Menu

Latest articles

Richard Weinberger reported that unsquashfs in squashfs-tools, the tools to create and extract Squashfs filesystems, does not check for duplicate filenames within a directory. An attacker can take advantage of this flaw for writing to arbitrary files to the filesystem if a malformed

An update that solves 6 vulnerabilities and has 44 fixes is now available.

An update that contains security fixes can now be installed.

When it comes to ransomware, your fightback should start long before you’re attacked
White House ransomware summit calls for virtual asset crackdown, without mentioning cryptocurrency

An update that fixes one vulnerability is now available.

Client-side content scanning as an unworkable, insecure disaster for democracy

security update

USN-5091-1 introduced a regression in the Linux kernel for Microsoft Azure cloud systems.

Rickroll Grad Prank Exposes Exterity IPTV Bug

security update

WhatsApp’s got your back(ups) with encryption for stored messages
Google’s VirusTotal reports that 95% of ransomware spotted targets Windows

Red Hat Advanced Cluster Management for Kubernetes 2.2.9 General Availability release images, which provide security updates, one or more container updates, and bug fixes. Red Hat Product Security has rated this update as having a security impact

Verizon’s Visible Wireless Carrier Confirms Credential-Stuffing Attack

Fix CVE-2021-29063 regular expression denial of service References: – https://bugs.mageia.org/show_bug.cgi?id=29537 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3M5O55E7VUDMXCPQR6MQTOIFDKHP36AA/

Don’t get phished! How to be the one that got away

If it looks like a duck, swims like a duck, and quacks like a duck, then it’s probably a duck. Now, how do you apply the duck test to defense against phishing? The post Don’t get phished! How to be the one that got away appeared first on WeLiveSecurity

3D printing site Thingiverse suffers breach of 228,000 email addresses amid sluggish disclosure
Analysis of 80 million ransomware samples reveals a world under attack
CryptoRom Scam Rakes in $1.4M by Exploiting Apple Enterprise Features
Podcast: 67% of Orgs Have Been Hit by Ransomware at Least Once
S3 Ep54: Another 0-day, double Apache patch, and Fight The Phish [Podcast]

Security fix for CVE-2021-41617

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform Cross-Site Scripting (XSS) attacks or impersonate other users.

US invites friends to multilateral cybersecurity meetings – Russia and China strangely absent

An update for httpd is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.6 Advanced Update Support, Red Hat

The container suse/sles12sp4 was updated. The following patches have been included in this update:

Ad-blocking browser extension actually adds ads, say Imperva researchers

Red Hat 3scale API Management 2.11.0 Release – Container Images A security update for Red Hat 3scale API Management is now available from the Red Hat Container Catalog. Red Hat Product Security has rated this update as having a security impact

Smashing Security podcast #247: Rickrolling submarine secrets

The Rise of Ransomware Ransomware attacks dominate news coverage of the cybersecurity industry. And it’s no wonder – with million-dollar payouts, infrastructure attacks and international manhunts, ransomware makes for exciting headlines. But its recent domination of the airwaves has been a long time coming.   “The first types of ransomware have existed for quite some […]

FreakOut Botnet Turns DVRs Into Monero Cryptominers
Romance scams with a cryptocurrency twist – new research from SophosLabs
Microsoft thwarts record‑breaking DDoS attack

The attack, which clocked in at 2.4 Tbps, targeted one of Azure customers based in Europe The post Microsoft thwarts record‑breaking DDoS attack appeared first on WeLiveSecurity

Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers

Malware leaps from the darkness to envelop our lives in a cloak of stolen information, lost data and worse. But to know your enemy is to defeat your enemy. So we peered over the ledge leading to the dark web and leapt. The forces we sought are disruptors – without warning, they disturb our businesses […]

Incident Response: 5 Principles to Boost the Infosec/Legal Relationship
Ex-camera biz Olympus investigating ‘suspicious’ network activity again a month after ransomware hit
Mandating a Zero-Trust Approach for Software Supply Chains
OpenSea ‘Free Gift’ NFTs Drain Cryptowallet Balances
30 Mins or Less: Rapid Attacks Extort Orgs Without Ransomware

Squashfs-Tools could be made to overwrite files.

