FEDORA-EPEL-2022-66c028a837
Packages in this update:
slurm-20.11.9-1.el7
Update description:
Update to 20.11.9 to fix CVE-2022-29500 and CVE-2022-29501.
slurm-20.11.9-1.el7
Update to 20.11.9 to fix CVE-2022-29500 and CVE-2022-29501.
slurm-20.11.9-1.el8
Update to 20.11.9 to fix CVE-2022-29500 and CVE-2022-29501.
supertux-0.6.3-4.fc36
Fix CVE-2022-30292
slurm-21.08.8-1.fc36
Update to 21.08.8 to fix CVE-2022-29500, CVE-2022-29501, and CVE-2022-29502.
slurm-21.08.8-1.fc34
Update to 21.08.8 to fix CVE-2022-29500, CVE-2022-29501, and CVE-2022-29502.
slurm-21.08.8-1.fc35
Update to 21.08.8 to fix CVE-2022-29500, CVE-2022-29501, and CVE-2022-29502.
By Oliver Devane
McAfee has identified several Youtube channels which were live-streaming a modified version of a live stream called ‘The B Word’ where Elon Musk, Cathie Wood, and Jack Dorsey discuss various aspects of cryptocurrency.
The modified live streams make the original video smaller and put a frame around it advertising malicious sites that it claims will double the amount of cryptocurrency you send them. As the topic of the video is on cryptocurrency it adds some legitimacy to the websites being advertised.
The original video is shown below on the left and a modified one which includes a reference to a scam site is shown on the right.
We identified several different streams occurring at a similar same time. The images of some are shown below:
The YouTube streams advertised several sites which shared a similar theme. They claim to send cryptocurrency worth double the value which they’ve received. For example, if you send 1BTC you will receive 2BTC in return. One of the site‘s frequently asked questions (FAQ) is shown below:
Here are some more examples of the scam sites we discovered:
The sites attempt to trick the visitors into thinking that others are sending cryptocurrency to it by showing a table with recent transactions. This is fake and is generated by JavaScript which creates random crypto wallets and amounts and then adds these to the table.
The wallets associated with the malicious sites have received a large number of transactions with a combined value of $280,000 as of 5 PM UTC on the 5th of May 2022
Scam Site
Crypto Type
Wallet
Value as on 5PM UTC 5th May 2022
22ark-invest[.]org
ETH
0x820a78D8e0518fcE090A9D16297924dB7941FD4f
$25,726.46
22ark-invest[.]org
BTC
1Q3r1TzwCwQbd1dZzVM9mdFKPALFNmt2WE
$29,863.78
2xEther[.]com
ETH
0x5081d1eC9a1624711061C75dB9438f207823E694
$2,748.50
2x-musk[.]net
ETH
0x18E860308309f2Ab23b5ab861087cBd0b65d250A
$10,409.13
2x-musk[.]net
BTC
17XfgcHCfpyYMFdtAWYX2QcksA77GnbHN9
$4,779.47
arkinvest22[.]net
ETH
0x2605dF183743587594A3DBC5D99F12BB4F19ac74
$11,810.57
arkinvest22[.]net
BTC
1GLRZZHK2fRrywVUEF83UkqafNV3GnBLha
$5,976.80
doublecrypto22[.]com
ETH
0x12357A8e2e6B36dd6D98A2aed874D39c960eC174
$0.00
doublecrypto22[.]com
BTC
1NKajgogVrRYQjJEQY2BcvZmGn4bXyEqdY
$0.00
elonnew[.]com
ETH
0xAC9275b867DAb0650432429c73509A9d156922Dd
$0.00
elonnew[.]com
BTC
1DU2H3dWXbUA9mKWuZjbqqHuGfed7JyqXu
$0.00
elontoday[.]org
ETH
0xBD73d147970BcbccdDe3Dd9340827b679e70d9d4
$18,442.96
elontoday[.]org
BTC
bc1qas66cgckep3lrkdrav7gy8xvn7cg4fh4d7gmw5
$0.00
Teslabtc22[.]com
ETH
0x9B857C44C500eAf7fAfE9ed1af31523d84CB5bB0
$27,386.69
Teslabtc22[.]com
BTC
18wJeJiu4MxDT2Ts8XJS665vsstiSv6CNK
$17,609.62
tesla-eth[.]org
ETH
0x436F1f89c00f546bFEf42F8C8d964f1206140c64
$5,841.84
tesla-eth[.]org
BTC
1CHRtrHVB74y8Za39X16qxPGZQ12JHG6TW
$132.22
teslaswell[.]com
ETH
0x7007Fa3e7dB99686D337C87982a07Baf165a3C1D
$9.43
teslaswell[.]com
BTC
bc1qdjma5kjqlf7l6fcug097s9mgukelmtdf6nm20v
$0.00
twittergive[.]net
ETH
0xB8e257C18BbEC93A596438171e7E1E77d18671E5
$25,918.90
twittergive[.]net
BTC
1EX3dG9GUNVxoz6yiPqqoYMQw6SwQUpa4T
$99,123.42
Scammers have been using social media sites such as Twitter and Youtube to attempt to trick users into parting ways with their cryptocurrency for the past few years. McAfee urges its customers to be vigilant and if something sounds too good to be true then it is most likely not legitimate.
Our customers are protected against the malicious sites detailed in this blog as they are blocked with McAfee Web Advisor
Type
Value
Product
Blocked
URL – Crypto Scam
twittergive[.]net
McAfee WebAdvisor
YES
URL – Crypto Scam
tesla-eth[.]org
McAfee WebAdvisor
YES
URL – Crypto Scam
22ark-invest[.]org
McAfee WebAdvisor
YES
URL – Crypto Scam
2xEther[.]com
McAfee WebAdvisor
YES
URL – Crypto Scam
Teslabtc22[.]com
McAfee WebAdvisor
YES
URL – Crypto Scam
elontoday[.]org
McAfee WebAdvisor
YES
URL – Crypto Scam
elonnew[.]com
McAfee WebAdvisor
YES
URL – Crypto Scam
teslaswell[.]com
McAfee WebAdvisor
YES
URL – Crypto Scam
2x-musk[.]net
McAfee WebAdvisor
YES
URL – Crypto Scam
doublecrypto22[.]com
McAfee WebAdvisor
YES
URL – Crypto Scam
arkinvest22[.]net
McAfee WebAdvisor
YES
The post Crypto Scammers exploit talk on Cryptocurrency appeared first on McAfee Blog.
It was discovered that jbig2dec incorrectly handled memory when parsing
invalid files. An attacker could use this issue to cause jbig2dec to crash,
leading to a denial of service. (CVE-2017-9216)
It was discovered that jbig2dec incorrectly handled memory when processing
untrusted input. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2020-12268)
slurm-21.08.8-1.fc37
Automatic update for slurm-21.08.8-1.fc37.
* Thu May 5 2022 Carl George <carl@george.computer> – 21.08.8-1
– Update to 21.08.8, resolves: rhbz#2082276
– Fix CVE-2022-29500, resolves: rhbz#2082286
– Fix CVE-2022-29501, resolves: rhbz#2082289
– Fix CVE-2022-29502, resolves: rhbz#2082293
CIS excited to sponsor and attend the 2022 AWS Summit Washington, DC at Booth 520. Join us and learn about CIS STIG resources.