Threat actors may spread false claims about compromised voting systems in order to undermine confidence in the electoral process The post FBI, CISA warn of disinformation campaigns about hacked voting systems appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
Updated OpenShift Container Storage packages fixing various security issues and other bugs are now available for Red Hat OpenShift Container Storage with 3.11.z Async update. Red Hat Product Security has rated this update as having a security impact
An update that solves four vulnerabilities and has two fixes is now available.
Several security improvements were added to Samba.
Several security issues were fixed in Tomcat.
security update
Reading Time: ~ 2 min. DHS Announces Massive Increase in LokiBot Attacks By monitoring and tracking of cyberattacks over 2020, U.S. Department of Homeland Security (DHS) officials have uncovered a significant increase in cyberattacks being carried out by LokiBot, a malicious info-stealer of stored passwords and cryptocurrency information. The increase in LokiBot attacks can likely […]
The package podman before version 2.1.0-1 is vulnerable to information disclosure.
The package firefox before version 81.0-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, cross-site scripting and denial of service.
The package chromium before version 85.0.4183.121-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution, information disclosure and insufficient validation.
The package libvirt before version 6.5.0-2 is vulnerable to privilege escalation.
An update that solves 11 vulnerabilities and has one errata is now available.
An update that solves 10 vulnerabilities and has one errata is now available.
Several security issues were fixed in iTALC.
libuv could be made to crash or execute arbitrary code if it received a specially crafted path.
Reading Time: ~ 2 min. “Ten years ago, you didn’t see state actors attacking [small businesses]. But it’s happening now,” warns George Anderson, product marketing director at Carbonite + Webroot, OpenText companies. Sadly, many of today’s managed service providers who serve small and medium-sized businesses now have to concern themselves with these very threats. Independent […]
ImageMagick could be made to crash if it opened a specially crafted file.
Several vulnerabilities were discovered in the Perl5 Database Interface (DBI). An attacker could trigger a denial-of-service (DoS) and possibly execute arbitrary code.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has 6 fixes is now available.
An update that fixes 7 vulnerabilities is now available.
grub2 updates for boothole vulnerabilities in f31/f32.
security update
x86 pv: Crash when handling guest access to MSR_MISC_ENABLE [XSA-333, CVE-2020-25602] (#1881619) Missing unlock in XENMEM_acquire_resource error path [XSA-334, CVE-2020-25598] (#1881616) race when migrating timers between x86 HVM vCPU-s [XSA-336, CVE-2020-25604] (#1881618) PCI passthrough code reading back hardware registers [XSA-337, CVE-2020-25595] (#1881587) once valid event
An update that fixes 7 vulnerabilities is now available.
Two issues have been found in yaws, a high performance HTTP 1.1 webserver written in Erlang.
Two issues have been found in nfdump, a netflow capture daemon. Both issues are related to either a buffer overflow or an integer overflow, which could result in a denial of service or a local code
An issue has been found in curl, a command line tool for transferring data with URL syntax. In rare circumstances, when using the multi API of curl in combination
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
security update
There is no evidence that cybercriminals were also able to steal customer data The post Ray‑Ban parent company reportedly suffers major ransomware attack appeared first on WeLiveSecurity
An update that solves one vulnerability and has one errata is now available.
Several security issues were fixed in Gnuplot.
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work: SpecialUserRights could leak whether a user existed or not, multiple code paths lacked HTML sanitisation allowing for cross-site scripting and TOTP validation applied insufficient rate
Sanitize could be made to perform XSS attacks if it received specially crafted input.
Disable pkcs11 related test case running into GnuTLS locking bug
CVE-2020-12100: Parsing mails with a large number of MIME parts could have resulted in excessive CPU usage or a crash due to running out of stack memory. CVE-2020-12673: Dovecot’s NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. CVE-2020-10967: lmtp/submission:
The sting is said to be the US Government’s largest operation targeting crime in the internet’s seedy underbelly The post 179 arrested in massive dark web bust appeared first on WeLiveSecurity
