Menu

Latest articles

It was discovered that the previous upload of the package prosody versioned 0.9.12-2+deb9u3 introduced a regression in the mod_auth_internal_hashed module. Big thanks to Andre Bianchi for the reporting an issue and for testing the update.

Update to 1.6.15 Security If an authenticated client connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur. Affects versions 1.6 to 2.0.10 inclusive.

CVE-2021-3560 mitigation

Backport fix for CVE-2021-33503.

2.0.11 Security If an authenticated client connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur. Affects versions 1.6 to 2.0.10 inclusive. Broker Fix possible crash having just upgraded from 1.6 if per_listener_settings true is set, and a SIGHUP is sent to the broker before a client has […]

This updates nettle to the latest upstream release 3.7.3, which contains security fix for RSA decryption: https://lists.lysator.liu.se/pipermail/nettle- bugs/2021/009545.html

Can *YOU* blow a PC speaker using only a Linux kernel driver?
Most health apps engage in unhealthy data‑harvesting habits

Most medical and fitness apps in Google Play have tracking capabilities enabled and their data collection practices aren’t transparent The post Most health apps engage in unhealthy data‑harvesting habits appeared first on WeLiveSecurity

What’s Making Your Company a Ransomware Sitting Duck
Repairmen suspected of installing ransomware on customers’ PCs. Arrests in South Korea
Carnival Cruise Cyber-Torpedoed by Cyberattack

The package connman before version 1.40-1 is vulnerable to arbitrary code execution.

The package grub before version 2:2.06-1 is vulnerable to multiple issues including access restriction bypass and arbitrary code execution.

The package go before version 2:1.16.5-1 is vulnerable to multiple issues including insufficient validation, url request injection and denial of service.

Multiple security vulnerabilities were discovered in Tor, a connection-based low-latency anonymous communication system, which could result in denial of service or spoofing.

Insider Versus Outsider: Navigating Top Data Loss Threats
CREST president Ian Glover to retire after 13 years – but where’s the transparency, bossman?
‘Oddball’ Malware Blocks Access to Pirated Software
Faux ‘DarkSide’ Gang Takes Aim at Global Energy, Food Sectors
Poltergeist attack could leave autonomous vehicles blind to obstacles – or haunt them with new ones
5 essential things to do before ransomware strikes

By failing to prepare you are preparing to fail – here’s what you can do today to minimize the impact of a potential ransomware attack in the future The post 5 essential things to do before ransomware strikes appeared first on WeLiveSecurity

Several security issues were fixed in GRUB 2.

Google dishes out homemade SLSA, a recipe to thwart software supply-chain attacks

An update that solves two vulnerabilities and has one errata is now available.

Clop Raid: A Big Win in the War on Ransomware?
Ex-Brave staffer launches GDPR sueball in Germany over tech giants’ real-time bidding for ad inventory
Cisco Smart Switches Riddled with Severe Security Holes
Geek Squad Vishing Attack Bypasses Email Security to Hit 25K Mailboxes
OSINT 101: What is open source intelligence and how is it used?

OSINT can be used by anyone, both for good and bad ends – here’s how defenders can use it to keep ahead of attackers The post OSINT 101: What is open source intelligence and how is it used? appeared first on WeLiveSecurity

CVS Health Records for 1.1 Billion Customers Exposed
Tim Cook: Sideloading is a disaster and proposed App Store reforms would harm user privacy and security
S3 Ep37: Quantum crypto, refunding Bitcoins, and Alpaca problems [Podcast]

Several security issues were fixed in libxml2.

Threat Actors Use Google Docs to Host Phishing Attacks
Hiccup in Akamai’s DDoS Mitigation Service Triggers Massive String of Outages

The package python-django before version 3.2.4-1 is vulnerable to multiple issues including insufficient validation and directory traversal.

The package radare2 before version 5.3.1-1 is vulnerable to denial of service.

The package thefuck before version 3.31-1 is vulnerable to arbitrary file overwrite.

The package aspnet-runtime-3.1 before version 3.1.16.sdk116-1 is vulnerable to denial of service.

The package aspnet-runtime before version 5.0.7.sdk204-1 is vulnerable to denial of service.

