Menu

Monthly Archives: October 2022

From today, America and UK follow new rules on how they can demand your data from each other
It’s 2058. A quantum computer is just another decade away. Still, you curse Cloudflare
National Cybersecurity Awareness program 18 years on: Don’t click that
Student data leaked after LA school district says it won’t pay ransom
There’s good and bad news about the Microsoft Exchange server zero-day exploit
FBI: We tracked who was printing secret documents to unmask ex-NSA suspect
Cyber-proofing data in the cloud

Several security issues were fixed in the Linux kernel.

Founder of cybersecurity firm Acronis is afraid of his own vacuum cleaner
Between ransomware and month-long engagements, IR teams need a hug – and a nap

An update that fixes three vulnerabilities is now available.

This update includes the changes in tzdata 2022d for the Perl bindings. For the list of changes, see DLA-3134-1. For Debian 10 buster, this problem has been fixed in version

Moody’s turns up the heat on ‘riskiest’ sectors for cyberattacks

This update includes the changes in tzdata 2022d. Notable changes are: – – Palestine now switches back to standard time on October 29.

An invalid HTTP request (websocket handshake) may cause a NULL pointer dereference in the wstunnel module. For Debian 10 buster, this problem has been fixed in version

Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Steganography alert: Backdoor spyware stashed in Microsoft logo
BlackCat malware lashes out at US defense IT contractor

The container bci/python was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

ESET Research into new attacks by Lazarus – Week in security with Tony Anscombe

The attack involved the first recorded abuse of a security vulnerability in a Dell driver that was patched in May 2021 The post ESET Research into new attacks by Lazarus – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Amazon‑themed campaigns of Lazarus in the Netherlands and Belgium

ESET researchers have discovered Lazarus attacks against targets in the Netherlands and Belgium that use spearphishing emails connected to fake job offers The post Amazon‑themed campaigns of Lazarus in the Netherlands and Belgium appeared first on WeLiveSecurity

S3 Ep102.5: “ProxyNotShell” Exchange bugs – an expert speaks [Audio + Text]

An update that fixes two vulnerabilities is now available.

Gone in a day: Ethical hackers say it would take mere hours to empty your network

The container suse/sles12sp4 was updated. The following patches have been included in this update:

Two issues were found in GDAL, a geospatial library, that could lead to denial of service via application crash or possibly the execution of arbitrary code if maliciously crafted data was parsed.

thenify is a Promisify a callback-based function using any-promise. Affected versions of this package are vulnerable to Arbitrary Code Execution. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval