Menu

Monthly Archives: April 2022

An issue has been found in tinyxml, a C++ XML parsing library. Crafted XML messages could lead to an infinite loop in

Three issues have been found in libarchive, a multi-format archive and compression library.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

TA410 under the microscope – Week in security with Tony Anscombe

Here’s what you should know about FlowingFrog, LookingFrog and JollyFrog – the three teams making up the TA410 espionage umbrella group The post TA410 under the microscope – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Call for Contributors with Knowledge of Linux Firewalls!>
Facebook’s Meta, tracking code, and the student financial aid website

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Data-wiper malware strains surge as Ukraine battles ongoing invasion

This vulnerability could potentially be exploited by a local user to execute arbitrary code with root privileges.

SDL (Simple DirectMedia Layer) could be made to crash or run programs if it opened a specially crafted file.

GitHub issues final report on supply-chain source code intrusions
Microsoft Edge’s ‘Secure Network’ sounds a lot like a built-in VPN
Ransomware costs show prevention is better than the cure
Don’t expect to get your data back from the Onyx ransomware group
Security Turbulence in the Cloud: Survey Says…
Interpol: We can’t arrest our way out of cybercrime
Cyberespionage APT Now Identified as Three Separate Actors
India gives local techies 60 days to hit 6-hour deadline for infosec incident reporting
Elon Musk says Twitter DMs should be end-to-end encrypted
Sina Weibo, China’s Twitter analog, reveals users’ locations and IP addresses
Bumblebee malware loader emerges as Conti’s BazarLoader fades

Security fixes for CVE-2022-1227, CVE-2022-21698, CVE-2022-27191, CVE-2022-27649

Security fix for CVE-2021-28021, CVE-2021-42715, CVE-2021-42716, and CVE-2022-28041

Security fix for CVE-2021-25220

Security fix for CVE-2018-25032

security update

A lookback under the TA410 umbrella: Its cyberespionage TTPs and activity

ESET researchers reveal a detailed profile of TA410: we believe this cyberespionage umbrella group consists of three different teams using different toolsets, including a new version of the FlowCloud espionage backdoor discovered by ESET. The post A lookback under the TA410 umbrella: Its cyberespionage TTPs and activity appeared first on WeLiveSecurity

Cloudflare stomps huge DDoS attack on crypto platform

This kernel-linus update is based on upstream 5.15.35 and fixes at least the following security issues: A denial of service (DOS) issue was found in the Linux kernel smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet

This kernel update is based on upstream 5.15.35 and fixes at least the following security issues: A denial of service (DOS) issue was found in the Linux kernel smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet

S3 Ep80: Ransomware news, phishing woes, NAS bugs, and a giant hole in Java [Podcast]
Attacker Breach ‘Dozens’ of GitHub Repos Using Stolen OAuth Tokens

Several security issues were fixed in networkd-dispatcher.

Cyberattacks Rage in Ukraine, Support Military Operations

An update for zlib is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that solves one vulnerability, contains one feature and has one errata is now available.

An update that fixes one vulnerability is now available.

Compliance as Code: Extending compliance automation for process improvement
Smashing Security podcast #272: Going ape over the Kardashians, and the face of romance scams
US offers $10 million reward for information about Russian military hackers implicated in NotPetya attack
Money or your business: Ensure your ransomware defense strategy beats off disruptions, extortions
Five Eyes nations reveal 2021’s fifteen most-exploited flaws
Microsoft points at Linux and shouts: Look, look! Privilege-escalation flaws here, too!
Looking for the latest insight to ensure cyber security in the long term? It’s right here
Emotet is Back From ‘Spring Break’ With New Nasty Tricks
Feds offer big rewards for info on suspected Russian Sandworm intel officers
Ransomware Survey 2022 – like the Curate’s Egg, “good in parts”
China turns cyber-espionage eyes to Russia as Ukraine invasion grinds on

Updated web-admin-build packages are now available for Red Hat Gluster Storage 3.5 Web Administration on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Millions of Java Apps Remain Vulnerable to Log4Shell

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Block over two billion known breached passwords from your AD with Specops Password Policy tools
Chinese drone-maker DJI suspends ops in Russia, Ukraine
Should security teams be giving service with a smile?
Study: How Amazon uses Echo smart speaker conversations to target ads
Who is exploiting VMware right now? Probably Iran’s Rocket Kitten, to name one

security update

Coca-Cola probes pro-Kremlin gang’s claims of 161GB data theft
USA’s plan to decouple its tech with China lacks a strategy – report
DDoS attacks at an all-time-high in Q1 2022, says Kaspersky

Updated virtualbox packages fix security vulnerabilities: Vulnerability in the Oracle VM VirtualBox prior to 6.1.34 contains an easily exploitable vulnerability that allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to

Firms Push for CVE-Like Cloud Bug System

An update for maven-shared-utils is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for xmlrpc-c is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for xmlrpc-c is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

UNS-5376-1 was missing patches to properly fix the addressed issues.

Nation-state Hackers Target Journalists with Goldbackdoor Malware
Microsoft fixes Point of Sale bug that delayed Windows 11 startup for 40 minutes

An update that fixes 9 vulnerabilities is now available.

The trouble with BEC: How to stop the costliest internet scam

BEC fraud generated more losses for victims than any other type of cybercrime in 2021. It’s long past time that organizations got a handle on these scams. The post The trouble with BEC: How to stop the costliest internet scam appeared first on WeLiveSecurity

Ransomware attack attempted to destabilise Costa Rica, says outgoing president
India inks tech pact with EU – only the US has the same deal
Crooks steal NFTs worth ‘$3m’ in Bored Ape Yacht Club heist
Intuit sued over alleged cryptocurrency thefts via Mailchimp intrusion
Homeland Security bug bounty program uncovers 122 holes in its systems
Phishing goes KISS: Don’t let plain and simple messages catch you out!
Flaw could have granted criminals control over Ever Surf crypto wallets
Ukraine’s postal service prints stamp mocking sunken Russian ship, and gets hit by DDoS attack

Git could be made to run arbitrary commands in platforms with multiple users support.

Lapsus$ Hackers Target T-Mobile

Several security issues were fixed in barbican.

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Webcam hacking: How to know if someone may be spying on you through your webcam

Camfecting doesn’t ‘just’ invade your privacy – it could seriously impact your mental health and wellbeing. Here’s how to keep an eye on your laptop camera. The post Webcam hacking: How to know if someone may be spying on you through your webcam appeared first on WeLiveSecurity

FBI: BlackCat ransomware scratched 60-plus orgs

The newest upstream commit Security fixes for CVE-2022-1381, CVE-2022-1420

Security fix for [CVE-2022-1227]

A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document. (CVE-2021-45341) A buffer overflow vulnerability in CDataList of the jwwlib component of

A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. (CVE-2021-21898)

An update that fixes two vulnerabilities is now available.