Menu

Latest articles

Rogue Marketplace AlphaBay Reboots

security update

security update

US govt scores a point against Assange in run-up to extradition appeal showdown
Black Hat: Novel DNS Hack Spills Confidential Corp Data

The system could be made to crash or run programs as an administrator.

Lukas Euler discovered a path traversal vulnerability in commons-io, a Java library for common useful IO related classes. When invoking the method FileNameUtils.normalize with an improper input string, like “//../foo”, or “\..foo”, the result would be the same value, thus possibly providing access

AdLoad Malware 2021 Samples Skate Past Apple XProtect
Think your backups will protect you against ransomware? They’re top of the target list
IISerpent: Malware‑driven SEO fraud as a service

The last in our series on IIS threats introduces a malicious IIS extension used to manipulate page rankings for third-party websites The post IISerpent: Malware‑driven SEO fraud as a service appeared first on WeLiveSecurity

Ransomware Payments Explode Amid ‘Quadruple Extortion’
Lockbit ransomware attack didn’t affect ops, claims Accenture amid lurid payoff rumours
S3 Ep45: Routers attacked, hacking tool hacked, and betrayers betrayed [Podcast]
Accenture hit by apparent ransomware attack
QR Code Scammers Get Creative with Bitcoin ATMs
Microsoft Warns: Another Unpatched PrintNightmare Zero-Day

An update that solves 5 vulnerabilities, contains one feature and has one errata is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability, contains one feature is now available.

Using RHEL System Roles to automate and manage Network Bound Disk Encryption
COVID-19 cases surge as do sales of fake vaccination cards – around $100 for something you could get free

USN-3809-1 introduced a regression in OpenSSH.

Singaporean telco leaked personal data of over 57,000 customers

An update for .NET 5.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for rh-dotnet50-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Thief hands back at least a third of $600m in crypto-coins stolen from Poly Network
Accenture Confirms LockBit Ransomware Attack
NSA Watchdog Will Review Tucker Carlson Spying Claims
Hacker grabs $600m in cryptocash from blockchain company Poly Networks
Ransomware runs rampant, so how can you combat this threat?

A new paper explains how ransomware has become one of the top cyberthreats of the day and how your organization can avoid becoming the next victim The post Ransomware runs rampant, so how can you combat this threat? appeared first on WeLiveSecurity

‘Friends’ Reunion Anchors Video Swindle
Kaseya’s ‘Master Key’ to REvil Attack Leaked Online
SAP Patches Nine Critical & High-Severity Bugs
Crypto Hack Earned Crooks $600 Million

Philipp Jeitner and Haya Shulman discovered a stack-based buffer overflow in libspf2, a library for validating mail senders with SPF, which could result in denial of service, or potentially execution of arbitrary code when processing a specially crafted SPF record.

Microsoft responds to PrintNightmare by making life that little bit harder for admins

Philipp Jeitner and Haya Shulman discovered a stack-based buffer overflow in libspf2, a library for validating mail senders with SPF, which could result in denial of service, or potentially execution of arbitrary code when processing a specially crafted SPF record.

Chinese espionage group targets Israel while suggesting the source could be Iran
Avast, ye takeover lawyers! Norton LifeLock to acquire security rival

Red Hat OpenShift Container Platform release 4.7.23 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes 27 vulnerabilities is now available.

Boffins propose Pretty Good Phone Privacy to end pretty invasive location data harvesting by telcos
Connected Farms Easy Pickings for Global Food Supply-Chain Hack

Security fix for CVE-2021-34558

Actively Exploited Windows Zero-Day Gets a Patch

Security fix for CVE-2021-34558

$600m in cryptocurrencies swiped from Poly Network servers after security snafu

security update

Microsoft Patch Tuesday bug drought: No, it’s not climate change or unexpected code quality improvements

