Menu

Latest articles

Air gaps have been ‘shattered’, says new Indian policy on power sector security

Due to a data race in the crossbeam-deque in the crossbeam crate, one or more tasks in the worker queue could have been be popped twice instead of other tasks that are forgotten and never popped. If tasks are allocated on the heap, this could have caused a double free and a memory leak (CVE-2021-32810).

New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Navy Warship’s Facebook Page Hacked to Stream ‘Age of Empires’ Gaming
Twitch Leak Included Emails, Passwords in Clear Text: Researcher

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Russian spies reportedly used SolarWinds hack to steal US counterintelligence details
You know what ransomware attackers really, really like? Yes, your backups…
4 Key Questions for Zero-Trust Success
Google to turn on 2FA by default for 150 million users, 2 million YouTubers

Two-factor authentication is a simple way to greatly enhance the security of your account The post Google to turn on 2FA by default for 150 million users, 2 million YouTubers appeared first on WeLiveSecurity

To the moon and hack: Fake SafeMoon app drops malware to spy on you

Cryptocurrencies rise and fall, but one thing stays the same – cybercriminals attempt to cash in on the craze The post To the moon and hack: Fake SafeMoon app drops malware to spy on you appeared first on WeLiveSecurity

S3 Ep53: Apple Pay, giftcards, cybermonth, and ransomware busts [Podcast]
NSO Group’s Pegasus malware was used to spy on Dubai princess’s lawyers during child custody dispute
Ransom disclosure law would give firms 48 hours to disclose payments to ransomware gangs

Several security issues were fixed in MySQL.

Rebase to libssh-0.9.6 Fix CVE-2021-3634

Cherie Blair and the Dubai ruler who spied on his ex-wife’s phone with Pegasus spyware
3 focus areas for DevSecOps success

Updated container images that fix various bugs are now available for Red Hat OpenShift Container Storage 3.11 Update 8 in the Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact

Updated packages that provide Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 9, and fix an important security issue, are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 9 zip release for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows is available. Red Hat Product Security has rated this update as having a security impact

Bottle could be made to cache malicious requests if it received a specially crafted input.

State-sponsored Chinese crims targeted India with tax and COVID phishing
Smashing Security podcast #246: Facebook has fallen
Canopy Parental Control App Wide Open to Unpatched XSS Bugs
VMware ESXi Servers Encrypted by Lightning-Fast Python Script
Are you making good progress with Kubernetes? Cybercriminals are progressing faster
ESPecter Bootkit Malware Haunts Victims with Persistent Espionage
Apache web server zero-day bug is easy to exploit – patch now!
UEFI threats moving to the ESP: Introducing ESPecter bootkit

ESET research discovers a previously undocumented UEFI bootkit with roots going back all the way to at least 2012 The post UEFI threats moving to the ESP: Introducing ESPecter bootkit appeared first on WeLiveSecurity

Running a recent Apache web server version? You probably need to patch it. Now
Twitch Gets Gutted: All Source Code Leaked
Recorded Future’s intelligence summit, Predict 21, is happening next week – and you’re invited!
Things that are not PogChamp: Twitch has its source code, streamer payout data leaked

The updated packages fix a security vulnerabilities: While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Element celebrates The Great Facebook Outage with a Signal bridge for Matrix

Red Hat JBoss Web Server 5.5.1 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated Red Hat JBoss Web Server 5.5.1 packages are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Google to auto-enroll 150m users, 2m YouTubers with two-factor authentication

New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

IP Surveillance Bugs in Axis Gear Allow RCE, Data Theft

security update

security update

Apache Web Server Zero-Day Exposes Sensitive Data
How to Build an Incident-Response Plan, Before Security Disaster Strikes
Facebook Blames Outage on Faulty Router Configuration
Oops! Compound DeFi Platform Gives Out $90M, Would Like it Back, Please
Europol announces two more ransomware busts in Ukraine
Telegraph newspaper bares 10TB of subscriber data and server logs to world+dog

Update to 8.6.0.

Squid could be made to crash or expose sensitive information over the network.

DevSecOps tools, culture and misconceptions: Advice from Red Hatters

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated samba packages that fix several bugs with added enhancement are now available for Red Hat Gluster Storage 3.5 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Updated samba packages that fix several bugs with added enhancement are now available for Red Hat Gluster Storage 3.5 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Update to 8.6.0.

