Menu

Monthly Archives: August 2022

KiCad is a suite of programs for the creation of printed circuit boards. It includes a schematic editor, a PCB layout tool, support tools and a 3D viewer to display a finished & fully populated PCB.

An update that fixes three vulnerabilities is now available.

The container sles-15-sp3-chost-byos-v20220818-x86-64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220818-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220818-x86_64-gen2 was updated. The following patches have been included in this update:

Code execution via malicious map file (CVE-2021-43518) References: – https://bugs.mageia.org/show_bug.cgi?id=30717 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JIYZ7EVY6NZBM7FQF6GVUARYO6MKSEAT/

Ex-HP finance manager jailed after going on $5m spending spree using company plastic

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

iPhone Users Urged to Update to Patch 2 Zero-Days
Two years on, Apple iOS VPNs still leak IP addresses

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

The truth about that draft law banning Uncle Sam buying insecure software

rsync could be made to crash or run programs if it received specially crafted input.

Keeping the keys to the kingdom secure
Google blocks third record-breaking DDoS attack in as many months
Apple patches double zero-day in browser and kernel – update now!
S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, healthcare security [Audio + Text]
Google Patches Chrome’s Fifth Zero-Day of the Year

PostgreSQL could be made to run programs when creating or updating extensions.

Streamlining IT security operations with Red Hat Insights and Red Hat Satellite
Open-Source VPN Protocols Compared: Why WireGuard is on the Rise!

An update that fixes 14 vulnerabilities is now available.

A command injection vulnerability was found in FreeCAD, a parametric 3D modeler, when importing DWG files with crafted filenames. For Debian 10 buster, this problem has been fixed in version

A step‑by‑step guide to enjoy LinkedIn safely

LinkedIn privacy settings are just as overwhelming as any other social media settings. There’s a lot of menus, a lot buttons to enable, select, accept or reject. To make sure you have control over your information we bring you a step-by-step guide on how to enjoy LinkedIn safely. The post A step‑by‑step guide to enjoy […]

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Ransomware attack on UK water company clouded by confusion
Deluge of of entries to Spamhaus blocklists includes ‘various household names’
Janet Jackson music video declared a cybersecurity exploit

security update

security update

Google, Apple squash exploitable browser bugs

security update

security update

security update

security update

Software developer cracks Hyundai car security with Google search
After 7 years, long-term threat DarkTortilla crypter is still evolving

The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-32792

How to stop the evil lurking in the shadows
TikTok wants your trust around US midterm elections data
APT Lazarus Targets Engineers with macOS Malware
Chrome browser gets 11 security fixes with 1 zero-day – update now!

USN-5526-1 introduced a regression in PyJWT.

Kubescape boosts Kubernetes scanning capabilities

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-32792

Mozilla finds 18 of 25 popular reproductive health apps leak data
Russian military uses Chinese drones and bots in combat, over manufacturers’ protests

The container suse/sles12sp4 was updated. The following patches have been included in this update:

RubyGems now requires multi-factor auth for top package maintainers
SEC says brokerage accounts hijacked for $1.3m pump-and-dump scam

Update to yara-4.2.3 —- Update to 4.2.0 —- Update to 4.2.2

Update to yara-4.2.3 —- Update to 4.2.0 —- Update to 4.2.2

security update

US offers reward “up to $10 million” for information about the Conti gang
Do you know what’s happening on your users’ devices?
U.K. Water Supplier Hit with Clop Ransomware Attack
Microsoft’s macOS Tamper Protection hits general availability
1,900 Signal users exposed: Twilio attacker ‘explicitly’ looked for certain numbers
DEF CON – “don’t worry, the elections are safe” edition

Don’t worry, elections are safe. Our Security Researcher Cameron Camp provide us highlights from the DEF CON 30 conference. The post DEF CON – “don’t worry, the elections are safe” edition appeared first on WeLiveSecurity

Xiaomi Phone Bug Allowed Payment Forgery

An update that solves one vulnerability, contains one feature and has 7 fixes is now available.

An update that fixes 22 vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Reckon Russian spies are lurking in your inbox? Check for these IOCs, Microsoft says
How a spoofed email passed the SPF check and landed in my inbox

The Sender Policy Framework can’t help prevent spam and phishing if you allow billions of IP addresses to send as your domain The post How a spoofed email passed the SPF check and landed in my inbox appeared first on WeLiveSecurity

Digital Ocean dumps Mailchimp after attack leaked customer email addresses
It’s 2022 and there are still thousands of public systems using password-less VNC
Oh Deere: Farm hardware jailbroken to run Doom
CIA accused of illegally spying on Americans visiting Assange in embassy
Dutch authorities arrest 29-year-old dev with suspected ties to Tornado Cash
Zoom for Mac patches get-root bug – update now!
Black Hat and DEF CON Roundup
Open Source OSINT Tools and Techniques

An update that fixes three vulnerabilities is now available.

Black Hat USA 2022: Burnout, a significant issue

The digital skills gap, especially in cybersecurity, is not a new phenomenon. This problematic is now exacerbate by the prevalence of burnout, which was presented at Black Hat USA 2022 The post Black Hat USA 2022: Burnout, a significant issue appeared first on WeLiveSecurity

Black Hat – Windows isn’t the only mass casualty platform anymore

Windows used to be the big talking point when it came to exploits resulting in mass casualties. Nowadays, talks turned to other massive attack platforms like #cloud and cars The post Black Hat – Windows isn’t the only mass casualty platform anymore appeared first on WeLiveSecurity

Several security issues were fixed in WebKitGTK.

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for collectd-libpod-stats is now available for Red Hat OpenStack Platform 16.2 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for collectd-libpod-stats is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for .NET 6.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Indian military ready to put long-range quantum key distribution on the line
Black Hat and DEF CON visitors differ on physical risk management
Elon Musk wrote article for China’s internet regulator, hinted at aged care robots

Multiple vulnerabilities have been discovered in libarchive, the worst of which could result in arbitrary code execution.

Multiple vulnerabilities have been discovered in QEMU, the worst of which could result in remote code execution (guest sandbox escape).

Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution.

Multiple vulnerabilities have been discovered in the GNU C Library, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in Xen, the worst of which could result in remote code execution (guest sandbox escape).

The 5.18.17 stable kernel update contains a number of important fixes across the tree.

security update

The potential consequences of data breach, and romance scams – Week in security with Tony Anscombe

The NHS was victim of a potential cyberattack, which raises the question of the impact of those data breach for the public. The post The potential consequences of data breach, and romance scams – Week in security with Tony Anscombe appeared first on WeLiveSecurity