Menu

Monthly Archives: August 2022

Black Hat 2022‑ Cyberdefense in a global threats era

Our Security evangelist’s take on this first day of Black Hat 2022, where cyberdefense was on every mind. The post Black Hat 2022‑ Cyberdefense in a global threats era appeared first on WeLiveSecurity

Safety first: how to tweak the settings on your dating apps

Tinder, Bumble or Grindr – popular dating apps depend heavily on your location, personal data, and loose privacy settings. Find out how to put yourself out there safely by following our suggested settings tweaks. The post Safety first: how to tweak the settings on your dating apps appeared first on WeLiveSecurity

Ukraine’s cyber chief comes to Black Hat in surprise visit

The container bci/bci-micro was updated. The following patches have been included in this update:

A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit (CVE-2022-34526) References: – https://bugs.mageia.org/show_bug.cgi?id=30716

A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service. (CVE-2022-32189) References:

A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. (CVE-2022-27337) References:

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected. (CVE-2022-34265)

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. (CVE-2022-29970) References: – https://bugs.mageia.org/show_bug.cgi?id=30542

Let there be ambient light sensing, without fear of data theft
Palo Alto bug used for DDoS attacks and there’s no fix yet
Starlink satellite dish cracked on stage at Black Hat

security update

US reveals ‘Target’ pic of Conti man with $10m reward offer
Feds: Zeppelin Ransomware Resurfaces with New Compromise, Encryption Tactics
Microsoft trumps Google for 2021-22 bug bounty payouts
An eighties classic – Zero Trust

A deep-dive in Zero-trust, to help you navigate in a zero-trust world and further secure your organization. The post An eighties classic – Zero Trust appeared first on WeLiveSecurity

Intel ups protection against physical chip attacks in Alder Lake
Facebook’s In-app Browser on iOS Tracks ‘Anything You Do on Any Website’
Emergency services call-handling provider: Ransomware forced it to pull servers offline

An update that fixes one vulnerability is now available.

Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in HTTP request smuggling, cache poisoning or information disclosure.

Ransomware attack blamed for closure of all 7-Eleven stores in Denmark
Chinese criminals scam kids desperate to play games for more than three hours a week

The container bci/rust was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

FAANGs failing on keeping user data safe from bug hunters
Higher risks and premiums are creating critical gap in cyber insurance
Security needs to learn from the aviation biz to avoid crashing
Russian invasion has dangerously destabilized cyber security norms
AWS and Splunk partner for faster cyberattack response
Ex-CIA security boss predicts coming crackdown on spyware
Sonatype spots another PyPI package behaving badly
Keeping the enemy at the gate
Don’t be surprised if your organization suffers multiple cyberattacks
Starlink Successfully Hacked Using $25 Modchip
New Hacker Forum Takes Pro-Ukraine Stance
Years after claiming DogWalk wasn’t a vulnerability, Microsoft confirms flaw is being exploited and issues patch
S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]

The following updated rpms for Oracle Linux 7 have been uploaded to the Unb= reakable Linux Network:

Cisco Confirms Network Breach Via Hacked Employee Google Account
Implementing security benchmarks with Red Hat Ansible Automation Platform

An update that fixes 5 vulnerabilities is now available.

Making the cloud a safer place with SANS

Booth could be made to be stop working under certain circumstances.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Cisco admits corporate network compromised by gang with links to Lapsus$
Podcast: Inside the Hackers’ Toolkit
Meta privacy red team lead: Does your business know its privacy adversaries?
Boffins rate npm and PyPI package security and it’s not good
Ex-CISA chief Krebs calls for US to get serious on security
As Black Hat kicks off, the US government is getting the message on hiring security talent

security update

Maui ransomware linked to North Korean group Andariel
APIC/EPIC! Intel chips leak secrets even the kernel shouldn’t see…
Google’s bug bounty boss: Finding and patching vulns? ‘Totally useless’

When was the last time you secretly smiled when ransomware gangs had their bitcoin stolen, their malware servers shut down, or were forced to disband? We hang on to these infrequent victories because history tells us that most ransomware collectives don’t go away—they reinvent themselves under a new name, with new rules, new targets, and […]

Cloudflare: Someone tried to pull the Twilio phishing tactic on us too

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Microsoft Patches ‘Dogwalk’ Zero-Day and 17 Critical Flaws

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The Story Behind the Linux Security Quick Reference Guide
Businesses should dump Windows for the Linux desktop
Patch Tuesday: Yet another Microsoft RCE bug under active exploit

security update

security update

Slack admits to leaking hashed passwords for five years
Virtual Currency Platform ‘Tornado Cash’ Accused of Aiding APTs
APIC fail: Intel ‘Sunny Cove’ chips with SGX spill secrets
Malicious deepfakes used in attacks up 13% from last year, VMware finds

Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Microsoft’s fix for ‘data damage’ risk hits PC performance

An update that fixes three vulnerabilities is now available.

Benefits & Drawbacks of Using a VPN on Linux
How to check if your PC has been hacked, and what to do next

Has your PC been hacked? Whatever happens, don’t panic. Read on for ten signs your PC has been hacked and handy tips on how to fix it. The post How to check if your PC has been hacked, and what to do next appeared first on WeLiveSecurity

An update for vim is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 6 vulnerabilities is now available.

Chinese scammers target kids with promise of extra gaming hours

Red Hat OpenShift Container Platform release 4.10.26 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

China-linked spies used six backdoors to steal info from defense, industrial enterprise orgs
US treasury whips up sanctions for crypto mixer Tornado Cash
Twilio customer data exposed after its staffers got phished
Microsoft tightens Edge security for less visited websites
Phishers Swim Around 2FA in Coinbase Account Heists
Slack leaked hashed passwords from its servers for years

Sandipan Roy discovered two vulnerabilities in InfoZIP’s unzip program, a de-archiver for .zip files, which could result in denial of service or potentially the execution of arbitrary code.

phpLiteAdmin could allow cross-site scripting (XSS) attacks.

GDK-PixBuf could be made to crash or run programs as your login if it opened a specially crafted file.

Several security issues were fixed in libjpeg-turbo.

An update for openshift-istio-kiali-rhel8-container is now available for OpenShift Service Mesh 2.0. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat Kiali for OpenShift Service Mesh 2.2 Containers Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from