Menu

Monthly Archives: May 2022

Beijing needs the ability to ‘destroy’ Starlink, say Chinese researchers

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

5 reasons why GDPR was a milestone for data protection

The landmark regulation changed everyone’s mindset on how companies worldwide collect and use the personal data of EU citizens The post 5 reasons why GDPR was a milestone for data protection appeared first on WeLiveSecurity

This update upgrades Firefox to version 91.9.1 ESR. * Mozilla: Untrusted input used in JavaScript object indexing, leading to prototype pollution (CVE-2022-1529) * Mozilla: Prototype pollution in Top-Level Await implementation (CVE-2022-1802) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 [More…]

Quad nations pledge deeper collaboration on infosec, data-sharing, and more
About half of popular websites tested found vulnerable to account pre-hijacking
Indian stock markets given ten day deadline to file infosec report, secure board signoff
Predator spyware sold with Chrome, Android zero-day exploits to monitor targets
Poisoned Python and PHP packages purloin passwords for AWS access
Patch now: Zoom chat messages can infect PCs, Macs, phones with malware
Why do hackers keep coming back to attack you? Because they can
Facebook opens political ad data vaults to researchers
Fronton IOT Botnet Packs Disinformation Punch

Multiple security vulnerabilities were discovered in Puma, a HTTP server for Ruby/Rack applications, which could result in HTTP request smuggling or information disclosure.

Multiple vulnerabilities have been discovered in the lrzip compression program which could result in denial of service or potentially the execution of arbitrary code.

Automating firewall configuration with RHEL System Roles

An update that solves one vulnerability, contains one feature and has two fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Jail for man who hacked the email of female students, stole and traded their private photos
It’s 2022 and there are still malware-laden PDFs in emails exploiting bugs from 2017
Screencastify fixes bug that would have let rogue websites spy on webcams

security update

security update

security update

Complete Guide to Keylogging in Linux: Part 1>
Clearview AI face-matching service fined a lot less than expected

Several security issues were fixed in libpng.

Zero Trust for Data Helps Enterprises Detect, Respond and Recover from Breaches

Several security issues were fixed in Thunderbird.

Firefox could be made to execute JavaScript in a privileged context if it opened a malicious website.

Snake Keylogger Spreads Through Malicious PDFs

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Common NFT scams and how to avoid them

As NFTs exploded in popularity, scammers also jumped on the hype. Watch out for counterfeit NFTs, rug pulls, pump-and-dumps and other common scams plaguing the industry. The post Common NFT scams and how to avoid them appeared first on WeLiveSecurity

How to find NPM dependencies vulnerable to account hijacking
Microsoft sounds the alarm on – wait for it – a Linux botnet
South Korean and US presidents gang up on North Korea’s cyber-offensives

The updated postgresql packages fix a security vulnerability: Autovacuum, REINDEX, and others omit “security restricted operation” sandbox (CVE-2022-1552).

Manfred Paul discovered two security issues in the Mozilla Firefox web browser, which could result in the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed

Nokogiri did not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a ‘String’ by calling ‘#to_s’ or equivalent.

This update provides ffmpeg version 4.3.4, which fixes several security vulnerabilities and other bugs which were corrected upstream. References: – https://bugs.mageia.org/show_bug.cgi?id=30444

Updated nvidia-current packages fix security vulnerabilities: NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead

Updated nvidia390 packages fix security vulnerabilities: NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead

Conti: Russian-backed rulers of Costa Rican hacktocracy?

This kernel-linus update is based on upstream 5.15.41 and fixes at least the following security issues: A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel BPF subsystem

This kernel update is based on upstream 5.15.41 and fixes at least the following security issues: A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel BPF subsystem

Updated microcodes for Intel processors, fixing various functional issues, and at least the following security issues: Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to

A bug was found in runc where runc exec –cap executed processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set

The container bci/dotnet-aspnet was updated. The following patches have been included in this update:

Mozilla patches Wednesday’s Pwn2Own double-exploit… on Friday!
Microsoft patches the Patch Tuesday patch that broke authentication

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

security update

security update

China-linked Twisted Panda caught spying on Russian defense R&D
Cryptocurrency: secure or not? – Week in security with Tony Anscombe

When you hear the term ‘cryptocurrency’, does ‘secure’ also spring to mind? Here are some implications of the lack of sound security practices in the world of crypto. The post Cryptocurrency: secure or not? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Sandworm uses a new version of ArguePatch to attack targets in Ukraine

ESET researchers spot an updated version of the malware loader used in the Industroyer2 and CaddyWiper attacks The post Sandworm uses a new version of ArguePatch to attack targets in Ukraine appeared first on WeLiveSecurity

Greenland hit by cyber attack, finds its health service crippled
Bank refuses to pay ransom to hackers, sends dick pics instead
US Government says: Patch VMware right now, or get off our network
Microsoft patches the patch that broke Windows authentication
Closing the Gap Between Application Security and Observability
380K Kubernetes API Servers Exposed to Public Internet
Microsoft Bing censors politically sensitive Chinese terms

Fabian Vogt and Dominik Penner discovered that the Ark archive manager did not sanitize extraction paths, which could result in maliciously crafted archives with symlinks writing outside the extraction directory.

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has one errata is now available.

Protecting data now as the quantum era approaches

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

Canada bans Huawei and ZTE from 5G networks, citing national security risks
India slightly softens infosec incident reporting and data retention rules
US won’t prosecute ‘good faith’ security researchers under CFAA
Phishing gang that stole over 400,000 Euros busted in Spain
US recovers a record $15m from the 3ve ad-fraud crew

Webroot Console 6.5 is here To help get us closer to retiring the Endpoint Protection Console, we’ve introduced three new functionality features with Webroot Console 6.5. Friendly name support To help get us closer to retiring the Endpoint Protection Console, we’ve introduced three new functionality features with Webroot Console 6.5. Friendly name support To improve […]

Iran, China-linked gangs join Putin’s disinformation war online
S3 Ep83: Cracking passwords, patching Firefox, and Apple vulns [Podcast]
Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover

OpenLDAP could be made to perform arbitrary modifications to the database.

Hackers are finding it too easy to achieve their initial access, warn agencies

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2022:4642

The quantum menace: Quantum computing and cryptography
Hot glare of the spotlight doesn’t slow BlackByte ransomware gang
The flip side of the coin: Why crypto is catnip for criminals

Cybercriminals continue to mine for opportunities in the crypto space – here’s what you should know about coin-mining hacks and crypto theft The post The flip side of the coin: Why crypto is catnip for criminals appeared first on WeLiveSecurity

The cyber threat isn’t going anywhere, but the fight back starts in London
Your snoozing iOS 15 iPhone may actually be sleeping with one antenna open
Patch your VMware gear now – or yank it out, Uncle Sam tells federal agencies
Smashing Security podcast #275: Jail for Bing, and mental health apps may not be good for you
Meet Wizard Spider, the multimillion-dollar gang behind Conti, Ryuk malware

security update

security update