Smashing Security podcast #232: Zoomolympics and language matters
Biden to Putin: Get your ransomware gangs under control and don’t you dare cyber-attack our infrastructure
South Korea has a huge problem with digital sex crimes against women says Human Rights Watch
GPRS-era mobile data encryption algorithm GEA/1 was ‘weak by design’, still lingers in today’s phones
How to hack a bicycle – Peloton Bike+ rooting bug patched

security update

School teacher accused of pocketing $1m+ in insider trading using tips from Silicon Valley pal
IKEA Fined $1.2M for Elaborate ‘Spying System’
Exclusive Ransomware Poll: 80% of Victims Don’t Pay Up
Microsoft takes down large‑scale BEC operation

The fraudsters ran their campaigns from the cloud and used phishing and email forwarding rules to steal their targets’ financial information. The post Microsoft takes down large‑scale BEC operation appeared first on WeLiveSecurity

Takeaways from the Colonial Pipeline Ransomware Attack
Ryuk ransomware recovery cost us $8.1m and counting, says Baltimore school authority
Euros-Driven Football Fever Nets Dumb Passwords
We’ve found another reason not to use Microsoft’s Paint 3D – researchers
Clop ransomware suspects busted in Ukraine, money and motors seized
Cuffed: Ukraine police collar six Clop ransomware gang suspects in joint raids with South Korean cops
5 Tips to Prevent and Mitigate Ransomware Attacks
Avaddon Ransomware Gang Evaporates Amid Global Crackdowns  
Papa don’t breach: UK data watchdog fines that other pizza place £10,000 over unsolicited marketing blitz

Upstream details at : https://access.redhat.com/errata/RHSA-2018:3140

Upstream details at : https://access.redhat.com/errata/RHSA-2021:1512

Researchers: Booming Cyber-Underground Market for Initial-Access Brokers
Peloton Bike+ Bug Gives Hackers Complete Control

Several security issues were fixed in BlueZ.

What is Azure Confidential Ledger?

Several security issues were fixed in BlueZ.

An update for gupnp is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for openvswitch2.11 is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Alibaba suffers billion-item data leak of usernames and mobile numbers
Millions of Connected Cameras Open to Eavesdropping
Zoll Defibrillator Dashboard would execute contents of random Excel files ordinary users could import
Malicious PDFs Flood the Web, Lead to Password-Snarfing
Vishing: What is it and how do I avoid getting scammed?

How do vishing scams work, how do they impact businesses and individuals, and how can you protect yourself, your family and your business? The post Vishing: What is it and how do I avoid getting scammed? appeared first on WeLiveSecurity

Microsoft Disrupts Large-Scale, Cloud-Based BEC Campaign
NCSC chief: Ransomware is more of a threat to Britain than hostile nations’ spies
Insider Risks In the Work-From-Home World
SASE & Zero Trust: The Dream Team

kernel: Integer overflow in Intel(R) Graphics Drivers (CVE-2020-12362) * kernel: Use after free via PI futex state (CVE-2021-3347) * kernel: use-after-free in n_tty_receive_buf_common function in drivers/tty/n_tty.c (CVE-2020-8648) * kernel: Improper input validation in some Intel(R) Graphics Drivers (CVE-2020-12363) * kernel: Null pointer dereference in some Intel(R) Graphics Drivers (CVE [More…]

TimeCache aims to block side-channel cache attacks – without hurting performance

An update for ceph, ceph-ansible, ceph-iscsi, python-waitress, and tcmu-runner is now available for Red Hat Ceph Storage 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Microsoft Gets Second Shot at Banning hiQ from Scraping LinkedIn User Data
Brit IT firms wound up by court order after fooling folk into paying for ‘support’ over fake computer errors
“Face of Anonymous” suspect deported from Mexico to face US hacking charges
Apple Hurries Patches for Safari Bugs Under Active Attack
The latest REvil ransomware victim? Sol Oriens. Oh, a US nuclear weapons contractor

Open Liberty 21.0.0.6 Runtime is now available from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in ImageMagick.

gupnp: allows DNS rebinding which could result in tricking browser into triggering actions against local UPnP services (CVE-2021-33516) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_ [More…]

When security gets physical: Mossad boss hints at less-than-subtle Stuxnet followup
NATO summit communiqué compares repeat cyberattacks to armed attacks – and stops short of saying ‘one-in, all-in’ rule will always apply

Red Hat OpenShift Container Platform release 4.7.16 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

G7 nations call out Russia for harbouring ransomware crims ahead of Biden-Putin powwow
Utilities ‘Concerningly’ at Risk from Active Exploits
Ex-NSA leaker Reality Winner released from prison early for ‘exemplary’ behavior
Microsoft Teams: Very Bad Tabs Could Have Led to BEC
Moobot Milks Tenda Router Bugs for Propagation
Volkswagen Vendor Exposed Data of 3.3m Drivers
Norton dodges UK courts after telling Brit watchdog it will be nicer to consumers
Ransomware is the biggest threat, says GCHQ cybersecurity chief
Meat supplier JBS probed after paying $11 million ransom to attackers