Menu

Latest articles

IPv6 has been a long time coming. Drafted by the Internet Engineering Task Force (ITEF) in 1998, it became an Internet Standard in 2017. Though the rollout of IPv6 addresses has proceeded at a glacial pace since then, adoption numbers continue to inch higher. Worldwide IPv6 adoption, according to Google’s handy tracker, is around 33 […]

Google’s OSS-Fuzz extends fuzzing to Java apps

Spanish labor agency suffers ransomware attack Multiple systems were taken offline following a ransomware attack on the Spanish government labor agency SEPE, which has affected all 700 of their offices across the country. While some critical systems were impacted by the attack, officials have confirmed that the systems containing customer and other sensitive payroll data […]

Every device on an MSP’s managed network provides insight into what’s happening on that network. This includes network routers, switches, printers, wireless devices to servers, endpoints, IoT devices and everything else connected to the network. Each creates a log in its own format, or syntax, that a technician can review for troubleshooting, configuration confirmation, the […]

150,000 security cameras allegedly breached in “too much fun” hack
WhatsApp may soon roll out encrypted chat backups

While chats are end-to-end encrypted, their backups are not – this may change soon The post WhatsApp may soon roll out encrypted chat backups appeared first on WeLiveSecurity

Belgian cops crack down on encrypted phone network Sky ECC in 200 overnight raids as firm denies criminal ties

Two security issues have been detected in zeromq3. CVE-2021-20234

Reflections on 2020 security vulnerabilities
Online health security – when ‘opt out’ isn’t an option

What happens when you try to opt out of e-health to avoid issues in the event of a breach? The post Online health security – when ‘opt out’ isn’t an option appeared first on WeLiveSecurity

Brit cybercops issue tender to rip and replace their formerly flaw-ridden CyberAlarm tool

The container suse-sles-15-sp2-chost-byos-v20210304-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp2-chost-byos-v20210304-gen2 was updated. The following patches have been included in this update:

The container sles-15-sp2-chost-byos-v20210304 was updated. The following patches have been included in this update:

The container sles-15-sp1-chost-byos-v20210304 was updated. The following patches have been included in this update:

The container suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

Missing colleagues in cybersecurity? That’s no surprise – the world is missing 3.5 million

Italy targeted by Ursnif banking Trojan Over 100 banks in Italy have fallen victim to the Ursnif banking trojan, which has stolen thousands of login credentials since it was first discovered in 2007. The attack may have compromised up to 1,700 additional pairs of banking credentials through a payment processor, some of which were already […]

India pauses blockchain-powered SMS spam-scrubber after it swallows people’s one-time login codes
Apple’s Device Location-Tracking System Could Expose User Identities
Microsoft Patch Tuesday Updates Fix 14 Critical Bugs
Beware the IDEs of March: Microsoft’s latest monthly fixes land after frantic Exchange Server updates
Dark Web Markets for Stolen Data See Banner Sales
Adobe Critical Code-Execution Flaws Plague Windows Users

Despite the rising ransomware numbers and the numerous related headlines, many small and medium-sized businesses (SMBs) still don’t consider themselves at risk from cyberattacks. Nothing could be further from the truth. Smaller organizations are a prime target, and ransomware authors have only upped the ante in their methods to ensure they get paid. For example, […]

One of the reasons why there’s so much cybercrime is because there are so many ways for cybercriminals to exploit vulnerabilities and circumvent even the best defenses. You may be surprised to find that one of the biggest vulnerabilities is users. Many successful attacks could actually be prevented if users just knew what to look […]

US newspaper’s ‘Biden will hack Russia’ claim: A good way to reassure Putin you’ll leave him alone

Multiple vulnerabilites were discovered in privoxy, a web proxy with advanced filtering capabilities. CVE-2021-20272

Women in cybersecurity: Gender gap narrows but not enough

The number of women joining the ranks of cybersecurity practitioners is steadily increasing, but a lot still needs to be done to close the gap The post Women in cybersecurity: Gender gap narrows but not enough appeared first on WeLiveSecurity

Google Play Harbors Malware-Laced Apps Delivering Spy Trojans
Apple Plugs Severe WebKit Remote Code-Execution Hole

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

European Banking Authority restores email service in wake of Microsoft Exchange hack
Serious Security: Webshells explained in the aftermath of HAFNIUM attacks
The Microsoft Exchange Server mega-hack – what you need to know

Red Hat Ansible Tower 3.8.2-1 – Container Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

So it appears some of you really don’t want us to use the word ‘hacker’ when we really mean ‘criminal’

Red Hat Ansible Tower 3.6.7-1 – RHEL7 Container Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat Ansible Tower 3.7.5-1 – RHEL7 Container Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat Ansible Automation Platform 1.2.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

