Menu

Latest articles

Hackers pumped and dumped GAS cryptocurrency for $16.8 million, alleges US DOJ
Zerologon – hacking Windows servers with a bunch of zeros

apng2gif could be made to expose sensitive information if it opened a specifically crafted APNG file.

The Intel vPro Platform is ‘Built for Business’ – what this means to you

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Samba would allow unintended access to files over the network.

You have to be very on-trend as a cybercrook – hence why coronavirus-themed phishing is this year’s must-have look

LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength. (CVE-2020-15503)

util-linux could be made to run programs when performing bash completion.

Fake Zoom alerts and dodgy medical freebies among COVID-cracks detected by Taiwan’s CERT
Smashing Security podcast #196: Smart guns, smart cars, and smart street lights – oh my!

Reading Time: ~ 4 min. Since launching our web classification service in 2006, we’ve seen tremendous interest in our threat and web classification services, along with an evolution of the types and sizes of cybersecurity vendors and service providers looking to integrate this type of curated data into their product or service. Over the years, […]

Hackers Continue Cyberattacks Against Vatican, Catholic Orgs
Emotet strikes Quebec’s Department of Justice: An ESET Analysis

The cyber attack affects 14 inboxes belonging to the Department of Justice was confirmed by ESET researchers.  The post Emotet strikes Quebec’s Department of Justice: An ESET Analysis appeared first on WeLiveSecurity

Good: US boasts it collared two in Chinese hacking bust. Bad: They aren’t the actual hackers, rest are safe in China
Where China leads, Iran follows: US warns of ‘contract’ hackers exploiting Citrix, Pulse Secure and F5 VPNs
Zoom makes 2FA available for all its users

Zoom now supports phone calls, text messages and authentication apps as forms of two-factor authentication   The post Zoom makes 2FA available for all its users appeared first on WeLiveSecurity

DDoS Attacks Skyrocket as Pandemic Bites
DoJ Indicts Two Hackers for Defacing Websites with Pro-Iran Messages

An update that contains security fixes can now be installed.

An update that solves three vulnerabilities and has 26 fixes is now available.

An update that solves one vulnerability and has 8 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

MCabber could be made to modify the roster and intercept messages if it received specially crafted XMPP packets.

Report Looks at COVID-19’s Massive Impact on Cybersecurity
Bluetooth Spoofing Bug Affects Billions of IoT Devices
Best File and Disk Encryption Tools For Linux>
Microsoft open-sources fuzzing tool it uses in-house to keep Windows so very secure
Worried about bootkits, rootkits, UEFI nasties? Have you tried turning on Secure Boot, asks the No Sh*! Agency
Data Breaches Exposes Vets, COVID-19 Patients
Dunkin’ Donuts drops some dough to glaze over lawsuit accusing it of covering up customer account hacks

security update

QR Codes Serve Up a Menu of Security Concerns
IBM Spectrum Protect Plus Security Open to RCE
£2.5bn sueball claims Google slurps kids’ YouTube browsing habits then sells them on
Windows Exploit Released For Microsoft ‘Zerologon’ Flaw

Apache XML-RPC could be made to execute arbitrary code if it received specially crafted data by a malicious XML-RPC server.

Russian hacker selling how-to vid on exploiting unsupported Magento installations to skim credit card details for $5,000
US Customs has one heck of a false positive over “counterfeit Apple AirPods”

An update for librepo is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the mysql:8.0 module is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Update to version 0.9.5 * https://www.libssh.org/2020/09/10/libssh-0-9-5/ * Fixes CVE-2020-16135

QEMU: usb: out-of-bounds r/w access issue [XSA-335, CVE-2020-14364] (#1871850)

Apache Log4j could be made to remotely execute arbitrary code if it received specially crafted log data.

MFA Bypass Bugs Opened Microsoft 365 to Attack
Have hackers, cybercrims worked their way into your corporate net while you’ve been working from home?
Chinese database detailing 2.4 million influential people, their kids, their addresses, and how to press their buttons revealed
Infosec big names rally against US voting app maker’s bid to outlaw unsanctioned bug hunting via T&Cs
What do F5, Citrix, Pulse Secure all have in common? China exploiting their flaws to hack govt, biz – Feds
Feds Warn Nation-State Hackers are Actively Exploiting Unpatched Microsoft Exchange, F5, VPN Bugs
Court hearing on election security is zoombombed on 9/11 anniversary with porn, swastikas, pics of WTC attacks
Take your pick: ‘Hack-proof’ blockchain-powered padlock defeated by Bluetooth replay attack or 1kg lump hammer
Cloud Leak Exposes 320M Dating-Site Records
Personal data from Experian on 40% of South Africa’s population has been bundled onto a file-sharing website
TikTok Fixes Flaws That Opened Android App to Compromise

