Menu

Monthly Archives: September 2022

Update to 102.3.1 * https://www.mozilla.org/en- US/security/advisories/mfsa2022-43/ * https://www.thunderbird.net/en- US/thunderbird/102.3.1/releasenotes/

security update

An issue has been found in tinyxml, a C++ XML parsing library. Crafted XML messages could lead to an infinite loop in TiXmlParsingData::Stamp(), which results in a denial of service.

Protecting teens from sextortion: What parents should know

Online predators increasingly trick or coerce youth into sharing explicit videos and photos of themselves before threatening to post the content online The post Protecting teens from sextortion: What parents should know appeared first on WeLiveSecurity

Prison for ex-eBay staff who aggressively cyberstalked company’s critics with Craigslist sex party ads and funeral wreaths
Enterprises embrace devsecops practices against supply chain attacks
Watchfinder warns customers that hackers stole their data
URGENT! Microsoft Exchange double zero-day – “like ProxyShell, only different”

An issue has been found in libhttp-daemon-perl, a simple http server class. Due to insufficient Content-Length: handling in HTTP-header an attacker

Connecting to the RHEL web console, part 2: Running the Cockpit web server

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

This update upgrades Thunderbird to version 102.3.0. * Mozilla: Leaking of sensitive information when composing a response to an HTML email with a META refresh tag (CVE-2022-3033) * Mozilla: Bypassing FeaturePolicy restrictions on transient pages (CVE-2022-40959) * Mozilla: Data-race when parsing non-UTF-8 URLs in threads (CVE-2022-40960) * Mozilla: Memory safety bugs fixed in Firefox 105 […]

This update upgrades Firefox to version 102.3.0 ESR. * Mozilla: Bypassing FeaturePolicy restrictions on transient pages (CVE-2022-40959) * Mozilla: Data-race when parsing non-UTF-8 URLs in threads (CVE-2022-40960) * Mozilla: Memory safety bugs fixed in Firefox 105 and Firefox ESR 102.3 (CVE-2022-40962) * Mozilla: Bypassing Secure Context restriction for cookies with __Host and __Secure pref [More…]

Microsoft warns of North Korean crew posing as LinkedIn recruiters
Stop us if you’ve heard this one before: Exchange Server zero-day being actively exploited
Ex-eBay execs jailed for cyberstalking web critics
How CIA betrayed informants with shoddy front websites built for covert comms
Pentagon is far too tight with its security bug bounties

security update

security update

IT admin admits sabotaging ex-employer’s network in bid for higher salary
S3 Ep102: Cutting through cybersecurity news hype [Audio + Transcript]
Covert malware targets VMware shops for hypervisor-level espionage

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Red Hat Shares ― Edge computing: Security
Why developers hold the key to cloud security
Microsoft to kill off old access rules in Exchange Online
Smashing Security podcast #291: Deepfake dangers, AI image opt out, and controlling your urges
Matrix chat encryption sunk by five now-patched holes
Cryptojacking, DDoS attacks increase in container-based cloud systems

security update

security update

The web’s cruising at 13 million new and nefarious domain names a month
Samsung sued for gobbling up too much personal info that miscreants then stole
Want to sneak a RAT into Windows? Buy Quantum Builder on the dark web
Hacked Fast Company sends ‘obscene and racist’ alerts via Apple News
Reducing the risk of human error in cyber security
Optus breach – Aussie telco told it will have to pay to replace IDs
Ever suspected bankers could just use WhatsApp comms? $1.8b says you’re right

Several vulnerabilities were discovered in lighttpd, a fast webserver with minimal memory footprint. CVE-2022-37797

An update that fixes two vulnerabilities is now available.

It was discovered that the Commandline class in maven-shared-utils, a collection of various utility classes for the Maven build system, can emit double-quoted strings without proper escaping, allowing shell injection attacks.

An update that solves 20 vulnerabilities and has 8 fixes is now available.

Memory-related security fixes, BZ 2127755

The container suse/sle15 was updated. The following patches have been included in this update:

Here’s how crooks will use deepfakes to scam your biz
Australia asks FBI to help find attacker who stole data from millions of users
A question of identity
Sophos fixes critical firewall hole exploited by miscreants

security update

security update

What happens with a hacked Instagram account – and how to recover it

Had your Instagram account stolen? Don’t panic – here’s how to get your account back and how to avoid getting hacked (again) The post What happens with a hacked Instagram account – and how to recover it appeared first on WeLiveSecurity

WhatsApp “zero-day exploit” news scare – what you need to know
Meta busts first Chinese campaign prodding US midterms
Microsoft boosts phishing protection in Windows 11 22H2
Microsoft bets on hardware/software duo for Win11 security

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Edge solutions in rail transportation deliver efficiencies, security and flexibility with open source solutions
Official Guide on Rocky Linux & How to Install It

Several security issues were fixed in Ghostscript.

Cloud’s key role in the emerging hybrid workforce

An update that solves 11 vulnerabilities and has 21 fixes is now available.

China’s infosec researchers obeyed Beijing and stopped reporting vulns … or did they?
Ukraine fears ‘massive’ Russian cyberattacks on power, infrastructure
SQL Server admins warned about Fargo ransomware
TAP Air Portugal confirms hack, as Ragnar Locker gang leaks data – including that of Portugese president
Beware Revolut frozen card scams sent via SMS text
How do you run rings around ransomware?

Several security issues were fixed in WebKitGTK.

Several security issues were fixed in Squid.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Teen hacking suspect charged with computer misuse and breach of bail conditions

An update that solves one vulnerability and has two fixes is now available.

Expat could be made to crash or execute arbitrary code.

An expert guide to securing APIs
See how Pentera identifies and mitigates the risk of your most exploitable exposed credentials
India seeks verified IDs to register email accounts

An update that fixes one vulnerability is now available.

Multiple vulnerabilities have been found in Oracle JDK and JRE, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been discovered in Fetchmail, the worst of which could result in email disclosure to third parties.

Multiple vulnerabilities have been discovered in libaacplus, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in GRUB, the worst of which may allow for secureboot bypass.

Multiple vulnerabilities have been discovered in HarfBuzz, the worst of which could result in arbitrary code execution.

Noberus ransomware gets info-stealing upgrades, targets Veeam backup software
Uber and Rockstar – has a LAPSUS$ linchpin just been busted (again)?

security update

5 tips to help children navigate the internet safely

The online world provides children with previously unimagined opportunities to learn and socialize, but it also opens them up to a range of hazards. How can you steer kids toward safe internet habits? The post 5 tips to help children navigate the internet safely appeared first on WeLiveSecurity

How to integrate Red Hat Advanced Cluster Security for Kubernetes with ServiceNow

An update that fixes two vulnerabilities is now available.