Menu

Latest articles

Prioritize alerts and jump-start your investigations with Recorded Future’s free browser extension. Sign up now.
IT services giant Cognizant hit by Maze ransomware attack
New sextortion scam: “High level of risk. Your account has been hacked.”
Bot creates millions of fake eyeballs to rip off smart-TV advertisers
Tor Project loses a third of staff in coronavirus cuts: Unlucky 13 out as nonprofit hacks back to core ops
Monday review – the hot 13 stories of the week

An update that fixes one vulnerability is now available.

Ministry of Defence lowers supplier infosec standards thanks to COVID-19 outbreak
Contact-tracing or contact sport? Defections and accusations emerge among European COVID-chasing app efforts
Hackers selling 267 million Facebook records on hacker forum

It was discovered that there was a path-traversal issue in Apache Shiro, a security framework for the Java programming language. A specially-crafted request could cause an authentication bypass.

An update that fixes 26 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Fraud & hacking guides are the most sold item on dark web
Fake Coronavirus apps hit Android & iOS users with spyware, adware
Busted: Man streamed “worst child abuse content ever seen”

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file’s parent is a symlink to a directory outside of the

Following CVEs were reported against the jackson-databind source package :

Following CVEs were reported against the awl source package: CVE-2020-11728

DHS Urges Pulse Secure VPN Users To Update Passwords

security update

Fixes CVE-2020-1730

Security fix for CVE-2020-5260 From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.4.txt): > With a crafted URL that contains a newline in it, the credential > helper machinery can be fooled to give credential information for > a wrong host. The attack has been made impossible by forbidding > a newline character in any value

Bugfix release from Google for 80.0.3987.162. —- Update to 80.0.3987.162. Fixes the following CVEs: * CVE-2020-6450 * CVE-2020-6451 * CVE-2020-6452

Attacks on Linksys Routers Trigger Mass Password Reset
Critical bug in Google Chrome – get your update now

Reading Time: ~ 2 min. Florida City Sees Lasting Effects of Ransomware Attack Nearly three weeks after the City of Jupiter, Florida suffered a ransomware attack that took many of their internal systems offline, the city has yet to return to normal. City officials announced they would be working to rebuild their systems from backups, […]

Hackers use typosquatting to trojanize 700 libraries in Ruby Repository
That critical VMware vuln allowed anyone on your network to create new admin users, no creds needed
Zoom Bombing Attack Hits U.S. Government Meeting
Hackers Update Age-Old Excel 4.0 Macro Attack
Google declares war on Android fleeceware scamming users through sneaky subscriptions
Google: We’ve blocked 126 million COVID-19 phishing scams in the last week
I’ve sent my worst enemies to Earworm Island
US offers up to $5m reward for information on North Korean hackers
GitHub users targeted by Sawfish phishing campaign

An update that solves two vulnerabilities and has one errata is now available.

Europe publishes draft rules for coronavirus contact-tracing app development, on a relaxed schedule
India says ‘Zoom is a not a safe platform’ and bans government users

New openvpn packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Poorly Secured Docker Image Comes Under Rapid Attack
You’re a botnet, you’ve got a zero-day, so where do you go? After fiber, because that’s where the bandwidth is
New PoetRAT Hits Energy Sector With Data-Stealing Tools

With a crafted URL that contains a newline in it, the credential helper machinery can be fooled to give credential information for a wrong host. The attack has been made impossible by forbidding a newline character in any value passed via the credential protocol (CVE-2020-5260).

Chromium-browser 81.0.4044.92 fixes security issues: Multiple flaws were found in the way Chromium 80.0.3987.149 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code,

Hackers steal 10 TB of data in ransomware attack on energy giant

– New Firefox and NSS upstream update – More info at https://www.mozilla.org/en- US/firefox/75.0/releasenotes/

– New Firefox and NSS upstream update – More info at https://www.mozilla.org/en- US/firefox/75.0/releasenotes/

Cisco IP Phone Harbors Critical RCE Flaw
Authorities bust multi-million online Coronavirus face mask scam
TikTok announces “Family Pairing” – bust your moves but cap the risk
Govt minister’s Zoom webinar hijacked to display porn
A Zoom zero-day exploit is up for sale for $500,000
Streaming TV Fraudsters Steal Millions of Ad Dollars in ‘ICEBUCKET’ Attack
Alleged Zoom Zero-Days for Windows, MacOS for Sale, Report
49 crypto-wallet pickpocketing browser extensions booted from the Chrome web store

Reading Time: ~ 3 min. One of the most notable findings to come from the Webroot 2020 Threat Report was the significant rise in the number of active phishing sites over 2019—a 640% rise, to be exact. This reflects a year-over-year rise in active phishing sites, but it’s important to keep this (dangerous) threat in […]

Bad news: So much of your personal data has been hacked that lesson manuals on how to use it are the latest hot property
49 malicious Chrome extensions caught pickpocketing crypto wallets
‘Double Extortion’ Ransomware Attacks Spike
Password security is critical in a remote work environment – see where businesses are putting themselves at risk
Update now! Windows zero-day flaws fixed in Patch Tuesday

An update that fixes one vulnerability is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that solves 8 vulnerabilities and has two fixes is now available.

An update for ipmitool is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

United Nations reportedly tears up Tencent’s invite to its big 75th birthday bash
Stuck inside with time on your hands? The US govt would like to remind you it’s paying $5m for Nork hacking scalps
Smashing Security #174: Garry Kasparov and Animal Crossing
Malicious Google Web Extensions Harvest Cryptowallet Secrets
Taxpayers Targeted With Improved NetWire RAT Variant

security update

Linksys forces password reset for Smart Wi-Fi accounts after router DNS hack pointed users at COVID-19 malware
49 malware infected Chrome extensions found stealing user data
Tencent Ups Top Bug-Bounty Award to $15K
Zoom passwords for sale on the Dark Web – “ten-a-penny” by all accounts
How to host safer Zoom meetings
Think before filling in that convenient flight refund form with all your delicious details – there’s a scam going about
Intel Fixes High-Severity Flaws in NUC, Discontinues Buggy Compute Module
PPE, COVID-19 Medical Supplies Targeted by BEC Scams
Know Your Enemy: Honeynets>
Decade of the RATs: Is Linux Secure?>
Top 5 Open-Source Serverless Security Tools>
IBM extends z15 mainframe family, intensifies Linux security>
EA Sports down – Gaming giant hit by massive DDoS attacks
Signal: We’ll be eaten alive by EARN IT Act’s anti-encryption wolves
WordPress WooCommerce sites targeted by card swiper attacks
Another day, another Google cull: Chocolate Factory axes 49 malicious Chrome extensions from web store
Apple: We respect your privacy so much we’ve revealed a little about what we can track when you use Maps

An update that fixes 26 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

At least someone’s making out like a bandit: Scammers have pocketed $13m in Coronavirus fraud from the US this year

A directory traversal vulnerability resulting from insufficient input sanitization was discovered in the Horde Application Framework. An authenticated remote attacker could use this flaw to execute code in the

A remote code execution vulnerability was discovered in the Horde Application Framework. An authenticated remote attacker could use this flaw to cause execution of uploaded CSV data.

A vulnerability was discovered in graphicsmagick, a collection of image processing tools, that results in a heap overflow in 32-bit applications because of a signed overflow on range check in the HuffmanDecodeImage

April 2020 and – rest assured – your Windows PC can still be pwned by something so innocuous as an unruly font

security update

An update that fixes one vulnerability is now available.