Menu

Monthly Archives: April 2022

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Cisco’s Webex app phoned home audio telemetry even when muted
Microsoft-led move takes down ZLoader botnet domains

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

US Government warns of new malware attacks on ICS/SCADA systems
ESET takes part in global operation to disrupt Zloader botnets

ESET researchers provided technical analysis, statistical information, and known command and control server domain names and IP addresses The post ESET takes part in global operation to disrupt Zloader botnets appeared first on WeLiveSecurity

Feds: APTs Have Tools That Can Take Over Critical Infrastructure
S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]
Threat group builds custom malware to attack industrial systems

Several issues have been found in fribidi, a free Implementation of the Unicode BiDi algorithm. The issues are related to stack-buffer-overflow, heap-buffer-overflow, and a SEGV.

Update to 91.8.0

Rebase on upstream version 42.2.25. This rebase fixes CVE-2022-21724.

Security fix for CVE-2022-21698

Security fix for CVE-2022-21698

An update that solves 21 vulnerabilities and has 7 fixes is now available.

OpenSSH SCP deprecation in RHEL 9: What you need to know
Smashing Security podcast #270: Bearded Barbie, EDR scams, and hobbyist crime detectives
Microsoft details how China-linked crew’s malware hides scheduled Windows tasks
Don’t let ransomware crooks spend months in your network – like this govt agency did
Apache says Struts 2 security bug wasn’t fully fixed in 2020
RaidForums hacking site shut down by police, alleged admin arrested
US cryptocurrency coder gets 5 years for North Korea sanctions busting
Taiwan, China square off over chip tech espionage laws
Feds Shut Down RaidForums Hacking Marketplace
Enemybot botnet uses Gafgyt source code with a sprinkling of Mirai
Git for Windows issues update to fix running-someone-else’s-code vuln
Security blind spots in the era of cloud communication & collaboration. Are you protected?

Gzip could be made to overwrite arbitrary files.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

A minor version update (from 7.10.1 to 7.10.2) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

Red Hat OpenShift Container Platform release 4.7.48 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

An update for rh-dotnet31-curl is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Updated images that include numerous enhancements, security, and bug fixes are now available for Red Hat OpenShift Data Foundation 4.10.0 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

Investment firm KKR buys Barracuda Networks
Huawei reportedly furloughs Russian staff and stops taking orders
Microsoft’s huge Patch Tuesday includes fix for bug under attack

security update

Stolen-data market RaidForums taken down in domain seizure
CitySprint confirms security breach, warns delivery drivers their personal data may be in the hands of hackers
Microsoft Zero-Days, Wormable Bugs Spark Concern
AWS fixes local file vuln on internal credential access for Relational Database Service
Hardware-assisted security poised for growth, says Intel
Menswear Brand Zegna Reveals Ransomware Attack
Can we solve the zero-day threat once and for all? No, but here’s what we can do
Five critical bugs fixed in hospital robot control system
Industrial cybersecurity group gathers lobbying force
OpenSSH takes aim at ‘capture now, decrypt later’ quantum attacks

Red Hat OpenShift Container Platform release 4.8.36 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for expat is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.

Red Hat OpenShift Virtualization release 4.8.5 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that solves four vulnerabilities and has one errata is now available.

Critical bug allows attacker to remotely control medical robot
Industroyer2: Industroyer reloaded

This ICS-capable malware targets a Ukrainian energy company The post Industroyer2: Industroyer reloaded appeared first on WeLiveSecurity

Singapore to license pentesters and managed infosec operators
Defending the Endpoint with AI
HCL and HP named in unflattering audit of India’s biometric ID system
European officials reportedly targeted by NSO spyware
Microsoft Takes Down Domains Used in Cyberattack Against Ukraine
Attackers exploit Spring4Shell flaw to let loose the Mirai botnet
OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default
There are few guarantees when it comes to ransomware, except that you’re a target
Identity access management has a new price: $6.9 billion

Security fix for CVE-2022-1154 Security fix for CVE-2022-1160 —- The newest upstream commit Security fix for CVE-2022-0943

Update to 1.6.2 (rhbz#2068277). Mitigates CVE-2022-24769 / GHSA-c9cp-9c75-9v8c.

Update to 1.1.4 (rhbz#2068719). Mitigates CVE-2022-24778 (rhbz#2069368, rhbz#2069369).

libarchive could be made to expose sensitive information if it received a specially crafted archive file.

– Update to latest upstream (Firefox 99.0 & nss 3.77).

– Update to latest upstream (Firefox 99.0 & nss 3.77).

“Pen tester” who helped FIN7 gang cause $1 billion damage, sentenced to five years behind bars
Google Play pulls sneaky data-harvesting apps with 46m+ downloads

Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec. CVE-2020-27842

GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment). (CVE-2021-45943)

Stack based buffer overflow. (CVE-2022-25308) Heap-buffer-overflow in fribidi_cap_rtl_to_unicode. (CVE-2022-25309) SEGV in fribidi_remove_bidi_marks. (CVE-2022-25310) References:

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record’s value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal’s colors. (CVE-2022-28391)

A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault […]

A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination. (CVE-2021-3700)

GitHub enhances secret scanning for tighter code security

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Finnish govt websites knocked down as Ukraine President addresses MPs
Microsoft dogs Strontium domains to stop attacks on Ukraine

security update

You are Tracked Online – Why? And How To Avoid Being Tracked Online>

The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-22624

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-22624

Five security issues have been discovered in libxml2: XML C parser and toolkit. CVE-2016-9318

Red Hat OpenShift Container Platform release 4.10.8 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

Zero days are for life, not just for Christmas. Here’s how to deal with them
Google Play Bitten by Sharkbot Info-stealer ‘AV Solution’
Popular Ruby Asciidoc toolkit patched against critical vuln – get the update now!

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,