Menu

Monthly Archives: October 2022

Education tech giant gets an F for security after sensitive info on 40 million users stolen

security update

Extortion fears after hacker stole patient files from Dutch mental health clinics
Psychotherapy extortion suspect: arrest warrant issued
The White House’s global ransomware summit couldn’t come at a better time
Ordinary web access request or command to malware?

Libtasn1 could cause a crash when processing certain inputs.

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

Twilio reveals hackers compromised its systems a month earlier than previously thought
Apple patches actively exploited iPhone, iPad kernel vulns
Singapore hosts ICS/OT cybersecurity training extravaganza
Indian government creates body with power to order social media content takedowns

security update

security update

security update

Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine. CVE-2021-43980

It was discovered that Apache Batik, a SVG library for Java, allowed attackers to run arbitrary Java code by processing a malicious SVG file. For the stable distribution (bullseye), these problems have been fixed in

A security issue was discovered in Chromium, which could result in the execution of arbitrary code. For the stable distribution (bullseye), this problem has been fixed in

It was discovered that libxml2, the GNOME XML library, was vulnerable to integer overflows and memory corruption. CVE-2022-40303

A heap use-after-free vulnerability after overeager destruction of a shared DTD in the XML_ExternalEntityParserCreate function in Expat, an XML parsing C library, may result in denial of service or potentially the execution of arbitrary code.

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version

Courts vs. cybercrime – Week in security with Tony Anscombe

A look at a recent string of law enforcement actions directed against (in some cases suspected) perpetrators of various types of cybercrime The post Courts vs. cybercrime – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Chrome issues urgent zero-day fix – update now!

It was discovered that Apache Batik, a SVG library for Java, allowed attackers to run arbitrary Java code by processing a malicious SVG file. For Debian 10 buster, these problems have been fixed in version

Everything You Need To Know About Open Source Network Monitoring Tools

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

An issue has been found in openvswitch, a software-based, Ethernet virtual switch.

An issue has been found in ncurses, a collection of shared libraries for terminal handling. This issue is about an out-of-bounds read in convert_strings in the

This Windows worm evolved into slinging ransomware. Here’s how to detect it

security update

Federal bans aren’t stopping US states from buying forbidden Chinese kit
Why your phone is slow – and how to speed it up

You probably don’t have to ditch your phone just yet – try these simple tips and tricks to make any Android device or iPhone run faster The post Why your phone is slow – and how to speed it up appeared first on WeLiveSecurity

Multiple vulnerabilities were discovered in Django, a popular Python-based web development framework: * CVE-2020-24583: Fix incorrect permissions on intermediate-level

The top cloud cyber security threats unpacked
Updates to Apple’s zero-day update story – iPhone and iPad users read this!
Post-quantum cryptography: Hash-based signatures
3 primo cloud gigs in 2023

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Biden now wants to toughen up chemical sector’s cybersecurity

security update

New York Post was hacked from the inside, employee fired after offensive articles posted online
S3 Ep106: Facial recognition without consent – should it be banned?
Parcel delivery scams are on the rise: Do you know what to watch out for?

As package delivery scams that spoof DHL, USPS and other delivery companies soar, here’s how to stay safe not just this shopping season The post Parcel delivery scams are on the rise: Do you know what to watch out for? appeared first on WeLiveSecurity

LinkedIn’s new security features fight scammers, deepfakes, and hackers
The point solution IAM evolution under reform

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Cryptographic signatures for zip distributions

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Purpleurchin cryptocurrency miners spotted scouring free GitHub, Heroku accounts
Japan to citizens: Get a digital ID or health insurance gets harder
Pro-China crew ramps up disinfo ahead of US midterms. Not that anyone’s falling for it
Feds accuse Ukrainian of renting out PC-raiding Raccoon malware to fiends
Cisco AnyConnect Windows client under active attack
Microsoft realizes it hasn’t updated list of banned dodgy Windows 10 drivers in years
Online ticketing company “See” pwned for 2.5 years by attackers

This is the October 2022 release of .NET Core 3.1 This updates .NET Core 3.1 SDK to 3.1.424 and Runtime to 3.1.30. This includes fixes for CVE-2022-41032

added patches to fix CVE-2022-41751

– New version 4.4.3-P1 (rhbz#2132240) – Fix for CVE-2022-2928 (rhbz#2132429) – Fix for CVE-2022-2929 (rhbz#2132430)

Update to 1.12.24 * Fix CVE-2022-42010, CVE-2022-42011, CVE-2022-42012

This is the October 2022 release of .NET Core 3.1 This updates .NET Core 3.1 SDK to 3.1.424 and Runtime to 3.1.30. This includes fixes for CVE-2022-41032

added patches to fix CVE-2022-41751

Service Preview of Red Hat Advanced Cluster Security Cloud Service
New Year, new cyber security career
Ransomware down this year – but there’s a catch
If someone tries ransacking your Windows network, it’s a bit easier now to grok in Microsoft 365 Defender
Health insurer Medibank’s data breach diagnosis keeps getting worse
Clearview AI image-scraping face recognition service hit with €20m fine in France
FTC slaps down Drizly CEO after 2.4m user records stolen from ‘careless’ booze app biz
PayPal ditches passwords, at least on Apple devices
The safety of numbers
Cybersecurity event cancelled after scammers disrupt LinkedIn live chat

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

What Should Be on My Resume as a Linux Administrator?

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Why you’re getting cloud security wrong
Gone phishing: UK data watchdog fines construction biz £4.4m for poor infosec hygiene
Seven months after it found out, FamilySearch tells users their personal data has been breached
Uncle Sam says these Chinese nationals are Beijing agents breaking the law on US soil
Apple megaupdate: Ventura out, iOS and iPad kernel zero-day – act now!
Payment terminal malware steals $3.3m worth of credit card numbers – so far

security update

Car dealer group Pendragon refuses to pay $60 million to ransomware extortionists