Reading Time: ~ 3 min. Women of Webroot and Carbonite talk about what drew them to the field and their advice for others looking to break into STEM. The lack of representative diversity in tech has been long acknowledged and well-studied.  Organizations and non-profit groups like National Center for Women & Information Technology (NCWIT), Girls […]

Magecart Attack Impacts More Than 10K Online Shoppers
Sorry we shut you out, says Tutanota: Encrypted email service weathers latest of ongoing DDoS storms

An update that solves 8 vulnerabilities and has 17 fixes is now available.

An update that solves 8 vulnerabilities and has 17 fixes is now available.

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3617

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3631

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3643

Another month, another cryptocurrency exchange hacked and ‘millions of dollars’ stolen by miscreants

An update that fixes one vulnerability is now available.

New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

– https://www.drupal.org/project/drupal/releases/7.72 – [Drupal core – Critical – Cross Site Request Forgery – SA- CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 – https://www.drupal.org/project/drupal/releases/7.71 – https://www.drupal.org/project/drupal/releases/7.70 – [Drupal core –

https://lists.gnupg.org/pipermail/gnutls-help/2020-September/004669.html

– https://www.drupal.org/project/drupal/releases/7.72 – [Drupal core – Critical – Cross Site Request Forgery – SA- CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 – https://www.drupal.org/project/drupal/releases/7.71 – https://www.drupal.org/project/drupal/releases/7.70 – [Drupal core –

An update that fixes one vulnerability is now available.

Update to upstream bugfix and security release 2.9.13.

update to 2.2.16, CVE-2020-24583, CVE-2020-24584

New F31 selinux-policy build

Update to .NET Core SDK 3.1.107 and Runtime 3.1.7. This fixes CVE-2020-1597 – Release Notes: https://github.com/dotnet/core/blob/master/release- notes/3.1/3.1.7/3.1.7.md

Update to .NET Core SDK 3.1.107 and Runtime 3.1.7. This fixes CVE-2020-1597 – Release Notes: https://github.com/dotnet/core/blob/master/release- notes/3.1/3.1.7/3.1.7.md

Don’t pay the ransom, mate. Don’t even fix a price, say Australia’s cyber security bods
APT28 Mounts Rapid, Large-Scale Theft of Office 365 Logins
Office 365 Phishing Attack Leverages Real-Time Active Directory Validation
It’s No ‘Giggle’: Managing Expectations for Vulnerability Disclosure
Who is calling? CDRThief targets Linux VoIP softswitches

ESET researchers have discovered and analyzed malware that targets Voice over IP (VoIP) softswitches. The post Who is calling? CDRThief targets Linux VoIP softswitches appeared first on WeLiveSecurity

WordPress Plugin Flaw Allows Attackers to Forge Emails
What an IDORable Giggle: AI-powered ‘female only’ app gets in Twitter kerfuffle over breach notification
Serious Security: Hacking Windows passwords via your wallpaper
“Yourefired” was Donald Trump’s Twitter password, claim hackers

Multiple vulnerabilities were discovered in WordPress, a popular content management framework. CVE-2019-17670

Adtech’s bogeymen are tracking everything – even your web visits to mental health charities, claim campaigners

Reading Time: ~ 3 min. This year more than others, for many of us, it’s gaming that’s gotten us through. Lockdowns, uncertainty, and some pretty darn good releases have kept our computers and consoles switched on in 2020. GamesIndustry.biz, a website tracking the gaming sector, reported a record number of concurrent users on the gaming […]

Secure your Zoom account with Two-Factor Authentication

An update that solves 8 vulnerabilities and has 12 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Stop unauthorized applications with RHEL 8’s File Access Policy Daemon

8u265 update, disable LTO

Update built with the new CMake settings Number of files which should have been owned by the testsuite subpackage are now owned by it Started building MeCab plugin

Three middle-aged Dutch hackers slipped into Donald Trump’s Twitter account days before 2016 US election
Billions of Bluetooth gadgets bothered by ‘BLURtooth’ miscreant-in-the-middle bug
China, Russia and Iran all attacking US elections and using some nasty new tactics, says Microsoft

Reading Time: ~ 4 min. Today’s work-from-home environment has created an abundance of opportunities for offering new cybersecurity services in addition to your existing business. With cyberattacks increasing in frequency and sophistication, business owners and managers need protection now more than ever. MSPs are ideally positioned to deliver the solutions businesses need in order to […]