Menu

Monthly Archives: August 2022

Dark Utilities C2 service draws thousands of cyber criminals

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

It was discovered that libtirpc, a transport-independent RPC library, does not properly handle idle TCP connections. A remote attacker can take advantage of this flaw to cause a denial of service.

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

security update

security update

DuckDuckGo says Hell, Hell, No to those Microsoft trackers after web revolt
Develop a zero‑trust environment to protect your organization – Week in security with Tony Anscombe

Learn the basics of zero-trust, and how building a zero-trust environment can protect your organization. The post Develop a zero‑trust environment to protect your organization – Week in security with Tony Anscombe appeared first on WeLiveSecurity

This kernel-linus update is based on upstream 5.15.58 and fixes at least the following security issues: Kernel lockdown bypass when UEFI secure boot is disabled / unavailable and IMA appraisal is enabled (CVE-2022-21505).

This kernel update is based on upstream 5.15.58 and fixes at least the following security issues: Kernel lockdown bypass when UEFI secure boot is disabled / unavailable and IMA appraisal is enabled (CVE-2022-21505).

Jan-Niklas Sohn discovered that multiple input validation failures in the Xkb extension of the X.org X server may result in privilege escalation if the X server is running privileged.

Hi, I’ll be your ransomware negotiator today – but don’t tell the crooks that

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

security update

Nomad to crypto thieves: Please give us back 90%, keep 10% as a reward. Deal?
Warning! Critical flaws found in US Emergency Alert System
Traffic Light Protocol for cybersecurity responders gets a revamp
Open Redirect Flaw Snags Amex, Snapchat User Data

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Kaspersky blames “misconfiguration” after customers receive “dear and lovely” email
Critical flaws found in four Cisco SMB router ranges – for the second time this year
Bloke robbed of $800,000 in cryptocurrency by fake wallet app wants payback from Google
S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!) [Audio + Text]

Jan-Niklas Sohn discovered two out of bound memory writes in X.Org Server’s ProcXkbSetGeometry and ProcXkbSetDeviceInfo Xkb extensions. These issues could be exploited by an attacker to cause denial of service, privilege escalation or arbitrary code execution.

mod-wsgi could allow unintended access to network services.

Several security issues were fixed in GnuTLS.

Django could be made to expose sensitive information if it received an specially crafted input.

Taiwanese military reports DDoS in wake of Pelosi visit
Smashing Security podcast #286: Hackers doxxed, Pornhub probs, and Co-op security measures
I will take the Red (Hat) SLSA please: Introducing a framework for measuring supply chain security maturity
How a WAF Could Improve the Security of Your Linux Web Applications

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Zero-knowledge proof finds new life in the blockchain
Don’t get singed by scammers while you’re carrying the torch for Tinder 

Are you on Tinder? With 75 million monthly active users, you might be able to find the right one. However there are also traps you need to look out for. Read more about catfishing, sextortion, phishing and other practices used by scammers. The post Don’t get singed by scammers while you’re carrying the torch for […]

India scraps data protection law in favor of better law coming … sometime
Student crashes Cloudflare beta party, redirects email, bags a bug bounty
UK Parliament bins its TikTok account over China surveillance fears
Solana, Phantom blame Slope after millions in crypto-coins stolen from 8,000 wallets
GitHub blighted by “researcher” who created thousands of malicious projects
Microsoft widens enterprise access to its threat intelligence pool
Ex-T-Mobile US store owner phished staff, raked in $25m from unlocking phones
Sonatype shines light on typosquatting ransomware threat in PyPI
Post-quantum cryptography – new algorithm “gone in 60 minutes”
You can’t choose when you’ll be hit by ransomware, but you can choose how you prepare
VMWare Urges Users to Patch Critical Authentication Bypass Bug

This update upgrades Firefox to version 91.12.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 103 and 102.1 (CVE-2022-2505) * Mozilla: Directory indexes for bundled resources reflected URL parameters (CVE-2022-36318) * Mozilla: Mouse Position spoofing with CSS transforms (CVE-2022-36319) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, [More…]

Red Hat OpenShift Container Platform release 4.10.25 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the mariadb:10.5 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-17-openjdk is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for go-toolset-1.17 and go-toolset-1.17-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

NortonLifeLock and Avast $8.6b deal gets provisional yes from UK regulator
Post-quantum crypto cracked in an hour with one core of an ancient Xeon
Nancy Pelosi ties Chinese cyber-attacks to need for Taiwan visit
VMware patches critical ‘make me admin’ auth bypass bug, plus nine other flaws
How a crypto bridge bug led to a $200m ‘decentralized crowd looting’
Universities Put Email Users at Cyber Risk

security update

Robinhood’s crypto unit hit with $30m fine over security, anti-crime misses
Threat groups embrace messaging apps to spread malware, communicate
Cryptocoin “token swapper” Nomad loses $200 million in coding blunder
Bot army risk as 3,000+ apps found spilling Twitter API keys
Installing SurfShark VPN On Kali Linux: The Authoritative Guide
Best Practices for PHP Security
Linux Mint 21 Vanessa Is Now Available for Download, This Is Whats New
LibreOffice Security Update Fixes Macro Execution Bypass and Potential Password Leaking

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Imran Khan’s Instagram account hacked to promote phoney Elon Musk $100 million crypto giveaway
Miscreants aim to cause Discord discord with malicious npm packages
Start as you mean to go on: the top 10 steps to securing your new computer

Whether you are getting ready for back-to-school season, getting new work laptop or fancying a new gamer’s pc, learn the steps to protect your new PC from cyberthreats. The post Start as you mean to go on: the top 10 steps to securing your new computer appeared first on WeLiveSecurity

Charges filed over $300m ‘textbook pyramid and Ponzi scheme’ crypto startup

security update

GnuTLS patches memory mismanagement bug – update now!
Defence against the dark arts of ransomware
Securing Your Move to the Hybrid Cloud

Multiple security vulnerabilities have been discovered in cURL, an URL transfer library. These flaws may allow remote attackers to obtain sensitive information, leak authentication or cookie header data or facilitate a denial of service attack.

Several security issues were fixed in Net-SNMP.

OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) (CVE-2022-34169) * OpenJDK: class compilation issue (Hotspot, 8281859) (CVE-2022-21540) * OpenJDK: improper restriction of MethodHandle.invokeBasic() (Hotspot, 8281866) (CVE-2022-21541) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE [More…]

OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) (CVE-2022-34169) * OpenJDK: class compilation issue (Hotspot, 8281859) (CVE-2022-21540) * OpenJDK: improper restriction of MethodHandle.invokeBasic() (Hotspot, 8281866) (CVE-2022-21541) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE [More…]

squid: DoS when processing gopher server responses (CVE-2021-46784) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 squid-3.5.20-17.el7_9.7.x86_64.rpm squid-debuginfo-3.5.20-17.el7_9.7.x86_64.rpm squid-migration-script-3.5.20-17.el7_9.7.x86_64.rpm squid-sysvinit-3.5 [More…]

An update that fixes one vulnerability is now available.

How Cloudflare emerged to take on AWS, Azure, and GCP
Akamai: We stopped record DDoS attack in Europe
Spyware developer charged by Australian Police after 14,500 sales