Menu

Monthly Archives: November 2022

Latest insights on APT activity – Week in security with Tony Anscombe

What have some of the world’s most notorious APT groups been up to lately? A new ESET report released this week has the answers. The post Latest insights on APT activity – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Ouch! Ransomware gang says it won’t attack AirAsia again due to the “chaotic organisation” and sloppy security of hacked airline’s network

Several security issues were fixed in FreeRDP.

Several security issues were fixed in FreeRDP.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 10 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Microsoft’s attempts to harden Kerberos authentication broke it on Windows Servers
World Cup phishing emails spike in Middle Eastern countries
How social media scammers buy time to steal your 2FA codes
US offshore oil and gas installation at ‘increasing’ risk of cyberattack
Cyber security pros: move to the next level next year
Keeping Your Private Files Private: An Introduction to GNU Privacy Guard

An update that fixes two vulnerabilities is now available.

An update that solves 10 vulnerabilities, contains 10 features and has three fixes is now available.

An update that solves 10 vulnerabilities, contains 10 features and has three fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

Google looking outside the usual channels to fix security skills gap
Serendipitous discovery nets security researcher $70k bounty

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Tor vs. VPN: Which should you choose?

Both Tor and a VPN can greatly help you keep prying eyes away from your online life, but they’re also two very different beasts. Which is better for you? The post Tor vs. VPN: Which should you choose? appeared first on WeLiveSecurity

Greg Hudson discovered integer overflow flaws in the PAC parsing in krb5, the MIT implementation of Kerberos, which may result in remote code execution (in a KDC, kadmin, or GSS or Kerberos application server process), information exposure (to a cross-realm KDC acting

Greg Hudson discovered integer overflow flaws in the PAC parsing in krb5, the MIT implementation of Kerberos, which may result in remote code execution (in a KDC, kadmin, or GSS or Kerberos application server process), information exposure (to a cross-realm KDC acting

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

security update

Hive ransomware crooks extort $100m from 1,300 global victims

security update

security update

Police force published sexual assault victims’ names and addresses on its website
Red Hat Enterprise Linux and Microsoft security update of November 2022
Hardware-assisted encryption of data in use gets confidential

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 52 vulnerabilities, contains one feature is now available.

An update that fixes 52 vulnerabilities, contains one feature is now available.

Z-Library operators arrested, charged with criminal copyright infringement
Israel sets robotic target-tracking turrets in the West Bank
Security firms hijack New York trees to monitor private workforce

security update

S3 Ep109: How one leaked email password could drain your business
Open banking: Tell me what you buy, and I’ll tell you who you are

The convenience with which you manage all your financial wants and needs may come at a cost The post Open banking: Tell me what you buy, and I’ll tell you who you are appeared first on WeLiveSecurity

Google wins lawsuit against alleged Russian botnet herders

It was discovered that php-phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v2), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific

It was discovered that phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v1), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific situations.

It was discovered that phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v1), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific situations.

Black Friday and retail season – watch out for PayPal “money request” scams

Expat could be made to crash or execute arbitrary code.

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler,

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler,

Notorious Emotet botnet returns after a few months off
Smashing Security podcast #298: Housing market scams, Twitter 2FA, and the fesshole

security update

Iranian cyberspies exploited Log4j to break into a US govt network
Germany says nein to Qatari World Cup spyware, err, apps

security update

security update

security update

WASP malware stings Python developers
Firefox fixes fullscreen fakery flaw – get the update now!
Cloud vendors should take some responsibility for stolen compute, says Canalys CEO

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c (CVE-2022-3550) * xorg-x11-server: memory leak in ProcXkbGetKbdByName() in xkb/xkb.c (CVE-2022-3551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 xorg-x11-server-Xephyr-1.20.4-19.el7_9.x86_64.rpm xorg- [More…]

xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c (CVE-2022-3550) * xorg-x11-server: memory leak in ProcXkbGetKbdByName() in xkb/xkb.c (CVE-2022-3551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 xorg-x11-server-Xephyr-1.20.4-19.el7_9.x86_64.rpm xorg- [More…]

An update that fixes one vulnerability is now available.

Swiss bankers warn: Three quarters of retail Bitcoin investors are in the red
Boosting telcos’ 5G cyber resilience
It’s time. Delete your Twitter DMs
Eggheads show how network flaw could lead to NASA crew pod loss. Key word: Could
Shocker: EV charging infrastructure is seriously insecure
Log4Shell-like code execution hole in popular Backstage dev tool
Healthcare sector warned of Venus ransomware attacks
Securing the mail

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform SQL injection, create open redirects, bypass authorization access, or perform Cross-Site Request Forgery (CSRF) or Cross-Site Scripting (XSS) attacks.

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform SQL injection, create open redirects, bypass authorization access, or perform Cross-Site Request Forgery (CSRF) or Cross-Site Scripting (XSS) attacks.

Several bugs were discovered in PostgreSQL, a relational database server system. This new LTS minor version update fixes over 25 bugs that were reported in the last several months. The complete and detailed list of issues could be found at: https://www.postgresql.org/docs/release/11.18.

Several bugs were discovered in PostgreSQL, a relational database server system. This new LTS minor version update fixes over 25 bugs that were reported in the last several months. The complete and detailed list of issues could be found at: https://www.postgresql.org/docs/release/11.18.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Country that still uses fax machines wants to lead the world on data standards at G7
Data sovereignty and compliance need help
Russia-based Pushwoosh tricks US Army and others into running its code – for a while
GitHub sets up private vulnerability reports for public repos to avoid ‘naming and shaming’

security update

security update

“Gucci Master” business email scammer Hushpuppi gets 11 years