Facebook Outage Drags Down Instagram, WhatsApp, Messenger, Oculus VR
Encrypted & Fileless Malware Sees Big Growth
Lawsuit claims hospital ransomware infection cost baby her life
UK’s £5bn National Cyber Force HQ to be sited in Lancashire beside Defence Secretary’s constituency
Transnational Fraud Ring Bilks U.S. Military Service Members Out of Millions
Ukrainian cops cuff two over $150m ransomware gang allegations, seize $1.3m in cryptocurrency

Imlib2 could be made to denial of service and possibly execute arbitrary code.

€70 million ransomware gang busted in Ukraine
The Pandora Papers is the Panama Papers turned up to 11
Cybersecurity Awareness Month: #BeCyberSmart
Leveraging the “Power of the Crowd” to Fight Cybercrime with a Unique, Collaborative Intrusion Prevention System>

An update that fixes 9 vulnerabilities is now available.

Python could allow unintended access to network services.

Sir Tim Berners-Lee and the BBC stage a very British coup to rescue our data from Facebook and friends
Firewalls? Pfft – it’s no match for my mighty spares-bin PC

Multiple security vulnerabilities have been discovered in fig2dev, utilities for converting XFig figure files. Buffer overflows, out-of-bounds reads and NULL pointer dereferences could lead to a denial-of-service or other unspecified impact.

– Update cranelift crates to version 0.77.0. – Update the wast crate to version 38.0.0. – Update the wat crate to version 1.0.40. – Update the wasmparser crate to version 0.80.1. – Update wasmtime crates to version 0.30.0. – Update the backtrace crate to version 0.3.61. – Update the addr2line crate to version 0.16.0. – […]

– Update cranelift crates to version 0.77.0. – Update the wast crate to version 38.0.0. – Update the wat crate to version 1.0.40. – Update the wasmparser crate to version 0.80.1. – Update wasmtime crates to version 0.30.0. – Update the backtrace crate to version 0.3.61. – Update the addr2line crate to version 0.16.0. – […]

An update that contains security fixes can now be installed.

Update to 94.0.4606.61. Fixes a big pile of security issues: CVE-2021-30542 CVE-2021-30543 CVE-2021-30558 CVE-2021-30625 CVE-2021-30626 CVE-2021-30627 CVE-2021-30628 CVE-2021-30629 CVE-2021-30630 CVE-2021-30631 CVE-2021-30632 CVE-2021-30633 CVE-2021-37972 CVE-2021-37956 CVE-2021-37957 CVE-2021-37958 CVE-2021-37959 CVE-2021-37960 CVE-2021-37961 CVE-2021-37962 CVE-2021-37963

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

Security fix for [PUT CVEs HERE]

One security issue has been discovered in plib. Integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.

2020 was a year of immense change. One thing is for certain – the world collectively witnessed the increase of digital interconnectivity. We began even more to rely on the internet as a conduit to the world. The rise of remote access to businesses, entertainment and interpersonal connections surged. The death of distance accelerated. The […]

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

Security fix for [PUT CVEs HERE]

– CVE-2021-22947 – STARTTLS protocol injection via MITM – CVE-2021-22946 – protocol downgrade required TLS bypassed – CVE-2021-22945 – use-after-free and double-free in MQTT sending

MFA Glitch Leads to 6K+ Coinbase Customers Getting Robbed
Internet Archive’s 2046 Wayforward Machine says Google will cease to exist

An issue has been found in openssl1.0, a Secure Sockets Layer library. The issue is related to read buffer overruns while processing ASN.1 strings.

Two issues have been found in curl, a command line tool and an easy-to-use client-side library for transferring data with URL syntax.

Sure, you can do Kubernetes at scale. But can you do it securely too?
3.1M Neiman Marcus Customer Card Details Breached
Hackers could force locked iPhones to make contactless payments

Flaws in Apple Pay and Visa could allow criminals to make arbitrary contactless payments – no authentication needed, research finds The post Hackers could force locked iPhones to make contactless payments appeared first on WeLiveSecurity

ESET Threat Report T2 2021

A view of the T2 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T2 2021 appeared first on WeLiveSecurity

That ‘anti-NSO Pegasus spyware’ download is actually a Trojan – so don’t touch it
Gift card fraud: four suspects hit with money laundering charges
Flubot Malware Targets Androids With Fake Security Updates
IKEA: Cameras were hidden in the ceiling above warehouse toilets for ‘health and safety’