Menu

Monthly Archives: May 2022

CANs Reinvent LANs for an All-Local World
F5 Warns of Critical Bug Allowing Remote Code Execution in BIG-IP Systems
VHD Ransomware Linked to North Korea’s Lazarus Group
See me speak at Cyber Security Nordic – either in Helsinki or online
There’s no sugarcoating it: That online sugar daddy may be a scammer

The bitter truth about how fraudsters dupe online daters in this new twist on romance fraud The post There’s no sugarcoating it: That online sugar daddy may be a scammer appeared first on WeLiveSecurity

Phishing operation hits NHS email accounts to harvest Microsoft credentials
Biden orders new quantum push to ensure encryption isn’t cracked by rivals
Beijing-backed gang looted IP around the world for years, claims Cybereason
GitHub to require two factor authentication for code contributors by late 2023
Smashing Security podcast #273: Password blips, and who’s calling the airport?
US Cyber Command shored up nine nations’ defenses last year
China-linked APT Caught Pilfering Treasure Trove of IP
Keeper Connection Manager : Privileged access to remote infrastructure with zero-trust and zero-knowledge security
Android monthly updates are out – critical bugs found in critical places!
Communication around Heroku security incident dubbed ‘train wreck’

– New upstream version (100.0) – Fix mozbz#1759137 (ffmpeg crash)

Attackers Use Event Logs to Hide Fileless Malware

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in OpenSSL.

Several security issues were fixed in DPDK.

An update for firefox is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Container Platform release 4.6.57 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.6.

Unpatched DNS Bug Puts Millions of Routers, IoT Devices at Risk
Putin threatens supply chains with counter-sanction order
Cyber-spies target Microsoft Exchange to steal M&A info

Passwords have become a common way to access and manage our digital lives. Think of all the accounts you have with different providers. Having a password allows you to securely access your information, pay bills or connect with friends and family on various platforms. However, having a password alone is not enough. Your password for […]

security update

SEC nearly doubles cryptocurrency cop roles in special cyber unit
Firefox hits 100*, fixes bugs… but no new zero-days this month
Zero trust is more than just vendors and products – it requires process
Microsoft’s standalone Defender for Business hits GA
Mozilla: Lack of Security Protections in Mental-Health Apps Is ‘Creepy’
Lockbit ransomware attack cripples parts of German library service
Cops ignored call to nearby robbery, preferring to hunt Pokémon

100 Chromium releases! Of course, at the rate they release now, we’ll probably be at 150 before the end of the year. Anyway, here’s the update. Fixes: CVE-2022-1232 CVE-2022-1305 CVE-2022-1306 CVE-2022-1307 CVE-2022-1308 CVE-2022-1309 CVE-2022-1310 CVE-2022-1311 CVE-2022-1312 CVE-2022-1313 CVE-2022-1314 CVE-2022-1364

100 Chromium releases! Of course, at the rate they release now, we’ll probably be at 150 before the end of the year. Anyway, here’s the update. Fixes: CVE-2022-1232 CVE-2022-1305 CVE-2022-1306 CVE-2022-1307 CVE-2022-1308 CVE-2022-1309 CVE-2022-1310 CVE-2022-1311 CVE-2022-1312 CVE-2022-1313 CVE-2022-1314 CVE-2022-1364

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Several issues were discovered in OpenVPN, a Virtual Private Network server and client, that could lead to authentication bypass when using deferred auth plugins.

Critical vulnerabilities found in ‘millions of Aruba and Avaya switches’
What’s behind the record‑high number of zero days?

Organizations need to get better at mitigating threats from unknown vulnerabilities, especially as both state-backed operatives and financially-motivated cybercriminals are increasing their activity The post What’s behind the record‑high number of zero days? appeared first on WeLiveSecurity

Several security issues were fixed in MySQL.

Privacy pathology: It’s time for the users to gather a little data – evidence

An update that fixes three vulnerabilities is now available.

Google starts testing fenced frames to guard its Privacy Sandbox

security update

Security is a pain for American Dental Association: Ransomware infection feared
SSE kicks the ‘A’ out of SASE
Dell brings data recovery tools to Apex and the cloud
Spanish PM, defense minister latest Pegasus spyware victims
WinMagic SecureDoc for Linux: Fortify Your Infosec Architecture & Zero Trust Strategy with Defense-in-Depth & Endpoint Encryption>

Several security issues were fixed in libvirt.

libinput could be made to crash or expose sensitive information.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Bad Actors Are Maximizing Remote Everything

The components for Red Hat OpenShift support for Windows Containers 2.0.5 are now available. This product release includes a moderate security update for the following packages: windows-machine-config-operator and windows-machine-config-operator-bundle.

Updated Red Hat JBoss Web Server 5.6.2 packages are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Deep Dive: Protecting Against Container Threats in the Cloud

New pidgin packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue.

The newest upstream commit Security fixes for CVE-2022-1381, CVE-2022-1420

Fix CVE-2022-29536

zgrep applied to a crafted file name with two or more newlines can no longer overwrite an arbitrary, attacker-selected file. reproducer: $ touch foo.gz $ echo foo | gzip > “$(printf ‘|n;e touch pwnedn#.gz’)” $ zgrep foo *.gz (the unfixed version of zgrep creates the file called pwned)