β REvil/Sodinokibi Ransomware Universal Decryptor Key Is Out β
π Read
via "Threat Post".
Bitdefender worked with law enforcement to create a key to unlock victims encrypted in ransomware attacks before REvil's servers went belly-up on July 13.π Read
via "Threat Post".
Threat Post
REvil/Sodinokibi Ransomware Universal Decryptor Key Is Out
Bitdefender worked with law enforcement to create a key to unlock victims encrypted in ransomware attacks before REvil's servers went belly-up on July 13.
β Financial Cybercrime: Following Cryptocurrency via Public Ledgers β
π Read
via "Threat Post".
John Hammond, security researcher with Huntress, discusses a wallet-hijacking RAT, and how law enforcement recovered millions in Bitcoin after the Colonial Pipeline attack.π Read
via "Threat Post".
Threat Post
Financial Cybercrime: Following Cryptocurrency via Public Ledgers
John Hammond, security researcher with Huntress, discusses a wallet-hijacking RAT, and how law enforcement recovered millions in Bitcoin after the Colonial Pipeline attack.
β DDoS Attacks: A Flourishing Business for Cybercrooks β Podcast β
π Read
via "Threat Post".
Impervaβs Peter Klimek on how DDoS attacks started out as inconveniences but evolved to the point where attackers can disrupt businesses for as little as the price of a cup of coffee,π Read
via "Threat Post".
ποΈ Meris botnet leverages HTTP pipelining to smash DDoS attack records ποΈ
π Read
via "The Daily Swig".
Source of attacks βalmost entirely composed of Mikrotik devicesβπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Meris botnet leverages HTTP pipelining to smash DDoS attack records
Source of attacks βalmost entirely composed of Mikrotik devicesβ
βΌ CVE-2020-14119 βΌ
π Read
via "National Vulnerability Database".
There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom< 1.1.12π Read
via "National Vulnerability Database".
βΌ CVE-2020-14109 βΌ
π Read
via "National Vulnerability Database".
There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router AX3600 with ROM version =< 1.1.12π Read
via "National Vulnerability Database".
βΌ CVE-2021-34576 βΌ
π Read
via "National Vulnerability Database".
In Kaden PICOFLUX Air in all known versions an information exposure through observable discrepancy exists. This may give sensitive information (water consumption without distinct values) to third parties.π Read
via "National Vulnerability Database".
βΌ CVE-2020-14124 βΌ
π Read
via "National Vulnerability Database".
There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12.π Read
via "National Vulnerability Database".
βΌ CVE-2021-34571 βΌ
π Read
via "National Vulnerability Database".
Multiple Wireless M-Bus devices by Enbra use Hard-coded Credentials in Security mode 5 without an option to change the encryption key. An adversary can learn all information that is available in Enbra EWM.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40066 βΌ
π Read
via "National Vulnerability Database".
The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14.π Read
via "National Vulnerability Database".
βΌ CVE-2021-34573 βΌ
π Read
via "National Vulnerability Database".
In Enbra EWM in Version 1.7.29 together with several tested wireless M-Bus Sensors the events backflow and "no flow" are not reconized or misinterpreted. This may lead to wrong values and missing events.π Read
via "National Vulnerability Database".
βΌ CVE-2021-34572 βΌ
π Read
via "National Vulnerability Database".
Enbra EWM 1.7.29 does not check for or detect replay attacks sent by wireless M-Bus Security mode 5 devices. Instead timestamps of the sensor are replaced by the time of the readout even if the data is a replay of earlier data.π Read
via "National Vulnerability Database".
βΌ CVE-2021-40067 βΌ
π Read
via "National Vulnerability Database".
The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v12.14.π Read
via "National Vulnerability Database".
βΌ CVE-2020-14130 βΌ
π Read
via "National Vulnerability Database".
Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809π Read
via "National Vulnerability Database".
ποΈ Manufacturing industry must limit internal data access to prevent sensitive leaks β report ποΈ
π Read
via "The Daily Swig".
Sector advised to monitor what employees can do on company networksπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Manufacturing industry must limit internal data access to prevent sensitive leaks β report
Sector advised to monitor what employees can do on company networks
π¦Ώ Bitdefender offers free decryptor for REvil ransomware victims π¦Ώ
π Read
via "Tech Republic".
The free decryption tool will help victims restore their encrypted files from attacks made before July 13, 2021, says Bitdefender.π Read
via "Tech Republic".
TechRepublic
Bitdefender offers free decryptor for REvil ransomware victims
The free decryption tool will help victims restore their encrypted files from attacks made before July 13, 2021, says Bitdefender.
β OMIGOD, an exploitable hole in Microsoft open source code! β
π Read
via "Naked Security".
Got Linux? Here's a bug you weren't expecting, in software you might not know you have.π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
β S3 Ep50: Two 0-days plus another 0-day plus a fast food bug [Podcast] β
π Read
via "Naked Security".
Bugs! So many bugs! Latest episode - listen now...π Read
via "Naked Security".
Naked Security
S3 Ep50: Two 0-days plus another 0-day plus a fast food bug [Podcast]
Bugs! So many bugs! Latest episode β listen nowβ¦
π GNU Privacy Guard 2.2.31 π
π Read
via "Packet Storm Security".
GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions. This is the LTS release.π Read
via "Packet Storm Security".
Packetstormsecurity
GNU Privacy Guard 2.2.31 β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
βΌ CVE-2021-41079 βΌ
π Read
via "National Vulnerability Database".
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36160 βΌ
π Read
via "National Vulnerability Database".
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).π Read
via "National Vulnerability Database".