Menu

Latest articles

Emotet botnet takedown – what you need to know

An update that fixes one vulnerability is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

How do most cloud security breaches happen? Orca’s “State of Public Cloud Security” report reveals all
If you want to leg it through China’s Great Firewall, don’t forget to pull on your newly darned Shadowsocks
Smashing Security podcast #212: Dutch leaks, Peeping Toms, and researchers under fire
Apple patches three iOS zero‑days under attack

The company emits emergency updates to fix bugs affecting devices ranging from iPhones to Apple Watches The post Apple patches three iOS zero‑days under attack appeared first on WeLiveSecurity

TeamTNT Cloaks Malware With Open-Source Tool
FTC warns of scam website that promises refund for victims of online scams
NetWalker Ransomware Suspect Charged: Tor Site Seized
Update your iPhone now to protect against vulnerabilities that hackers may have actively exploited

Update to 2.53.6

Update to latest upstream version.

Remote Attackers Can Now Reach Protected Network Devices via NAT Slipstreaming
Knock, knock. Who’s there? NAT. Nat who? A NAT URL-borne killer

security update

North Korean hackers attempt to hack security researchers investigating zero-day vulnerabilities
Stack Overflow 2019 hack was guided by advice from none other than… Stack Overflow
Sudo Bug Gives Root Access to Mass Numbers of Linux Systems
ADT Security Camera Flaws Open Homes to Eavesdropping
Emotet Takedown Disrupts Vast Criminal Infrastructure; NetWalker Site Offline
Command ‘n’ control botnet of notorious Emotet Windows ransomware shut down in multinational police raid
Wormable Android malware spreads via WhatsApp messages

“Download This application and Win Mobile Phone”, reads the message attempting to trick users into downloading a fake Huawei app The post Wormable Android malware spreads via WhatsApp messages appeared first on WeLiveSecurity

Today’s ‘sophisticated cyber attack’ victim is the Woodland Trust: Pre-Xmas breach under investigation
Apple critical patches fix in-the-wild iPhone exploits – update now!

An update that fixes 26 vulnerabilities is now available.

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Apple Patches Three Actively Exploited Zero-Days, Part of iOS Emergency Update

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Multiple vulnerabilities have been found in phpMyAdmin, allowing remote attackers to conduct XSS.

Multiple vulnerabilities have been found in Telegram, the worst of which could result in information disclosure.

US cyber intelligence officer jailed for kidnapping her kid, trying to hawk top secrets to Russia in Mexico
Nvidia Squashes High-Severity Jetson DoS Flaw
DanaBot Malware Roars Back into Relevancy
Decade-old bug in Linux world’s sudo can be abused by any logged-in user to gain root privileges
Apple emits emergency iOS security updates while warning holes may have been exploited in wild by hackers

security update

23M Gamer Records Exposed in VIPGames Leak
Ghost hack – criminals use deceased employee’s account to wreak havoc
Criminal, Domestic Violence Case Info Exposed in Cook County Leak
Nefilim Ransomware Gang Hits Jackpot with Ghost Account
North Korea Targets Security Researchers in Elaborate 0-Day Campaign
I was targeted by North Korean 0-day hackers using a Visual Studio project, vuln hunter tells El Reg

The Qualys Research Labs discovered a heap-based buffer overflow vulnerability in sudo, a program designed to provide limited super user privileges to specific users. Any local user (sudoers and non-sudoers) can exploit this flaw for root privilege escalation.

XStream: remote code execution due to insecure XML deserialization when relying on blocklists (CVE-2020-26217) SL7 noarch xstream-1.3.1-12.el7_9.noarch.rpm xstream-javadoc-1.3.1-12.el7_9.noarch.rpm – Scientific Linux Development Team

TikTok Flaw Lay Bare Phone Numbers, User IDs For Phishing Attacks

An update that fixes 26 vulnerabilities is now available.

