Menu

Latest articles

We regret to inform you there’s an RCE vuln in old version of WinRAR. Yes, the file decompression utility
S3 Ep55: Live malware, global encryption, dating scams, and secret emanations [Podcasts]
Why is Cybersecurity Failing Against Ransomware?

fix memory leak when verbose mode is on

Security fix for CVE-2021-3618

Ransomware Sinks Teeth into Candy-Corn Maker Ahead of Halloween

libcaca could be made to crash if it received a specially crafted image.

Research finds consumer-grade IoT devices showing up… on corporate networks

Tenable discovered that in Babel, a set of tools for internationalizing Python applications, Babel.Locale allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution. This

What is self-learning AI and how does it tackle ransomware?

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Smashing Security podcast #248: Press F12 to hack
Uncle Sam to clip wings of Pegasus-like spyware – sorry, ‘intrusion software’ – with proposed export controls
Brave browser replaces Google with its own search engine

Brave Search will become the default search option for new users in the US, UK, Canada, Germany and France, with more countries to follow soon The post Brave browser replaces Google with its own search engine appeared first on WeLiveSecurity

security update

Google Crushes YouTube Cookie-Stealing Channel Hijackers
We don’t want to be critical, but humans alone aren’t enough to protect your ICS
VPN Exposes Data for 1M Users, Leading to Researcher Questioning
A recipe for failure: Predictably poor passwords

Security professionals advise to never use ‘beef stew’ as a password. It just isn’t stroganoff. The post A recipe for failure: Predictably poor passwords appeared first on WeLiveSecurity

“To the moon!” Cryptocurrency hamster Mr Goxx trades online 24/7
Geriatric Microsoft Bug Exploited by APT Using Commodity RATs
Not just deprecated, but deleted: Google finally strips File Transfer Protocol code from Chrome browser
NHS Digital exposes hundreds of email addresses after BCC blunder copies in entire invite list to ‘Let’s talk cyber’ event

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

How security has changed in the era of cloud computing

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the redis:6 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The security update of smarty3, the compiling PHP template engine, issued as DLA 2618-1 introduced a regression in the smarty_security class when secure directories are evaluated. Updated smarty3 packages are now available to correct this issue.

An update for the redis:5 module is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Centre for Computing History apologises to customers for ’embarrassing’ breach
When it comes to ransomware, every second hurts
Crims target telcos’ Linux and Solaris boxes, which don’t get enough infosec love
Acer servers cracked in India and Taiwan – including systems with customer data
You’ve heard of HTTPS. Now get a load of HTTPA: Web services in verified remote trusted environments?
Squirrel Bug Lets Attackers Execute Code in Games, Cloud Services

security update

Fresh APT Harvester Reaps Telco, Government Data
BlackMatter ransomware gang will target agriculture for its next harvest – Uncle Sam
$5.2 billion worth of Bitcoin transactions possibly tied to ransomware

Threat actors are increasingly using advanced tactics to obfuscate and launder their illicit gains, a report by the US Government finds The post $5.2 billion worth of Bitcoin transactions possibly tied to ransomware appeared first on WeLiveSecurity

Scrambling to counter a ransomware attack could leave you with egg on your face
Lyceum APT Returns, This Time Targeting Tunisian Firms
Email phishing crapcannon operators TA505 are back from the dead, researchers warn
UK competition watchdog unveils principles to make a kinder antivirus business

Earlier this year, the National Institute for Standards and Technology (NIST) published updated recommendations for phishing simulations in security awareness training programs. We discussed it on our Community page soon after the updated standards were released, but the substance of the change bears repeating. “Practical exercises include no-notice social engineering attempts to collect information, gain […]

A Guide to Doing Cyberintelligence on a Restricted Budget
Feds Warn BlackMatter Ransomware Gang is Poised to Strike

Update to upstream stable release 2.9.4, includes a fix for CVE-2021-3802 (#2003650, #2003649)

Several security issues were fixed in strongSwan.

Free BlackByte decryptor released, after researchers say they found flaw in ransomware code
3 things to add to your 2022 cloud to-do list

An update for the redis:5 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

TA505 Gang Is Back With Newly Polished FlawedGrace RAT

An update is now available for Red Hat Quay 3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in strongSwan.

Reg scribe spends week being watched by government Bluetooth wristband, emerges to more surveillance

The container suse/sle15 was updated. The following patches have been included in this update:

Japanese messaging giant Line admits it mishandled user data, promises to do better

What do the terms artificial intelligence and machine learning mean to you? If what comes to mind initially involves robot butlers or rogue computer programs, you’re not alone. Even IT pros at large enterprise organizations can’t escape pop culture visions fed by films and TV. But today, as cyberattacks against businesses and individuals continue to […]

Time to Build Accountability Back into Cybersecurity
Podcast: Could the Zoho Flaw Trigger SolarWinds 2.0?
Sinclair Confirms Ransomware Attack That Disrupted TV Stations
TikTok Serves Up Fresh Gamer Targets via Fake Among Us, Steam Offerings
Microsoft called out as big malware hoster – thanks to OneDrive and Office 365 abuse
Twitter Suspends Accounts Used to Snare Security Researchers

Red Hat OpenShift Container Platform release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenShift Container Platform release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Cybersecurity Awareness Month: Building your career

An update that fixes one vulnerability is now available.

Ardour could be made to crash or possibly arbitrary code execute if it received a specially crafted XML file.

A security issue was fixed in nginx.

DLA-2743-1 was issued for CVE-2017-5715, affecting amd64-microcode, processor microcode firmware for AMD CPUs. However, the binaries for the resulting upload weren’t built and published, thereby preventing the users to upgrade to a fixed version.

Chinese tech minister says he’s ‘dealt with’ 73,000 sites that breached the law
Whatever sort of disaster we’re talking about, if your backups are fried, you’re not going to recover
US gov claims ransomware ‘earned’ $590m in the first half of 2021 alone – mostly in Bitcoin

security update

https://lib.openmpt.org/libopenmpt/2021/10/04/security- updates-0.5.12-0.4.24-0.3.33/

The newest upstream commit Security fix for CVE-2021-3796 Security fix for CVE-2021-3778

https://lib.openmpt.org/libopenmpt/2021/10/04/security- updates-0.5.12-0.4.24-0.3.33/

Two security issues have been discovered in LibreOffice’s support for digital signatures in ODF documents, which could result in incorrect signature indicators/timestamps being presented.

NFTs not annoying enough? Now they come with wallet-emptying malware

Two security issue have been discovered in nghttp2: server, proxy and client implementing HTTP/2. CVE-2018-1000168

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 20 vulnerabilities is now available.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Amazon textbook rental service scammed for $1.5m

security update

security update

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

TrickBot Gang Enters Cybercrime Elite with Fresh Affiliates
Missouri Vows to Prosecute ‘Hacker’ Who Informed State About Data Leak
LANtenna hack spies on your data from across the room! (Sort of)
Employee offboarding: Why companies must close a crucial gap in their security strategy

There are various ways a departing employee could put your organization at risk of a data breach. How do you offboard employees the right way and ensure your data remains safe? The post Employee offboarding: Why companies must close a crucial gap in their security strategy appeared first on WeLiveSecurity

Acer hacked (for the second time this year)
Disrupt adversaries and prevent identity fraud with Recorded Future Identity Intelligence

Richard Weinberger reported that unsquashfs in squashfs-tools, the tools to create and extract Squashfs filesystems, does not check for duplicate filenames within a directory. An attacker can take advantage of this flaw for writing to arbitrary files to the filesystem if a malformed

An update that solves 6 vulnerabilities and has 44 fixes is now available.