Menu

Category Archives: Security

Articles about security

Updated okular packages fix security vulnerability: Okular can be tricked into executing local binaries via specially crafted PDF files. This binary execution can require almost no user interaction. No parameters can be passed to those local binaries (CVE-2020-9359).

Updated webkit2 packages fix security vulnerability: WebKitGTK through 2.26.4 contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution (CVE-2020-10018).

Small business loans app blamed as 500,000 financial records leak out of … you guessed it, an open S3 bucket
Magecart Cyberattack Targets NutriBullet Website
Pervasive digital surveillance of citizens deployed in COVID-19 fight, with rules that send genie back to bottle
A COVID-19 Cybersecurity Poll: Securing a Remote Workforce
This Stalkerware Delivers Extra-Creepy Features
Remember cryptojacking from way, way back (2019)? Site infections are down 99% – thanks to death of Coinhive
FBI warns of human traffickers luring victims on dating apps

The warning highlights one of the potential risks associated with revealing too much private information online The post FBI warns of human traffickers luring victims on dating apps appeared first on WeLiveSecurity

security update

Fake WiseCleaner website spreading CoronaVirus ransomware
APT36 Taps Coronavirus as ‘Golden Opportunity’ to Spread Crimson RAT

An update that fixes one vulnerability is now available.

An update for slirp4netns is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Nigerian spammer made 3X average national salary firehosing macro-laden Word docs at world+dog

An update for python-flask is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for zsh is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for python-pip is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Activities of a Nigerian Cybercriminal Uncovered

Reading Time: ~ 3 min. “Cold Cuts Day,” “National Anthem Day,” “What if Cats and Dogs had Opposable Thumbs Day”… If you’ve never heard of World Backup Day, you’d be forgiven for thinking it’s another of the gimmicky “holidays” that seem to be snatching up more and more space on the calendar. (Did you know […]

Talking love and viruses on the BBC World Service
Vimeo freezes accounts after malware hunts for logins, coronavirus map app infected with evil code, and more
Virtual machines, real problems: VMware fixes bug trio including guest-to-host hole in Workstation, Fusion
Convincing Google Impersonation Opens Door to MiTM, Phishing
Google & Microsoft launch tools to address Coronavirus outbreak
US Health and Human Services targeted by DDoS scum at just the time it’s needed to be up and running

security update

Microsoft Edge Shares Privacy-Busting Telemetry, Research Alleges
Coronavirus related cyber attacks hit HHS in US, testing center in Czech
Health workers are top of phishers’ target lists thanks to data value
UK intelligence agency warns of cybercriminals exploiting the Coronavirus outbreak
Malicious Coronavirus victim tracking app demands ransom payment from Android users
Microsoft Teams goes down as Europe starts working from home
COVID‑19 and the forced workplace exodus

As the pandemic forces many employees to work from home, can your organization stay productive – and safe? The post COVID‑19 and the forced workplace exodus appeared first on WeLiveSecurity

Several issue were found in Simple Linux Utility for Resource Management (SLURM), a cluster resource management and job scheduling system.

Multiple vulnerabilities have been found in Squid, the worst of which could lead to arbitrary code execution.

An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

This update fixes several vulnerabilities in Graphicsmagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed media files are processed.

Cookiethief Android malware hijacks Facebook accounts without password
Beware scams exploiting coronavirus fears

From malware-laden emails to fake donations, these are some of the most common cons you should watch out for amid the public health crisis The post Beware scams exploiting coronavirus fears appeared first on WeLiveSecurity

Working from Home: COVID-19’s Constellation of Security Challenges
Coronavirus Tracking App is ransomware; locks phones for ransom
WordPress Plugin Bug in Popup Builder Threatens 100K Websites
Your data was ‘taken without permission’, customers told, after personal info accessed in O2 UK partner’s database
Hey, friends. We know it’s a crazy time for the economy, but don’t forget to enable 2FA for payments by Saturday
Coronavirus-Themed APT Attack Spreads Malware
Europol nabs SIM hacking network from across Europe
ACLU Sues Over U.S. Airport Facial-Recognition Technology

Reading Time: ~ 2 min. Paradise Ransomware Spreading Through Unusual Attachments While Paradise ransomware isn’t new to the scene, the latest methods it’s using to spread are a bit surprising. Though it sticks to using email for transmission, it now offers up an IQY attachment instead of a typical word document or excel spreadsheet. These […]

