Menu

Category Archives: Security

Articles about security

Update to 4.9.0

REvil hackers leaks email conversation on Trump amid ransom demand

Update to latest upstream 8.8.8

Are you ready, kids? I said, are you ready? Whoooooo has another update for you to see? Google Chromium! For browsing and tweeting (but not FTP) Google Chromium! If improved security be something you wish Google Chromium! Then run dnf while you flop like a fish! Google Chromium! Google Chromium! Google Chromium! Google Chromium! Ahem. […]

Authorities bust hacker group planning to hit hospitals with ransomware
Flaws in cyber security firm’s firewall & VPN tech exposed 100k+ devices

It was discovered that exim4, a mail transport agent, suffers from a authentication bypass vulnerability in the spa authentication driver. The spa authentication driver is not enabled by default.

Cybercrime marketplace MagBo selling access to 43,000 hacked websites

OpenConnect, a VPN software, had a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.

Version update + security fix

security update

security update

Version update + security fix

Update to OpenEXR-2.4.1, see https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.4.1 for details.

Update to OpenEXR-2.4.1, see https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.4.1 for details.

Hoaxcalls Botnet Exploits Symantec Secure Web Gateways
Mandrake Android malware stealing Facebook, crypto data since 2016
News Wrap: Ransomware Extortion Tactics, Contact-Tracing App Security Worries
Zero-day attacks are potent cyber threats that require serious response
Mikroceen: Spying backdoor leveraged in high‑profile networks in Central Asia

ESET researchers dissect a backdoor deployed in attacks against multiple government agencies and major organizations operating in two critical infrastructure sectors in Asia The post Mikroceen: Spying backdoor leveraged in high‑profile networks in Central Asia appeared first on WeLiveSecurity

Pay $42m or Trump’s ‘dirty laundry’ goes online – REvil ransomware hackers
Cyber attack against UK power grid middleman Elexon sparks in-house IT recovery efforts
RATicate Group Hits Industrial Firms With Revolving Payloads
An outbreak of Coronavirus trojans and scams
You can’t have it both ways: Anti-coronavirus masks may thwart our creepy face-recog cameras, London cops admit

Updated libreswan packages fix security vulnerability: An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan. An unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange

Updated suricata packages fix security vulnerabilities: The suricata package has been updated to version 4.1.8, which fixes security issues and other bugs. See the upstream announcements for details.

Updated jbig2dec packages fix security vulnerability: jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow (CVE-2020-12268).

The updated packages fix security vulnerabilities including: ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled

Updated netkit-telnetd packages fix security vulnerability: A vulnerability was found where incorrect bounds checks in the telnet server’s (telnetd) handling of short writes and urgent data, could lead to information disclosure and corruption of heap data. An unauthenticated

8 best dark web search engines for 2020
Paying Ransomware Crooks Doubles Clean-up Costs, Report
Security flaws mitigated by compiler optimizations

An update that fixes one vulnerability is now available.

Vint Cerf suggests GDPR could hurt coronavirus vaccine development
Brit defense contractor hacked, up to 100,000 past and present employees’ details siphoned off – report
Innovative Spy Trojan Targets European Diplomatic Targets

security update

TikTok Violated Children’s Privacy Law, FTC Complaint Says
Stolen database trading site WeLeakData hacked; data leaked
Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks

ESET researchers uncover several instances of malware that uses various attack vectors to target systems isolated by an air gap The post Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks appeared first on WeLiveSecurity

Microsoft Adds DNS-Over-HTTPS Support for Windows 10 Insiders
The most-targeted security vulnerabilities – despite patches having been available for years

An update that solves two vulnerabilities and has four fixes is now available.

An update that fixes one vulnerability is now available.

Utah Says No to Apple/Google COVID-19 Tracing; Debuts Startup App
New malware Ramsay can steal data from air-gapped computers
BEC Gang Exploits G Suite, Long Domain Names in Cyberattacks
Login with Facebook Bug Earns $20K Bounty
Multi-part Android spyware lurked on Google Play Store for 4 years, posing as a bunch of legit-looking apps
Google Firebase misconfiguration exposes data of 20k+ Android users
Understanding the DTLS all-zero ClientHello.random vulnerability

An update that solves 35 vulnerabilities and has 21 fixes is now available.

‘iOS security is f**ked’ says exploit broker Zerodium: Prices crash for taking a bite out of Apple’s core tech

NOTE: This DLA was intially sent on 2020-04-14 but for reasons unknown failed to reach the mailing list. It is being re-sent now to ensure that it appears in the mailing list archive. No new version of

An update that fixes one vulnerability is now available.

