Menu

Monthly Archives: February 2022

Quarter of a million lawyer disciplinary records leak
Ukraine-Russia Cyber Warzone Splits Cyber Underground
Conti ransomware gang leak: 60,000 messages online
Instagram scammers as busy as ever: passwords and 2FA codes at risk
Toyota to Close Japan Plants After Suspected Cyberattack
Beware of charity scams exploiting war in Ukraine

Looking to help people in Ukraine? Donate wisely – do your research first so you give without getting scammed The post Beware of charity scams exploiting war in Ukraine appeared first on WeLiveSecurity

#ShieldsUp – Now is the time to double‑check cybersecurity processes and operations

As the conflict in Ukraine heightens the risk of cyberattacks globally, what can organizations do to improve their resiliency? The post #ShieldsUp – Now is the time to double‑check cybersecurity processes and operations appeared first on WeLiveSecurity

Kremlin and Russia’s TASS news agency websites offline following attacks
Play for Ukraine game aims to knock Russian websites offline

The container trento/trento-db was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220222-gen2 was updated. The following patches have been included in this update:

Nmap Basics: What Is Nmap & How Is It Used?>
Russia is the advanced persistent threat that just triggered. Ready?

Several security issues were fixed in QEMU.

Several security issues were fixed in WebKitGTK.

Several security issues were fixed in MariaDB.

policykit-1 could be made to crash if it received specially crafted data.

Tech world’s Ukraine response mixes evacuation efforts, ad bans, free phones, infosec FUD

The 5.16.11 stable kernel update contains a number of important fixes across the tree.

One issue have been discovered in ujson: ultra fast JSON encoder and decoder for Python. CVE-2021-45958

It was discovered that the SQL plugin in cyrus-sasl2, a library implementing the Simple Authentication and Security Layer, is prone to a SQL injection attack. An authenticated remote attacker can take advantage of this flaw to execute arbitrary SQL commands and for

An update for openshift-gitops-applicationset-container, openshift-gitops-container, openshift-gitops-kam-delivery-container, and openshift-gitops-operator-container is now available for Red Hat OpenShift GitOps 1.3 on OCP 4.7-4.9. (GitOps v1.3.4)

Security fix for CVE-2022-0554 —- Security fixes for CVE-2022-0714, CVE-2022-0729 —- Security fix for CVE-2022-0696 —- Security fix for CVE-2022-0629 —- Security fix for CVE-2022-0572 —- Security fixes for CVE-2022-0408, CVE-2022-0413, CVE-2022-0393, CVE-2022-0417, CVE-2022-0443 —- Security fix for CVE-2022-0685

Ukrainian military personnel targeted with phishing attacks

Several issues have been found in htmldoc, an HTML processor that generates indexed HTML, PS, and PDF.

Nvidia probes cyberattack on internal systems
TrickBot Takes a Break, Leaving Researchers Scratching Their Heads
Microsoft Exchange Bugs Exploited by ‘Cuba’ Ransomware Gang
Ukraine seeks volunteers to defend networks as Russian troops menace Kyiv
6 Cyber-Defense Steps to Take Now to Protect Your Company
Did we learn nothing from Y2K? Why are some coders still stuck on two digit numbers?
Conti ransomware gang: You attack Russia, we’ll hack you back
HermeticWiper: New data‑wiping malware hits Ukraine

Hundreds of computers in Ukraine compromised just hours after a wave of DDoS attacks brings down a number of Ukrainian websites The post HermeticWiper: New data‑wiping malware hits Ukraine appeared first on WeLiveSecurity

Ukraine calls for volunteer hackers to protect its critical infrastructure and spy on Russian forces

# New in release OpenJDK 11.0.14.1 (2022-02-08): Live versions of these release notes can be found at: * https://bitly.com/openjdk110141 * https://builds.shipilev.net/backports-monitor/release-notes-11.0.14.1.txt # Changes * [JDK-8218546](https://bugs.openjdk.java.net/browse/JDK-8218546): Unable to connect to https://google.com using java.net.HttpClient —- # New

virtiofsd: Drop membership of all supplementary groups (CVE-2022-0358)

Security fix for https://www.gnutls.org/security-new.html#GNUTLS-SA-2022-01-17

Security fix for CVE-2021-0561

The newest upstream commit — Security fixes for CVE-2022-0714, CVE-2022-0729

The 5.16.11 stable kernel update contains a number of important fixes across the tree.

