The MS- and EI-ISAC Cyber Threat Intelligence team helps support SLTTs’ cybersecurity defenses. Here’s what we mean when we say “CTI.”
Daily Archives: October 12, 2023
WordPress 6.3.2 – Maintenance and Security release
This security and maintenance release features 19 bug fixes on Core, 22 bug fixes for the Block Editor, and 8 security fixes.
WordPress 6.3.2 is a short-cycle release. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.
Because this is a security release, it is recommended that you update your sites immediately. Backports are also available for other major WordPress releases, 4.1 and later.
The next major release will be version 6.4 planned for 7 November 2023.
If you have sites that support automatic background updates, the update process will begin automatically.
You can download WordPress 6.3.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”.
For more information on this release, please visit the HelpHub site.
Security updates included in this release
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
Marc Montpas of Automattic for finding a potential disclosure of user email addresses.
Marc Montpas of Automattic for finding an RCE POP Chains vulnerability.
Rafie Muhammad and Edouard L of Patchstack along with a WordPress commissioned third-party audit for each independently identifying a XSS issue in the post link navigation block.
Jb Audras of the WordPress Security Team and Rafie Muhammad of Patchstack for each independently discovering an issue where comments on private posts could be leaked to other users.
John Blackbourn (WordPress Security Team), James Golovich, J.D Grimes, Numan Turle, WhiteCyberSec for each independently identifying a way for logged in user to execute any shortcode.
mascara7784 and a third-party security audit for identifying a XSS vulnerability in the application password screen.
Jorge Costa of the WordPress Core Team for identifying XSS vulnerability in the footnotes block.
s5s and raouf_maklouf for independently identifying a cache poisoning DoS vulnerability.
Thank you to these WordPress contributors
This release was led by Joe McGill, Aaron Jorbin and Jb Audras, with the help of David Baumwald on mission control.
WordPress 6.3.2 would not have been possible without the contributions of the following people. Their asynchronous coordination to deliver maintenance and security fixes into a stable release is a testament to the power and capability of the WordPress community.
Aaron Jorbin, Aki Hamano, Akihiro Harai, Alex Concha, Andrew Ozz, Andy Fragen, Anthony Burchell, Aurooba Ahmed, Ben Dwyer, Carolina Nymark, Colin Stewart, Corey Worrell, Damon Cook, David Biňovec, David E. Smith, Dean Sas, Dennis Snell, Dhruvi Shah, Dion Hulse, Ehtisham S., Felix Arntz, George Mamadashvili, Greg Ziółkowski, Huzaifa Al Mesbah, Isabel Brison, Jb Audras, Joe Hoyle, Joe McGill, John Blackbourn, John James Jacoby, Jonathan Desrosiers, Jonny Harris, Jorge Costa, Justin Tadlock, K. Adam White, Kim Coleman, LarryWEB, Liam Gladdy, Mehedi Hassan, Miguel Fonseca, Mukesh Panchal, Nicole Furlan, Paul Biron, Paul Kevan, Peter Wilson, Pooja N Muchandikar, Rajin Sharwar, Ryan McCue, Sal Ferrarello, Sergey Biryukov, Shail Mehta, Stephen Bernhardt, Teddy Patriarca, Timothy Jacobs, Weston Ruter, Zunaid Amin, ahardyjpl, beryldlg, floydwilde, jastos, martin.krcho, masteradhoc, petitphp, ramonopoly, vortfu, zieladam
How to contribute
To get involved in WordPress core development, head over to Trac, pick a ticket, and join the conversation in the #core and #6-4-release-leads channels. Need help? Check out the Core Contributor Handbook.
Already testing WordPress 6.4? The fourth beta is now available (zip) and it contains these security fixes. For more on 6.4, see the beta 3 announcement post.
Thanks to @jeffpaul, @chanthaboune, @peterwilsoncc and @rawrly for proofreading.
User Data from 23andMe Leaked Online – What Users Should Do, and the Rest of Us Too
A hacker claims to have hijacked profile information of “millions” of users from the popular genetic testing site 23andMe.com.
What’s at risk? Some of the most personal info possible. The profile info varies by user, which plans and services they’ve selected, and how the hacker accessed it. Yet it potentially includes personal info like name, sex, birth year, current location, and some details about genetic ancestry and health results.
23andMe continues to keep its users informed of the hijacked accounts on its blog. As of October 9, they shared the following:
“While we are continuing to investigate this matter, we believe threat actors were able to access certain accounts in instances where users recycled login credentials – that is, usernames and passwords that were used on 23andMe.com were the same as those used on other websites that have been previously hacked.”
