Menu

Category Archives: Security

Articles about security

Beware scams exploiting coronavirus fears

From malware-laden emails to fake donations, these are some of the most common cons you should watch out for amid the public health crisis The post Beware scams exploiting coronavirus fears appeared first on WeLiveSecurity

Working from Home: COVID-19’s Constellation of Security Challenges
Coronavirus Tracking App is ransomware; locks phones for ransom
WordPress Plugin Bug in Popup Builder Threatens 100K Websites
Your data was ‘taken without permission’, customers told, after personal info accessed in O2 UK partner’s database
Hey, friends. We know it’s a crazy time for the economy, but don’t forget to enable 2FA for payments by Saturday
Coronavirus-Themed APT Attack Spreads Malware
Europol nabs SIM hacking network from across Europe
ACLU Sues Over U.S. Airport Facial-Recognition Technology

Reading Time: ~ 2 min. Paradise Ransomware Spreading Through Unusual Attachments While Paradise ransomware isn’t new to the scene, the latest methods it’s using to spread are a bit surprising. Though it sticks to using email for transmission, it now offers up an IQY attachment instead of a typical word document or excel spreadsheet. These […]

Reviewing vulnerabilities in 2019: The annual Red Hat Product Security Risk Report
Open-source bug bonanza: Vulnerabilities up almost 50 per cent thanks to people actually looking for them
Avast pulls plug on insecure JavaScript engine in its security software suite
Fresh virus misery for Illinois: Public health agency taken down by… web ransomware. Great timing, scumbags
Researchers Warn of Novel PXJ Ransomware Strain
Trojan Raids Android Users’ Cookie Jars

security update

Thought you were done after Tuesday’s 115-fix day? Not yet: Microsoft emits SMBv3 worm-cure crisis patch
Hackers using fake live Coronavirus map to spread malware
US Congress: Spying law is flawed, open to abuse, and lacking in accountability – so let’s reauthorize it
Phishing attacks exploit YouTube redirects to catch the unwary
European power grid organization hit by cyberattack

The incident affected our office network, says ENTSO-E, as it implements measures to avoid future cyber-incursions The post European power grid organization hit by cyberattack appeared first on WeLiveSecurity

Microsoft takes down largest botnet network “Necurs”
$100K Paid Out for Google Cloud Shell Root Compromise
Akamai Talks Massive Uptick in Credential-Stuffing Attacks Against Bank APIs
Laying a foundation for more secure computing: Red Hat Enterprise Linux and Common Criteria
Tracking Turla: New backdoor delivered via Armenian watering holes

Can an old APT learn new tricks? Turla’s TTPs are largely unchanged, but the group recently added a Python backdoor. The post Tracking Turla: New backdoor delivered via Armenian watering holes appeared first on WeLiveSecurity

Russia-backed crew’s latest malware has discerning taste – when screening visitors to poisoned watering holes

Reading Time: ~ 3 min. The last thing you want to do when you get a new computer, mobile device, or tablet is spend a lot of time setting it up. But like any major appliance, these devices are something you want to invest a little time setting up properly. Often, they’re not cheap. And […]

Microsoft nukes 9 million-strong Necurs botnet after unpicking domain name-generating algorithm
Flaws Riddle Zyxel’s Network Management Software

security update

Phishing Attack Skirts Detection With YouTube
Meltdown The Sequel strikes Intel chips – and full mitigation against data-meddling LVI flaw will slash performance
Wormable, Unpatched Microsoft Bug Threatens Corporate LANs
Find out how to manage detection and response for better cyber security
Friend’s girlfriend sextortion scam infects PCs with Raccoon malware
New TrickBot Variant Updates Anti-Analysis Tricks
More Than Half of IoT Devices Vulnerable to Severe Attacks
Secret-sharing app Whisper shared secrets like last known location and actual password tokens in exposed database
Necurs Botnet in Crosshairs of Global Takedown Offensive
How to Tell if a Website Has Been Compromised
Securing the deployment of OpenShift Container Platform 4
The Reg produces exhibit A1: A UK court IT system running Windows XP
Google: You know we said that Chrome tracker contained no personally identifiable info? Forget we ever said that
Stuck at home? Need something to keep busy with? Microsoft has 115 ideas – including an awful SMBv3 security hole to worry about
That LVI CPU hole wasn’t the only Intel fix: Dozens of flaws patched to stop chips turning into potatoes
Critical Bugs in Rockwell, Johnson Controls ICS Gear
Microsoft Patches 26 Critical Bugs in Big March Update

security update

California tech industry gets its first big coronavirus hit: RSA Conference attendee infected, in serious condition
Popular ThemeREX WordPress Plugin Opens Websites to RCE
Firefox Bug Opens iPhone AirPods to Third-Party Snooping
High-Severity Flaws Plague Intel Graphics Drivers
You only LVI twice: Meltdown The Sequel strikes Intel chips – and full mitigation against data-meddling flaw will cost you 50%+ of performance
Hackers hit hackers in new malware campaign
Flaw in popular VPN service may have exposed customer data

