Menu

Monthly Archives: July 2022

security update

Twitter launches probe after miscreants claims to have swiped 5.4m users’ details

The RSA Conference 2022 – one of the world’s premier IT security conferences – was held June 6th-9th in San Francisco. The first in-person event for RSA since the global pandemic had a slightly lower turnout than in years past (26,000 compared to 36,000 attendees). But attendees and presenters alike made up for it with […]

Simon Josefsson discovered an out-of-bounds memory read in GNU SASL, an implementation of the Simple Authentication and Security Layer framework, which could result in denial of service.

Cyber-mercenaries for hire represent shifting criminal business model
T-Mobile to cough up $500 million over 2021 data breach
DoJ approves Google’s acquisition of Mandiant
Infosec not your job but your responsibility? How to be smarter than the average bear

An update that contains security fixes can now be installed.

Why Physical Security Maintenance Should Never Be an Afterthought
Realizing your software has a vulnerability is bad. Realizing you’ve shipped it to thousands of customers…
NFT: A new‑fangled trend or also a new‑found treasure?

I’ve created an NFT so you don’t have to – here’s the good, the bad and the intangible of the hot-ticket tokens The post NFT: A new‑fangled trend or also a new‑found treasure? appeared first on WeLiveSecurity

PHP could be made to crash or run programs if it processed specially crafted data.

This update provides the upstream 6.1.36 maintenance release that fixes at least the following security vulnerabilities: A vulnerability in the Oracle VM VirtualBox prior to 6.1.36 contains an easily exploitable vulnerability that allows a high privileged attacker

Apply proposed patch for CVE-2022-28506.

An update that solves 8 vulnerabilities and has one errata is now available.

An update that solves 8 vulnerabilities and has one errata is now available.

security update

security update

macOS malware: myth vs. reality – Week in security with Tony Anscombe

ESET research shows yet again that macOS is not immune to malware and why some users can benefit from Apple’s Lockdown Mode The post macOS malware: myth vs. reality – Week in security with Tony Anscombe appeared first on WeLiveSecurity

The container suse/pcp was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

Office macro security: on-again-off-again feature now BACK ON AGAIN!
My Big Coin founder is – you guessed it – a $6m crypto-fraudster

**Changelog** “` * Thu Jul 07 2022 Clemens Lang – 1:1.1.1q-1 – Upgrade to 1.1.1q Resolves: CVE-2022-2097 “` —- “` * Thu Jun 30 2022 Clemens Lang – 1:1.1.1p-1 – Upgrade to 1.1.1p Resolves: CVE-2022-2068 Related: rhbz#2099975 “` Security fix for CVE-2022-2068

Microsoft closes off two avenues of attack: Office macros, RDP brute-forcing
Don’t dive head first into that crypto pool, FBI warns

An update that fixes one vulnerability is now available.

At the edge, nobody can hear your IoT devices scream …

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

British intelligence recycles old argument for thwarting strong encryption: Think of the children!
Russia, Iran discuss tech manufacturing, infosec and e-governance collaboration

security update

Ex-Coinbase manager charged in first-ever crypto insider trading case
US Cyber Command spots another 20 malware strains targeting Ukraine
Last member of Gozi malware troika arrives in US for criminal trial
ESET Research Podcast: Hot security topics at RSA or mostly hype?

Listen to Cameron Camp, Juraj Jánošík, and Filip Mazán discuss the use of machine learning in cybersecurity, followed by Cameron’s insights into the security of medical devices The post ESET Research Podcast: Hot security topics at RSA or mostly hype? appeared first on WeLiveSecurity

S3 Ep92: Log4Shell4Ever, travel tips, and scamminess [Audio + Text]
Simplifying backup and recovery management

This update fixes many bugs some of which are security relevant.

