Menu

Latest articles

security update

US distrust of Huawei linked in part to malicious software update in 2012

An update that fixes one vulnerability is now available.

It was discovered that modsecurity-apache, an Apache module to tighten the Web application security, does not properly handles excessively nested JSON objects, which could result in denial of service. The update introduces a new ‘SecRequestBodyJsonDepthLimit’ option to limit the

CISA issues emergency directive to fix Log4j vulnerability

security update

xwayland 21.1.4 Security fix for CVE-2021-4008, CVE-2021-4009, CVE-2021-4010, CVE-2021-4011 Store EGLcontext to avoid superfluous eglMakeCurrent() calls Prefer EGLStream with NVIDIA proprietary driver if both GBM and EGLstream are available

Update log4j to 2.16.0 – Disables JNDI by default

Fix out of bounds read issue in *larrv functions (CVE-2021-4048)

– Update the libsqlite3-sys crate to version 0.23.2. – Update the rusqlite crate to version 0.26.3. This update also contains a fix for RUSTSEC-2021-0128.

Facebook Bans Spy-for-Hire Firms for Targeting 50K People
Spider-Man Movie Release Frenzy Bites Fans with Credit-Card Harvesting
Malicious Joker App Scores Half-Million Downloads on Google Play
Serious Security: OpenSSL fixes “error conflation” bugs – how mixing up mistakes can lead to trouble
Brand-New Log4Shell Attack Vector Threatens Local Hosts
Convergence Ahoy: Get Ready for Cloud-Based Ransomware
RAF shoots down ‘terrorist drone’ over US-owned special ops base in Syria
Conti Gang Suspected of Ransomware Attack on McMenamins
Over Log4j? VMware has another critical flaw for you to patch
Facebook locks out 1,500 fake accounts used by cyber-spy firms to snoop on people, alerts 50k potential targets

security update

‘Tropic Trooper’ Reemerges to Target Transportation Outfits

Managed service providers (MSPs) deliver critical operational support for businesses around the world. As third-party providers of remote management, MSPs are typically contracted by small and medium-sized businesses (SMBs), government agencies and non-profit organizations to perform daily maintenance of information technology (IT) systems. Similar to an MSP, managed security service providers (MSSPs) offer comparable organizations […]

‘PseudoManuscrypt’ Mass Spyware Campaign Targets 35K Systems
Why ransomware attacks happen out of hours or during the holidays
S3 Ep63: Log4Shell (what else?) and Apple kernel bugs [Podcast+Transcript]
The dirty dozen of Latin America: From Amavaldo to Zumanek

The grand finale of our series dedicated to demystifying Latin American banking trojans The post The dirty dozen of Latin America: From Amavaldo to Zumanek appeared first on WeLiveSecurity

Free eBook! Ransomware – how to stop it, and how to survive an attack
East Londoners nicked under Computer Misuse Act after NHS vaccine passport app sprouted clump of fake entries
How developers scrambled to secure the Log4j vulnerability
The DHS is inviting hackers to break into its systems, but there are rules of engagement
‘DarkWatchman’ RAT Shows Evolution in Fileless Malware
Move fast, break security: Why CISOs must push back against Agile IT
National Cyber Strategy will lead to BritChip for mobile devices by 2025, claims UK.gov
Japan draws a LINE: web giants must reveal where they store user data
Facebook expands bug bounty program to include scraping attacks, two years after it was scraped – hard
Smashing Security podcast #256: Virgin Media just won’t take no for an answer, NFT apes, and bad optics
As CISA tells US govt agencies to squash Log4j bug by Dec 24, fingers start pointing at China, Iran, others
Relentless Log4j Attacks Include State Actors, Possible Worm
US lawmakers want to put NSO Group, 3 other spyware makers out of business with fresh severe sanctions
Malicious Exchange Server Module Hoovers Up Outlook Credentials
SAP Kicks Log4Shell Vulnerability Out of 20 Apps
What every business leader needs to know about Log4Shell

Hundreds of thousands of attempts to exploit the vulnerability are under way The post What every business leader needs to know about Log4Shell appeared first on WeLiveSecurity

5 warning signs your identity has been stolen

By spotting these early warning signs of identity theft, you can minimize the impact on you and your family The post 5 warning signs your identity has been stolen appeared first on WeLiveSecurity

