Menu

Latest articles

Make-me-admin holes found in Windows, Linux kernel
Journo who went to prison for 2 years for breaking US cyber-security law is jailed again
Researchers: NSO Group’s Pegasus Spyware Should Spark Bans, Apple Accountability
Law Firm to the Fortune 500 Breached with Ransomware
Fortinet’s security appliances hit by remote code execution vulnerability
Apple iPhone patches are out – no news if recent Wi-Fi bug is fixed
Why Your Business Needs a Long-Term Remote Security Strategy
16-Year-Old HP Printer-Driver Bug Impacts Millions of Windows Machines

Several security issues were fixed in systemd.

A New Security Paradigm: External Attack Surface Management

The Qualys Research Labs discovered that an attacker-controlled allocation using the alloca() function could result in memory corruption, allowing to crash systemd and hence the entire operating system.

MosaicLoader Malware Delivers Facebook Stealers, RATs
Northern Train’s ticketing system out to lunch as ransomware attack shuts down servers
Verified: UK.gov launching plans for yet another digital identity scheme
6 Must-Have Open-Source Tools to Secure Your Linux Server>
US legal eagles representing Apple, IBM, and more take 5 months to inform clients of ransomware data breach

The Qualys Research Labs discovered that an attacker-controlled allocation using the alloca() function could result in memory corruption, allowing to crash systemd and hence the entire operating system.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An integer overflow flaw was found in glibc that may result in reading of arbitrary memory when wordexp is used with a specially crafted untrusted regular expression input (CVE-2021-35942). References:

This update provides Mbed TLS 2.16.11, with a number of bug fixes, including security fixes. The intermediate version 2.16.10 are included security fixes. See the referenced release notes and advisories for details.

What’s Next for REvil’s Victims? 
Unpatched iPhone Bug Allows Remote Device Takeover

security update

Cloudstar – IT provider for real estate, finance, insurance worlds – downed by ransomware
Ruthless Attackers Target Florida Condo Collapse Victims
TLS Email Encryption Explained – How To Encrypt Email with TLS>
Protecting Phones From Pegasus-Like Spyware Attacks
Leaked NSO Group Data Hints at Widespread Pegasus Spyware Infections
UK and chums call out Chinese Ministry of State Security for Hafnium Microsoft Exchange Server attacks
Keeping Your System Secure is Easier than Ever with LinuxSecurity Customized Advisories!>
Patch your Linux, hackers are actively exploiting the “Dirty COW” flaw>

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. CVE-2021-30547

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update for nettle is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Amnesty International and French media protection org claim massive misuse of NSO spyware
S3 Ep41: Crashing iPhones, PrintNightmares, and Code Red memories [Podcast]

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the stable distribution (buster), these problems have been fixed in

Multiple vulnerabilities have been found in Dovecot, the worst of which could result in a Denial of Service condition.

New upstream version (90.0) Disabled Wayland on KDE by default due to popup bugs.

Fix crash in ThemeService (thanks to OpenSUSE) —- Security fixes. CVE-2021-30506 CVE-2021-30507 CVE-2021-30508 CVE-2021-30509 CVE-2021-30510 CVE-2021-30511 CVE-2021-30512 CVE-2021-30513 CVE-2021-30514 CVE-2021-30515 CVE-2021-30516 CVE-2021-30517 CVE-2021-30518 CVE-2021-30519 CVE-2021-30520 CVE-2021-30521 CVE-2021-30522 CVE-2021-30523 CVE-2021-30524 CVE-2021-30525

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

Multiple vulnerabilities have been found in MediaWiki, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been found in Apache Commons FileUpload, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been found in Apache, the worst of which could result in a Denial of Service condition.

