Menu

Monthly Archives: February 2022

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Critical ‘remote escalation’ flaw in Android 12 fixed in Feb security patch batch
Sri Lanka to adopt India’s Aadhaar digital identity scheme
Microsoft manages a mere 51 security fixes for February update bundle
FBI seizes $3.6bn in Bitcoin after New York ‘tech couple’ arrested over Bitfinex robbery

security update

No Critical Bugs for Microsoft February 2022 Patch Tuesday, 1 Zero-Day
Canadian Netwalker ransomware crook pleads guilty to million-dollar crimes
At last! Office macros from the internet to be blocked by default
UK.gov threatens to make adults give credit card details for access to Facebook or TikTok
China Suspected of News Corp Cyberespionage Attack
A US hacker blasted North Korea off the internet following missile tests

An update for aide is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat AMQ Streams 1.6.7 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat AMQ Streams 2.0.1 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for aide is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for ansible-runner for Red Hat Ansible Automation Platform 2.0 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for aide is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Vice Society said to be behind digital break-in at UK umbrella and accounting group
Labour reminds UK.gov that it’s supposed to be reforming the Computer Misuse Act
Experience is really everything with SASE
Microsoft to block downloaded VBA macros in Office – you may be able to run ’em anyway
CISA Orders Federal Agencies to Fix Actively Exploited Windows Bug
Medusa Malware Joins Flubot’s Android Distribution Network
LockBit, BlackCat, Swissport, Oh My! Ransomware Activity Stays Strong
QuaDream, 2nd Israeli Spyware Firm, Weaponizes iPhone Bug
Roaming Mantis Expands Android Backdoor to Europe
Microsoft 365 gives you the tools to run your business. But where are the tools to protect it?
Microsoft blocks web installation of its own App Installer files
Who dropped the DB? Find out with Teleport Database Access
Twitter blackout for Vodafone customers

Upstream details at : https://access.redhat.com/errata/RHSA-2022:0442

An update that fixes 18 vulnerabilities is now available.

Several security issues were fixed in Django.

US carriers want to junk three times more Chinese comms kit than planned

Rebuild with 1.58.1 toolchain to incorporate remove_dir_all bug fix

Backport patch for CVE-2021-45930.

Rebuild with 1.58.1 toolchain to incorporate remove_dir_all bug fix

It was found that in libphp-adodb, a PHP database abstraction layer library, an attacker can inject values into the PostgreSQL connection string by bypassing adodb_addslashes(). The function can be bypassed in phppgadmin, for example, by surrounding the username in quotes and

The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.

The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.

The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.

Backport patches for CVE-2021-3933 and CVE-2021-3941.

Backport patch for head overflow.

Impacts from a new reality drive the need for an enhanced digital identity framework
Suspected Chinese spies break into cloud accounts of News Corp journalists

security update

security update

The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.

The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.

The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.

Security bugs in libmount, CVE-2021-3996 and CVE-2021-3995.

‘Long Live Log4Shell’: CVE-2021-44228 Not Dead Yet
Argo CD Security Bug Opens Kubernetes Cloud Apps to Attackers
Wormhole cryptotrading company turns over $340,000,000 to criminals
Open-source Kubernetes tool Argo CD has a high-severity path traversal flaw: Patch now
Attackers Target Intuit Users by Threatening to Cancel Tax Accounts

An update that solves three vulnerabilities, contains one feature and has one errata is now available.

Several vulnerabilities have been discovered in apng2gif, a tool for converting APNG images to animated GIF format. Improper sanitization of user input can result in denial of service (application crash) or possible execution of arbitrary code if a malformed image file is processed.

An update that fixes three vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

That’s a signature move: How $320m in Ether was stolen from crypto biz Wormhole
Kronos Still Dragging Itself Back From Ransomware Hell
Low-Detection Phishing Kits Increasingly Bypass MFA
Privacy Shield: EU citizens might get right to challenge US access to their data
Phishing kits’ use of man-in-the-middle reverse proxies is growing, warns Proofpoint

This update addresses a bugs in the handling of timestamps in the `recvmsg` and `recvmmsg` on armhpf and i686 ([swbz#28349](https://sourceware.org/bugzilla/show_bug.cgi?id=28349), [swbz#28350](https://sourceware.org/bugzilla/show_bug.cgi?id=28350)). A bug in some optimized versions of `wcsncmp` on x86_64 is fixed

Bump version to 2.0.14-1 —- Security fix for CVE-2021-45720

Critical Cisco Bugs Open VPN Routers to Cyberattacks
JumpCloud joins the patch management crowd, starting with Windows and Mac updates
Wormhole Crypto Platform: ‘Funds Are Safe’ After $314M Heist
Ransomware is terrifying – but never underestimate the damage an employee with unmonitored access can do
BlackCat ransomware – what you need to know
KP Snacks hit by ransomware: Crisps and nuts firm KO’d by modern scourge
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Some fraudsters may use low-tech tactics to steal your sensitive information – peering over your shoulder as you enter that data is one of them The post Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone appeared first on WeLiveSecurity

S3 Ep68: Bugs, scams, privacy …and fonts?! [Podcast + Transcript]
Thousands of Malicious npm Packages Threaten Web Apps
PowerPoint Files Abused to Take Over Computers
Execs keep flinging money at us instead of understanding security, moan infosec pros

An update for the varnish:6 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the varnish:6 module is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the varnish:6 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated images are now available for Red Hat Advanced Cluster Security for Kubernetes (RHACS). The updated image includes a bug fixes, security patches and new feature enhancements. Red Hat Product Security has rated this update as having a security impact

Release of OpenShift Serverless Client kn 1.20.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Smashing Security podcast #260: New hire mystery, hacktivist ransomware, and digi-dating
Linux Legend “maddog” Shares Exclusive Security Insights with LinuxSecurity>
Crunch! Ransomware hits KP Nuts, Hula Hoops, and McCoys crisps
Welsh home improvement biz fined £200,000 over campaign of 675,478 nuisance calls
FBI says more cyber attacks come from China than everywhere else combined
Worried about occasional npm malware scares? It’s more common than you may think
KP Snacks Left with Crumbs After Ransomware Attack

Threat actors are becoming more sophisticated, agile and relentless in their pursuit of stealing personal information for financial gain. Rapid and evolving shifts in the threat landscape require the knowledge and solutions to prepare and prevent threats that could spell disaster for organizations’ reputations and operations. Organizations of all sizes remain at risk. Small to […]

Supply-Chain Security Is Not a Problem…It’s a Predicament
Remote code execution vulnerability in Samba due to macOS interop module
Elementor WordPress plugin has a gaping security hole – update now