Menu

Latest articles

Ex-Cisco Employee Pleads Guilty to Deleting 16K Webex Teams Accounts
New Chrome, Firefox versions fix security bugs, bring productivity features

Chrome gets a new way of managing tabs while Firefox now features a new add-ons blocklist The post New Chrome, Firefox versions fix security bugs, bring productivity features appeared first on WeLiveSecurity

Facebook Hits Back At Apple’s iOS 14 Privacy Update
Magecart’s Success Paves Way For Cybercriminal Credit Card ‘Sniffer’ Market

The handler for the XkbSetNames request does not validate the request length before accessing its contents (CVE-2020-14345). An integer underflow exists in the handler for the XIChangeHierarchy request (CVE-2020-14346).

There is an integer overflow and a double free vulnerability in the way LibX11 handles locales. The integer overflow is a necessary precursor to the double free (CVE-2020-14363). References:

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed (CVE-2020-15664).

The read_xbm_body function in gui/image/qxbmhandler.cpp has a buffer over-read (CVE-2020-17507). References: – https://bugs.mageia.org/show_bug.cgi?id=27173

NSS could be made to expose sensitive information if it received a specially crafted input.

Russian cybercrime suspect arrested in $1m ransomware conspiracy

An update is now available for CloudForms Management Engine 5.10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Malicious Attachments Remain a Cybercriminal Threat Vector Favorite
Revamped Qbot Trojan Packs New Punch: Hijacks Email Threads
‘My wife tried to order some clothes tonight. When she logged in, she was in someone else’s account … Now someone’s charged her card’
DDoS downs New Zealand stock exchange for third consecutive day

security update

Smashing Security podcast #193: Hacking the CIA, Bridgefy, and college lockdowns
Forget your space-age IT security systems. It might just take a $1m bribe and a willing employee to be pwned
North Korean hacking gang targets banks worldwide, US Government warns

security update

Cisco Patches ‘High-Severity’ Bugs Impacting Switches, Fibre Storage
Here’s a neat exploit to trick someone into inadvertently emailing their files to you from their Mac, iPhone via Safari
“Chrome considered harmful” – the Law of Unintended Consequences
Researchers shine light on hackers-for-hire op that hit estate agent with malicious plugin for Autodesk 3ds Max
Hackers Exploit Autodesk Flaw in Recent Cyberespionage Attack
Disinformation Spurs a Thriving Industry as U.S. Election Looms

An update that fixes one vulnerability is now available.

Medical Data Leaked on GitHub Due to Developer Errors
US election 2020: The disinfo operations have evolved, but so have state governments

It was reported that the Lua module for Nginx, a high-performance web and reverse proxy server, is prone to a HTTP request smuggling vulnerability.

Mozilla: Attacker-induced prompt for extension installation (CVE-2020-15664) * Mozilla: Use-After-Free when aborting an operation (CVE-2020-15669) SL6 x86_64 firefox-68.12.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.12.0-1.el6_10.x86_64.rpm firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm i386 firefox-68.12.0-1.el6_10.i686.rpm firefox-d [More…]

How to Write a Cybersecurity Playbook During a Pandemic

Several security issues were fixed in libmysofa.

An update that fixes three vulnerabilities is now available.

– New upstream version (80.0)

security update

Four More Bugs Patched in Microsoft’s Azure Sphere IoT Platform
FBI, CISA warn of spike in vishing attacks

Cybercriminals increasingly take aim at teleworkers, setting up malicious duplicates of companies’ internal VPN login pages The post FBI, CISA warn of spike in vishing attacks appeared first on WeLiveSecurity

Cyber attacks: Several Canadian government services disrupted

Several services from the Canadian government, including the national revenue agency, had to be shut down following a series of credential stuffing cyberattacks. The post Cyber attacks: Several Canadian government services disrupted appeared first on WeLiveSecurity

How to secure your TikTok account

From keeping your account safe to curating who can view your liked content, we look at how you can increase your security and privacy on TikTok The post How to secure your TikTok account appeared first on WeLiveSecurity

Impersonating users of ‘protest’ app Bridgefy was as simple as sniffing Bluetooth handshakes for identifiers
Safari Bug Revealed After Apple Takes Nearly a Year to Patch
Lazarus Group Targets Cryptocurrency Firms Via LinkedIn Messages
Be very afraid! British Army might scrap battle tanks for keyboard warriors – report

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

Shoring Up the 2020 Election: Secure Vote Tallies Aren’t the Problem
North Korean hackers pwned cryptocurrency sysadmin with GDPR-themed LinkedIn lure, says F-Secure
The Viking Snowden: Denmark spy chief ‘relieved of duty’ after whistleblower reveals illegal snooping on citizens
Google Fixes High-Severity Chrome Browser Code Execution Bug

security update

Iran-Linked ‘Newbie’ Hackers Spread Dharma Ransomware Via RDP Ports

An update that fixes 21 vulnerabilities is now available.

