Menu

Category Archives: Security

Articles about security

An update that solves 5 vulnerabilities and has 22 fixes is now available.

If a Cyber Security Report Falls in a Forest, Is Anyone Listening?
What You Need to Know About Linux Rootkits [Updated]>

It was discovered that there was an out-of-bounds access vulnerability in the server-server protocol in the ngircd Internet Relay Chat (IRC) server.

Updated gnutls packages fix security vulnerability: It was found that GnuTLS 3.6.4 introduced a regression in the TLS protocol implementation. This caused the TLS server to not securely construct a session ticket encryption key considering the application

security update

Damian Poddebniak and Fabian Ising discovered two security issues in the STARTTLS handling of the Mutt mail client, which could enable MITM attacks.

IT guy from FEMA hacked medical center, sold data on dark web
Hey NYPD, when you’re done tear-gassing and running over protesters, can you tell us about your spy gear?
Former DIA Analyst Sentenced to Prison Over Data Leak

security update

Australia’s Lion brewery hit by second cyber attack as nation staggers under suspected Chinese digital assault
Digging up InvisiMole’s hidden arsenal

ESET researchers reveal the modus operandi of the elusive InvisiMole group, including newly discovered ties with the Gamaredon group The post Digging up InvisiMole’s hidden arsenal appeared first on WeLiveSecurity

News Wrap: Malicious Chrome Extensions Removed, CIA ‘Woefully Lax’ Security Policies Bashed
70 malicious Chrome extensions found spying on 32 million+ users

Two vulnerabilities were found in Ruby on Rails, a MVC ruby-based framework geared for web application development, which could lead to remote code execution and untrusted user input usage, depending on the

Woman who deliberately deleted firm’s Dropbox is sentenced
Netgear Zero-Day Allows Full Takeover of Dozens of Router Models

An update for jaeger-all-in-one-rhel7-container, jaeger-collector-rhel7-container, and jaeger-ingester-rhel7-container is now available for Jaeger-1.17. Red Hat Product Security has rated this update as having a security impact

An update that solves 5 vulnerabilities and has 22 fixes is now available.

An update that solves 5 vulnerabilities and has 22 fixes is now available.

An update that fixes one vulnerability is now available.

Reading Time: ~ 2 min. Ransomware Knocks Out Knoxville, TN Knoxville, Tennessee officials have been working over the past week to secure systems and determine if any sensitive information was stolen after a ransomware attack was identified. Fortunately, city IT staff were able to quickly implement security protocols and shut down critical systems before the […]

Aussie surfer’s hacked Instagram sent sexually explicit images to her 40,000 followers
Mozilla VPN – Firefox private network VPN is finally arriving

Mozilla: Security downgrade with IMAP STARTTLS leads to information leakage (CVE-2020-12398) * Mozilla: Use-after-free in SharedWorkerService (CVE-2020-12405) * Mozilla: JavaScript Type confusion with NativeTypes (CVE-2020-12406) * Mozilla: Memory safety bugs fixed in Firefox 77 and Firefox ESR 68.9 (CVE-2020-12410) SL6 x86_64 thunderbird-68.9.0-1.el6_10.x86_64.rpm thunderbird-de [More…]

At Mozilla VPN stands for Vague Product News: Foundation reveals security product will launch eventually, with temporary pricing, in unspecified places
Australian PM says nation under serious state-run ‘cyber attack’ – Microsoft, Citrix, Telerik UI bugs ‘exploited’
Feds cuff Detroit man for allegedly hacking University of Pittsburgh Medical Center
Nothing fills you with confidence in an IT contractor more than hearing its staff personal records were stolen by ransomware hackers. Right, Cognizant?
WebEx vulnerability lets hackers impersonate & download meetings
Google Yanks 106 ‘Malicious’ Chrome Extensions
Facebook’s FTC-Mandated Privacy Committee Now in Effect
‘Work pressure’ sees Maze ransomware gang demand payoff from wrong company
IcedID Banker is Back, Adding Steganography, COVID-19 Theme
Operation In(ter)ception: Aerospace and military companies in the crosshairs of cyberspies

ESET researchers uncover targeted attacks against high-profile aerospace and military companies The post Operation In(ter)ception: Aerospace and military companies in the crosshairs of cyberspies appeared first on WeLiveSecurity

Used Cisco Webex recently? Memory vuln could have let remote attackers snoop on your meetings and files
Cisco Webex, Router Bugs Allow Code Execution
Chrome extensions are ‘the new rootkit’ say researchers linking surveillance campaign to Israeli registrar Galcomm
AWS suffers largest ever DDoS attack of 2.3 TBPS
Key Security Tips for Online Trading
BofA Phish Gets Around DMARC, Other Email Protections
Five Password Tips for Securing the New WFH Normal
Phishing Campaign Targeting Office 365, Exploits Brand Names
Copied master key forces South African bank to replace 12 million cards

An update that fixes 7 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Drupal 7 has an Open Redirect vulnerability. For example, a user could be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves 55 vulnerabilities and has 93 fixes is now available.

