Menu

Monthly Archives: June 2022

Even Russia’s Evil Corp now favors software-as-a-service

– New upstream update (101.0) —- – Fixed missing popups in some scenarios on Wayland (https://bugzilla.mozilla.org/show_bug.cgi?id=1771104)

To cut off all nearby phones with these Chinese chips, this is the bug to exploit
ESET Threat Report T 1 2022

A view of the T 1 2022 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T 1 2022 appeared first on WeLiveSecurity

Atlassian announces 0-day hole in Confluence Server – update soon!
Old Hacks Die Hard: Ransomware, Social Engineering Top Verizon DBIR Threats – Again
Evil Corp Pivots LockBit to Dodge U.S. Sanctions
Clipminer rakes in $1.7m in crypto hijacking scam

An update that solves two vulnerabilities and has two fixes is now available.

An update that solves 27 vulnerabilities, contains four features and has 17 fixes is now available.

Healthcare organizations face rising ransomware attacks – and are paying up

This update upgrades Thunderbird to version 91.10.0. * Mozilla: Braille space character caused incorrect sender email to be shown for a digitally signed email (CVE-2022-1834) * Mozilla: Cross-Origin resource’s length leaked (CVE-2022-31736) * Mozilla: Heap buffer overflow in WebGL (CVE-2022-31737) * Mozilla: Browser window spoof using fullscreen mode (CVE-2022-31738) * Mozilla: Register all [More…]

Sebastian Krause discovered that manipulated inline images can force PyPDF2, a pure Python PDF library, into an infinite loop, if a maliciously crafted PDF file is processed.

Red Hat OpenShift Container Platform release 4.7.47 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

An update for gzip is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Atlassian: Unpatched years-old flaw under attack right now to hijack Confluence
FBI, CISA: Don’t get caught in Karakurt’s extortion web

security update

Conti spotted working on exploits for Intel Management Engine flaws

The popularity of online gaming surged during the COVID-19 pandemic—and so did cyberattacks against gamers. If you’re the parent of a gamer, or if you’re a gamer yourself, it’s important to learn about the risks. Why are cyber threats to gamers on the rise? It might seem strange that cybercriminals are targeting gamers. But there […]

The cyber threat landscape keeps evolving at lightning-speed. According to the latest 2022 BrightCloud® Threat Report, small to medium-sized businesses (SMBs) are particularly vulnerable to becoming a victim of a ransomware attack. Cybercriminals also are becoming more selective of the organizations they target. Without human security experts and solutions at their disposable, these businesses remain […]

Yet another zero-day (sort of) in Windows “search URL” handling
S3 Ep85: Now THAT’S what I call a Microsoft Office exploit! [Podcast]

Several security issues were fixed in cifs-utils.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Cybercriminals Expand Attack Radius and Ransomware Pain Points

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Scammers Target NFT Discord Channel
Dear Europe, here again are the reasons why scanning devices for unlawful files is not going to fly
International Authorities Take Down Flubot Malware Network
Being prepared for adversarial attacks
Super-spreader FluBot squashed by Europol
ExpressVPN moves servers out of India to escape customer data retention law
US ran offensive cyber ops to support Ukraine, says general
Firefox 101 is out, this time with no 0-day scares (but update anyway!)

ImageMagick could be made to crash if it opened a specially crafted file.

The container suse/389-ds was updated. The following patches have been included in this update:

The container suse/rmt-nginx was updated. The following patches have been included in this update:

The container suse/rmt-mariadb-client was updated. The following patches have been included in this update:

An update that solves 27 vulnerabilities, contains four features and has 5 fixes is now available.

Microsoft Releases Workaround for ‘One-Click’ 0Day Under Active Attack

OpenShift Serverless version 1.22.1 contains a moderate security impact. The References section contains CVE links providing detailed severity ratings for each vulnerability. Ratings are based on a Common Vulnerability Scoring System (CVSS) base score.

Watch out for phishing emails that inject spyware trio
Talking to children about the internet: A kid’s perspective

A 14-year-old shares his thoughts about technology and the potential privacy and security implications of the internet The post Talking to children about the internet: A kid’s perspective appeared first on WeLiveSecurity

Hospitals are for healing humans. But protecting and healing hospitals needs machines
What if ransomware evolved to hit IoT in the enterprise?
EnemyBot malware adds enterprise flaws to exploit arsenal

security update

security update