UK Computer Misuse Act reformers visit Parliament
When it comes to software pipelines, zero days shouldn’t mean zero productivity

Making the case The pros behind Carbonite + Webroot joined forces with industry leading researchers at IDC to develop an easy-to-understand framework for fighting back against cybercrime. The results? A 6-step plan for adopting a cyber resilience strategy meant to keep businesses safe. IDC looked into the data and past the alarming headlines with million-dollar […]

White House Denies Mulling Massive Cyberattacks Against Russia
Cyberwarfare looms as Russia shells, invades Ukraine
The Harsh Truths of Cybersecurity in 2022, Part II

security update

Zenly Social-Media App Bugs Allow Account Takeover
Microsoft App Store Sizzling with New ‘Electron Bot’ Malware
Technology, Progress, and Climate

The climate solutions we need to transform every sector are here. The question is: what role will you play in this transformation? You, your community, your business, your government? The post Technology, Progress, and Climate appeared first on WeLiveSecurity

S3 Ep71: VMware escapes, PHP holes, WP plugin woes, and scary scams [Podcast + Transcript]
BlueVoyant pulls in another $250m in venture funding
Manufacturing was the top industry targeted by ransomware last year, claims report
Web Filtering and Compliances for Wi-Fi Providers
Cyberattackers Leverage DocuSign to Steal Microsoft Outlook Logins
Cloudflare buys anti-phishing business Area 1 for $162m
The Art of Non-boring Cybersec Training–Podcast
Creaky Old WannaCry, GandCrab Top the Ransomware Scene

An update for python-pillow is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for python-pillow is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for cyrus-sasl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Red Hat OpenShift Container Platform release 3.11.634 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for cyrus-sasl is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for python-pillow is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Understand the RSA encryption algorithm
How Attack Path Modelling from Darktrace can help you prevent your next cyber-attack
US winds up national security team dedicated to Chinese espionage
Smashing Security podcast #263: Problèmes de Weefeee, AI artists, and Web 3.0
‘Hundreds of computers’ in Ukraine hit with wiper malware as conflict continues
Millions of dollars pour into security compliance startups amid pressure on business
Samsung Shattered Encryption on 100M Phones

security update

Anatomy of suspected top-tier NSA backdoor that was hidden for years
Ukraine hit by DDoS attacks, Russia deploys malware
Apple AirTag anti-stalking protection bypassed by researchers
Microsoft adds GCP to Defender for Cloud
Sextortion Rears Its Ugly Head Again
Teenage cybercrime: How to stop kids from taking the wrong path

It’s never too late to prevent children from being dragged to the dark side and to ensure their skills are a force for good The post Teenage cybercrime: How to stop kids from taking the wrong path appeared first on WeLiveSecurity

Ubuntu applies security fixes for all versions back to 14.04

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Dutch govt issues data protection report card for Microsoft
How to protect your Kubernetes infrastructure from the Argo CD vulnerability
Cisco warns firewall customers of four-day window for urgent updates
China’s APT10 cyber-spies ‘targeted Taiwanese financial firms’
Samsung shipped ‘100 million’ phones with flawed encryption

The UK government has released a National Cyber Strategy to help guide the country’s strategic approach to combating the proliferation of cyber threats. As part of this strategy, the UK government is looking to expand its regulations under the Network and Information Systems (NIS) to include managed service providers (MSPs). The government’s efforts follow a […]

According to the latest ISACA State of Security 2021 report, social engineering is the leading cause of compromises experienced by organizations. Findings from the Verizon 2021 Data Breach Investigations Report also point to social engineering as the most common data breach attack method. Social engineering is a term used to describe the actions a cybercriminal […]

Gaming, Banking Trojans Dominate Mobile Malware Scene
Cyberattackers Cook Up Employee Personal Data Heist for Meyer
Xenomorph Malware Burrows into Google Play Users, No Facehugger Required
The machine fights back: AI that fights cyber-threats on behalf of humans
WordPress backup plugin maker Updraft says “You should update”…
Integer overflow: How does it occur and how can it be prevented?

Make no mistake, counting on a computer is not as easy as it may seem. Here’s what happens when a number gets “too big”. The post Integer overflow: How does it occur and how can it be prevented? appeared first on WeLiveSecurity

Asustor NAS owners hit by DeadBolt ransomware attack
Airtag clones can sidestep Apple anti-stalker tech