Reviewing vulnerabilities in 2019: The annual Red Hat Product Security Risk Report
Open-source bug bonanza: Vulnerabilities up almost 50 per cent thanks to people actually looking for them
Avast pulls plug on insecure JavaScript engine in its security software suite
Fresh virus misery for Illinois: Public health agency taken down by… web ransomware. Great timing, scumbags
Researchers Warn of Novel PXJ Ransomware Strain
Trojan Raids Android Users’ Cookie Jars

security update

Thought you were done after Tuesday’s 115-fix day? Not yet: Microsoft emits SMBv3 worm-cure crisis patch
Hackers using fake live Coronavirus map to spread malware
US Congress: Spying law is flawed, open to abuse, and lacking in accountability – so let’s reauthorize it
Phishing attacks exploit YouTube redirects to catch the unwary
European power grid organization hit by cyberattack

The incident affected our office network, says ENTSO-E, as it implements measures to avoid future cyber-incursions The post European power grid organization hit by cyberattack appeared first on WeLiveSecurity

Microsoft takes down largest botnet network “Necurs”
$100K Paid Out for Google Cloud Shell Root Compromise
Akamai Talks Massive Uptick in Credential-Stuffing Attacks Against Bank APIs
Laying a foundation for more secure computing: Red Hat Enterprise Linux and Common Criteria
Tracking Turla: New backdoor delivered via Armenian watering holes

Can an old APT learn new tricks? Turla’s TTPs are largely unchanged, but the group recently added a Python backdoor. The post Tracking Turla: New backdoor delivered via Armenian watering holes appeared first on WeLiveSecurity

Russia-backed crew’s latest malware has discerning taste – when screening visitors to poisoned watering holes

Reading Time: ~ 3 min. The last thing you want to do when you get a new computer, mobile device, or tablet is spend a lot of time setting it up. But like any major appliance, these devices are something you want to invest a little time setting up properly. Often, they’re not cheap. And […]

Microsoft nukes 9 million-strong Necurs botnet after unpicking domain name-generating algorithm
Flaws Riddle Zyxel’s Network Management Software

security update

Phishing Attack Skirts Detection With YouTube
Meltdown The Sequel strikes Intel chips – and full mitigation against data-meddling LVI flaw will slash performance
Wormable, Unpatched Microsoft Bug Threatens Corporate LANs
Find out how to manage detection and response for better cyber security
Friend’s girlfriend sextortion scam infects PCs with Raccoon malware
New TrickBot Variant Updates Anti-Analysis Tricks
More Than Half of IoT Devices Vulnerable to Severe Attacks
Secret-sharing app Whisper shared secrets like last known location and actual password tokens in exposed database
Necurs Botnet in Crosshairs of Global Takedown Offensive
How to Tell if a Website Has Been Compromised
Securing the deployment of OpenShift Container Platform 4
The Reg produces exhibit A1: A UK court IT system running Windows XP
Google: You know we said that Chrome tracker contained no personally identifiable info? Forget we ever said that
Stuck at home? Need something to keep busy with? Microsoft has 115 ideas – including an awful SMBv3 security hole to worry about
That LVI CPU hole wasn’t the only Intel fix: Dozens of flaws patched to stop chips turning into potatoes
Critical Bugs in Rockwell, Johnson Controls ICS Gear
Microsoft Patches 26 Critical Bugs in Big March Update

security update

California tech industry gets its first big coronavirus hit: RSA Conference attendee infected, in serious condition
Popular ThemeREX WordPress Plugin Opens Websites to RCE
Firefox Bug Opens iPhone AirPods to Third-Party Snooping
High-Severity Flaws Plague Intel Graphics Drivers
You only LVI twice: Meltdown The Sequel strikes Intel chips – and full mitigation against data-meddling flaw will cost you 50%+ of performance
Hackers hit hackers in new malware campaign
Flaw in popular VPN service may have exposed customer data

NordVPN praised its bug bounty program and said that a fix had been shipped within two days The post Flaw in popular VPN service may have exposed customer data appeared first on WeLiveSecurity

Variant of Paradise Ransomware Targets Office IQY Files