Menu

Monthly Archives: June 2022

World Economic Forum wants a global map of online crime

security update

Threat and risk specialists signal post-COVID conference season is back on
RSA – Digital healthcare meets security, but does it really want to?

Technology is understandably viewed as a nuisance to be managed in pursuit of the health organizations’ primary mission The post RSA – Digital healthcare meets security, but does it really want to? appeared first on WeLiveSecurity

Symbiote Linux malware spotted, and infections are ‘very hard to detect’
You can be tracked via your Bluetooth signal, researchers claim
DogWalk zero-day Windows bug receives patch – but not from Microsoft

An update that solves 6 vulnerabilities and has three fixes is now available.

An update that solves 6 vulnerabilities and has two fixes is now available.

An update that solves 6 vulnerabilities and has two fixes is now available.

An update that solves 6 vulnerabilities and has two fixes is now available.

An update that solves 7 vulnerabilities and has three fixes is now available.

“Legacy” cryptography in Fedora 36 and Red Hat Enterprise Linux 9

An update that solves 6 vulnerabilities and has three fixes is now available.

Apple M1 chip contains hardware vulnerability that bypasses memory defense
Emotet malware gang re-emerges with Chrome-based credit card heistware
Chinese ‘Aoqin Dragon’ gang runs undetected ten-year espionage spree
Hardware flaws give Bluetooth chipsets unique fingerprints that can be tracked
Russia, China, warn US its cyber support of Ukraine has consequences
What keeps Mandiant Intelligence EVP Sandra Joyce up at night? The coming storm
Cloud services proving handy for cybercriminals, SANS Institute warns
Google has more reasons why it doesn’t like antitrust law that affects Google
Smashing Security podcast #278: Tim Hortons, avoiding sanctions, and good faith security research
Facebook phishing campaign nets millions in IDs and cash
RSA – Creepy real‑world edition

Digital fiddling somehow got mixed up in a real war The post RSA – Creepy real‑world edition appeared first on WeLiveSecurity

S3 Ep86: The crooks were in our network for HOW long?! [Podcast + Transcript]
Microsoft disrupts Bohrium spear-phishing ring by seizing 41 domains
Symantec: More malware operators moving in to exploit Follina

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Containers vulnerability risk assessment

An update that fixes 6 vulnerabilities is now available.

Several vulnerabilities were discovered in Mailman, a web-based mailing list manager. An attacker could impersonate more privileged accounts through different vectors.

Several security issues were fixed in FFmpeg.

Five Eyes alliance’s top cop says techies are the future of law enforcement

Red Hat Advanced Cluster Management for Kubernetes 2.5.0 is now generally available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Supply chain attacks will get worse: Microsoft Security Response Center boss
Now Windows Follina zero-day exploited to infect PCs with Qbot

security update

SSNDOB Market domains seized, identity theft “brokerage” shut down
Feds raid dark web market selling data on 24 million Americans
Taming the Digital Asset Tsunami
Intel offers ‘server on a card’ reference design for network security
Paying Ransomware Paints Bigger Bullseye on Target’s Back
Getting a list of fixes for a Red Hat product between two dates is easy with daysofrisk.pl
Joomla Security in 2022 – Best Practices To Secure Your Website
Black Basta Ransomware Teams Up with Malware Stalwart Qbot

An update that solves one vulnerability and has four fixes is now available.

MongoDB: From jokes to juggernaut

python-twisted: possible http request smuggling (CVE-2022-24801) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 python-twisted-web-12.1.0-8.el7_9.x86_64.rpm – Scientific Linux Development Team

Beijing-backed baddies target unpatched networking kit to attack telcos
US cyber chiefs: Moving to Shields Down isn’t gonna happen

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

Ukraine’s secret cyber-defense that blunts Russian attacks: Excellent backups

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

GitHub adds supply chain security tools for Rust language
RSA – Spot the real fake

How erring on the side of privacy might ultimately save you from chasing down a virtual rendition of you doing the bidding of a scammer The post RSA – Spot the real fake appeared first on WeLiveSecurity

Know your enemy! Learn how cybercrime adversaries get in…
Cyber Risk Retainers: Not Another Insurance Policy
Conducting Modern Insider Risk Investigations
Follina Exploited by State-Sponsored Hackers
Complete Guide to Keylogging in Linux: Part 2
Attackers Use Public Exploits to Throttle Atlassian Confluence Flaw

An update for rh-postgresql13-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A patch update (from 7.10.2 to 7.10.2.P1) is now available for Red Hat on OpenShift for EAP, Karaf, and Spring Boot. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

An update for python-twisted-web is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in ntfs-3g.

Cybersecurity awareness training: What is it and what works best?

Give employees the knowledge needed to spot the warning signs of a cyberattack and to understand when they may be putting sensitive data at risk The post Cybersecurity awareness training: What is it and what works best? appeared first on WeLiveSecurity

IBM buys Randori to address multicloud security messes
Microsoft seizes 41 domains tied to ‘Iranian phishing ring’
Cisco EVP: We need to lift everyone above the cybersecurity poverty line

Security fixes for CVE-2022-1886, CVE-2022-1942 —- Security fixes for CVE-2022-1851, CVE-2022-1898, CVE-2022-1897, CVE-2022-1927

Apple protected App Store users from $1.5 billion fraud last year

FreeRDP could allow unintended access to network services.

Several security issues were fixed in Vim.

Several security vulnerabilities were found in glib2.0, a general-purpose utility library for the GNOME environment. CVE-2021-27218

An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-nodejs12-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for rh-postgresql12-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Maximize your cloud security with isolation zones
Costa Rican government held up by ransomware … again
Yandex CEO Arkady Volozh resigns after being added to EU sanctions list

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

Security fixes for CVE-2022-1851, CVE-2022-1898, CVE-2022-1897, CVE-2022-1927

The 5.17.12 stable kernel update contains a number of important fixes across the tree.

The 5.17.12 stable kernel update contains a number of important fixes across the tree.

Upstream release notes: https://github.com/dotnet/core/blob/main/release- notes/3.1/3.1.25/3.1.25.md

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Key insights from ESET’s latest Threat Report – Week in security with Tony Anscombe

A review of the key trends that defined the threatscape in the first four months of 2022 and what these developments mean for your cyber-defenses The post Key insights from ESET’s latest Threat Report – Week in security with Tony Anscombe appeared first on WeLiveSecurity

100 days of war in Ukraine: How the conflict is playing out in cyberspace

It’s been 100 days since Russia invaded Ukraine, and we look back at various cyberattacks connected to the conflict The post 100 days of war in Ukraine: How the conflict is playing out in cyberspace appeared first on WeLiveSecurity

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed

Linux Cybersecurity Education & Training is Integral to Growing Your Career
Feeling highly stressed about your job? You must be a CISO

An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the postgresql:10 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for compat-openssl11 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,