Menu

Category Archives: Security

Articles about security

New nasty Android EventBot malware infects devices by evading 2FA
ESET Threat Report

A view of the Q1 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report appeared first on WeLiveSecurity

Cybercriminals are using Google reCAPTCHA to hide their phishing attacks
New Android Malware Targets PayPal, CapitalOne App Users
Nursery school teacher arrested for years-long dark web child abuse

It was discovered that there was a integer signedness error in the miniupnpc UPnP client that could allow remote attackers to cause a denial of service attack.

An issue has been found in pound, A request smuggling vulnerability was discovered in pound, a everse proxy, load balancer and HTTPS front-end for Web servers, that may allow

Two issues have been found in w3m, WWW browsable pager with excellent tables/frames support.

An issue has been found in yodl, a pre-document language. Hanno Bock discovered that there was a buffer over-read vulnerability.

Newly-discovered Android malware steals banking passwords and 2FA codes
Shade Threat Actors Call It Quits, Release 750K Encryption Keys
Salt peppered with holes? Automation tool vulnerable to auth bypass: Patch now

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Critical WordPress e-Learning Plugin Bugs Open Door to Cheating
In trying times like these, it’s reassuring to know you can still get pwned five different ways by Adobe Illustrator files
Smashing Security #176: Hacking hacks and university attacks
High-Severity Cisco IOS XE Flaw Threatens SD-WAN Routers
Millions of Brute-Force Attacks Hit Remote Desktop Accounts
Android users worldwide hit by sophisticated Google Play malware
Grandoreiro: How engorged can an EXE get?

Another in our occasional series demystifying Latin American banking trojans The post Grandoreiro: How engorged can an EXE get? appeared first on WeLiveSecurity

ThreatList: Human-Mimicking Bots Spike, Targeting e-Commerce and Travel
Critical GitLab Flaw Earns Bounty Hunter $20K
Shade ransomware calls it a day, 750,000 decryption keys released

An update that solves 7 vulnerabilities and has 77 fixes is now available.

An update that solves 7 vulnerabilities and has 77 fixes is now available.

An update that solves 13 vulnerabilities and has 157 fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves 6 vulnerabilities and has 8 fixes is now available.

Academics demand answers from NHS over potential data timebomb ticking inside new UK contact-tracing app

An update that solves 13 vulnerabilities and has 157 fixes is now available.

EFF: Google, Apple’s Contact-Tracing System Open to Cyberattacks
ProtonMail-run website boasting ‘complete guide’ to GDPR left credential-baring .git repo exposed online
San Francisco trial of Russian bloke extradited and accused of hacking LinkedIn, Dropbox, Formspring stalls again amid pandemic lockdown
Enterprise Security Woes Explode with Home Networks in the Mix
Best legal & free online streaming sites for movies & TV shows 2020
‘Black Rose Lucy’ is Back, Now Pushing Ransomware

security update

Critical Adobe Illustrator, Bridge and Magento Flaws Patched

Reading Time: ~ 3 min. A popular military maxim speaks to the need for redundancy and it goes like this: “Two is one and one is none.” Redundancy is also a key principle when it comes to cyber-resilience. A popular rule in data protection and disaster recovery is called the 3-2-1 backup rule. IT pros […]

Hackers Leak Biopharmaceutical Firm’s Data Stolen in Ransomware Attack
WordPress Plugin Bug Opens 100K Websites to Compromise
Sophisticated Android Spyware Attack Spreads via Google Play
Ransomware hackers leak pharmaceutical giant’s data on dark web
Vulnerability allowed hijacking of Microsoft Teams account with a GIF
Nine million logs of Brits’ road journeys spill onto the internet from password-less number-plate camera dashboard
Troves of Zoom Credentials Shared on Hacker Forums

re2c could be made to execute arbitrary code if it received a specially crafted file.

An update that solves 15 vulnerabilities and has 8 fixes is now available.

An update that solves 10 vulnerabilities and has 89 fixes is now available.

An update that solves 5 vulnerabilities and has 7 fixes is now available.

An update that fixes one vulnerability is now available.

We’re going on a vuln hunt. We’re going catch a big one: Researchers find Windows bugs dominate – but fixes are fast

An update that fixes three vulnerabilities is now available.