Currently, it appears that 23andMe’s systems weren’t breached. Rather, it appears human error is to blame—people who reused the same compromised passwords across different sites led to their accounts being compromised.
However, the attacker gained access to info from many users who were not themselves compromised but opted in for the DNA Relatives feature. According to 23andMe, DNA Relatives works like so:
If you choose to opt in and participate in DNA Relatives, all your matches will be able to view the following information about you:
Your display name.
Your profile gender.
Your profile picture.
Your predicted relationship.
The percent DNA and number of segments you share, but not the location of those segments.
Relatives in common.
This widens the impact of the attack yet more. Users who have compromised accounts might contain info from uncompromised accounts because both parties have opted in for the DNA Relatives feature. In this way, one hack potentially leads to broader information leakage. Even if the other users have secure passwords.
Per reports, the hacker claiming responsibility has offered it up for sale on a dark web forum. As an apparent example of how the data can be packaged, the hacker listed alleged data of one million Jewish Ashkenazi users—people of Central or Eastern European Jewish descent. Another has reportedly listed 100,000 alleged records of people of Chinese descent.
What steps has 23andMe taken to protect its users?
Per the company’s statement on its blog, “If we learn that a customer’s data has been accessed without their authorization, we will notify them directly with more information.” Moreover, the company said,
“Our investigation continues and we have engaged the assistance of third-party forensic experts. We are also working with federal law enforcement officials.
We are reaching out to our customers to provide an update on the investigation and to encourage them to take additional actions to keep their account and password secure. Out of caution, we are requiring that all customers reset their passwords and are encouraging the use of multi-factor authentication (MFA).”
Additionally, we suggest you take those steps and more.
The three steps every 23andMe user must take right away.
As potentially unsettling this news may come, 23andMe users can take the following steps. They’ll secure your accounts moving forward and help you fend off attempts at identity theft.
Change your passwords immediately: Given the attack, 23andMe has forced all its users to reset their passwords. However, changing passwords is not enough. Every password must be strong and unique. For every account. If that sounds like a task, a password manager can help. It creates strong, unique passwords—and stores them securely. This way, you can avoid falling victim to attacks where bad actors try to use passwords stolen from one account to break into another. That’s the beauty of no-repeat passwords.
Use multi-factor authentication (MFA): Many online accounts offer MFA, also known as 2-factor authentication or 2FA. It adds an extra step to the login process, such as sending a six-digit code to your phone with a call or text. If your accounts support this, use it. It makes it far more difficult for hackers to break into your account—even if they end up with your password. Also, never provide an authentication number to anyone else. It’s yours, and yours alone. Treat it like the secret code it is. Specific to 23andMe users, you can enable MFA with the instructions on this page.
Monitor your identity, credit, and transactions: In the wake of any attack where your personal info might be at risk, keep an eye on all things you. Your bank accounts, credit cards, online finances, and your credit rating. Hackers view personal info as a gold mine. Rightly so. With it, they can go on to compromise other accounts or commit other identity crimes. Like file insurance claims or open new lines of credit in your name. Comprehensive online protection software can help you spot unauthorized account activity, changes in your credit report, or if your personal info winds up on the dark web. It saves you hours and hours of effort, and it gives you assurance that all’s well with a quick glance.
Look into identity theft protection
Our Identity Theft & Restoration Coverage can help you set things straight if identity theft happens to you. Licensed recovery experts can take steps to repair your identity and credit. Further, you gain up to $2 million in coverage for lawyer fees, travel expenses, and stolen funds reimbursement. This offers you stronger assurance lifts the time and financial burden of identity theft off your shoulders.
And for everyone, consider what you share online.
Far and beyond 23andMe users, everyone who goes online should take note of this attack. Which is pretty much all of us. It makes one of the strongest cases for strong, unique passwords—and for limiting the info you share online. In this case, even a secure password was no help in protecting the personal info of millions of people.
If you’re a 23andMe user, you can opt out of DNA Relatives by selecting the Manage Preferences option within DNA Relatives or from your Account Settings page. Granted, this will remove your ability to gain deeper genetic insights from other users, yet it will offer additional protection if a similar attack occurs.
For all of us, sharing and storing personal info is a fact of life online. The more you share and store online, the more risk you take on. And you have some control over that.
Consider what you’re sharing, who you’re sharing it with, what they do with that info, who they share it with, and in what form and circumstances. Yes, that’s a lot to consider. Complicating that yet more, many of the sites, services, and apps we use don’t make it easy to answer those questions. Terms of service and data policies rarely make for light and understandable reading.
