Menu

Latest articles

The 5.15.5 stable kernel update contains a number of important fixes across the tree.

ScarCruft APT Mounts Desktop/Mobile Double-Pronged Spy Attacks
Unpatched Windows Zero-Day Allows Privileged File Access
More than 1,000 arrested in global crackdown on online fraud

The INTERPOL-led operation involved law enforcement from 20 countries and led to the seizure of millions of dollars in illicit gains The post More than 1,000 arrested in global crackdown on online fraud appeared first on WeLiveSecurity

Shape-Shifting ‘Tardigrade’ Malware Hits Vaccine Makers
Wind turbine maker Vestas confirms recent security incident was ransomware
Social media firms will be forced to unmask online trolls, says Australia

An update for samba is now available for Red Hat Gluster Storage 3.5 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat OpenShift Container Storage 4.8.5 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for samba is now available for Red Hat Gluster Storage 3.5 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Container Platform release 4.9.9 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.9.

Several vulnerabilities were fixed in the OpenSC smart card utilities. CVE-2019-15945

Australia will force social networks to identify trolls, so they can be sued for defamation

Release of stargz snapshotter v0.10.1. This release contains the mitigation for CVE-2021-41190. Please see the release note for details. https://github.com/containerd/stargz-snapshotter/releases/tag/v0.10.1 —- Update to v0.10.0. See changes at https://github.com/containerd/stargz- snapshotter/releases/tag/v0.10.0

Rongxin Wu discovered a use-after-free vulnerability in the International Components for Unicode (ICU) library which could result in denial of service or potentially the execution of arbitrary code.

An infinite loop when –sparse is used with file shrinkage during read access was fixed in the GNU tar archiving utility. For Debian 9 stretch, this problem has been fixed in version

Update to 7.12.1

This is a security update to address CVE-2021-35063 and other misc bugs.

Update to 7.12.1

An out-of-bounds buffer read on truncated key frames in vp8_decode_frame has been fixed in libvpx, a popular library for the VP8 and VP9 video codecs. For Debian 9 stretch, this problem has been fixed in version

Several vulnerabilities were discovered in BlueZ, the Linux Bluetooth protocol stack. An attacker could cause a denial-of-service (DoS) or leak information.

It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not properly sanitize requests and mail messages. This would allow an attacker to perform Cross-Side Scripting (XSS) or SQL injection attacks.

security update

Couple arrested for secretly installing cryptomining software on department store PCs

The 5.15.4 stable kernel rebase contains improved hardware support, new features, and a number of important fixes across the tree.

The 5.15.4 stable kernel rebase contains improved hardware support, new features, and a number of important fixes across the tree.

The 5.15.4 stable kernel rebase contains improved hardware support, new features, and a number of important fixes across the tree.

– Update to 21.08.4. – Closes security issue CVE-2021-43337.

Cloud Security: Don’t wait until your next bill to find out about an attack!
The triangle of holiday shopping: Scams, social media and supply chain woes

‘Tis the season to avoid getting played by scammers hijacking Twitter accounts and promoting fake offers for PlayStation 5 consoles and other red-hot products The post The triangle of holiday shopping: Scams, social media and supply chain woes appeared first on WeLiveSecurity

EU needs more cybersecurity graduates, says ENISA infosec agency – pointing at growing list of master’s degree courses
Privacy Sandbox saga continues: UK watchdog extracts more commitments from Google over ad tech

The following updated rpms for Oracle Linux 8 have been uploaded to the Unb= reakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unb= reakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unb= reakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unb= reakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Government-favoured child safety app warned it could violate the UK’s Investigatory Powers Act with message-scanning tech
If you want to see off next year’s cyber-threats, the time to prepare is … now
Microsoft Defender for Endpoint laid low. Not by malware, but by another buggy Windows patch
Try out 1Password 8 for Windows, where security meets productivity
It’s about the survival of the fittest – CISOs must be brave enough to throw away their security playbook, or suffer the consequences
Avoiding the shopping blues: How to shop online safely this holiday season

With the holiday shopping bonanza right around the corner, here’s how to make sure your online spending spree is hacker-free The post Avoiding the shopping blues: How to shop online safely this holiday season appeared first on WeLiveSecurity

Sophisticated Tardigrade malware launches attacks on vaccine manufacturing infrastructure
New Twists on Gift-Card Scams Flourish on Black Friday
Smashing Security podcast #253: Cybercrime unicorns, HVAC hacks, and NFT piracy – with Mikko Hyppönen
New UK IoT law means huge fines and a ban on default passwords
S3 Ep60: Exchange exploit, GoDaddy breach and cookies made public [Podcast]
Veeam Ransomware Protection with Red Hat Enterprise Linux as the Immutable Repository
UK.gov emits draft IoT and smartphone security law for Parliamentary scrutiny

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685. (CVE-2019-7282)

Integer-overflow in Imf_3_1::bytesPerDeepLineTable. (CVE-2021-3933) Divide-by-zero in Imf_3_1::RGBtoXYZ. (CVE-2021-3941) References: – https://bugs.mageia.org/show_bug.cgi?id=29657

