Menu

Monthly Archives: March 2022

Red Hat OpenShift Container Platform release 4.10.5 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

Red Hat OpenShift Container Platform release 4.9.25 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Hackers demand $15 million ransom from TransUnion after cracking “password” password

The container ses/6/rook/ceph was updated. The following patches have been included in this update:

The container ses/6/ceph/ceph was updated. The following patches have been included in this update:

The container ses/6/cephcsi/cephcsi was updated. The following patches have been included in this update:

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

An update that fixes one vulnerability is now available.

The 5.16.15 stable kernel update includes a number of important fixes across the tree. It also includes a temporary revert of the feature that makes QNAP NFS mounts fail. We will carry this revert through the 5.16 series in attempt to give the vendor more time to come out with an update, or upstream to […]

WordPress 5.9.2 Security & Maintenance Release

New upstream release 3.1.4

The security update announced as DLA 2955-1 caused a regression in named due to an incomplete fix for CVE-2021-25220 when the Forwarders option was configured. Updated bind9 packages are now available to correct this issue.

Regulatory compliance at scale with Red Hat Insights
This browser-in-browser attack is perfect for phishing
Agencies Warn on Satellite Hacks & GPS Jamming Affecting Airplanes, Critical Infrastructure

It was found that bind9, an internet domain name server, was vulnerable to cache poisoning. When using forwarders, bogus NS records supplied by, or via, those forwarders may be cached and used by named if it needs to recurse for any reason, causing it to obtain and pass on potentially incorrect answers.

Cyclops Blink malware sets up shop in ASUS routers
DarkHotel APT Targets Wynn, Macao Hotels to Rip Off Guest Data
OpenSSL patches infinite-loop DoS bug in certificate verification
Sandworm APT Hunts for ASUS Routers with Cyclops Blink Botnet
Exotic Lily is a business-like access broker for ransomware gangs
Google Blows Lid Off Conti, Diavol Ransomware Access-Broker Ops

The container trento/trento-web was updated. The following patches have been included in this update:

The container trento/trento-runner was updated. The following patches have been included in this update:

The container trento/trento-db was updated. The following patches have been included in this update:

CISOs face ‘perfect storm’ of ransomware and state-supported cybercrime

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

SAP community website leaks member data to savvy users
Has Trickbot gang hijacked your router? This scanner may have an answer
Dev Sabotages Popular NPM Package to Protest Russian Invasion
As tax deadlines approach, Emotet malware disguises itself in an IRS email
US military vs. Silicon Valley – a cultural divide

The US military knows it needs to speed up technology adoption through optimization, something at the heart of Silicon Valley culture The post US military vs. Silicon Valley – a cultural divide appeared first on WeLiveSecurity

Misconfigured Firebase Databases Exposing Data in Mobile Apps
Deepfake President Zelensky calls on Ukraine to surrender, as TV station hacked
S3 Ep74: Cybercrime busts, Apple patches, Pi Day, and disconnect effects [Podcast]
Reporting Mandates to Clear Up Feds’ Hazy Look into Threat Landscape – Podcast
How CAPTCHAs can cloak phishing URLs in emails

This is a maintenance release of OpenVPN 2.5 with a security fix when used in server mode ([CVE-2022-0547](https://community.openvpn.net/openvpn/wiki/CVE-2022-0547)). The other changes are available in [Changes.rst](https://github.com/OpenVPN/openvpn/blob/release/2.5/Changes.rst).

Update to 91.7.0

Update to version 1.5.5. This includes a fix for a denial-of-service vulnerability ([RUSTSEC-2022-0013](https://rustsec.org/advisories/RUSTSEC-2022-0013.html) / [CVE-2022-24713](https://cve.mitre.org/cgi- bin/cvename.cgi?name=CVE-2022-24713)).

Fix potential DoS in pesign daemon

Brit data regulator fines five cold-calling fiends £405k

An update that fixes one vulnerability, contains one feature is now available.

An update that fixes one vulnerability, contains one feature is now available.

Devil-may-care Lapsus$ gang is not the aspirational brand infosec needs
Smashing Security podcast #266: Dick pics, secret spies, and Kaspersky
CafePress fined for covering up 2019 customer info leak
LokiLocker ransomware family spotted with built-in wiper

security update

Linux botnet exploits Log4j flaw to pwn Arm, x86 systems
Police arrest scammer on FBI’s “Most Wanted” list in relation to $100 million fraud
‘CryptoRom’ Crypto-Scam is Back via Side-Loaded Apps
Another Destructive Wiper Targets Organizations in Ukraine
Beware bogus Betas – cryptocoin scammers abuse Apple’s TestFlight system
Russia-linked attackers breach NGO by exploiting MFA, PrintNightmare vuln

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Update to 3.24: fix CVE-2022-26495, CVE-2022-26496

Update to 3.24: fix CVE-2022-26495, CVE-2022-26496

UK regulator puts NortonLifeLock merger with Avast on ice

An update that contains security fixes and contains one feature can now be installed.

An update that solves 13 vulnerabilities and has three fixes is now available.

An update that contains security fixes and contains one feature can now be installed.

Phony Instagram ‘Support Staff’ Emails Hit Insurance Company
The Windows malware on Ukraine CERT’s radar
CISA warning: “Russian actors bypassed 2FA” – what happened and how to avoid it
OpenSSL patches crash-me bug triggered by rogue certs
Cyberattacks Against Israeli Government Sites: ‘Largest in the Country’s History’
Microsoft Azure DevOps revives TLS 1.0/1.1 with rollback
SentinelOne pays $617m for identity biz Attivo Networks
UK Supreme Court snubs Julian Assange’s anti-extradition bid
A first look at threat intelligence and threat hunting tools

An overview of some of the most popular open-source tools for threat intelligence and threat hunting The post A first look at threat intelligence and threat hunting tools appeared first on WeLiveSecurity

Huge DDoS attack temporarily kicks Israeli government sites offline
Most QNAP NAS Devices Affected by ‘Dirty Pipe’ Linux Flaw
Apple patches 87 security holes – from iPhones and Macs to Windows
Germany advises citizens to uninstall Kaspersky antivirus
NVIDIA staff shouldn’t have chosen passwords like these…
Russian demand for VPNs skyrockets by 2,692%

OpenSSL could be made to stop responding if it opened a specially crafted certificate.

UK criminal defense lawyer hadn’t patched when ransomware hit
Pandora Ransomware Hits Giant Automotive Supplier Denso

Tavis Ormandy discovered that the BN_mod_sqrt() function of OpenSSL could be tricked into an infinite loop. This could result in denial of service via malformed certificates.

rsh would allow unintended modification of target directory permissions.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

10 Common Security Mistakes Sysadmins Make & How To Avoid These Pitfalls>
Another data-leaking Spectre bug found, smashes Intel, Arm defenses
NASA in ‘serious jeopardy’ due to big black hole in security
Russia’s invasion of Ukraine tears open political rift between cybercriminals
Happy #PiDay – even if you aren’t in North America!
CaddyWiper: New wiper malware discovered in Ukraine

This is the third time in as many weeks that ESET researchers have spotted previously unknown data wiping malware taking aim at Ukrainian organizations The post CaddyWiper: New wiper malware discovered in Ukraine appeared first on WeLiveSecurity

Staff Think Conti Group Is a Legit Employer – Podcast

security update

security update

security update