UK snubs Apple-Google coronavirus app API, insists on British control of data, promises to protect privacy
How Web Application Firewall (WAF) protects your website
Australian contact-tracing app leaks telling info and increases chances of third-party tracking, say security folks
GDPR Compliance Site Leaks Git Data, Passwords

security update

A GIF image could have let hackers hijack Microsoft Teams at your firm
Microsoft Teams flaw could let attackers hijack accounts

Microsoft plugs a security hole that could have enabled attackers to weaponize a GIF in order to hijack Teams accounts and steal data The post Microsoft Teams flaw could let attackers hijack accounts appeared first on WeLiveSecurity

Hackers Mount Zero-Day Attacks on Sophos Firewalls
U.S. Universities Hit With ‘Adult Dating’ Spear-Phishing Attack
Eight Common OT / Industrial Firewall Mistakes
Chinese COVID-19 detection firm hacked; source code sold on dark web

An update that solves 11 vulnerabilities and has 96 fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves 12 vulnerabilities and has 139 fixes is now available.

Don’t vote for me and Smashing Security in the EU Security awards

Several security issues were fixed in OpenEXR.

We could have pwned Microsoft Teams with a GIF, claims Israeli infosec outfit
Apple and Google tweak key bits of contact-tracing privacy plan
Single Malicious GIF Opened Microsoft Teams to Nasty Attack
Rabobank security cert expires and gives its Australian Android app a case of internet-blindness

Update to latest upstream OpenVPN 2.4.9 release. It contains a security fix for CVE-2020-11810. This security issue is quite hard to abuse, requiring a fairly precise timing attack combined with guessing a just assigned peer-id reference. If successful, only a single client just initiating a new connection will experience a denial of service situation. This […]

6.2.6

Australia’s contact-tracing app regulation avoids ‘woolly’ principles in comparable cyber-laws, say lawyers
Exclusive: Scammers using fake WHO Bitcoin wallet to steal donation

Three issues have been found in php5, a server-side, HTML-embedded scripting language.

Sophos XG firewalls hacked, hotfix ready. Texts wreck Apple iThings. Yup, business as usual in infosec world
Hackers’ malicious script skimmed credit card details off Robert Dyas website

Hanno Boeck discovered that it was possible to create a cross site scripting attack on the webarchives of the Mailman mailing list manager, by sending a special type of attachement.

Called to an urgent Zoom meeting with HR? It might be a phishing attack

Update to WebKitGTK 2.28.1: * Fix position of default option element popup windows under Wayland. * Fix rendering after a cross site navigation with PSON enabled and hardware acceleration forced. * Fix a crash in nested wayland compositor when closing a tab with PSON enabled. * Update Chrome and Firefox versions in user agent quirks. […]

Security fix for CVE-2020-5260 From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.5.txt): > With a crafted URL that contains a newline or empty host, or lacks > a scheme, the credential helper machinery can be fooled into > providing credential information that is not appropriate for the > protocol in use and host being

Update to WebKitGTK 2.28.1: * Fix position of default option element popup windows under Wayland. * Update Chrome and Firefox versions in user agent quirks. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-11793

Update to version 1.26. Resolves CVE-2017-18640.

Dark web hackers selling 400,000 South Korean & US payment card data

security update

Hackers deface church service on Zoom with child abuse content
VictoryGate cryptominer infected 35,000 devices via USB drives
Open Source Intelligence, Security Hacking, and Security Blogger Dancho Danchev>

It was discovered that python-reportlab, a Python library to create PDF documents, is prone to a code injection vulnerability while parsing a color attribute. An attacker can take advantage of this flaw to execute arbitrary code if a specially crafted document is processed.

security update

This update fixes the following security vulnerabilities: CVE-2018-20536, CVE-2018-20537, CVE-2018-20539, CVE-2018-20540

**PHP version 7.3.17** (16 Apr 2020) **Core:** * Fixed bug php#79364 (When copy empty array, next key is unspecified). (cmb) * Fixed bug php#78210 (Invalid pointer address). (cmb, Nikita) **CURL:** * Fixed bug php#79199 (curl_copy_handle() memory leak). (cmb) **Date:** * Fixed bug php#79396 (DateTime hour incorrect during DST jump forward). (Nate Brunette) **Iconv:**

3.2.3 —- New version 3.2.2 Security fix for CVE-2020-7044, CVE-2020-9428, CVE-2020-9430, CVE-2020-9431

Fix mistakes in Wayland wrapper change —- Fixes Wayland issue when running from terminal —- Update sound touch library, fixes some known security issues.

Security fix for CVE-2015-9541

Spyware maker NSO can’t claim immunity, Facebook lawyers insist – it’s time to face the music