Menu

Monthly Archives: May 2022

Europe proposes tackling child abuse by killing privacy, strong encryption
Ukraine war a sorting hat for cyber-governance loyalties: Black Hat founder Jeff Moss
Five Eyes turn spotlight on MSPs: Potential weak links in IT supply-chain security
Fresh ransomware samples indicate REvil is back

An update for the virt:av and virt-devel:av modules is now available for Advanced Virtualization for RHEL 8.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenStack Platform 16.2 (Train) director Operator containers are available for technology preview. 2. Description: Release osp-director-operator images

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Intel Memory Bug Poses Risk for Hundreds of Products
Novel Phishing Trick Uses Weird Links to Bypass Spam Filters

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Managing Red Hat Enterprise Linux at the edge
Actively Exploited Zero-Day Bug Patched by Microsoft
Ransomware Deals Deathblow to 157-year-old College
Progress launches Chef Cloud Security to extend DevSecOps to cloud-native assets
US college set to permanently close after 157 years, following ransomware attack
Opportunity out of crisis: Tapping the Great Resignation to close the cybersecurity skills gap

What can organizations do to capitalize on the current fluidity in the job market and bring fresh cybersecurity talent into the fold? The post Opportunity out of crisis: Tapping the Great Resignation to close the cybersecurity skills gap appeared first on WeLiveSecurity

Yahoo Japan strives for universal passwordless authentication
Microsoft closes Windows LSA hole under active attack
Email domain for NPM lib with 6m downloads a week grabbed by expert to make a point
US, Europe formally blame Russia for data wiper attacks against Ukraine, Viasat

security update

Colonial Pipeline facing $1,000,000 fine for poor recovery plans
Malware goes regional as attackers change tactics

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Hackers Actively Exploit F5 BIG-IP Bug

An update for libpq is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for c-ares is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the maven:3.5 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for libtiff is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Conti Ransomware Attack Spurs State of Emergency in Costa Rica
Industry pushes back against India’s data security breach reporting requirements
Low-rent RAT Worries Researchers
Biden signs cybercrime tracking bill into law

security update

It costs just $7 to rent DCRat to backdoor your network
FBI: Rise in Business Email-based Attacks is a $43B Headache
US offers $15m reward for information about Conti ransomware gang
Tractor giant AGCO hit by ransomware, halts production and sends home staff
RubyGems supply chain rip-and-replace bug fixed – check your logs!
Russian TV listings hacked with messages about war crimes in Ukraine
Ransomware plows through farm machinery giant AGCO

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

Microsoft Security Experts: Humans and automation to fight off cyber threats
Colonial Pipeline faces nearly $1m fine one year after ransomware attack

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Podcast: The State of the Secret Sprawl
China wants its youth to stop giving livestreamers money
Common LinkedIn scams: Beware of phishing attacks and fake job offers

LinkedIn scammers attack when we may be at our most vulnerable – here’s what to look out for and how to avoid falling victim to fraud when using the platform The post Common LinkedIn scams: Beware of phishing attacks and fake job offers appeared first on WeLiveSecurity

Update to 91.9.0

Release of OpenShift Serverless Client kn 1.22.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes two vulnerabilities is now available.

India’s ongoing outrage over Pegasus malware tells a bigger story about privacy law problems

Potential heap buffer overflow in TCP syslog server (receiver) components (CVE-2022-24903) References: – https://bugs.mageia.org/show_bug.cgi?id=30383

Fix for possible DOS by regex. (CVE-2022-24836) References: – https://bugs.mageia.org/show_bug.cgi?id=30322 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/XMDCWRQXJQ3TFSETPCEFMQ6RR6ME5UA3/

– Fixed h.264 video playback over va-api (https://bugzilla.mozilla.org/show_bug.cgi?id=1762725) —- – New upstream version (100.0)

Oracle 04/2022 critical path update * https://www.oracle.com/security- alerts/cpuapr2022.html#AppendixJAVA * Cross fingers I had not messed up system JDK. * java-maint tests passed * **Still karma is highly appreciated**

Oracle 04/2022 critical path update * https://www.oracle.com/security- alerts/cpuapr2022.html#AppendixJAVA * Cross fingers I had not messed up system JDK. * java-maint tests passed * **Still karma is highly appreciated**

Oracle 04/2022 critical path update * https://www.oracle.com/security- alerts/cpuapr2022.html#AppendixJAVA * Cross fingers I had not messed up system JDK. * java-maint tests passed * **Still karma is highly appreciated**

Defending against APT attacks – Week in security with Tony Anscombe

The conflict in Ukraine has highlighted the risks of cyberespionage attacks that typically involve Advanced Persistent Threat groups and often target organizations’ most valuable data The post Defending against APT attacks – Week in security with Tony Anscombe appeared first on WeLiveSecurity

One security issue has been found in a compression library libz-mingw-w64. Danilo Ramos discovered that incorrect memory handling in

False-flag cyberattacks a red line for nation-states, says Mandiant boss

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container suse/sles12sp3 was updated. The following patches have been included in this update:

In ecdsautils, a collection of ECDSA elliptic curve cryptography command line tools, an improper verification of cryptographic signatures was detected. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures.

Update to 2.9.14 Fix CVE-2022-29824: Integer overflow in xmlBuf and xmlBuffer

Update to freetype 2.12.1 which fixes CVE-2022-27404, CVE-2022-27405, CVE-2022-27406 and adds support for OT-SVG fonts.

security update

security update

Cryptocurrency laundromat Blender shredded by US Treasury in sanctions first
You didn’t leave enough space between ROSE and AND, and AND and CROWN

The container trento/trento-runner was updated. The following patches have been included in this update:

The container trento/trento-db was updated. The following patches have been included in this update:

Rsyslog could be made to crash if it received a specially crafted request.

The container bci/bci-init was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container ses/7.1/ceph/keepalived was updated. The following patches have been included in this update:

Security recommendations for SAP HANA on RHEL
USB-based Wormable Malware Targets Windows Installer
Walking away from ransomware unscathed. Can you? Really?
Bank for International Settlements calls for reform of data governance
F5, Cisco admins: Stop what you’re doing and check if you need to install these patches
FBI: Cyber-scams cost victims $6.9b-plus worldwide in 2021

security update

security update

Microsoft, Apple, Google accelerate push to eliminate passwords
3 most dangerous types of Android malware

Here’s what you should know about some of the nastiest mobile malware – from malicious software that takes phones and data hostage to RATs that allow hackers to control devices remotely The post 3 most dangerous types of Android malware appeared first on WeLiveSecurity

$43 billion stolen through Business Email Compromise since 2016, reports FBI
World Password Day – the 1960s just called and gave you your passwords back
S3 Ep81: Passwords (still with us!), Github, Firefox at 100, and network worms [Podcast]
Google chases sovereignty market with EU Workspace Data product

An update for thunderbird is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The Migration Toolkit for Containers (MTC) 1.7.1 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,