An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5, 6, and 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

There’s Norway you’re going to believe this: Government investment fund conned out of $10m in cyber-attack
US-CERT lists the 10 most-exploited security bugs and, yeah, it’s mostly Microsoft holes people forgot to patch
Aussie money-manager MyBudget goes down for five days

security update

Smashing Security #178: Office pranks, meat dresses, and robocop dogs
Now there’s nothing stopping the PATRIOT Act allowing the FBI to slurp web-browsing histories without a warrant
Senator Wyden demands deep probe into spyware after hacking toolkit offered to American cops by NSO Group
Texas Courts Won’t Pay Up in Ransomware Attack
Leaked NHS Docs Reveal Roadmap, Concerns Around Contact-Tracing App
Stop tracking me, Google: Austrian citizen files GDPR legal complaint over Android Advertising ID
WannaCryptor remains a global threat three years on

WannaCryptor is still alive and kicking, so much so that it sits atop the list of the most commonly detected ransomware families The post WannaCryptor remains a global threat three years on appeared first on WeLiveSecurity

Lukas Stefanko: How we fought off a DDoS attack from a mobile botnet

Hot on the heels of his research into an attack that attempted to take down ESET’s website, Lukas Stefanko sheds more light on threats posed by mobile botnets The post Lukas Stefanko: How we fought off a DDoS attack from a mobile botnet appeared first on WeLiveSecurity

Ramsay Malware Targets Air-Gapped Networks
Healthcare Giant Magellan Struck with Ransomware, Data Breach
Danger zone! Brit research supercomputer ARCHER’s login nodes exploited in cyber-attack, admins reset passwords and SSH keys
Feds Reveal Hidden Cobra’s Trove of Espionage Tools
Info on NHS Coronavirus app leaks out via Google Drive snafu

Reading Time: ~ 3 min. If you’ve been working in the technology space for any length of time, you’ve undoubtedly heard about the rising importance of artificial intelligence (AI) and machine learning (ML). But what can these tools really do for you? More specifically, what kinds of benefits do they offer for cybersecurity and business […]

An update for .NET Core is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that solves one vulnerability and has one errata is now available.

How SELinux separates containers using Multi-Level Security

Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category may cause kernel panic (CVE-2020-10711) SL6 x86_64 kernel-2.6.32-754.29.2.el6.x86_64.rpm kernel-debug-2.6.32-754.29.2.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-754.29.2.el6.i686.rpm kernel-debug-debuginfo-2.6.32-754.29.2.el6.x86_64.rpm kernel-debug-devel-2.6.32-754.29.2.el6.i686 [More…]

USN-3911-1 introduced a regression in file.

Several security issues were fixed in Squid.

IPRoute could be made to execute arbitrary code if it received a specially crafted input.

Sadly, 111 in this story isn’t binary. It’s decimal. It’s the number of security fixes emitted by Microsoft this week
Thunderbolt flaws open millions of PCs to physical hacking

A new attack method enables bad actors to access data on a locked computer via an evil maid attack within 5 minutes The post Thunderbolt flaws open millions of PCs to physical hacking appeared first on WeLiveSecurity

REvil Ransomware Attack Hits A-List Celeb Law Firm
Microsoft Addresses 111 Bugs for May Patch Tuesday

Reading Time: ~ 2 min. Adult Website Leaks Trove of Sensitive Data An recently discovered unsecured database belonging to the adult streaming site Cam4 was found to contain nearly 11 billion unique records amounting to seven terabytes of data. For a site with billions of visitors each year, the exposed data could affect millions who […]

Researchers spot thousands of Android apps leaking user data through misconfigured Firebase databases
Over 160 million user records put up for sale on the dark web

Eleven companies, ranging from online marketplaces to news websites, have had their user databases poached The post Over 160 million user records put up for sale on the dark web appeared first on WeLiveSecurity

Breaking news? App promises news feeds, brings DDoS attacks instead

After being targeted by an Android DDoS app, ESET seized the opportunity to analyze the attack and to help put an end to it The post Breaking news? App promises news feeds, brings DDoS attacks instead appeared first on WeLiveSecurity

WordPress Page Builder Plugin Bugs Threaten 1 Million Sites with Full Takeover
Adobe Kills 16 Critical Flaws in Acrobat and Reader, Digital Negative SDK
Chatbooks Confirms Breach After ‘Shiny Hunters’ Sell Data
Anubis Malware Upgrade Logs When Victims Look at Their Screens

An update that solves 53 vulnerabilities and has 32 fixes is now available.

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

An update for libreswan is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

India releases data-use protocols for its contact-tracing app… after five weeks and 100 million downloads

An update for libreswan is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,