Linux Variant of HelloKitty Ransomware Targets VMware ESXi Servers
Top CVEs Trending with Cybercriminals
Instagram Security Check hopes to make life harder for account hackers
You’ll want to shut down the Windows Print Spooler service (yes, again): Another privilege escalation bug found
The Evolving Role of the CISO
Critical Juniper Bug Allows DoS, RCE Against Carrier Networks
Sports events and online streaming: prepare your cybersecurity

If you’ll be watching Sports Streaming events on your SmartTV, laptop, tablet or cell phone, learn the tips to keep you and your personal data safe. The post Sports events and online streaming: prepare your cybersecurity appeared first on WeLiveSecurity

Wanted: State-backed bandits planning cyberattacks on US infrastructure. Reward: $10m
More PrintNightmare: “We TOLD you not to turn the Print Spooler back on!”
Windows 0-Days Used Against Dissidents in Israeli Broker’s Spyware
Want to earn $10 million? Snitch on a cybercrook!
Irish hospital sued by cancer patient after ransomware attack

The package vivaldi before version 4.0.2312.41-1 is vulnerable to arbitrary code execution.

The package chromium before version 91.0.4472.164-1 is vulnerable to arbitrary code execution.

The package systemd before version 249-2 is vulnerable to denial of service.

The package varnish before version 6.6.1-1 is vulnerable to url request injection.

The package mbedtls before version 2.26.0-1 is vulnerable to information disclosure.

The package python-pillow before version 8.3.0-1 is vulnerable to arbitrary code execution.

The Matt Hancock CCTV footage leak – why it’s right for the ICO to investigate
Microsoft: New Unpatched Bug in Windows Print Spooler           
Microsoft, Google, Citizen Lab blow lid off zero-day bug-exploiting spyware sold to governments

It’s not just that they’re making headlines more often. Ransomware rates really are rising. Given the recent spate of high-profile attacks, it’s worth remembering the difference between standard backup and high-availability replication. Our research suggests that the costs of ransomware for businesses can amount to much more than an extortion payment. They include lost hours […]

Zero-Day Attacks on Critical WooCommerce Bug Threaten Databases

security update

The Code Red worm 20 years on – what have we learned?
Microsoft Patch Tuesday fixes 13 critical flaws, including 4 under active attack

The latest Patch Tuesday brings a new batch of security updates addressing a total of 117 vulnerabilities The post Microsoft Patch Tuesday fixes 13 critical flaws, including 4 under active attack appeared first on WeLiveSecurity

Fake Zoom App Dropped by New APT ‘LuminousMoth’
This is the data watchdog! Surrender your Matt Hancock smoochy-kiss pics right now!
SonicWall Warns Secure VPN Hardware Bugs Under Attack
US offers $10 million reward in hunt for state-sponsored ransomware attackers
Regulating facial recognition technology? It’s the ‘Wild West out there,’ says US law boffin

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

This advisory resolves CVE issues filed against XP2 releases that have been fixed in the underlying EAP 7.3.x base. There are no changes to the EAP XP2 code base. NOTE: This advisory is informational only. There are no code changes

Smashing Security podcast #236: Stingrays, soccer, and smart homes
Safari Zero-Day Used in Malicious LinkedIn Campaign

Several vulnerabilities were discovered in php5, a server-side, HTML-embedded scripting language. An attacker could cause denial of service (DoS), memory corruption and potentially execution of arbitrary code, and server-side request forgery (SSRF) bypass.

NortonLifeLock sniffs around Avast, announces ‘advanced discussions’ for acquisition
Report sheds light on ‘cocky’ but ‘creative’ Mespinoza ransomware group
Restoring your privacy costs money, which makes it a marker of class

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

So nice of China to put all of its network zero-day vulns in one giant database no one will think to break into

security update

Cryptominer Farm Rigged with 3,800 PS4s Busted in Ukraine
Facial-recognition technology gets a smack in the chops from civil rights campaigners
Choosing your MSP: What the Kaseya incident tells us about third‑party cyber risk

Lessons to learn from the Kaseya cyberincident to protect your business’ data when doing business with a MSP. The post Choosing your MSP: What the Kaseya incident tells us about third‑party cyber risk appeared first on WeLiveSecurity

The hybrid workplace: What does it mean for cybersecurity?

How can organizations mitigate the risk of damaging cyberattacks while juggling the constantly changing mix of office and off-site workers? The post The hybrid workplace: What does it mean for cybersecurity? appeared first on WeLiveSecurity

Linux-Focused Cryptojacking Gang Tracked to Romania
Apps Built Better: Why DevSecOps is Your Security Team’s Silver Bullet
Trickbot Malware Rebounds with Virtual-Desktop Espionage Module
Home delivery scams get smarter – don’t get caught out