NordVPN praised its bug bounty program and said that a fix had been shipped within two days The post Flaw in popular VPN service may have exposed customer data appeared first on WeLiveSecurity

Variant of Paradise Ransomware Targets Office IQY Files
7 Cybersecurity Trends to Look Out for in 2020
Android anti-virus products put to the test – which are the best at stopping new malicious apps?
Spear-Phishing Attack Lures Victims With ‘HIV Results’
Avast’s AntiTrack promised to protect your privacy. Instead, it opened you to miscreant-in-the-middle snooping
AMD, boffins clash over chip data-leak claims: New side-channel holes in decades of cores, CPU maker disagrees
Hackers are exploiting critical vulnerability in Microsoft Exchange server
NSO Group fires back at Facebook: You lied to the court, claims spyware slinger, and we’ve got the proof
Microsoft: 99.9 percent of hacked accounts didn’t use MFA

Only 11 percent of all enterprise accounts have multi-factor authentication enabled The post Microsoft: 99.9 percent of hacked accounts didn’t use MFA appeared first on WeLiveSecurity

Microsoft Exchange Server Flaw Exploited in APT Attacks
Months-long trial of alleged CIA Vault 7 exploit leaker ends with hung jury: Ex-sysadmin guilty of contempt, lying to FBI
Dark Web search engine Kilos lets users find hidden marketplaces
Comcast Xfinity published the contact details of 200,000 customers who paid for them to be kept private
UK Defence Committee probe into national security threat of Huawei sure to uncover lots of new and original insights
AMD Downplays CPU Threat Opening Chips to Data Leak Attacks
Coronavirus map used to spread malware
Spyware maker NSO runs scared from Facebook over WhatsApp hacking charges, fails to show up in court
UK.gov is not sharing Brits’ medical data among different agencies… but it’s having a jolly good think about it
Check Point chap: Small firms don’t invest in infosec then hope they won’t get hacked. Spoiler alert: They get hacked
Virgin Media & T-Mobile data breach exposes customers data

An update that fixes one vulnerability is now available.

Don’t be fooled, experts warn, America’s anti-child-abuse EARN IT Act could burn encryption to the ground
Next-Gen Ransomware Packs a ‘Human’ Punch, Microsoft Warns
FYI: When Virgin Media said it leaked ‘limited contact info’, it meant p0rno filter requests, IP addresses, IMEIs as well as names, addresses and more
2 in 5 Android devices found vulnerable worldwide – That’s over a billion
UK spy auditor gives state snoops a big pat on the back for job well done – except MI5
Spread of Coronavirus-Themed Cyberattacks Persists with New Attacks
Critical Zoho Zero-Day Flaw Disclosed
Virgin Media left 900,000 consumers’ details exposed in unsecured database
201 million US demographic, personal records leaked online
Over one billion Android devices at risk as they no longer receive security updates
NordVPN quietly plugged vuln where an HTTP POST request without authentication would return detailed customer data

sudo: Stack based buffer overflow when pwfeedback is enabled (CVE-2019-18634) SL6 x86_64 sudo-1.8.6p3-29.el6_10.3.x86_64.rpm sudo-debuginfo-1.8.6p3-29.el6_10.3.x86_64.rpm sudo-debuginfo-1.8.6p3-29.el6_10.3.i686.rpm sudo-devel-1.8.6p3-29.el6_10.3.i686.rpm sudo-devel-1.8.6p3-29.el6_10.3.x86_64.rpm i386 sudo-1.8.6p3-29.el6_10.3.i686.rpm sudo-debuginfo-1.8.6p3-29.e [More…]

The updated package fixes a security vulnerability: A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning. (CVE-2019-20479)

Updated pure-ftpd packages fix security vulnerabilities: An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called,

The updated packages fix several issues including security vulnerabilities: In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. (CVE-2019-19221)

Updated dojo package fixes security vulnerability: dojox was vulnerable to Cross-site Scripting. This was due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them (CVE-2019-10785).

The updated packages fix a security vulnerability: Mutation XSS in bleach.clean when noscript and raw tag whitelisted. (CVE-2020-6802)

Boots suspends loyalty card payments after hackers try to compromise accounts
More than a billion hopelessly vulnerable Android gizmos in the wild that no longer receive security updates – research
Like a Virgin, hacked for the very first time… UK broadband ISP spills 900,000 punters’ records into wrong hands from insecure database
Android users, if you could pause your COVID-19 panic buying for one minute to install these critical security fixes, that would be great
Man hacks Indian tech support scam call center; leaks CCTV footage