Menu

Monthly Archives: May 2022

security update

How these crooks backdoor online shops and siphon victims’ credit card info
DOJ Says Doctor is Malware Mastermind
APTs Overwhelmingly Share Known Vulnerabilities Rather Than Attack O-Days
April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell
Your data’s auctioned off up to 987 times a day, NGO reports
Pwn2Own hacking schedule released – Windows and Linux are top targets
Add security to Azure applications with Azure WAF
Microsoft warns partners to revoke unused authorizations that drive your software
Fake news – why do people believe it?

In the age of the perpetual news cycle and digital media, the risks that stem from the fake news problem are all too real The post Fake news – why do people believe it? appeared first on WeLiveSecurity

State of internet crime in Q1 2022: Bot traffic on the rise, and more
Monero-mining botnet targets Windows, Linux web servers
Google Cloud launches services to bolster open-source security, simplify zero-trust rollouts
FBI warns of North Korean cyberspies posing as foreign IT workers
Pentester pops open Tesla Model 3 using low-cost Bluetooth module
What You Need to Know about the Sysrv-K Cryptomining Botnet in Less than a Minute>
Google assuring open source code to secure software supply chains
Sysrv-K Botnet Targets Windows, Linux

Several security issues were fixed in PCRE.

Several security issues were fixed in Apport.

iPhones Vulnerable to Attack Even When Turned Off

needrestart could be made to run programs.

zlib: A flaw found in zlib when compressing (not decompressing) certain inputs (CVE-2018-25032) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 zlib-1.2.7-20.el7_9.i686.rpm zlib-1.2.7-20.el7_9.x86_64.rpm zlib-debuginfo-1.2.7-20.el7_9.i686.rpm zlib-debuginfo-1.2.7-20 [More…]

Jakub Wilk discovered a local privilege escalation in needrestart, a utility to check which daemons need to be restarted after library upgrades. Regular expressions to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate

Only DevSecOps can save the metaverse
Apple patches zero-day kernel hole and much more – update now!

OpenLDAP could be made to perform arbitrary modifications to the database.

Facebook rated least safe e-commerce option in government rankings
Europe moves closer to stricter cybersecurity standards, reporting regs
Venezuelan cardiologist charged with designing and selling ransomware
Red Hat releases open source StackRox to the community
The State of Kubernetes Security in 2022
China reveals its top five sources of online fraud
US brings first-of-its-kind criminal charges of Bitcoin-based sanctions-busting
Hackers are after your data. So why are you making it so easy for them?
“Incompetent” council leaks details of students with special educational needs
Russian cyber attack on Eurovision foiled by Italian authorities

The ffmpeg project released the new version 3.2.18 with fixes for various issues found by the OSS-Fuzz project. For Debian 9 stretch, this release is packaged in version 7:3.2.18-0+deb9u1.

Microsoft’s May Patch Tuesday Updates Cause Windows AD Authentication Errors

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes 8 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

San Francisco police use driverless cars for surveillance
More money for open source security won’t work
The downside of ‘debugging’ ransomware

The decision to release a ransomware decryptor involves a delicate balancing act between helping victims recover their data and alerting criminals to errors in their code The post The downside of ‘debugging’ ransomware appeared first on WeLiveSecurity

Firefox out-of-band update to 100.0.1 – just in time for Pwn2Own?

Infinite loop vulnerability in the CHM file parser. Issue affects versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions. (CVE-2022-20770) Infinite loop vulnerability in the TIFF file parser. Issue affects versions

cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call. (CVE-2017-9814) References:

CERTINFO never-ending busy-loop. (CVE-2022-27781) TLS and SSH connection too eager reuse. (CVE-2022-27782) References: – https://bugs.mageia.org/show_bug.cgi?id=30410

FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face. (CVE-2022-27404) FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. (CVE-2022-25235) References:

When using Waitress versions 2.1.0 and prior behind a proxy that does not properly validate the incoming HTTP request matches the RFC7230 standard, Waitress and the frontend proxy may disagree on where one request starts and where it ends. This would allow requests to be smuggled via the front-end proxy to waitress and later behavior. […]

CVE-2021-3596 A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in information disclosure or denial of service. For Debian 9 stretch, these problems have been fixed in version

The container trento/trento-runner was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

Shopping for malware: $260 gets you a password stealer. $90 for a crypto-miner…
Ukrainian crook jailed in US for selling thousands of stolen login credentials

security update

security update

security update

Another ex-eBay exec admits cyberstalking web souk critics
Software patching must work like car safety recalls, says US cyber boss
He cracked passwords for a living – now he’s serving 4 years in prison
Most organizations hit by ransomware would pay up if hit again
Malware Builder Leverages Discord Webhooks
How to spot and avoid a phishing attack – Week in security with Tony Anscombe

Can you spot the tell-tale signs of a phishing attempt and check if an email that has landed in your inbox is legit? The post How to spot and avoid a phishing attack – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Upstream details at : https://access.redhat.com/errata/RHSA-2022:1440

Upstream details at : https://access.redhat.com/errata/RHSA-2022:2191

Upstream details at : https://access.redhat.com/errata/RHSA-2022:2213

Upstream details at : https://access.redhat.com/errata/RHSA-2022:1487

‘Peacetime in cyberspace is a chaotic environment’ says senior US advisor
Iran-linked Cobalt Mirage extracts money, info from US orgs – report
Threat Actors Use Telegram to Spread ‘Eternity’ Malware-as-a-Service
Researchers find 134 flaws in the way Word, PDFs, handle scripts
To predict the targets of Chinese malware, look at the target of Chinese laws
Anatomy of a campaign to inject JavaScript into compromised WordPress sites

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

* Updating for Keylime release v6.4.0 * Fixes CVE-2022-1053

If you’ve got Intel inside, you probably need to get these security patches inside, too
S3 Ep82: Bugs, bugs, bugs (and Colonial Pipeline again) [Podcast]
Serious Security: Learning from curl’s latest bug update
Ransomware the final nail in coffin for small university
Smashing Security podcast #274: Hands off my biometrics, and a wormhole squirmish

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

You Can’t Eliminate Cyberattacks, So Focus on Reducing the Blast Radius
Novel ‘Nerbian’ Trojan Uses Advanced Anti-Detection Tricks
9 questions you should ask about your cloud security
10 reasons why we fall for scams

The ‘it won’t happen to me’ mindset leaves you unprepared – here are some common factors that put any of us at risk of online fraud The post 10 reasons why we fall for scams appeared first on WeLiveSecurity

In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don’t check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2’s buffer functions, for example libxslt through 1.1.35, is affected as well.

APT gang ‘Sidewinder’ goes on two-year attack spree across Asia
It’s time to kick China off social media, says tech governance expert