Menu

Monthly Archives: June 2022

NinjaForms WordPress plugin, actively exploited in wild, receives forced security update

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

An update that solves 30 vulnerabilities and has 14 fixes is now available.

Hardening Virtio for emerging security usecases
Heineken giving away free beer for Father’s Day? It’s a WhatsApp scam
Password recovery from beyond the grave

Red Hat OpenShift Container Platform release 4.6.59 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.6.

The container suse/sles12sp5 was updated. The following patches have been included in this update:

Interpol anti-fraud operation busts call centers behind business email scams
RSAC branded a ‘super spreader event’ as attendees share COVID-19 test results
S3 Ep87: Follina, AirTags, ID theft and the Law of Big Numbers [Podcast]
Interpol arrests thousands of scammers in operation “First Light 2022”

Several security issues were fixed in Exempi.

Want to block two billion known breached passwords from being used at your company? It’s easy with Specops Password Policy tools
State-Sponsored Phishing Attack Targeted Israeli Military Officials
Ransomware Risk in Healthcare Endangers Patients
Post-quantum cryptography, an introduction
Complete Guide to Keylogging in Linux: Part 3

An update that fixes one vulnerability is now available.

Facebook Messenger Scam Duped Millions

Several security issues were fixed in the kernel.

Okta’s Matt Raible: How I became a Java hipster
Elasticsearch server with no password or encryption leaks a million records

Red Hat OpenShift Container Platform release 4.7.53 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

Smashing Security podcast #279: Encrypted notes, and a deadly case of AirTag spying

The 5.17.14 stable kernel update contains a number of important fixes across the tree.

golang-x-sys: Bump to commit bc2c85ada10aa9b6aa9607e9ac9ad0761b95cf1d golang- github-containernetworking-cni: Update to 1.1.1. golang-github-containerd-cni: Update to 1.1.6. Fixes rhbz#2092632. containerd: Update to 1.6.6. Mitigates GHSA-5ffw-gxpp-mxpf / CVE-2022-31030.

Heineken says there’s no free beer, warns of phishing scam
Microsoft continues cyber security spending spree with Miburo buy
Kaiser Permanente Exposes Nearly 70K Medical Records in Data Breach
Linux Malware Deemed ‘Nearly Impossible’ to Detect
DragonForce Gang Unleash Hacks Against Govt. of India
Travel-related Cybercrime Takes Off as Industry Rebounds
In Cybersecurity, What You Can’t See Can Hurt You
Save time and money with Red Hat Insights Compliance reporting
The Three Best Tools You Need to Scan Your Linux System for Malware

An update that fixes 28 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

DDoS-for-hire service which bombarded websites with attacks earns man two years in prison
Kubernetes users struggle with security, Red Hat survey says

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Malaysia-linked DragonForce hacktivists attack Indian targets
Unpatched Exchange server, stolen RDP logins… How miscreants get BlackCat ransomware on your network
Microsoft fixes under-attack Windows zero-day Follina
Follina gets fixed – but it’s not listed in the Patch Tuesday patches!
Former US state agency CIO, IT exec plead guilty to bribery and extortion scheme
Cloudflare says it thwarted record-breaking HTTPS DDoS flood
Man gets two years in prison for selling 200,000 DDoS hits
Murder suspect admits she tracked cheating partner with hidden AirTag
Azure issues not adequately fixed for months, complain bug hunters

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

Open Source Security: Key Benefits & Drawbacks You Should Know
New Ultra-Stealthy Linux Backdoor Isnt Your Everyday Malware Discovery

An update that solves 7 vulnerabilities and has 14 fixes is now available.

An update that fixes one vulnerability is now available.

UK health privacy watchdog still in talks over who is accessing country’s COVID data store
Detect cloud native security threats with Tracee
Inside the RSAC expo: Buzzword bingo and the bear in the room
Chinese-sponsored gang Gallium upgrades to sneaky PingPull RAT
New Syslogk Linux Rootkit Uses Magic Packets to Trigger Backdoor

security update

security update

security update

The transition to a digital-first world enables us to connect, work and live in a realm where information is available at our fingertips. The children of today will be working in an environment of tomorrow that is shaped by hyperconnectivity. Operating in this environment means our present and future generations need to understand the importance […]

HelloXD ransomware bulked up with better encryption, nastier payload
You’re invited! Join us for a live walkthrough of the “Follina” story…
A Getting-Started Guide to Improving Security with Open-Source Static & Dynamic Security Scanners

Several security issues were fixed in liblouis.

Bluetooth Signals Can Be Used to Track Smartphones, Say Researchers

Firefox could be made to crash or run programs as your login if it opened a malicious website.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Industroyer: A cyber‑weapon that brought down a power grid

Five years ago, ESET researchers released their analysis of the first ever malware that was designed specifically to attack power grids The post Industroyer: A cyber‑weapon that brought down a power grid appeared first on WeLiveSecurity

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Two vulnerabilities were discovered that the containerd container runtime, which could result in denial of service or incomplete restriction of capabilities.

– lockState: do not print `error:` when exit code is unaffected (#2090926) —- – fix potential DoS from unprivileged users via the state file (CVE-2022-1348)

security update

Several vulnerabilities were discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of these flaws for local root privilege escalation.

Multiple vulnerabilities were discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed media file is opened.

3 takeaways from RSA Conference 2022 – Week in security with Tony Anscombe

Here are three themes that stood out at the world’s largest gathering of cybersecurity professionals The post 3 takeaways from RSA Conference 2022 – Week in security with Tony Anscombe appeared first on WeLiveSecurity

RSA – APIs, your organization’s dedicated backdoors

API-based data transfer is so rapid, there’s but little time to stop very bad things happening quickly The post RSA – APIs, your organization’s dedicated backdoors appeared first on WeLiveSecurity

U.S. Water Utilities Prime Cyberattack Target, Experts
Potent Emotet Variant Spreads Via Stolen Email Credentials
Feds Forced Travel Firms to Share Surveillance Data on Hacker
Kubernetes Operators: good security practices

An update that fixes one vulnerability is now available.

OMIGOD: Cloud providers still using secret middleware

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The container suse-sles-15-sp3-chost-byos-v20220609-x86_64-gen2 was updated. The following patches have been included in this update:

bump to v1.23.4, security fix for CVE-2022-21698 —- Add missing container networking dependencies (#2081834)