The issue at the heart of ransomware insurance will be familiar to most parents of young children: rewarding bad behavior only invites more of the same, so it’s generally not a good idea. But critics of the ransomware insurance industry argue that’s exactly what the practice does. Ransomware insurance has by now long been suspected […]

eCh0raix Ransomware Variant Targets QNAP, Synology NAS Devices
Deepfakes – the bot made me do it

As fraud involving highly believable synthetic media soars, what can you do to avoid getting scammed? The post Deepfakes – the bot made me do it appeared first on WeLiveSecurity

DEF CON 29: Satellite hacking 101

How peering into the innards of a future satellite can make cybersecurity in space more palatable The post DEF CON 29: Satellite hacking 101 appeared first on WeLiveSecurity

IISpy: A complex server‑side backdoor with anti‑forensic features

The second in our series on IIS threats dissects a malicious IIS extension that employs nifty tricks in an attempt to secure long-term espionage on the compromised servers The post IISpy: A complex server‑side backdoor with anti‑forensic features appeared first on WeLiveSecurity

Home and small business routers under attack – how to see if you are at risk
Chaos Malware Walks Line Between Ransomware and Wiper
Fuzz Off: How to Shake Up Code to Get It Right – Podcast
Learn how to build a culture of security with 1Password
Cutting Through the Noise from Daily Alerts
1M Stolen Credit Cards Hit Dark Web for Free

Red Hat OpenShift Virtualization release 2.6.6 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Tails 4.21 Is Out – Here’s What’s New & How To Get Started>

An update that fixes 27 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that solves 7 vulnerabilities and has 58 fixes is now available.

An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Solving authorization for software developers
We’ll drop SBOMs on UK.gov to solve Telecoms Security Bill’s technical demands, beams Cisco
Splunk spots malware targeting Windows Server on AWS to mine Monero

security update

security update

Apple responds to critics of CSAM scan plan with FAQs – says it’d block governments subverting its system
‘Glowworm’ Attack Turns Power Light Flickers into Audio
Black Hat: Scaling Automated Disinformation for Misery and Profit
Auth Bypass Bug Exploited, Affecting Millions of Routers
Android Malware ‘FlyTrap’ Hijacks Facebook Accounts

Perl could be made to run arbitrary programs.

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3028

Upstream details at : https://access.redhat.com/errata/RHSA-2021:1002

Black Hat USA 2021 & DEF CON 29 Highlights & Key Takeaways>

An update that fixes one vulnerability is now available.

This update provides a new upstream version.

An update for microcode_ctl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Black Hat security conference returns to Las Vegas – complete with hacks to quiet the hotel guest from hell

security update

Several vulnerabilities were discovered in Bluez, the Linux Bluetooth protocol stack. CVE-2020-26558 / CVE-2021-0129

S3 Ep44: Unreported holes, retro computing, and tech support for malware [Podcast]

– Resolves: rhbz#1985153 – mod_auth_openidc-2.4.9 is available – Resolves: rhbz#1986103 – CVE-2021-32786 mod_auth_openidc: open redirect in oidc_validate_redirect_url() – Resolves: rhbz#1986396 – CVE-2021-32791 mod_auth_openidc: hardcoded static IV and AAD with a reused key in AES GCM encryption – Resolves:

This kernel-linus update is based on upstream 5.10.56 and fixes atleast the following security issues: In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store

This kernel update is based on upstream 5.10.56 and fixes atleast the following security issues: In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Several vulnerabilities have been found in Ansible, a configuration management, deployment and task execution system, which could result in information disclosure or argument injection. In addition a race condition in become_user was fixed.

security update

Golang Cryptomining Worm Offers 15% Speed Boost
All your DNS were belong to us: AWS and Google Cloud shut down spying vulnerability
Amazon Kindle Vulnerable to Malicious EBooks

A cyber resilience strategy “I have used a lot of different security products over the years, and I get approached by a lot of vendors,” says Pedro Nuñez. As president and CEO of New England based MSP IT Management Solutions, Nuñez is always on the lookout for products that go beyond just a traditional security […]