Menu

Monthly Archives: July 2022

HTTP-Daemon could allow HTTP Request Smuggling attacks.

Google Boots Multiple Malware-laced Android Apps from Marketplace
CISA Urges Patch of Exploited Windows 11 Bug by Aug. 2
Securing data at rest and data in motion

An update that solves 11 vulnerabilities and has 44 fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that solves 10 vulnerabilities, contains one feature and has 43 fixes is now available.

An update that solves 9 vulnerabilities and has 9 fixes is now available.

The container sles-15-sp1-chost-byos-v20220715-x86-64 was updated. The following patches have been included in this update:

Bill for US telcos to bin Chinese kit blows out by $3 billion
TikTok’s chief security officer steps aside, thanks to Oracle move
Alibaba execs hauled in to discuss Shanghai Police data leak

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Rebuild for CVE-2022-{24675,28327,29526} in golang and other go ecosystem CVEs — This contains the result from the mass rebuild in F35 for all packages that require `golang` and provide binaries to mitigate the following CVEs: `golang` itself: – CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode – CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar […]

Rebuild for CVE-2022-{24675,28327,29526} in golang and other go ecosystem CVEs — This contains the result from the mass rebuild in F35 for all packages that require `golang` and provide binaries to mitigate the following CVEs: `golang` itself: – CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode – CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar […]

security update

security update

An update that fixes 5 vulnerabilities is now available.

Think twice before downloading pirated games – Week in security with Tony Anscombe

Why downloading pirated video games may ultimately cost you dearly and how to stay safe while gaming online The post Think twice before downloading pirated games – Week in security with Tony Anscombe appeared first on WeLiveSecurity

North Koreans spotted harassing SMBs with malware

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

**Version 2.13.0** Enhancement * 106: Refined types as per laminas/laminas- coding-standard:2.3.x upgrades thanks to @Ocramius * 103: Update to laminas/laminas-coding-standard:2.3.x, improved types and internal API thanks to @gsteel —- **Version 2.12.0** Bug * 99: Merge release 2.11.3 into 2.12.x thanks to @github-actions[bot] * 92: Fix typo in property name in

CISA pulls the fire alarm on Juniper Networks bugs
Thousands of websites run buggy WordPress plugin that allows complete takeover
API security moves mainstream

The heavyweights are now moving into API security, cementing it as “A Thing” The post API security moves mainstream appeared first on WeLiveSecurity

Emerging H0lyGh0st Ransomware Tied to North Korea
7 cybersecurity tips for your summer vacation!
Windows Network File System flaw results in arbitrary code execution as SYSTEM

An update that solves 15 vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Digital burglary at recruitment agency Morgan Hunt confirmed

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Meet Mantis – the tiny shrimp that launched 3,000 DDoS attacks

security update

security update

Homeland Security warns: Expect Log4j risks for ‘a decade or longer’

The 5.18.11 stable kernel update contains a number of important fixes across the tree. In addition to the 5.18.11 stable patches, this build contains the retbleed patches scheduled for 5.18.12 kernels.

– fix unpreserved file permissions (CVE-2022-32207) – fix Set-Cookie denial of service (CVE-2022-32205) – fix HTTP compression denial of service (CVE-2022-32206) – fix FTP-KRB bad message verification (CVE-2022-32208)

security update

SCOTUS judges ‘doxxed’ after overturning Roe v Wade
Collaboration and knowledge sharing key to progress in cybersecurity

In a world of ever-evolving cyberthreats, collaboration and knowledge exchange are vital for keeping an edge on attackers The post Collaboration and knowledge sharing key to progress in cybersecurity appeared first on WeLiveSecurity

S3 Ep91: CodeRed, OpenSSL, Java bugs and Office macros [Podcast + Transcript]
Lenovo issues firmware updates after UEFI vulnerabilities disclosed
Cloud security needs assistants
Smashing Security podcast #283: Disney’s social dumpster fire, Anom phones, and TikTok tragedies
Windows 8.1 displays full-screen warning as it nears its last day of support
Journalists Emerge as Favored Attack Target for APTs
10,000 organisations targeted by phishing attack that bypasses multi-factor authentication
Amazon handed doorbell cam Ring data to US police 11 times so far in 2022

An update that solves one vulnerability and has three fixes is now available.

An update that solves 21 vulnerabilities and has 6 fixes is now available.

An update that fixes one vulnerability is now available.

Hacker’s Corner: Complete Guide to Anti-Debugging in Linux – Part 2

An update that contains security fixes can now be installed.

Python could be made to run arbitrary code if it received a specially crafted input.

HTTP-Daemon could allow HTTP Request Smuggling attacks.

Why less can be more in backup and recovery management
1.9m patient records exposed in healthcare debt collector ransomware attack
This big phish can swim around MFA, says Microsoft Security
Mergers and acquisitions put zero trust to the ultimate test
Play it safe: 5 reasons not to download pirated games

It’s all fun and games until you get hacked – and this is just one risk of downloading cracked games The post Play it safe: 5 reasons not to download pirated games appeared first on WeLiveSecurity

Facebook 2FA scammers return – this time in just 21 minutes
X.org servers update closes 2 security holes, adds neat component tweaks
Large-Scale Phishing Campaign Bypasses MFA

An update that solves 9 vulnerabilities and has four fixes is now available.

Social Engineering vs Mistakes: Two sources of pain, one process

An update that solves 15 vulnerabilities and has 22 fixes is now available.

An update that fixes one vulnerability is now available.

uriparser could be made to crash if it received specially crafted input.

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

Microsoft’s July Patch Tuesday fixes actively exploited bug

security update

Amazon squashes years-old authentication bugs in AWS Kubernetes service
Older AMD, Intel chips vulnerable to data-leaking ‘Retbleed’ Spectre variant
Paying ransomware crooks won’t reduce your legal risk, warns regulator
How War Impacts Cyber Insurance
Microsoft 365 patches for Windows 7 to end in 2023
‘Callback’ Phishing Campaign Impersonates Security Firms

Several security issues were fixed in X.Org X Server.

Hacker’s Corner: Complete Guide to Anti-Debugging in Linux – Part 1

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

GnuPG could allow forged signatures.

Software developers have a supply chain security problem
UK Info Commissioner slams use of WhatsApp by health officials during pandemic

AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn’t written. In the special case of “in place” encryption, sixteen bytes of the plaintext would be […]

Take the day off: Windows Autopatch is live and can even fix cloudy PCs
San Francisco cops want real-time access to private security cameras for surveillance

security update

Rethinking Vulnerability Management in a Heightened Threat Landscape
Popular NFT Marketplace Phished for $540M