Security fixes for CVE-2022-2257, CVE-2022-2284, CVE-2022-2285, CVE-2022-2286, CVE-2022-2287, CVE-2022-2288, CVE-2022-2289, CVE-2022-2264, CVE-2022-2304, CVE-2022-2345, CVE-2022-2344, CVE-2022-2343.

Hackers for Hire: Adversaries Employ ‘Cyber Mercenaries’

This update fixes many bugs some of which are security relevant.

Apple patches “0-day” browser bug fixed 2 weeks ago in Chrome, Edge
DataDome looks to CAPTCHA the moment with test of humanity that doesn’t hurt
Complete Guide to Vulnerability Basics

An update that solves 9 vulnerabilities and has four fixes is now available.

Outlook email users alerted to suspicious activity from Microsoft-owned IP address
What does software supply chain pain really feel like? Find out right here

The container bci/nodejs was updated. The following patches have been included in this update:

An update that fixes three vulnerabilities is now available.

Atlassian reveals critical flaws in almost everything it makes and touches
Suspected Gozi malware gang ‘CIO’ extradited to US on fraud, hacking charges
Smashing Security podcast #284: The Most Wanted Missing CryptoQueen
Google: Kremlin-backed goons spread Android malware disguised as pro-Ukraine app
Boffins release tool to decrypt Intel microcode. Have at it, x86 giant says
I see what you did there: A look at the CloudMensis macOS spyware

Previously unknown macOS malware uses cloud storage as its C&C channel and to exfiltrate documents, keystrokes, and screen captures from compromised Macs The post I see what you did there: A look at the CloudMensis macOS spyware appeared first on WeLiveSecurity

More malware-infested apps, downloaded millions of times, found in the Google Play store
DoJ, FBI recover $500,000 in ransomware payments to Maui gang
Clunk flush! Bexplus cryptocurrency exchange closes suddenly, giving its users only 24 hours to withdraw funds

Red Hat OpenStack Platform 16.2 (Train) director operator containers, with several Important security fixes, are available for technology preview. 2. Description: Release osp-director-operator images

Conti’s Reign of Chaos: Costa Rica in the Crosshairs
Magecart Serves Up Card Skimmers on Restaurant-Ordering Systems

Apache XML Security for Java could be made to expose sensitive information.

An update that fixes one vulnerability is now available.

Several security issues were fixed in FreeType.

Several security issues were fixed in Checkmk.

Singapore distances itself from local crypto companies

The container suse-sles-15-sp3-chost-byos-v20220718-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

Amazon sues 10,000 Facebook Group admins for offering fake reviews
Belgium says Chinese cyber gangs attacked its government and military
Security flaws in GPS trackers can be abused to cut off fuel to vehicles, CISA warns
Google pulls malware-infected apps in its Store, over 3 million users at risk
Authentication Risks Discovered in Okta Platform
FBI Warns Fake Crypto Apps are Bilking Investors of Millions
Who on earth would be trying to promote EC-Council University via comment spam on my website?
Hacker hijacks NFT artist DeeKay’s Twitter account, steals $150,000 worth of NFTs from fans

An update that fixes one vulnerability is now available.

A collaborative approach to threat modeling
Hacker’s Corner: Complete Guide to Anti-Debugging in Linux – Part 3
Walmart-controlled flight booking service suffers substantial data leak
How we’ll solve software supply chain security

HarfBuzz could be made to crash if it opened specially crafted data.

The container sles-15-sp2-chost-byos-v20220718-x86-64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp2-chost-byos-v20220718-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp2-chost-byos-v20220718-x86_64-gen2 was updated. The following patches have been included in this update:

Several security issues were fixed in LibTIFF.

Jailed crooks told to cough up $600k for COVID fraud
Bogus cryptocurrency apps steal millions in mere months
Botnet malware disguises itself as password cracker for industrial controllers
8 months on, US says Log4Shell will be around for “a decade or longer”
Albanian government websites go dark after cyberattack
Microsoft’s latest security patch troubles Windows 11 users