Server processes unencrypted bytes from man-in-the-middle. (CVE-2021-23214) libpq processes unencrypted bytes from man-in-the-middle. (CVE-2021-23222) References:

All FreeRDP clients prior to version 2.4.1 using gateway connections (‘/gt:rpc’) fail to validate input data. A malicious gateway might allow client memory to be written out of bounds. This issue has been resolved in version 2.4.1. If you are unable to update then use `/gt:http` rather than /gt:rdp connections if possible or use a […]

Server-side Request Forgery (SSRF) References: – https://bugs.mageia.org/show_bug.cgi?id=29592 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/HMUJA5GZTPQ5WRYUCCK2GEZM4W43N7HH/

Privilege escalation that allows an attacker to add or remove data in any database or make configuration changes. (CVE-2021-38295) References: – https://bugs.mageia.org/show_bug.cgi?id=29548

Google advises passwords are good, spear phishing is bad, and free clouds get attacked
Huawei’s AppGallery riddled with malware-infected games
US bans Chinese firms – including one linked to HPE’s China JV – for feeding tech to Beijing’s military

security update

US government securities watchdog spoofed by investment scammers – don’t fall for it!
9.3M+ Androids Running ‘Malicious’ Games from Huawei AppGallery
GoDaddy Breach Widens to Include Reseller Subsidiaries
Apple’s NSO Group Lawsuit Amps Up Pressure on Pegasus Spyware-Maker
Max Schrems hits Irish Data Protection Commissioner with corruption complaint
Attackers Actively Target Windows Installer Zero-Day
How a malicious Android app could covertly turn the DSP in your MediaTek-powered phone into an eavesdropping bug

An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

openssh: privilege escalation when AuthorizedKeysCommand or AuthorizedPrincipalsCommand are configured (CVE-2021-41617) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 openssh-7.4p1-22.el7_9.x86_64.rpm openssh-askpass-7.4p1-22.el7_9.x86_64.rpm openssh-clients-7.4p1-22.e [More…]

krb5: NULL pointer dereference in process_tgs_req() in kdc/do_tgs_req.c via a FAST inner body that lacks server field (CVE-2021-37750) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 krb5-debuginfo-1.15.1-51.el7_9.i686.rpm krb5-debuginfo-1.15.1-51.el7_9.x86_64.rpm krb5- [More…]

kernel: use-after-free in drivers/infiniband/core/ucma.c ctx use-after- free (CVE-2020-36385) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * scsi: ibmvfc: Avoid link down on FS9100 canister reboot * crash in qla2x00_status_entry() because of corrupt srb * qedf driver: race c […]

Yes, ransomware is your number one security nightmare. But here’s how to sleep easy
China trying to export its Great Firewall and governance model

As the holiday season draws near, shoppers are eagerly searching for gifts online. Unfortunately, this time of year brings as much cybercrime as it does holiday cheer. Especially during the holidays, cybercriminals are eager to exploit and compromise your personal data. Even businesses large and small are not immune to the dark forces at work. […]

Attackers Will Flock to Crypto Wallets, Linux in 2022: Podcast
Apple sues ‘amoral 21st century mercenaries’ NSO for infecting iPhones with Pegasus spyware
Zero-day proof-of-concept exploit lands for Windows make-me-admin vulnerability
FBI, CISA urge organizations to be on guard for attacks during holidays

Threat actors have previously timed ransomware and other attacks to coincide with holidays and weekends The post FBI, CISA urge organizations to be on guard for attacks during holidays appeared first on WeLiveSecurity

Crypto for cryptographers! Infosec types revolt against use of ancient abbreviation by Bitcoin and NFT devotees
What to do if you receive a data breach notice

Receiving a breach notification doesn’t mean you’re doomed – here’s what you should consider doing in the hours and days after learning that your personal data has been exposed The post What to do if you receive a data breach notice appeared first on WeLiveSecurity

Check your patches – public exploit now out for critical Exchange bug
Common Cloud Misconfigurations Exploited in Minutes, Report

Several security issues were fixed in FreeRDP.

UK Ministry of Justice secures HVAC systems ‘protected’ by passwordless Wi-Fi after Register tipoff

Release of OpenShift Serverless Client kn 1.19.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Release of OpenShift Serverless 1.19.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Red Hat Integration Camel Extensions for Quarkus 2.2 is now GA. The purpose of this text-only errata is to inform you about the security issues fixed since the tech preview 2 release. Red Hat Product Security has rated this update as having a security impact

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rpm is now available for Red Hat Enterprise Linux 7.6 Advanced Update Support, Red Hat Enterprise Linux 7.6 Telco Extended Update Support, and Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions.

GoDaddy hack exposes accounts of 1.2 million customers
Infosec bods: After more than a year, Sky gets round to squashing hijacking bug in 6m home broadband routers
Indian bank smacks down allegation it exposed 180 million customers’ accounts
GoDaddy admits to password breach: check your Managed WordPress site!
GoDaddy’s Latest Breach Affects 1.2M Customers
On the trail of Russia’s $100 million Evil Corp hacking gang
SSL keys, sFTP passwords and more exposed after someone broke into GoDaddy Managed WordPress using ‘compromised password’
Online Merchants: Prevent Fraudsters from Becoming Holiday Grinches