Pen Test Partners: Anyone could view Gumtree users’ GPS location by pressing F12
Apache’s Fix for Log4Shell Can Lead to DoS Attacks
Gathering security data for container images using the Pyxis API
Securing the Kubernetes software supply chain
Microsoft closes installer hole abused by Emotet malware, Google splats Chrome bug exploited in the wild
In 2022, Expect More Supply Chain Pain and Changing Security Roles
Apache takes off, nukes insecure feature at the heart of Log4j from orbit with v2.16
Apple iOS Update Fixes Cringey iPhone 13 Jailbreak Exploit
Actively Exploited Microsoft Zero-Day Allows App Spoofing, Malware Delivery
400 Banks’ Customers Targeted with Anubis Trojan
You may have cracked serverless development, but it’s almost certain you haven’t solved serverless security
What the Log4Shell Bug Means for SMBs: Experts Weigh In
How to Buy Precious Patching Time as Log4j Exploits Fly
Popular password manager LastPass to be spun out from LogMeIn
MPs charged with analysing Online Safety Bill say end-to-end encryption should be called out as ‘specific risk factor’
‘Seedworm’ Attackers Target Telcos in Asia, Middle East
Apple security updates are out – and not a Log4Shell mention in sight
Log4Shell: The race is on to fix millions of systems and internet-connected devices
Kronos Ransomware Outage Drives Widespread Payroll Chaos
Log4j RCE latest: In case you hadn’t noticed, this is Really Very Bad, exploited in the wild, needs urgent patching
Log4Shell vulnerability: What we know so far

The critical flaw in the ubiquitous Log4j utility has sent shockwaves far beyond the security industry – here’s what we know so far The post Log4Shell vulnerability: What we know so far appeared first on WeLiveSecurity

Where the Latest Log4Shell Attacks Are Coming From
Malicious PyPI Code Packages Rack Up Thousands of Downloads
Log4Shell Is Spawning Even Nastier Mutations
When disaster strikes, data recovery really is a race against time
Is VPOTUS Bluetooth-phobic or sensible? The answer’s pretty clear
Timekeeping biz Kronos hit by ransomware and warns customers to engage biz continuity plans
Ooh, an update. Let’s install it. What could possibly go wro-
Log4Shell explained – how it works, why you need to know, and how to fix it

security update

Chen Zhaojun of Alibaba Cloud Security Team discovered a critical security vulnerability in Apache Log4j, a popular Logging Framework for Java. JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker

The container suse/sle15 was updated. The following patches have been included in this update:

An update that fixes 7 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

security update

How to detect the Log4j vulnerability in your applications
Irish Health Service ransomware attack happened after one staffer opened malware-ridden email

Apache Log4j2

– Update to latest upstream (95.0)

**MariaDB 10.5.13** Release notes: https://mariadb.com/kb/en/mariadb-10513-release-notes/ Maintainer notes: This update contains – conditionally only on F>=35 – patch for OpenSSL 3 This update enables LTO – Link Time Optimization This update disables DTRACE on ARMv7hl architecture as a temporary workaround for BZ #2026600

**MariaDB 10.5.13** Release notes: https://mariadb.com/kb/en/mariadb-10513-release-notes/ Maintainer notes: This update contains – conditionally only on F>=35 – patch for OpenSSL 3 This update enables LTO – Link Time Optimization This update disables DTRACE on ARMv7hl architecture as a temporary workaround for BZ #2026600

security update

Next-Gen Maldocs & How to Solve the Human Vulnerability

An update that contains security fixes can now be installed.

‘Appalling’ Riot Games Job Fraud Takes Aim at Wallets

CVE-2021-4052: Use after free in web apps. CVE-2021-4053: Use after free in UI. CVE-2021-4079: Out of bounds write in WebRTC. CVE-2021-4054: Incorrect security UI in autofill. CVE-2021-4078: Type confusion in V8.

Zero Day in Ubiquitous Apache Log4j Tool Under Active Attack
SnapHack: Watch out for those who can hack into anyone’s Snapchat!

Oh snap! This is how easy it may be for somebody to hijack your Snapchat account – all they need to do is peer over your shoulder. The post SnapHack: Watch out for those who can hack into anyone’s Snapchat! appeared first on WeLiveSecurity

“Log4Shell” Java vulnerability – how to safeguard your servers
Sprawling Active Attack Aims to Take Over 1.6M WordPress Sites
Log4j RCE: Emergency patch issued to plug critical auth-free code execution hole in widely-used logging utility
Revealed: Remember the Sony rootkit rumpus? It was almost oh so much worse
‘Karakurt’ Extortion Threat Emerges, But Says No to Ransomware
Gathering security data using the Red Hat Security Data API

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.