Home Artists Posts Import Register

Content

A flaw was found in libgcrypt, the notorious Emotet Is sinkholed by police, and Apple makes a slew of security updates! All that coming up now on ThreatWire. 

 #threatwire #hak5


Links:

Weekly security and privacy news, brought to you by Shannon Morse.


Watch this on youtube: https://youtu.be/F-nYtHFgDSA


Shop ThreatWire Merch Directly! - https://snubsie.com/shop


Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode 


Support ThreatWire!  https://www.patreon.com/threatwire 


Links:

0:00 Welcome!


Libgcrypt:

https://bugs.chromium.org/p/project-zero/issues/detail?id=2145

https://thehackernews.com/2021/01/google-discloses-severe-bug-in.html

https://threatpost.com/critical-libgcrypt-crypto-bug-arbitrary-code/163546/

https://gnupg.org/download/index.html

https://www.zdnet.com/article/libgcrypt-developers-release-urgent-update-to-tackle-severe-vulnerability/



Emotet:

https://www.cyberscoop.com/emotet-europol-us-ukraine-takedown-botnet/

https://threatpost.com/emotet-takedown-infrastructure-netwalker-offline/163389/

https://www.zdnet.com/article/authorities-plan-to-mass-uninstall-emotet-from-infected-hosts-on-april-25-2021/

https://www.youtube.com/watch?v=_BLOmClsSpc

https://www.npu.gov.ua/news/kiberzlochini/kiberpolicziya-vikrila-transnaczionalne-ugrupovannya-xakeriv-u-rozpovsyudzhenni-najnebezpechnishogo-v-sviti-komp-yuternogo-virusu-EMOTET/

https://www.europol.europa.eu/newsroom/news/world%E2%80%99s-most-dangerous-malware-emotet-disrupted-through-global-action

https://www.politie.nl/nieuws/2021/januari/27/11-internationale-politieoperatie-ladybird-botnet-emotet-wereldwijd-ontmanteld.html

https://www.zdnet.com/article/emotet-worlds-most-dangerous-malware-botnet-disrupted-by-international-police-operation/

https://www.politie.nl/themas/controleer-of-mijn-inloggegevens-zijn-gestolen.html#english

https://thehackernews.com/2021/01/european-authorities-disrupt-emotet.html



Apple:

https://thehackernews.com/2021/01/google-uncovers-new-ios-security.html

https://threatpost.com/apple-ios-imessage-blastdoor/163479/

https://thehackernews.com/2021/01/apple-warns-of-3-ios-zero-day-security.html

https://threatpost.com/apple-patches-zero-days-ios-emergency-update/163374/

https://www.theverge.com/2021/1/28/22253366/apple-app-tracking-transparency-opt-in-requirement-beta-launch

https://www.theverge.com/2021/2/1/22260274/facebook-prompt-apple-ios-ad-tracking-opt-in-permission-privacy-update

https://blog.google/products/ads-commerce/preparing-developers-and-advertisers-for-policy-updates/


Photo credit:

Apple



-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆

Our Site → https://www.hak5.org

Shop →  http://hakshop.myshopify.com/

Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1

Support → https://www.patreon.com/threatwire

Contact Us → http://www.twitter.com/hak5

Threat Wire RSS → https://shannonmorse.podbean.com/feed/

Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999


Host: Shannon Morse → https://www.twitter.com/snubs

Host: Darren Kitchen → https://www.twitter.com/hak5darren

Host: Mubix → http://www.twitter.com/mubix

-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆

Files

(No title)

Comments

Don Bright

reading the libgcrypt github.... i keep wondering how many of these bugs would be prevented by Rust language. Rust is kind of hilariously annoying how it doesnt like for you to mix unsigned and signed types but ... it seems like that might prevent this type of overflow.