Vulnerabilities

2 Likes
2 Likes

After years of complaints from YouTubers, Google has pinpointed the root cause of a series of account hijackings: software sponsorship deals that delivered malware.

[…]

2 Likes
2 Likes

I really hate this trouser leg of time we find ourselves in…

1 Like
3 Likes
1 Like
3 Likes

Well, this sucks.

5 Likes

Paying attention to your email attachments is still sound advice though, don’t open anything you’re not expecting or don’t know. Keeping your eyes open for those filename extensions as well.

5 Likes

Utility biz Delta-Montrose Electric Association loses billing capability and two decades of records after cyber attack

A US utility company based in Colorado was hit by a ransomware attack in November that wiped out two decades’ worth of records and knocked out billing systems that won’t be restored until next week at the earliest.

The attack was detailed by the Delta-Montrose Electric Association (DMEA) in a post on its website explaining that current customers won’t be penalised for being unable to pay their bills because of the incident.

[…]

2 Likes

Does this effect here?

ETA
I knew Little My would bite me in the arse!
:

5 Likes

It looks like Gravatar accidentally allows users’ data to be accessed using a sequential index number, instead accessing it only as part of a site that you’re already using. The main danger here, from what I can see, is the ability of the attacker to assemble a big index of users.

2 Likes

An “unintended interaction” between the app and Android prevented emergency calls from being placed properly. … Google also warns users running Teams on any Android 10+ device to make sure they’re signed into an account. If you aren’t signed in, uninstall and reinstall the app to prevent your 911 calls from being blocked.

5 Likes

https://www.riotimesonline.com/brazil-news/rio-politics/brazils-health-ministry-website-hacked-overnight-and-is-offline/

3 Likes

On Thursday, researchers noticed that a popular Java logging library (log4j) had a bug that allows for Remote Code Execution or RCE, hacker lingo for one of the most dangerous types of vulnerabilities, one that essentially allows hackers to take control of the target. GitHub labeled the vulnerability as “critical severity,” and many researchers, as well as the Director of Cybersecurity at the NSA, are sounding the alarm.

6 Likes

Begun, the patch wars have.

Apache can be affected, but I don’t think that I’m using anything that should touch Java and this library. Still, might as well do an update. (Still on Buster because the Bullseye upgrade is a kind of a mess.)

4 Likes

The Quebec government got on it quickly.

2 Likes

Relevant:

9 Likes
4 Likes