user details, devs rage to High Court of England and Wales