Tageszusammenfassung - 12.11.2021

End-of-Day report

Timeframe: Donnerstag 11-11-2021 18:00 - Freitag 12-11-2021 18:00 Handler: Dimitri Robl Co-Handler: Stephan Richter


Zoom dichtet Sicherheitslücken in mehreren Produkten und Clients ab

In einigen Produkten des Webkonferenz-Anbieters Zoom hat der Hersteller Sicherheitslücken geschlossen.


Kriminelle versenden betrügerische Mails im Namen der Post!

Derzeit melden uns zahlreiche LeserInnen ein betrügerisches E-Mail, das im Namen der Post verschickt wird. Darin behaupten die Kriminellen, dass für eine Bestellung zusätzliche Einfuhrgebühren notwendig seien. Auch wenn Sie gerade auf ein Paket warten, sollten Sie bei solchen E-Mails skeptisch sein. In diesem Fall versuchen die BetrügerInnen an Ihr Geld zu kommen!


HTML smuggling surges: Highly evasive loader technique increasingly used in banking malware, targeted attacks

HTML smuggling, a highly evasive malware delivery technique that leverages legitimate HTML5 and JavaScript features, is increasingly used in email campaigns that deploy banking malware, remote access Trojans (RATs), and other payloads related to targeted attacks.


Malware uses namesilo Parking pages and Googles custom pages to spread

Recently, we found a suspicious GoELFsample, which is a downloder mainly to spread mining malwares. The interesting part is that we noticed it using namesilos Parking page and Googles user-defined page to spread the sample and configuration. Apparently this is yet another attempt to hide control channel to avoid [...]


Murder-for-hire, money laundering, and more: How organised criminals work online

Europol has released an extensive report into serious and organized crime, including how these groups use the internet to aid in their criminal behaviour.


-We wait, because we know you.- Inside the ransomware negotiation economics.

Organizations worldwide continue to face waves of digital extortion in the form of targeted ransomware. Digital extortion is now classified as the most prominent form of cybercrime and the most devastating and pervasive threat to functioning [...]


Researcher Shows Windows Flaw More Serious After Microsoft Releases Incomplete Patch

A researcher has discovered that a Windows vulnerability for which Microsoft released an incomplete patch in August is more serious than initially believed.


When the alarms go off: 10 key steps to take after a data breach

It-s often said that data breaches are no longer a matter of -if-, but -when- - here-s what your organization should do, and avoid doing, in the case of a security breach


Network Code on Cybersecurity is out for public consultation

The draft for the Network Code for cybersecurity aspects of cross-border electricity flows has been released today for public consultation. ENCS has collaborated on the writing of the Network Code as part of the drafting team. During the public consultation period, stakeholders within the energy sector have the opportunity of sharing their views on the [...]


Number of Malicious Shopping Websites Jumps 178% ahead of November e-Shopping Holidays, Breaking Records

Highlights: Check Point Research (CPR) spots over 5300 different malicious websites per week, marking the highest since the beginning of 2021 Numbers show a 178% increase compared to 2021 so far 1 out of 38 corporate networks are being impacted on average per week in November, compared to 1 in 47 in October, and [...]



IBM Security Bulletins

IBM hat 15 Security Bulletins veröffentlicht.


Technical Advisory - Multiple Vulnerabilities in Victure WR1200 WiFi Router (CVE-2021-43282, CVE-2021-43283, CVE-2021-43284)

Victure-s WR1200 WiFi router, also sometimes referred to as AC1200, was found to have multiple vulnerabilities exposing its owners to potential intrusion in their local WiFi network and complete overtake of the device. Three vulnerabilities were uncovered, with links to the associated technical advisories below: [...]


Security updates for Friday

Security updates have been issued by Debian (node-tar, postgresql-11, postgresql-13, and postgresql-9.6), Fedora (autotrace, botan2, chafa, converseen, digikam, dmtx-utils, dvdauthor, eom, kxstitch, pfstools, php-pecl-imagick, psiconv, q, R-magick, radeontop, rss-glx, rubygem-rmagick, synfig, synfigstudio, vdr-scraper2vdr, vdr-skinelchihd, vdr-skinnopacity, vdr-tvguide, and WindowMaker), Mageia (kernel, kernel-linus, and openafs), openSUSE (kernel), Red Hat (freerdp), SUSE (bind and kernel), [...]



This advisory contains mitigation for Stack-based Buffer Overflow, and Out-of-bounds Write vulnerabilities in WECON PLC Editor ladder logic software.


Multiple Data Distribution Service (DDS) Implementations

This advisory contains mitigations for several vulnerabilities in Multiple Data Distribution Service (DDS) Implementations developed by a number of different vendors.


VMware Releases Security Update for Tanzu Application Service for VMs

VMware has released a security update to address a vulnerability in Tanzu Application Service for VMs. A remote attacker could exploit this vulnerability to cause a denial-of-service condition. CISA encourages users and administrators to review VMware Security Advisory VMSA-2021-0026 and apply the necessary update.


SYSS-2021-057: Open Redirect durch HTML Injection in Cryptshare

Im Cryptshare-Server besteht eine Schwachstelle. Sie erlaubt Angreifenden, die Empfänger einer manipulierten Nachricht auf beliebige Seiten weiterzuleiten.


Unlimited Sitemap Generator vulnerable to cross-site request forgery


PostgreSQL: Mehrere Schwachstellen


Red Hat Enterprise Linux: Schwachstelle ermöglicht Codeausführung