UK Cabinet Office spokesman tells House of Lords: We’re not being complacent about impact of SolarWinds hack

An update for cryptsetup is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for gnome-settings-daemon is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for net-snmp is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

North Korea infected infosec bods with backdoors via dodgy blog pages, Visual Studio files – Google

Skyrocketing Bitcoin prices prompt resurgence in mining malware As the price of the cryptocurrency Bitcoin pushes record highs, there’s been a corresponding resurgence in cryptomining malware. Illicit miners had slipped off the radar as Bitcoin’s value plummeted in recent years, but now authors are hoping to profit off the latest price increase. Researchers have identified […]

Biden said to be assembling cyber dream team to sort out US govt computer security
Breaking Down Joe Biden’s $10B Cybersecurity ‘Down Payment’
Outgoing FCC Chair Issues Final Security Salvo Against China
2.28M MeetMindful Daters Compromised in Data Breach

security update

Digital burglars break into the Australian Securities and Investments Commission
Cisco DNA Center Bug Opens Enterprises to Remote Attack
SonicWall Breach Stems from ‘Probable’ Zero-Days

An update that contains security fixes can now be installed.

Man arrested after UK school reports wiped hard drives on devices connected to network
Hundreds of thousands of cryptocurrency investors put at risk after BuyUCoin security breach

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest() (CVE-2020-26137). References:

It was discovered that pip did not properly sanitize the filename during pip install. A remote attacker could possible use this issue to read and write arbitrary files on the host filesystem as root, resulting in a directory traversal attack (CVE-2019-20916).

Showering malware-laced laptops on UK schoolchildren is the wrong way to teach them about cybersecurity

The update for gst-plugins-bad1.0 released as DSA 4833-1 choosed a package version incompatible with binNMUs and prevented upgrades to the fixed packages. Updated gst-plugins-bad1.0 packages are now available to correct this issue.

Several vulnerabilities were discovered in salt, a powerful remote execution manager. The flaws could result in authentication bypass and invocation of Salt SSH, creation of certificates with weak file permissions via the TLS execution module or shell injections with the

An update that fixes 35 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Security fixes: – fix buffer overrun in EUC-KR conversion module [bz #2497] (CVE-2019-25013) – arm: CVE-2020-6096: Fix multiarch memcpy for negative length [BZ #25620] – arm: CVE-2020-6096: fix memcpy and memmove for negative length [BZ #25620] – iconv: Fix incorrect UCS4 inner loop bounds [BZ #26923] (CVE-2020-29562)

Rebase SDDM to 0.19.0

security update

security update

security update

An update that fixes one vulnerability is now available.

ADT techie admits he peeked into women’s home security cams thousands of times to watch them undress, have sex

An update that fixes one vulnerability is now available.

The container suse/sle15 was updated. The following patches have been included in this update:

Microsoft Edge, Google Chrome Roll Out Password Protection Tools
Amazon Kindle RCE Attack Starts with an Email

Update to 87.0.4280.141. Fixes: CVE-2021-21106 CVE-2021-21107 CVE-2021-21108 CVE-2021-21109 CVE-2021-21110 CVE-2021-21111 CVE-2021-21112 CVE-2021-21113 CVE-2020-16043 CVE-2021-21114 CVE-2020-15995 CVE-2021-21115 CVE-2021-21116

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling (CVE-2020-10719). References:

A heap-based buffer overflow vulnerability was found in the blosc library. Depending on how the library is used, if there is a lack of space to write compressed data, an attacker might exploit this flaw to crash the program or potentially execute arbitrary code (CVE-2020-29367).

ADT Tech Hacks Home-Security Cameras to Spy on Women
Scottish enviro bods shrug off ransomware gang’s extortion attempt as 4,000 files dumped online, saying it’s nothing big
Discord-Stealing Malware Invades npm Packages
Ransomware Attackers Publish 4K Private Scottish Gov Agency Files
Vadokrist: A wolf in sheep’s clothing

Another in our occasional series demystifying Latin American banking trojans The post Vadokrist: A wolf in sheep’s clothing appeared first on WeLiveSecurity

Clop ransomware gang clips sensitive files from Atlantic Records’ London ad agency The7stars, dumps them online
Microsoft Edge goes homomorphic: Nobody will see your credentials… but you’ll need to sign in to use it
US administration adds “subliminal” ad to White House website

An update that fixes 13 vulnerabilities is now available.