GitHub bug briefly gave valid authenticated session cookies to wrong users
Azure flings out free virtual trusted platform module for cloudy VMs
Apple emits patches for iOS, macOS, Safari, etc to stop dodgy websites hijacking people’s gadgets
Google engineer urges web devs to step up and secure their code in this data-spilling Spectre-haunted world
Newest Intel Side-Channel Attack Sniffs Out Sensitive Data
Crypto-Miner Campaign Targets Unpatched QNAP NAS Devices
McAfee to offload enterprise business for $4bn, focus on consumer security
Fake Google reCAPTCHA Phishing Attack Swipes Office 365 Passwords
University of the Highlands and Islands shuts down campuses as it deals with ‘ongoing cyber incident’
Airline passenger data breached following “highly sophisticated attack”
How Secure Is Linux?>
SolarWinds just keeps getting worse: New strain of backdoor malware found in probe
6 security risks in software development and how to address them
Cybersecurity in 2021: Stopping the madness
Going dark: Service disruptions at stock exchanges and brokerages

Are you a bull or a bear? If you can’t access your data and money, do your sentiments about the market still matter? The post Going dark: Service disruptions at stock exchanges and brokerages appeared first on WeLiveSecurity

The torture garden of Microsoft Exchange: Grant us the serenity to accept what they cannot EOL

An update that solves 9 vulnerabilities and has 115 fixes is now available.

An update that fixes 42 vulnerabilities is now available.

The patch to address CVE-2019-5086 and CVE-2019-5087 was not portable and did not work on 32 bit processor architectures. This update fixes the problem. For reference, the original advisory text follows.

An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for screen is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for the nodejs:12 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

US National Security Council urges review of Exchange Servers in wake of Hafnium attack
Intel CPU interconnects can be exploited by malware to leak encryption keys and other info, academic study finds
Poison packages – “Supply Chain Risks” user hits Python community with 4000 fake modules

Fix for CVE-2020-13977 BZ1849087 Require plugins needed for localhost monitoring (#1932297) Update to 4.4.6

Fix for CVE-2020-13977 BZ1849087 Require plugins needed for localhost monitoring (#1932297) Update to 4.4.6

A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Stability update for hardware accelerated backend (mozbz#1694670). —- New upstream update (86.0). Should also fix some rendering issues in KDE in certain configurations. Depends on and cannot be pushed stable without https://bodhi.fedoraproject.org/updates/FEDORA-2021-bdc10e21fc .

An update that contains security fixes can now be installed.

An update that fixes four vulnerabilities is now available.

EFF urges Google to ground its FLoC: ‘Pro-privacy’ third-party cookie replacement not actually great for privacy
U.S. DoD Weapons Programs Lack ‘Key’ Cybersecurity Measures
WordPress Injection Anchors Widespread Malware Campaign
Massive Supply-Chain Cyberattack Breaches Several Airlines

Security update for CVE-2021-26937

Update to latest upstream release 1.4.1 (#1931574)

Multiple security issues were discovered in activemq, a message broker built around Java Message Service. CVE-2017-15709

Critics Blast Google’s Aim to Replace Browser Cookie with ‘FLoC’

A vulnerability was discovered in mqtt-client wher unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.

Oh SITA: Airline IT provider confirms passenger data leaked after major ‘cyber-attack’
D-Link, IoT Devices Under Attack By Tor-Based Gafgyt Variant

This update fixes a buffer-overrun bug related to the MNG LOOP chunk (which gets noticed even in PNG files if the -s option is used). (RHBZ#1908559). It also fixes a buffer overrun for certain invalid MNG PPLT chunk contents.

Infinite loop in SML lexer may lead to DoS. When the SMLLexer gets fed the string “exception” it seems to loop indefinitely (rhbz#1922136). References: – https://bugs.mageia.org/show_bug.cgi?id=28319

While Reg readers know the difference between a true hacker and cyber-crook, for everyone else, hacking means illegal activity
How ESET’s work on SafetyNet® helps protect children online

For over a decade, ESET and the San Diego Police Foundation have been working together to help keep children safe from online threats The post How ESET’s work on SafetyNet® helps protect children online appeared first on WeLiveSecurity

Dutch government: Did we say 10 ‘high data protection risks’ in Google Workspace block adoption? Make that 8
Biden administration labels China top tech threat, promises proportionate responses to cyberattacks
Microsoft, FireEye Unmask More Malware Linked to SolarWinds Attackers
Cyberattackers Target Top Russian Cybercrime Forums
AdGuard names 6,000+ web trackers that use CNAME chicanery: Feel free to feed them into your browser’s filter
Microsoft rushes out fixes for four zero‑day flaws in Exchange Server

At least one vulnerability is being exploited by multiple cyberespionage groups to attacks targets mainly in the US, per ESET telemetry The post Microsoft rushes out fixes for four zero‑day flaws in Exchange Server appeared first on WeLiveSecurity

National Surveillance Camera Rollout Roils Privacy Activists
CISA Orders Federal Agencies to Patch Exchange Servers
COVID-19 Vaccine Spear-Phishing Attacks Jump 26 Percent
Russian cybercriminal forum hacked, user details exposed
Wall Street targeted by new Capital Call investment email scammers
Like a challenge in a high profile ‘face-of-IT’ role? Welcome to the Home Office