Menu

Monthly Archives: December 2022

S3 Ep112: Data breaches can haunt you more than once! [Audio + Text]
Rackspace customers rage following ransomware attack, as class-action lawsuits filed
Guess which Fortune 500 brands and govt agencies share data with Twitter?
UK lawmakers look to enforce blocking tools for legal but harmful content

The container bci/bci-busybox was updated. The following patches have been included in this update:

Boss installed software from behind the Iron Curtain, techies ended up Putin things back together
North Korea using freelance techies to fund missiles and nukes

Fix a possible double free in `woffEncode()`. – Update License to SPDX – improved summary and description – Add hand-written man pages – Install HTML format description as documentation

Openshift Logging Bug Fix Release (5.3.14) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

REvil-hit Medibank to pull plug on IT, shore up defenses

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Credit card skimming – the long and winding road of supply chain failure
Fantasy – a new Agrius wiper deployed through a supply‑chain attack

ESET researchers analyzed a supply-chain attack abusing an Israeli software developer to deploy Fantasy, Agrius’s new wiper, with victims including the diamond industry The post Fantasy – a new Agrius wiper deployed through a supply‑chain attack appeared first on WeLiveSecurity

Metaparasites: The cybercriminals who rip each other off
North Korean hackers exploit Seoul Halloween tragedy in zero-day attack

Several security issues were fixed in Python.

Five British companies fined for making half a million nuisance calls

Logging Subsystem 5.5.5 – Red Hat OpenShift Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Weep for the cybercriminals who fell for online scams and lost $2.5m last year
North Korea hits new low by using Seoul Halloween tragedy to exploit Internet Explorer zero-day

An update for python-oslo-utils is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for python-ujson is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for erlang is now available for Red Hat OpenStack Platform 16.2.4 (Train) on Red Hat Enterprise Linux (RHEL) 8.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for python-django20 is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

States label TikTok ‘a malicious and menacing threat’
Egad, did Apple do something right? End-to-end encryption for (most) iCloud services
Smashing Security podcast #301: AI chatbot or the start of Skynet? Eufy privacy, and hot desks

security update

security update

San Francisco terminates explosive killer cop bots
Complexity is the enemy of cloud security

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat AMQ Broker 7.10.2 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Several security issues were fixed in NumPy.

Taiwan bans state-owned devices from running Chinese platform TikTok

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

Microsoft: (Cyber) winter is coming as DDoS attack disrupts Russian bank
Amnesty International Canada claims attack by China-backed forces
South Pacific vacations may be wrecked by ransomware
Rackspace confirms ransomware attack behind days-long email meltdown
SIM swapper sent to prison for 2FA cryptocurrency heist of over $20m
Tractors vs. threat actors: How to hack a farm

Forget pests for a minute. Modern farms also face another – and more insidious – breed of threat. The post Tractors vs. threat actors: How to hack a farm appeared first on WeLiveSecurity

Want to detect Cobalt Strike on the network? Look to process memory
KmsdBot botnet is down after operator sends typo in command

An update for grub2 is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for usbguard is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dbus is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for pki-core is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Complexity is the enemy of security
How to secure application identities at developmental speed

A distrusted certificate authority has been removed from ca-certificates.

TSA to expand facial recognition across America
Four suspects cuffed, face extradition over tax refund scam plot
Gunfire at electrical grid kills power for 45,000 in North Carolina
Google warns stolen Android keys used to sign info-stealing malware
Russian courts attacked by CryWiper malware that poses as ransomware

security update

security update

security update

Hacking cars remotely with just their VIN
ScarCruft updates its toolset – Week in security with Tony Anscombe

Deployed against carefully selected targets, the new backdoor combs through the drives of compromised systems for files of interest before exfiltrating them to Google Drive The post ScarCruft updates its toolset – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Whoops! Researchers accidentally crash botnet used to launch DDoS and cryptomining campaigns

A distrusted certificate authority has been removed from ca-certificates.

Heres Why You Should Get Started With Open Source Log Analytics & Monitoring Today!

Several security issues were fixed in libxml2.

Securing Application Identities in 2023

Several security issues were fixed in libxml2.

Remuneration coming for TrustCor customers impacted by CA revocation
Rackspace customers rage as email outage continues and migrations create migraines

The 6.0.11 stable kernel update contains a number of important fixes across the tree.

The 6.0.11 stable kernel update contains a number of important fixes across the tree.

The 6.0.11 stable kernel update contains a number of important fixes across the tree.

Number Nine! Chrome fixes another 2022 zero-day, Edge not patched yet

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Understanding the Confidential Containers Attestation Flow

Security fix for CVE-2022-45866

Security fix for CVE-2022-45866

New version 4.0.1, Fix for bug #2148308, fix for CVE-2022-3725

Security fix for CVE-2022-45866

Rackspace rocked by ‘security incident’ that has taken out some hosted Exchange services

pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the InputStream is larger than 2k. This

g810-led, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, including sensitive data.

Mitsurugi Heishiro found out that in VLC, multimedia player and streamer, a potential buffer overflow in the vnc module could trigger remote code execution if a malicious vnc URL is deliberately played.

US Air Force reveals B-21 Raider stealth bomber that’ll fly the unfriendly skies

Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.

Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.

Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.

Medibank prognosis gets worse after more stolen data leaked
Apple pushes out iOS security update that’s more tight-lipped than ever
FBI warns about Cuba, no, not that one — the ransomware gang

security update

Top tips to save energy used by your electronic devices

With the rapidly rising energy prices putting a strain on many households, what are some quick wins to help reduce the power consumption of your gadgets? The post Top tips to save energy used by your electronic devices appeared first on WeLiveSecurity

Cloud computing gets back to basics
What is DevSecOps? Securing devops pipelines
Domain aging gang CashRewindo picks vintage sites to push malvertising