Menu

Latest articles

Hackers claim to breach Microsoft’s GitHub account; steal 500GB of data
Cisco Fixes High-Severity Flaws In Firepower Security Software, ASA
More and more organizations are falling to ransomware – will you be next?
Zoom Beefs Up End-to-End Encryption to Thwart ‘Zoombombers’
Vcrypt ransomware brings along a buddy to do the encryption
Over 300 websites taken down in just two weeks as UK public report suspicious emails
For six years Samsung smartphone users have been at risk from critical security bug. Patch now
Hackers Dumpster Dive for Taxpayer Data in COVID-19 Relief Money Scams
Smashing Security #177: Elon Musk, Roblox, and Love Bug author found
How to customize crypto policies in RHEL 8.2
Senior MP tells UK Defence Committee on 5G security: Russia could become China’s cyber-attack dog
Naikon APT Hid Five-Year Espionage Attack Under Radar
Fake news Facebook accounts used coronavirus to attract followers
Police nab InfinityBlack hackers
So you’ve set up MFA and solved the Elvish riddle, but some still think passwords alone are secure enough

Update to 2.53.2 If you have Lightning and/or Chatzilla extensions previously disabled, they are enabled after the update. Disable it again if needed (in about:addons), or remove completely (which can improve startup time).

Update to Samba 4.11.8

Update to Samba 4.11.8

ceph-14.2.9 GA Security fix for CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS Security fix for CVE-2020-1759 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions

Update to Samba 4.10.15

Update to Samba 4.10.15

California’s privacy warriors are back – and this time they want to take their fight all the way to the ballot box
Lazarus Group Hides macOS Spyware in 2FA Application
Fake crypto-wallet extensions appear in Chrome Web Store once again, siphoning off victims’ passwords

security update

security update

InfinityBlack Dismantled After Selling Millions of Credentials
Fake Zoom installers infect PCs with RevCode WebMonitor RAT
Almost a million WordPress websites targeted in massive campaign

An unknown threat actor is exploiting vulnerabilities in plugins for which patches have been available for months, or even years The post Almost a million WordPress websites targeted in massive campaign appeared first on WeLiveSecurity

GitHub blasts code-scanning tool into all open-source projects
Help us understand the shifting sands of network security: What’s working for you – and what’s not?
Professional data leakage: How did that security vendor get my personal data?

…and why are they selling it to other security vendors and product testers? The post Professional data leakage: How did that security vendor get my personal data? appeared first on WeLiveSecurity

Kaiji IoT malware brute-forces Linux devices for DDoS attacks
Microsoft Shells Out $100K for IoT Security
Firefox 76.0 released with critical security patches – update now
Adult streaming site CAM4 leaks 7 TB of data with 11 billion records
Ransomware Attack Takes Down Toll Group Systems, Again
Attackers Claim Identity of Financial NGO to Steal Sharepoint, Office Credentials
Air gap security beaten by turning PC capacitors into speakers

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Now we know what the P really stands for in PwC: X-rated ads plastered over derelict corner of accountants’ website

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Transport biz Toll Group suffers second ransomware infection in just three months
India acknowledges, but brushes aside, features-not-bugs in Aarogya Setyu virus contact-tracing app

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform various Cross-Side Scripting (XSS) and Cross-Site Request Forgery (CSRF) attacks, create files on the server, disclose private information, create open

security update

security update

Sensitive user data found in Tesla car parts sold on eBay
Kaiji – a new strain of IoT malware seizing control and launching DDoS attacks
InfinityBlack hacking group dismantled; 5 hackers arrested
Spear-Phishing Attack Spoofs EE To Target Executives
Surprise surprise! Hostile states are hacking coronavirus vaccine research, warn UK and USA intelligence
VPN Concerns with Unplanned Remote Employees

An update that solves one vulnerability and has three fixes is now available.

An update that fixes three vulnerabilities is now available.

GoDaddy suffers data breach after hackers access SSH accounts
Ghost blogging platform servers hacked to mine cryptocurrency

Ghost wasn’t the only victim of break-ins over the weekend that exploited critical holes in infrastructure automation software for which patches were available The post Ghost blogging platform servers hacked to mine cryptocurrency appeared first on WeLiveSecurity

GoDaddy hack: Miscreant goes AWOL with 28,000 users’ SSH login creds after vandalizing server-side file
GoDaddy Hack Breaches Hosting Account Credentials
GoDaddy – “unauthorized individual” had access to login info
New Kaiji Botnet Targets IoT, Linux Devices
Google Android RCE Bug Allows Attacker Full Device Access
Malware can extract data from air-gapped PC using power supply
We beg, implore and beseech thee. Stop reusing the same damn password everywhere

Reading Time: ~ 3 min. Your password passing habit may not be as be as harmless as you think. And yes, that includes Netflix login info too. That’s one finding to come out of our newly released study of 2020’s Most (and Least) Cyber-Secure States. In this year’s analysis of the cyber readiness of all […]

It has been 20 years since cybercrims woke up to social engineering with an intriguing little email titled ‘ILOVEYOU’
Firefox’s Private Relay service tests anonymous email alias feature
Reveal the identities of alleged pirates, court tells ISP
More Salt in their wounds: DigiCert hit as hackers wriggle through (patched) holes in buggy config tool
UK finds itself almost alone with centralized virus contact-tracing app that probably won’t work well, asks for your location, may be illegal

A Denial of Service (DoS) vulnerability was discovered in the network time protocol server/client, ntp. ntp allowed an “off-path” attacker to block unauthenticated

An update for sqlite is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Apple-Google COVID-19 virus contact-tracing API to bar location-tracking access

Update to Samba 4.12.2

Update to Samba 4.12.2

Airplane Hack Exposes Weaknesses of Alert and Avoidance Systems
OK, so you’ve air-gapped that PC. Cut the speakers. Covered the LEDs. Disconnected the monitor. Now, about the data-leaking power supply unit…

security update

Hackers Exploit Critical Flaw in Ghost Platform with Cryptojacking Attack
Sweet TCAS! We can make airliners go up-diddly-up whenever we want, say infosec researchers
France’s largest newspaper exposed 8 TB of data with 7.4 billion records

A regression has been found in the patch for CVE-2016-10711 of pound, a reverse proxy, load balancer and HTTPS front-end for Web servers. Without the fix pound can be tricked to use 100% CPU.

Several vulnerabilities were discovered in the Tomcat servlet and JSP engine, which could result in HTTP request smuggling and code execution in the AJP connector (disabled by default in Debian).

Hackers exploit vulnerability to leak The Last of Us 2 spoiler video
UK COVID-19 contact tracing app data may be kept for ‘research’ after crisis ends, MPs told
ILOVEYOU: The Love Bug virus 20 years on – could it happen again?
Oracle: Unpatched Versions of WebLogic App Server Under Active Attack
Tarkett floored by cyber attack
It was 20 years ago today… The Love Bug remembered
AsSalt-ed at the weekend: Miscreants roast Ghost, LineageOS totters as Salt bug bites
My old-fashioned view on the terms “blacklist” and “whitelist”
Coronavirus pandemic coincides with spike in online puppy scams
Uncle Sam to agencies: No encrypted DNS for you!
Monday review – the hot 11 stories of the week
Xiaomi emits phone browser updates after almighty row over web activity harvested even in incognito mode
India makes contact-tracing app compulsory in viral hot zones despite most local phones not being smart

An update for cri-o is now available for Red Hat OpenShift Container Platform 4.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which