Luckily, you can turn to trustworthy resources to get answers. The Common Sense Privacy Program evaluates privacy policies with K-12 students in mind. The Mozilla Foundation’s Privacy Not Included website scores apps and connected devices for privacy, including apps, smart home devices, and cars.
In an otherwise murky landscape, the privacy question is this: is the reward worth the risk? If you share that info, are you okay with someone unwanted accessing it? Particularly if the privacy risks are tough to spot.
Put simply, less sharing means more privacy. Put careful thought into when and where you share. And with whom.
Shut down your old accounts for yet more privacy and security.
On that note, it might be time for a cleanup.
We’ve logged into all kinds of things over the years. Many of which we don’t log into anymore. And others we’ve completely forgotten about. Across these forums, sites, and stores, you’ll find your personal info to some degree or other. If one of those sites gets compromised, your personal info stored there might get compromised too. That gives you a solid reason to delete those old accounts.
A tool like our Online Account Cleanup can help remove your info from online accounts. You’ll find it in our online protection software, along with our Personal Data Cleanup—which helps remove your personal info from risky data broker sites. It shows you where your personal info was found, and what data the sites have. Depending on your plan, it can help clean it up.
The 23andMe compromised data—a wakeup call for all of us.
The 23andMe story continues to develop. Yet we’ve already (re)learned a big lesson from all of this. Strong, unique passwords are an absolute must. And the stakes for online privacy have never been higher.
Today we entrust the internet with so much, which increasingly includes our heath and wellness info, not to mention genetic info with services like 23andMe. Taking the steps outlined here can help protect yourself from invasions of privacy and the loss of personal info. And as we’ve seen, protect others too. Consider them whether you’re a 23andMe user or not.
The post User Data from 23andMe Leaked Online – What Users Should Do, and the Rest of Us Too appeared first on McAfee Blog.
ansible-core-2.14.11-1.fc37
FEDORA-2023-cdc7db366e
Packages in this update:
ansible-core-2.14.11-1.fc37
Update description:
Update to 2.14.11.
Mitigates CVE-2023-5115.
ansible-core-2.14.11-1.fc38
FEDORA-2023-e5d4a632a5
Packages in this update:
ansible-core-2.14.11-1.fc38
Update description:
Update to 2.14.11.
Mitigates CVE-2023-5115.
CISOs Receive Smaller Raises and Bonuses in 2023
rclone-1.64.0-1.fc40
FEDORA-2023-ff1e594f3d
Packages in this update:
rclone-1.64.0-1.fc40
Update description:
Automatic update for rclone-1.64.0-1.fc40.
Changelog
* Thu Oct 12 2023 Mikel Olasagasti Uranga <mikel@olasagasti.info> – 1.64.0-1
– Update to 1.64.0 – Closes rhbz#2238581 rhbz#2229610 rhbz#2229606
Vulnerability Exposed in WordPress Plugin User Submitted Posts
With over 20,000 active installations, the plugin is used for user-generated content submissions
California Enacts “Delete Act” For Data Privacy
Governor Newsom signed the first US bill requiring data brokers to delete personal data upon request
USN-6430-1: FFmpeg vulnerabilities
It was discovered that FFmpeg did not properly handle certain inputs in
vf_lagfun.c, resulting in a buffer overflow vulnerability. An attacker
could possibly use this issue to cause a denial of service via application
crash. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-22024)
It was discovered that FFmpeg incorrectly managed memory in avienc.c,
resulting in a memory leak. An attacker could possibly use this issue
to cause a denial of service via application crash. (CVE-2020-22039)
It was discovered that FFmpeg incorrectly handled certain files due to a
memory leak in frame.c. An attacker could possibly use this issue to cause
a denial of service via application crash. This issue affected
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-22040)
It was discovered that FFmpeg incorrectly handled certain files due to a
memory leak in fifo.c. An attacker could possibly use this issue to cause
a denial of service via application crash. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-22043)
It was discovered that FFmpeg incorrectly handled certain files due to a
memory leak in vf_tile.c. If a user or automated system were tricked into
processing a specially crafted MOV file, an attacker could possibly use
this issue to cause a denial of service. (CVE-2020-22051)
It was discovered that FFmpeg incorrectly handled certain MOV files in
timecode.c, leading to an integer overflow. An attacker could possibly
use this issue to cause a denial of service using a crafted MOV file.
This issue only affected Ubuntu 16.04 LTS. (CVE-2021-28429)