Menu

Monthly Archives: March 2022

China thrilled it captured already-leaked NSA cyber-weapon
Valorant aimbot hack lures the unwary into malware infection
Cryptocoin ATMs ruled illegal – “Shut down at once”, says regulator
Viasat, Rosneft hit by cyberattacks as Ukraine war spills online

Command injection in ruby bundler. (CVE-2021-43809) References: – https://bugs.mageia.org/show_bug.cgi?id=30162 – https://blog.sonarsource.com/securing-developer-tools-package-managers

This kernel-linus update is based on upstream 5.15.28 and fixes at least the following security issues: Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially

This kernel update is based on upstream 5.15.28 and fixes at least the following security issues: Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially

The chromium-browser-stable package has been updated to the 99.0.4844.51 version that fixes multiples security vulnerabilities. References: – https://bugs.mageia.org/show_bug.cgi?id=29988

Cybercrooks’ Political In-Fighting Threatens the West
New US law: Cyberattacks to be reported within 72 hours

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Brit techie shows us life in Ukraine amid Russian invasion
Is low-code safe and secure?
China: Attacks from US IP addresses hit us, moved on to Russia and Ukraine
Russia labels Meta an ‘extremist’ organization, bans Instagram
Taiwan rounds up 60 Chinese tech workers on suspicion of poaching tech and people
Ubisoft changes employee passwords after “cyber security incident”

A flaw was discovered in the way HAProxy, a fast and reliable load balancing reverse proxy, processes HTTP responses containing the “Set-Cookie2” header, which can result in an unbounded loop, causing a denial of service.

The update for expat released as DSA 5085-1 introduced regressions for applications using URI characters (‘:’ in particular) for a namespace separator (while the HTML API docs of function XML_ParserCreateNS have been advising against their use). Updated expat packages are now

Emmet Leahy reported that libphp-adodb, a PHP database abstraction layer library, allows to inject values into a PostgreSQL connection string. Depending on how the library is used this flaw can result in authentication bypass, reveal a server IP address or have other

Improve your hybrid cloud security with these 3 tips

Two vulnerabilities were discovered in the server for the Network Block Device (NBD), which could result in the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed

The container sles-15-sp3-chost-byos-v20220310 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220310-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220310-gen2 was updated. The following patches have been included in this update:

Null pointer dereference in MD_UPDATE. (CVE-2021-4209) References: – https://bugs.mageia.org/show_bug.cgi?id=30112 – https://lists.suse.com/pipermail/sle-security-updates/2022-March/010333.html

Singapore uncovers four critical vulnerabilities in Riverbed software

security update

security update

Multiple security vulnerabilities have been discovered in vim, an enhanced vi editor. Buffer overflows, out-of-bounds reads and Null pointer dereferences may lead to a denial of service (application crash) or other unspecified impact.

Russia Issues Its Own TLS Certs
Dunno about you, but we’re seeing an 800% increase in cyberattacks, says one MSP
Raccoon Stealer Crawls Into Telegram
Alleged Kaseya ransomware attacker arrives in Texas for trial

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

– New upstream update (98.0)

Update Chromium to 99.0.4844.51. Fixes, well, a LOT of security bugs. Sorry about that. CVE-2021-22570 CVE-2022-0096 CVE-2022-0097 CVE-2022-0098 CVE-2022-0099 CVE-2022-0100 CVE-2022-0101 CVE-2022-0102 CVE-2022-0103 CVE-2022-0104 CVE-2022-0105 CVE-2022-0106 CVE-2022-0107 CVE-2022-0108 CVE-2022-0109 CVE-2022-0110 CVE-2022-0111 CVE-2022-0112 CVE-2022-0113

Bugfix release. fixes CVE-2022-0518 2055256, 2055130 – https://github.com/radare org/radare2/commit/9650e3c352f675687bf6c6f65ff2c4a3d0e288fa fixes CVE-2022-0519 2055103, 2055104 – https://github.com/radareorg/radare2/commit/6c4428f018d385fc8 0a33ecddcb37becea685dd5 fixes CVE-2022-0520 2055145, 2055146 – https://github.co m/radareorg/radare2/commit/8525ad0b9fd596f4b251bb3d7b114e6dc7ce1ee8 fixes

Infosys, Wipro silent on their Russian operations
Moscow to issue HTTPS certs to Russian websites
Extradited Canadian accused of unleashing NetWalker ransomware
Analysis of leaked Conti files blows lid off ransomware gang
Fortinet says it’s all about the security ASICs
WhatsApp emits extension to detect tampering with desktop web apps

security update

security update

security update

Malware Posing as Russia DDoS Tool Bites Pro-Ukraine Hackers

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure, spoofing or sandbox bypass.

An update that solves one vulnerability and has two fixes is now available.

True or false? How to spot – and stop – fake news

How can you tell fact from fiction and avoid falling for and spreading falsehoods about the war in Ukraine? The post True or false? How to spot – and stop – fake news appeared first on WeLiveSecurity

Ragnar Locker ransomware – what you need to know
S3 Ep73: Ransomware with a difference, dirty Linux pipes, and much more [Podcast]
Alleged REvil suspect extradited and arraigned on ransomware spree charges
No, women in Ukraine aren’t up for a sexy webcam chat right now
Most Orgs Would Take Security Bugs Over Ethical Hacking Help
Smashing Security podcast #265: The Nigerian supercop and Alexa vs. Alexa
Russia May Use Ransomware Payouts to Avoid Sanctions
Multi-Ransomwared Victims Have It Coming–Podcast
Qakbot Botnet Sprouts Fangs, Injects Malware into Email Threads
Mitel VoIP systems used in staggering DDoS attacks
Reg reader rages over Virgin Media’s email password policy

An update that solves two vulnerabilities and has 11 fixes is now available.

Several security issues and a regression were fixed in Expat.

Huawei UK board members resign over silence on Ukraine invasion

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure, spoofing or sandbox bypass.

Ukraine invasion: This may be the quiet before the cyber-storm, IT staff warned

New mozilla-thunderbird packages are available for Slackware 15.0, and -current to fix security issues.

SEC proposes four-day rule for public companies to report cyberattacks
APT41 Spies Broke Into 6 US State Networks via a Livestock App

security update

security update

App, security teams need closer bond to fend off cyberattacks
Dell opts out of Microsoft’s Pluton security for Windows
Most ServiceNow Instances Misconfigured, Exposed
Russian APTs Furiously Phish Ukraine – Google
Millions of APC Smart-UPS devices vulnerable to TLStorm

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Securing healthcare: An IT health check on the state of the sector

No sector or organization is immune to rapidly escalating cyberthreats, but when it comes to healthcare, the stakes couldn’t be higher The post Securing healthcare: An IT health check on the state of the sector appeared first on WeLiveSecurity

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Where are the (serious) Russian cyberattacks?

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities, contains one feature is now available.

Internet backbone provider Lumen quits Russia
Ragnar ransomware gang hit 52 critical US orgs, says FBI
Microsoft patches critical remote-code-exec hole in Exchange Server and others
Cow-counting app abused by China ‘to spy on US states’
Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March Patch Tuesday

security update

security update

security update

security update

What should we do about ‘systemic’ cyber risks? Wait, what even are those
“Dirty Pipe” Linux kernel bug lets anyone to write to any file
IT security is at crisis point – so what are you going to do about it?