Menu

Monthly Archives: February 2022

security update

If you own a computer that seems to have slowed to a crawl, you may be thinking about replacing it. But what about all the files on your old dinosaur? You may be thinking about transferring them to an external hard drive, a time-consuming and tedious process, or you may have heard of the far […]

SquirrelWaffle Adds a Twist of Fraud to Exchange Server Malspamming
Journalist won’t be prosecuted for pressing ‘view source’
Massive cyberattack takes Ukraine military, big bank websites offline
Chrome Zero-Day Under Active Attack: Patch ASAP
From the back office to the till: Cybersecurity challenges facing global retailers

How well retailers can manage the surge in cyberthreats may be crucial for their prospects in a post‑pandemic world The post From the back office to the till: Cybersecurity challenges facing global retailers appeared first on WeLiveSecurity

Google announces zero-day in Chrome browser – update now!
TA2541: APT Has Been Shooting RATs at Aviation for Years

cryptsetup could be made to expose sensitive information.

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

In an arms race with criminals to protect our privacy, it’s too early to admit defeat
Your software supply chain is under attack – how are you going to react?
Cambodia cans critics of its snoopy Internet Gateway, says every nation has one
BlackByte Tackles the SF 49ers & US Critical Infrastructure
Getting to grips with protecting industrial systems? It’s going to get messy
Adobe fixes zero-day exploit in e-commerce code: update now!
San Francisco 49ers catch ransomware, sample files leaked online

security update

Ransomware is a clear and present danger. So why rely on legacy DR to recover from it?
‘Cities: Skylines’ Gaming Modder Banned Over Hidden Malware
Adobe: Zero-Day Magento 2 RCE Bug Under Active Attack
Power company pays out $3 trillion compensation to astonished customer
Increase in sophisticated, high-impact ransomware poses rising threat, warn government agencies
Linux tops Google’s Project Zero charts for fastest bug fixes

This update upgrades Firefox to version 91.6.0 ESR. * Mozilla: Extensions could have bypassed permission confirmation during update (CVE-2022-22754) * Mozilla: Memory safety bugs fixed in Firefox 97 and Firefox ESR 91.6 (CVE-2022-22764) * Mozilla: Drag and dropping an image could have resulted in the dropped object being an executable (CVE-2022-22756) * Mozilla: Sandboxed iframes […]

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Full-time internet surveillance comes to Cambodia this week
Spot the irony: India’s Reserve Bank says outsourcing and offshoring are risky

security update

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed

Security update for CVE-2022-23303, CVE-2022-23304 Update to version 2.10, which upstream maintainer advises for these CVEs.

**Version 3.3.8** (2022-02-04) * Fix a security issue when in a sandbox: the `sort` filter must require a Closure for the `arrow` parameter * Fix deprecation notice on `round` * Fix call to deprecated `convertToHtml` method

**Version 2.14.11** (2022-02-04) * Fix a security issue when in a sandbox: the `sort` filter must require a Closure for the `arrow` parameter * Fix deprecation notice on `round` * Fix call to deprecated `convertToHtml` method

**Version 3.3.8** (2022-02-04) * Fix a security issue when in a sandbox: the `sort` filter must require a Closure for the `arrow` parameter * Fix deprecation notice on `round` * Fix call to deprecated `convertToHtml` method

**Version 2.14.11** (2022-02-04) * Fix a security issue when in a sandbox: the `sort` filter must require a Closure for the `arrow` parameter * Fix deprecation notice on `round` * Fix call to deprecated `convertToHtml` method

Several vulnerabilities have been discovered in Expat, an XML parsing C library, which could result in denial of service or potentially the execution of arbitrary code, if a malformed XML file is processed.

Facebook exposes ‘god mode’ token that could siphon data

security update

Marcel Neumann, Robert Altschaffel, Loris Guba and Dustin Hermann discovered that debian-edu-config, a set of configuration files used for the Debian Edu blend configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.

Apple emits emergency fix for exploited-in-the-wild WebKit vulnerability
Critical MQTT-Related Bugs Open Industrial Networks to RCE Via Moxa

security update

Update to 2.34.5: * Improve VP8 codec selection when using GStreamer 1.20. * Fix connecting to the accessibility bus when using the Bubblewrap sandbox. * Fix links being incorrectly activated when starting a pinch zoom gesture. * Fix touch-based scrolling. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-22589, CVE-2022-22590, CVE-2022-22592

Update to 2.4.4, fixes CVE-2022-23990.