Microsoft says Azure fended off what might just be the world’s biggest-ever DDoS attack

The container suse/sle15 was updated. The following patches have been included in this update:

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Microsoft Oct. Patch Tuesday Squashes 4 Zero-Day Bugs

security update

Microsoft Patch Tuesday bug harvest festival comes to town
User locked out of Microsoft account by MFA bug, complains of customer-hostile support
Windows Zero-Day Actively Exploited in Widespread Espionage Campaign
Office 365 Spy Campaign Targets US Military Defense
Apple patches ‘actively exploited’ iPhone zero-day with iOS 15.0.2 update
Apple Releases Urgent iOS Updates to Patch New Zero-Day Bug

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes 25 vulnerabilities is now available.

An update for libxml2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openssl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Schools email marketing company told us to go away when we told them of exposed database creds, say infoseccers
Bank of America employee indicted for email scam that targeted businesses
Google gives away 10,000 free security keys to high-risk users
What’s missing from most ICS cybersecurity training? The ICS itself…
Apple quietly patches yet another iPhone 0-day – check you have 15.0.2
Zero-day hunters seek laws to prevent vendors suing them for helping out and doing their jobs
Ransomware cost US companies almost $21 billion in downtime in 2020

The victims lost an average of nine days to downtime and two-and-a-half months to investigations, an analysis of disclosed attacks shows The post Ransomware cost US companies almost $21 billion in downtime in 2020 appeared first on WeLiveSecurity

Russia-based criminals are still the UK’s number 1 cyber-foe, NSO Group’s wares a ‘red flag’ says NCSC chief
Cybersecurity awareness month: Fight the phish!
Man charged with hack which shared COVID-19 test details in protest against vaccine pass
An appearance on the IntoSecurity Chats podcast

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Brewdog might make an OK pint but its security sucks: Flaw opened door to free beers for anyone

An update that fixes 21 vulnerabilities is now available.

When criminals go corporate: Ransomware-as-a-service, bulk discounts and more
Gripped by cybersec career indecision? Don’t give up. Level up

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for httpd24-httpd is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

US nuke sub plans leaked on SD card hidden in peanut butter sandwich, claims FBI

security update

– New upstream update (93.0) – Fixed NSS package dependency (NSS 3.70) —- – New upstream release (93.0)

Two security issues were found in TIFF, a widely used format for storing image data, as follows: CVE-2020-19131

Update to f13cbcf (dr_wav 0.13.2) Fix a possible buffer overflow. —- Update to 8900af1 with dr_mp3 0.6.31 Fix a bug in dr_mp3 when loading from memory.

Upgrade Grafana to upstream version 7.5.10 —- rebuild to resolve CVE-2021-34558

Update to f13cbcf (dr_wav 0.13.2) Fixes a possible buffer overflow. —- Update to 8900af1 with dr_mp3 0.6.31 Fix a bug in dr_mp3 when loading from memory.

An update that solves three vulnerabilities and has one errata is now available.

The container caasp/v4/kured was updated. The following patches have been included in this update:

The container caasp/v4/kucero was updated. The following patches have been included in this update:

The container caasp/v4/kubernetes-client was updated. The following patches have been included in this update:

The container caasp/v4/hyperkube was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

security update

FontOnLake: Previously unknown malware family targeting Linux

ESET researchers discover a malware family with tools that show signs they’re used in targeted attacks The post FontOnLake: Previously unknown malware family targeting Linux appeared first on WeLiveSecurity

Apache patch proves patchy – now you need to patch the patch
Never mind Russia: Turkey and Vietnam are Microsoft’s new state-backed hacker threats du jour