InvisiMole Group Resurfaces Touting Fresh Toolset, Gamaredon Partnership
Smashing Security podcast #183: MAMILs, gameshows, and a surprise from eBay
Ah lovely, here’s something you can do with those Raspberry Pis, NUC PCs in the bottom of the drawer: Run Ubuntu Appliances on them

security update

Foodora suffers data breach 700,000+ users in 14 countries affected
The girl with the dragnet tattoo: How a TV news clip, Insta snaps, a glimpse of a tat and a T-shirt sold on Etsy led FBI to alleged cop car arsonist
AcidBox Malware Uncovered Using Repurposed VirtualBox Exploit
Premier League’s Return: A Hat Trick of Cyberthreats?
Zoom will offer proper end-to-end encryption to free vid-chat accounts – not just paid-up bods – once you verify your phone number…

security update

CIA failed to protect its sophisticated hacking tools from hackers
Ripple20 bugs expose hundreds of millions of devices to attacks

Devices used in the energy, transportation and communications sectors are also affected by the flaws in the TCP/IP software library The post Ripple20 bugs expose hundreds of millions of devices to attacks appeared first on WeLiveSecurity

Hackers posing as LinkedIn recruiters to scam military, aerospace firms
Shlayer Mac Malware Returns with Extra Sneakiness
Tune in online this week – and discover how to secure all of your attack surfaces
Survey shows rise in robocalls amid COVID‑19 fears

The unsolicited phone calls tout everything from miracle cures to financial relief – here’s how you can stay safe The post Survey shows rise in robocalls amid COVID‑19 fears appeared first on WeLiveSecurity

New Mac malware spreads disguised as Flash Player installer via Google search results
NHS Test & Trace sends text to wrong person, telling them they tested negative for Coronavirus

An update is now available for Red Hat build of Eclipse Vert.x. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For

Coronavirus-Themed Cyberattacks Drop, Microsoft
D-Link home routers plagued with critical & multiple vulnerabilities

An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For

NSS could be made to expose sensitive information over the network.

From the crew behind the Sony Pictures hack comes Operation Interception: An aerospace cyber-attack thriller
LinkedIn ‘Job Offers’ Targeted Aerospace, Military Firms With Malware

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 6 vulnerabilities is now available.

Boffins find that over nine out of ten ‘ethical’ hackers are being a bit naughty when it comes to cloud services
Business email compromise: What can be learned from the Norfund attack
If you’re despairing at staff sharing admin passwords, look on the bright side. That’s CIA-grade security
You. Yeah you, in the beret. Drop that media file right now unless you’ve patched Illustrator or After Effects
Qbot Trojan Reappears to Go After U.S. Banking Customers
Adobe Patches 18 Critical Flaws in Out-Of-Band Update
LinuxSecurity Celebrates 24 Years of Serving as the Linux Community’s Central Security Resource >
Warning issued over hackable security cameras

The owners of the vulnerable indoor cameras are advised to unplug the devices immediately The post Warning issued over hackable security cameras appeared first on WeLiveSecurity

Theft of CIA’s ‘Vault 7’ Secrets Tied to ‘Woefully Lax” Security
‘Ripple20’ Bugs Impact Hundreds of Millions of Connected Devices
Aqua-Fi – New optical networks can deliver Internet underwater
No Wiggle room: Two weeks after angry bike shop customers report mystery orders on their accounts, firm confirms payment cards delinked

The package intel-ucode before version 20200609-1 is vulnerable to information disclosure.

The package dbus before version 1.12.18-1 is vulnerable to denial of service.

Shadow IT: Why It’s Still a Major Risk in Today’s Environments

Reading Time: ~ 3 min. As these times stress the bottom lines of businesses and SMBs alike, many are looking to cut costs wherever possible. The problem for business owners and MSPs is that cybercriminals are not reducing their budgets apace. On the contrary, the rise in COVID-related scams has been noticeable. It’s simply no […]

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

845GB of sensitive explicit data on niche dating apps users exposed online