Menu

Latest articles

SaaS Attacks: Lessons from Real-Life Misconfiguration Exploits
Vivaldi update unleashes the ‘Cookie Crumbler’ to simply block any services asking for consent (sites may break)
S3 Ep30: AirDrop worries, Linux pests and ransomware truths [Podcast]
DoppelPaymer Gang Leaks Files from Illinois AG After Ransom Negotiations Break Down
Billions in data protection lawsuits rides on Google’s last-ditch UK Supreme Court defence for Safari Workaround sueball
Smashing Security podcast #225: Master of your domain, gripe sites, and John Deere Farmergeddon
48 ways you can avoid file-scrambling, data-stealing miscreants – or so says the Ransomware Task Force
Prime targets: Governments shouldn’t go it alone on cybersecurity

A year into the pandemic, ESET reveals new research into activities of the LuckyMouse APT group and considers how governments can rise to the cybersecurity challenges of the accelerated shift to digital The post Prime targets: Governments shouldn’t go it alone on cybersecurity appeared first on WeLiveSecurity

When you’re building a cybersecurity pro, you need to get the foundations right
Digital Ocean springs a leak: Miscreant exploits hole to peep on unlucky customers’ billing details for two weeks

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp3 was updated. The following patches have been included in this update:

New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Update to Jetty 9.4.40 (fixes multiple CVEs)

security update

Microsoft Office SharePoint Targeted With High-Risk Phish, Ransomware Attacks
Etsy-owned musical instrument marketplace Reverb suffers data breach
Google Chrome V8 Bug Allows Remote Code-Execution
Apple patches severe macOS security flaw

Mac users are being urged to update to macOS Big Sur 11.3 as at least one threat group is exploiting the zero-day bug to sneak past the operating system’s built-in security mechanisms The post Apple patches severe macOS security flaw appeared first on WeLiveSecurity

Ransomware crooks who broke into Merseyrail used director’s email address to brag about it – report
Gamers update! Nvidia patches GPU driver kernel escalation bugs
Brit MPs and campaigners come together to oppose COVID status certificates as ‘divisive and discriminatory’
Chase Bank Phish Swims Past Exchange Email Protections
Was the email account of Merseyrail’s MD hacked to spread word of ransomware attack?
Cybersecurity World Mourns Over Security Researcher Dan Kaminsky’s Passing>
Protect Your WordPress Sites with CrowdSec>
Minified Linux Offerings Boost Containers and Edge Processing>
Arrest after man replaces official COVID-19 check-in signs with anti-vaxxer QR code
Update your Macs! Malware attacks can exploit critical flaws in Apple’s built-in defences
Nintendo Sues Video-Game Pirates
Linux Kernel Bug Opens Door to Wider Cyberattacks
Here’s what Russia’s SVR spy agency does when it breaks into your network, says US CISA infosec agency
Smishing: Why Text-Based Phishing Should Be on Every CISO’s Radar
Babuk Ransomware Gang Targets Washington D.C. Police
Ransomware: don’t expect a full recovery, however much you pay
Washington DC police force confirms data breach after ransomware upstart Babuk posts trophies to Tor blog
Shells makes using Linux in the cloud incredibly easy>
Apple Patches Zero-Day MacOS Bug That Can Bypass Anti-Malware Defenses
Talking malware party tricks and cybersecurity trends

Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

An update for openldap is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for nss is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Patched Exchange to head off Hafnium? You might only be halfway to safety
Flubot Spyware Spreading Through Android Devices
HashiCorp reveals exposure of private code-signing key after Codecov compromise
Nvidia Warns: Severe Security Bugs in GPU Driver, vGPU Software
Security vendor Proofpoint snapped up by private equity for $12.3bn but still in search of profit
Secure, orchestrate, and manage your company’s infrastructure secrets with 1Password Secrets Automation
Naked Security Live – Just how (un)safe is AirDrop?
Scam victims find same fraudulent ads lurking on Facebook and Google even after flagging them up
4 common ways scammers use celebrity names to lure victims

All that glitters is not gold – look out for fake celebrity endorsements and other con jobs that aren’t going out of fashion any time soon The post 4 common ways scammers use celebrity names to lure victims appeared first on WeLiveSecurity

Ethics isn’t a county east of London, but it’s the only way to look at security
GCHQ boss warns China can rewrite ‘the global operating system’ in its own authoritarian image
Cloud security threats are growing – crucially, is your skills toolkit keeping pace?
India orders takedowns of social media posts it claims harm fight against raging COVID-19 outbreak
Emotet malware self-destructs after cops deliver time-bomb DLL to infected Windows PCs
Homebrew fixes Cask repo GitHub Actions bug that would have let anyone sneak malicious code onto machines
Volunteer-run pirate Manga website attacked, loses hashed passwords, has ‘nobody’ to fix the mess

security update

security update

security update

security update

security update

Computer security world in mourning over death of Dan Kaminsky, aged 42

security update

security update

security update

security update

Oscar-Bait, Literally: Hackers Abuse Nominated Films for Phishing, Malware
Prometei Botnet Could Fire Up APT-Style Attacks
5 Fundamental But Effective IoT Device Security Controls
Apple AirDrop has “significant privacy leak”, say German researchers
AirDrop flaws could leak phone numbers, email addresses

You can only stay safe by disabling AirDrop discovery in the system settings of your Apple device, a study says The post AirDrop flaws could leak phone numbers, email addresses appeared first on WeLiveSecurity

Apple AirDrop flaws could let hackers grab users’ phone numbers and email addresses
REvil’s Big Apple Ransomware Gambit Looks to Pay Off
3 cloud architecture mistakes we all make, but shouldn’t
Received an unexpected request to “confirm your Twitter account”?
If you have a QNAP NAS, stop what you’re doing right now and install latest updates. Do it before Qlocker gets you

security update

Mount Locker Ransomware Aggressively Changes Up Tactics
US aviation regulator warns of mid-air collision risk if Garmin TCAS boxes are not updated
Spotlight on Cybercriminal Supply Chains
Google rushes out fix for zero‑day vulnerability in Chrome

The update patches a total of seven security flaws in the desktop versions of the popular web browser The post Google rushes out fix for zero‑day vulnerability in Chrome appeared first on WeLiveSecurity

Linux team in public bust-up over fake “patches” to introduce bugs
S3 Ep29: Anti-tracking, rowhammer problems and IoT vulns [Podcast]
REvil ransomware – what you need to know
MI5 wants to shed its cocktail-guzzling posho image – so it’s opened an Instagram account
Telegram Platform Abused in ‘ToxicEye’ Malware Campaigns
It’s Easy to Become a Cyberattack Target, but a VPN Can Help
Smashing Security podcast #224: The Lazarus Heist, Facebook faux pas, and no-cost security
Apple, you’ve AirDrop’d the ball: Academics detail ways to leak contact info of nearby iThings for spear-phishing
Asian buyers set for security spending spree to catch up on shabby strategies
Signal app’s Moxie says it’s possible to sabotage Cellebrite’s phone-probing tools with booby-trapped file
4 Innovative Ways Cyberattackers Hunt for Security Bugs

security update