Menu

Monthly Archives: April 2022

An update that fixes four vulnerabilities is now available.

Now Mandiant says 2021 was a record year for exploited zero-day security bugs

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

The container bci/dotnet-aspnet was updated. The following patches have been included in this update:

US DOJ probes Google’s $5.4b Mandiant acquisition

verify upstream GPG signature

Backport fix for possible DOS by regex assigned as CVE-2022-24836.

Update for CVE-2022-27191

Hive ransomware affiliate zeros in on Exchange servers
QNAP warns of new bugs in its Network Attached Storage devices
Cybersecurity threats to critical infrastructure – Week in security with Tony Anscombe

As the Five Eyes nations warn of attacks against critical infrastructure, we look at the potentially cascading effects of such attacks and how essential systems and services can ramp up their defense The post Cybersecurity threats to critical infrastructure – Week in security with Tony Anscombe appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

Zero-Trust For All: A Practical Guide
Skeletons in the Closet: Security 101 Takes a Backseat to 0-days
The new Elastic CEO puts cloud front and center

An update that fixes 9 vulnerabilities is now available.

REvil resurrected? Ransomware crew appears to be back. Keyword: Appears

Red Hat OpenShift Container Platform release 4.10.10 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

Is your Lenovo laptop vulnerable to cyberattack?

Here’s what to know about vulnerabilities in more than 100 Lenovo consumer laptop models and what you can do right away to stay safe – all in under three minutes The post Is your Lenovo laptop vulnerable to cyberattack? appeared first on WeLiveSecurity

S3 Ep79: Chrome hole, a bad place for a cybersecurity holiday, and crypto-dodginess [Podcast]
YouTube terminates account for Hong Kong’s presumed next head of government
REvil reborn? Notorious gang’s dark web site redirects to new ransomware operation

Logging Subsystem 5.4 – Red Hat OpenShift Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Free Yanlouwang decryptor released, after flaw found in ransomware code
Smashing Security podcast #271: Crypto break-in, Google blurring, and mics not muting
Emotet reestablishes itself at the top of the malware world
Critical infrastructure: Under cyberattack for longer than you might think

Lessons from history and recent attacks on critical infrastructure throw into sharp relief the need to better safeguard our essential systems and services The post Critical infrastructure: Under cyberattack for longer than you might think appeared first on WeLiveSecurity

Red Hat OpenShift Container Platform release 4.9.29 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.9.

Red Hat Advanced Cluster Management for Kubernetes 2.4.3 General Availability release images. This update provides security fixes, bug fixes, and updates the container images. Red Hat Product Security has rated this update as having a security impact

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/dotnet-aspnet was updated. The following patches have been included in this update:

The container suse/sles12sp3 was updated. The following patches have been included in this update:

Five Eyes nations fear wave of Russian attacks against critical infrastructure
AWS’s Log4j patches blew holes in its own security
Oracle already wins ‘crypto bug of the year’ with Java digital signature bypass
Critical cryptographic Java security blunder patched – update now!
Most Email Security Approaches Fail to Block Common Threats
Russian-linked Shuckworm crew ramps up Ukraine attacks
Protect Your Executives’ Cybersecurity Amidst Global Cyberwar
Apple iCloud account attack results in man losing $650,000 from his cryptocurrency wallet
How can we support young people in harnessing technology for progress?

Young people are not passive victims of technology or helpless addicts. They are technology creators and agents with diverse backgrounds and interests. The post How can we support young people in harnessing technology for progress? appeared first on WeLiveSecurity

New Red Hat Single Sign-On 7.5.2 packages are now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat Single Sign-On 7.5 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Criminals adopting new methods to bypass improved defenses, says Zscaler
Google: 2021 was a Banner Year for Exploited 0-Day Bugs
US warns North Korean Lazarus gang rises against cryptocurrency outfits
Google tracked record 58 exploited-in-the-wild zero-day security holes in 2021

security update

security update

security update

security update

Kaspersky cracks Yanluowang ransomware, offers free decryptor
GitHub repositories compromised by stolen OAuth tokens
Rethinking Cyber-Defense Strategies in the Public-Cloud Age
‘CatalanGate’ Spyware Infections Tied to NSO Group
Beanstalk cryptocurrency heist: scammer votes himself all the money
ESET uncovers vulnerabilities in Lenovo laptops
Funky Pigeon stalls orders after hackers breach its systems
For cutting-edge web application and API protection – Trust Indusface WAAP

The Migration Toolkit for Containers (MTC) 1.5.4 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Virtualization release 2.6.10 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the container-tools:2.0 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat Ceph Storage 3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Funky Pigeon pauses all orders after ‘security incident’
7 ways to avoid a cloud misconfiguration attack
When “secure” isn’t secure at all: High‑impact UEFI vulnerabilities discovered in Lenovo consumer laptops

ESET researchers discover multiple vulnerabilities in various Lenovo laptop models that allow an attacker with admin privileges to expose the user to firmware-level malware The post When “secure” isn’t secure at all: High‑impact UEFI vulnerabilities discovered in Lenovo consumer laptops appeared first on WeLiveSecurity

UK Prime Minister, Catalan groups ‘targeted by NSO Pegasus spyware’
Microsoft ups bug bounties 30% for cloud lines, pays more for ‘scenario-based’ exploits
How To Create a Transparent Proxy through the Tor Network to Protect Your Privacy Online with archtorify & kalitorify>

Security fix for CVE-2018-25032

Security fix for CVE-2021-25220 New version 4.4.3 Add keama migration utility

Cyberattackers Put the Pedal to the Medal: Podcast

Several security issues were fixed in klibc.

Title::newMainPage() goes into an infinite recursion loop if it points to a local interwiki (CVE-2022-28201). Messages widthheight/widthheightpage/nbytes not escaped when used in galleries or Special:RevisionDelete (CVE-2022-28202).

– Update to 1.2.20 Release notes: https://www.cacti.net/info/changelog/1.2.20

– Update to 1.2.20 Release notes: https://www.cacti.net/info/changelog/1.2.20

A security issue was discovered in Chromium, which could result in the execution of arbitrary code. For the stable distribution (bullseye), this problem has been fixed in

Multiple vulnerabilities have been discovered in abcm2ps: program which translates ABC music description files to PostScript. CVE-2018-10753

Yet another Chrome zero-day emergency update – patch now!
Feds offer $5m reward for info on North Korean cyber crooks
Star loses $500,000 NFT after crooks exploit Rarible market

Containers were incorrectly started with non-empty inheritable Linux process capabilities (CVE-2022-24769) References: – https://bugs.mageia.org/show_bug.cgi?id=30279

Double free in Regexp compilation (CVE-2022-28738). A buffer overrun was found in String-to-Float conversion (CVE-2022-28739). References: – https://bugs.mageia.org/show_bug.cgi?id=30278

7zip reader: fix PPMD read beyond boundary. ZIP reader: fix possible out of bounds read. ISO reader: fix possible heap buffer overflow in read_children(). RARv4 redaer: fix multiple issues in RARv4 filter code (introduced in libarchive 3.6.0): – fix heap use after free in archive_read_format_rar_read_data();

Containers were started incorrectly with non-empty inheritable Linux process capabilities. (CVE-2022-27650) References: – https://bugs.mageia.org/show_bug.cgi?id=30267

Karakurt Ensnares Conti, Diavol Ransomware Groups in Its Web
Cybercriminals are doing their homework in latest banking scam
Google issues third emergency fix for Chrome this year

An update that fixes two vulnerabilities is now available.

North Korea’s Lazarus cyber-gang caught ‘spying’ on chemical sector companies