Several security issues were fixed in Net-SNMP.

APIs Are the Next Frontier in Cybercrime

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update for openshift-enterprise-hyperkube-container is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for jenkins and openshift is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Canadian shipping company Canpar gets an unwanted delivery – ransomware
Bletchley Park Trust can’t crack COVID-caused revenue slump without losing staff

Chrony’s method of opening its PID file could allow a compromised chrony user account to overwrite files in certain parts of the filesystem with chrony’s PID, using a symlink attack (CVE-2020-14367). References:

Reading Time: ~ 2 min. Ransomware Attack Targets Major Cruise Line Officials for Carnival Cruises have confirmed that a portion of their IT systems were encrypted following a cyberattack identified over the weekend. The company also revealed that sensitive information for both employees and customers was illicitly accessed, though they did not admit to what […]

Security fix for CVE-2020-14367

Several vulnerabilities have been discovered in sqlite3, a C library that implements an SQL database engine. CVE-2018-8740

Several memory leaks were discovered in proftpd-dfsg, a versatile, virtual-hosting FTP daemon, when mod_facl or mod_sftp is used which could lead to memory exhaustion and a denial-of-service.

Jason A. Donenfeld found an ansi escape sequence injection into software-properties, a manager for apt repository sources. An attacker could manipulate the screen of a user prompted to install an additional repository (PPA).

News Wrap: AWS Cryptojacking Worm, IBM Privacy Lawsuit and More

Multiple vulnerabilities were discovered in Python2.7, an interactive high-level object-oriented language.

Tim Starling discovered two vulnerabilities in firejail, a sandbox program to restrict the running environment of untrusted applications.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Utes gotta be kidding me… University of Utah handed $457K to ransomware creeps
Appearing on the Easy Prey podcast
Outlook “mail issues” phishing – don’t fall for this scam!
University of Utah Pays $457K After Ransomware Attack
CREST exam cheat-sheet scandal: New temp chairman at UK infosec body as lawyers and ex-copper get involved

An update that solves one vulnerability and has 22 fixes is now available.

An update that solves one vulnerability and has 19 fixes is now available.

Researchers Sound Alarm Over Malicious AWS Community AMIs
Using AI to fight hand-crafted Business Email Compromise
Shared memory vulnerability in IBM’s Db2 database could let nefarious insiders wreak havoc – so get patching
Former Uber CSO Charged With Paying ‘Hush Money’ in 2016 Breach Cover-Up

Several security issues were fixed in Bind.

Physical locks are less hackable than digital locks, right? Maybe not: Boffins break in with a microphone

An update that solves 7 vulnerabilities and has 109 fixes is now available.

Ex-Uber chief security officer charged, accused of covering up theft of personal info from databases by hackers

The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function. (CVE-2020-14148) References:

– fix expired pointer dereference via multi API with `CURLOPT_CONNECT_ONLY` option set (CVE-2020-8231)

IBM Settles Lawsuit Over Weather Channel App Data Privacy
How to prepare and protect your digital legacy

It’s never too soon to plan for what will happen to your digital presence after you pass away The post How to prepare and protect your digital legacy appeared first on WeLiveSecurity

Transparent Tribe Mounts Ongoing Spy Campaign on Military, Government
Microsoft Out-of-Band Security Update Fixes Windows Remote Access Flaws
Experian says it recovered and deleted data on 24 million South Africans after giving it to random ‘marketing’ person

Multiple vulnerabilities were found in ghostscript, an interpreter for the PostScript language and for PDF, allowing an attacker to escalate privileges and cause denial of service via crafted PS/EPS/PDF files.

An update that solves two vulnerabilities and has 6 fixes is now available.