Backport patch for CVE-2021-44648.

This is the December 2021 update for .NET Core 3.1 It updates .NET Core 3.1 to SDK 3.1.416 and Runtime 3.1.22

Cybercrooks Frame Targets by Planting Fabricated Digital Evidence
US govt: Here are another 15 security bugs under attack right now
Hidden in plain sight: How the dark web is spilling onto social media

A trip into the dark corners of Telegram, which has become a magnet for criminals peddling everything from illegal drugs to fake money and COVID-19 vaccine passes The post Hidden in plain sight: How the dark web is spilling onto social media appeared first on WeLiveSecurity

Apple zero-day drama for Macs, iPhones and iPads – patch now!
Apple Patches Actively Exploited WebKit Zero Day
Ransomware crew dumps stolen Optionis files online

Several vulnerabilities were discovered in Samba, a SMB/CIFS file, print, and login server for Unix. CVE-2021-44142

How Pure Storage helps customers guard against ransomware

An update that solves 11 vulnerabilities and has 29 fixes is now available.

CIA illegally harvested US citizens’ data, senators assert

security update

Decryptor Keys Published for Maze, Egregor, Sekhmet Ransomwares
Sharp SIM-Swapping Spike Causes $68M in Losses
This malware gang plants incriminating evidence on PCs, gets victims arrested

The ransomware attacks that make headlines and steer conversations among cybersecurity professionals usually involve major ransoms, huge corporations and notorious hacking groups. Kia Motors, Accenture, Acer, JBS…these companies were some of the largest to be compromised by ransomware in 2021. These were mainly hit with well-known variants, sometimes unleashed by state-backed hacking groups. But it’s […]

security update

– Updated to latest upstream (97.0)

– Update to upstream 2.1-34. 20220207 – Removal of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f; – Removal of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04) at revision 0xb00000f; – Removal of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05) at revision 0xb00000f; – Removal of 06-86-05/0x01 (SNR B1) microcode at revision

Security fixes for CVE-2022-0408, CVE-2022-0413, CVE-2022-0393, CVE-2022-0417, CVE-2022-0443

# New features: ## 0.45 – –only-cook ‘! ‘ enables confident mode where every possible prompt that matches a regexp is cooked immediately (so that even prompts that get printed while handling a large paste are cooked). – –no-children (-N) now enables direct mode whenever the client switches to the alternate screen. This makes editors […]

WhiteSource report warns of NPM registry risks
The bizarre couple alleged to be behind one of the biggest cryptocurrency hacks of all time
ESET Threat Report T3 2021

A view of the T3 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T3 2021 appeared first on WeLiveSecurity

SAP Patches Severe ‘ICMAD’ Bugs
Use Zoom on a Mac? You might want to check your microphone settings
PHP Everywhere Bugs Put 30K+ WordPress Sites at Risk of RCE
Beware scammy SMS messages claiming to come from HMRC
More than $400 million drained from hacked blockchain bridges in little more than a week
Smashing Security podcast #261: North Korea hacked, DEA cosplay, and Horizon Worlds drama

Speex could be made to denial of service if it received a specially crafted WAV file.

Red Hat OpenShift Container Platform release 4.9.19 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.9.

Swipe left: Snoops use dating apps to hook sources, says Australian Five Eyes boss

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, bypass of deserialization restrictions or information disclosure.

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

S3 Ep69: WordPress woes, Wormhole holes, and a Microsoft change of heart [Podcast + Transcript]
Cybercriminals Swarm Windows Utility Regsvr32 to Spread Malware
3 Tips for Facing the Harsh Truths of Cybersecurity in 2022, Part I
US: Your AI has to explain its decisions

No more turning a blind eye to algorithmic bias and discrimination if US lawmakers get their way The post US: Your AI has to explain its decisions appeared first on WeLiveSecurity

UK, US, Australia issue joint advisory: Ransomware on the loose, critical national infrastructure affected
Self-styled “Crocodile of Wall Street” arrested with husband over Bitcoin megaheist
MoleRats APT Flaunts New Trojan in Latest Cyberespionage Campaign
Ex-Gumshoe Nabs Cybercrooks with FBI Tactics

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: