Menu

Monthly Archives: June 2022

OpenSea phishing threat after rogue insider leaks customer email addresses

security update

Jenkins warns of security holes in these 25 plugins
California state’s gun control websites expose personal data
ZuoRAT Can Take Over Widely Used SOHO Routers
Google battles bots, puts Workspace admins on alert
Black Basta ransomware – what you need to know
How to Spend Less Time on Web and API Security

Several security issues were fixed in Vim.

S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]

A heap use-after-free vulnerability was found in systemd, a system and service manager, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate

A Guide to Surviving a Ransomware Attack

Several security issues were fixed in Libjpeg6b.

Costco 40th anniversary scam targets WhatsApp users

If the promise of a cash prize in return for answering a few questions sounds like a deal that is too good to be true, that’s because it is The post Costco 40th anniversary scam targets WhatsApp users appeared first on WeLiveSecurity

Israel plans ‘Cyber-Dome’ to defeat digital attacks from Iran and others

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Start using Modern Auth now for Exchange Online

– Update to new upstream (102.0)

Leaky Access Tokens Exposed Amazon Photos of Users
Sysdig Secure update adds ability to stop container attacks at runtime
‘Prolific’ NetWalker extortionist pleads guilty to ransomware charges
Firefox 102 fixes address bar spoofing security hole (and helps with Follina!)

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or spoofing.

Patchable and Preventable Security Issues Lead Causes of Q1 Attacks
Scanning container image vulnerabilities with Clair

An update that fixes 9 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 9 vulnerabilities is now available.

Do back offices mean backdoors?

War in Europe, a reminder for shared service centers and shoring operations to re-examine IT security posture The post Do back offices mean backdoors? appeared first on WeLiveSecurity

An update that fixes three vulnerabilities is now available.

Microsoft postpones shift to New Commerce Experience subscriptions
FBI warning: Crooks are using deepfake videos in interviews for remote gigs
Trio accused of selling $88m of pirated Avaya licenses
Walmart accused of turning blind eye to transfer fraud totaling millions of dollars

security update

security update

Guide to Web Application Penetration Testing
5 ways cybercriminals steal credit card details

Here are some of the most common ways hackers can get hold of other people’s credit card data – and how you can keep yours safe The post 5 ways cybercriminals steal credit card details appeared first on WeLiveSecurity

Carnival Cruises bruised by $6.25 million fine after series of cyberattacks
Customized malware coded to target OT systems
AMD targeted by RansomHouse, cybercrims claim to have ‘450Gb’ in stolen data
Have you modelled the attack paths into your organization? Because an attacker already has
Top Six Security Bad Habits, and How to Break Them
Mitel VoIP Bug Exploited in Ransomware Attacks
‘Killnet’ Adversary Pummels Lithuania with DDoS Attacks Over Blockade
Log4Shell Vulnerability Targeted in VMware Servers to Exfiltrate Data
The experience of bringing OpenSSL 3.0 into RHEL and Fedora
Cloud security risks remain very human

An update for kpatch-patch is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel-rt is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for python is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that fixes two vulnerabilities is now available.

Tencent admits to poisoned QR code attack on QQ chat platform
Carnival Cruises torpedoed by US states, agrees to pay $6m after wave of cyberattacks
India extends deadline for compliance with infosec logging rules by 90 days
OpenSSL 3.0.5 awaits release to fix potential worse-than-Heartbleed flaw
LGBTQ+ folks warned of dating app extortion scams

security update

Harmony blockchain loses nearly $100M due to hacked private keys
Drunk worker loses USB stick containing details of every resident of his city
FTC warns of LGBTQ+ extortion scams – be aware before you share!

Several security issues were fixed in curl.

An update that fixes 25 vulnerabilities is now available.

Contractor loses entire Japanese city’s personal data in USB fail
Security survives the budget axe
7 devops practices to improve application performance

Several security issues were fixed in SpiderMonkey JavaScript Library.

Updated images are now available for Red Hat Advanced Cluster Security for Kubernetes (RHACS). The updated image includes bug and security fixes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that contains security fixes can now be installed.

Beijing probes security at academic journal database
Singapore promises ‘brutal and unrelentingly hard’ action on dodgy crypto players

The system could be made to crash under certain conditions.

An update that fixes two vulnerabilities is now available.

This is the June 2022 monthly release for .NET 6. This updates .NET SDK to 6.0.106 and Runtime to 6.0.6. It includes at least one known security fix. Upstream release notes: https://github.com/dotnet/core/blob/main/release- notes/6.0/6.0.6/6.0.6.md

https://www.mediawiki.org/wiki/Release_notes/1.37#MediaWiki_1.37.2

This is the June 2022 monthly release for .NET 6. This updates .NET SDK to 6.0.106 and Runtime to 6.0.6. It includes at least one known security fix. Upstream release notes: https://github.com/dotnet/core/blob/main/release- notes/6.0/6.0.6/6.0.6.md

Security fix for CVE-2015-20107

An update that fixes one vulnerability is now available.

Instagram’s new age verification tool – Week in security with Tony Anscombe

As Instagram tests a new age verification tool, what are some of the concerns when it comes to confirming someone’s age on the internet? The post Instagram’s new age verification tool – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Security features in Red Hat Enterprise Linux 9
Thank You for Participating in Our Security Dashboard Redesign Survey
We’re now truly in the era of ransomware as pure extortion without the encryption

The container bci/python was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

More than $100m in cryptocurrency stolen from blockchain biz

An update is now available for Red Hat OpenShift GitOps 1.3 on OpenShift 4.6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated images are now available for Red Hat Advanced Cluster Security for Kubernetes (RHACS). The updated image includes bug and security fixes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat OpenShift GitOps 1.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that contains security fixes can now be installed.

OpenSSL issues a bugfix for the previous bugfix

An update that solves one vulnerability, contains one feature and has one errata is now available.

An update that solves four vulnerabilities and has 8 fixes is now available.

An update that solves 7 vulnerabilities and has 10 fixes is now available.

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

Google Warns Spyware Being Deployed Against Android, iOS Users