Menu

Monthly Archives: September 2022

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Update to bugfix/security release 2022-07-29a. Includes security fix for CVE-2022-3123.

Update to bugfix/security release 2022-07-29a. Includes security fix for CVE-2022-3123.

security update

security update

security update

security update

Open up, it’s the IRS. We’re here about the crypto tax you dodged
What to consider before disposing of personal data – Week in security with Tony Anscombe

A major financial services company has learned the hard way about the importance of proper disposal of customers’ personal data The post What to consider before disposing of personal data – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Significant customer data exposed in attack on Australian telco
Hey WeLiveSecurity, how does biometric authentication work?

Your eyes may be the window to your soul, but they can also be your airplane boarding pass or the key unlocking your phone. What’s the good and the bad of using biometric traits for authentication? The post Hey WeLiveSecurity, how does biometric authentication work? appeared first on WeLiveSecurity

Oxford teen arrested in UK on suspicion of hacking
Iran blocks Whatsapp, Instagram as citizens protest death of Mahsa Amini
Morgan Stanley fined millions for selling off devices full of customer PII
“Fake crypto millionaire” charged with alleged $1.7M cryptomining scam
Come to the National Information Security Conference in October, and see Smashing Security LIVE!

Several security issues were fixed in the Linux kernel.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Connecting to the RHEL web console, part 1: SSH access methods
Role-based access control for Red Hat Hybrid Cloud Console
Business VPNs: Now More Important Than Ever
Keeping secrets safe off prem

An update that fixes two vulnerabilities is now available.

Privacy watchdog steps up fight against Europol’s hoarding of personal data

The container suse/sles/15.4/virt-operator was updated. The following patches have been included in this update:

security update

Check out this Android spyware, says Microsoft, the home of a gazillion Windows flaws
S3 Ep101: Uber and LastPass breaches – is 2FA all it’s cracked up to be? [Audio + Text]
Cambodian authorities crack down on cyber slavery amid international pressure
Fake sites fool Zoom users into downloading deadly code
How to have fun negotiating with a ransomware gang
Smashing Security podcast #290: Uber, Rockstar, and crystal balls

Several security issues were fixed in etcd.

Several security issues were fixed in the Linux kernel.

Several security vulnerabilities were discovered in mediawiki, a website engine for collaborative work. Insufficiently escaped input text may allow a malicious user to perform cross-site-scripting (XSS) attacks.

An update that fixes three vulnerabilities is now available.

Linux Log Analysis

PCRE could be made to expose sensitive information.

Several vulnerabilities were discovered in BIND, a DNS server implementation. CVE-2022-2795

Alert: 15-year-old Python tarfile flaw lurks in ‘over 350,000’ code projects
San Francisco cops can use private cameras to live-monitor ‘significant events’
Malwarebytes blocks Google, YouTube as malware
Interested in cybersecurity? Join us for Security SOS Week 2022!
‘I Don’t Care About Cookies’ extension sold to Avast

Several security issues were fixed in Bind.

Reflections in your glasses can leak information while you’re on a Zoom call
WAAP it out for application security

It was discovered that the wordexp() function of tinygltf, a library to load/save glTF (GL Transmission Format) files was susceptible to command execution when processing untrusted files.

Energy bill rebate scams spread via SMS and email
ChromeLoader, what took you so long? Malvertising irritant now slings ransomware

Mako could be made to denial of service if it received a specially crafted regular expression.

Several security issues were fixed in Bind.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Look who’s fallen foul of Europe’s data retention rules. France and Germany
USA adds two more Chinese carriers to ‘probably a national security threat’ list
Crypto biz Wintermute loses $160m in cyber-heist, tells us not to stress out
Meta, Twitter, Apple, Google urged to up encryption game in post-Roe America
Can your iPhone be hacked? What to know about iOS security

Here are some of the most common ways that an iPhone can be compromised with malware, how to tell it’s happened to you, and how to remove a hacker from your device The post Can your iPhone be hacked? What to know about iOS security appeared first on WeLiveSecurity

Rising to the challenges of secure coding – Week in security with Tony Anscombe

The news seems awash this week with reports of both Microsoft and Apple scrambling to patch security flaws in their products The post Rising to the challenges of secure coding – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Several security issues were fixed in LibTIFF.

3 wins and 3 losses for cloud computing

Red Hat OpenShift Container Platform release 4.11.5 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11.

The container bci/python was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

The container bci/dotnet-aspnet was updated. The following patches have been included in this update:

An update that fixes one vulnerability is now available.

Uber explains how it was pwned this month, points finger at Lapsus$ gang

security update

Been hit by LockerGoga ransomware? A free fix is now out
Grand Theft Auto 6 maker confirms source code, vids stolen in cyber-heist
LastPass source code breach – incident response report released
Does Linux Need a Firewall & How To Configure the Linux Firewall with firewall-cmd
GPT-3 ‘prompt injection’ attack causes bad bot manners

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update for redhat-release-virtualization-host, redhat-virtualization-host, and redhat-virtualization-host-productimg is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

Maher Azzouzi found a local root escalation vulnerability in Enlightenment, an X11 window manager. For Debian 10 buster, this problem has been fixed in version

Indonesia accuses Google of abusing monopoly

– control code in cookie denial of service (CVE-2022-35252)

6.0.8, fixes CVE-2022-40626

An update that fixes one vulnerability is now available.

Security fix for CVE-2022-2309

S3 Ep100.5: Uber breach – an expert speaks [Audio + Text]

Update to latest upstream release

An update that fixes two vulnerabilities is now available.

Several vulnerabilities were discovered in ConnMan, a network manager for embedded devices, which could result in denial of service or the execution of arbitrary code.

Enhancing application container security and compliance with Podman
Can reflections in eyeglasses actually leak info from Zoom calls? Here’s a study into it

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

School chat app Seesaw abused to send ‘inappropriate image’ to parents, teachers

security update