Home Artists Posts Import Register

Content

Happy Monday morning! Here are a bunch of action alerts I found while researching for this week's show. Links are provided for additional context.

Action Alerts:

https://thehackernews.com/2021/01/a-set-of-severe-flaws-affect-popular.html - If you use DNSMasq, update to version 2.83 to patch an issue that could allow an attacker to mount DNS cache poisoning attacks and remotely execute code.

More info: https://www.zdnet.com/article/dnspooq-lets-attackers-poison-dns-cache-records/

https://threatpost.com/threat-actors-can-exploit-windows-rdp-servers-to-amplify-ddos-attacks/163248/ - Attackers are using RDP to distribute DDoS attacks, only when UDP running on TCP port 3389 is enabled.

More Info: https://www.zdnet.com/article/windows-rdp-servers-are-being-abused-to-amplify-ddos-attacks/

https://threatpost.com/nvidia-gamers-dos-data-loss-shield-tv-bugs/163200/ - Nvidia issued patches for a few vulnerabilities in the Shield TV and tesla-based GPUs. The flaws could allow for DOS, privilege escalation, and data loss.

https://www.zdnet.com/article/nsa-urges-system-administrators-to-replace-obsolete-tls-protocols/

Stop using those old and obsolete TLS protocols! "NSA recommends that only TLS 1.2 or TLS 1.3 be used; and that SSL 2.0, SSL 3.0, TLS 1.0, and TLS 1.1 not be used," the agency said.

https://www.zdnet.com/article/automated-exploit-of-critical-sap-solman-vulnerability-detected-in-the-wild/

SAP issued a patch for a major high critical vulnerability in SolMan version 7.2. A patch is available, so network admins are advised to update.

https://www.zdnet.com/article/hacker-leaks-data-of-millions-of-teespring-users/

Attackers posted data for millions of teespring users, including email addresses, some names, addresses, phone numbers and more. There is no knowledge of passwords being exposed, but I’d suggest changing passwords anyway just to stay on the safe side.

https://www.zdnet.com/article/qnap-warns-users-of-a-new-crypto-miner-named-dovecat-infecting-their-devices/

QNAP warned of new malware called Dovecat being used to target NAS devices to mine cryptocurrency. Attackers are targeting systems left online with weak passwords. Use strong passwords and disable internet facing protocols or services if not being used.

And something cool:

https://www.zdnet.com/article/brave-becomes-first-browser-to-add-native-support-for-the-ipfs-protocol/

Brave browser now supports the peer to peer IPFS protocol. Cool!

Comments

No comments found for this post.