Menu

Monthly Archives: January 2023

security update

Fujitsu: Quantum computers no threat to encryption just yet
Hybrid play: Leveling the playing field in online video gaming and beyond

Does VALORANT’s approach to cheating signal a turning point in how we deal with the continued hacks afflicting our hybrid world of work and play? The post Hybrid play: Leveling the playing field in online video gaming and beyond appeared first on WeLiveSecurity

How to use Red Hat Insights malware detection service

Red Hat OpenShift Container Platform release 4.10.50 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for pcs is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for sssd is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Apple patches are out – old iPhones get an old zero-day fix at last!
After data breach put their lives at risk, US releases 3000 immigrants seeking asylum
Serious Security: How dEliBeRaTe tYpOs might imProVe DNS security
FanDuel gamblers warned of phishing threat after data breach at Mailchimp
Microsoft took its macros and went home, so miscreants turned to Windows LNK files
Kolide – Endpoint security for people, not paper clips
How to Check if Your Linux System is Infected with a Virus

Setuptools could be made to crash if it received specially crafted input.

Multiple vulnerabilities were found in trafficserver, a caching proxy server. CVE-2021-37150

An update for sudo is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for sudo is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for sudo is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for sudo is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

US authorities release asylum seekers after leaking their data online
India floats plan to make big tech pay for news, walks back government censorship
Taking patch management to the next level with automation

– Update to 109.0

This updates .NET 6 to the January 2023 security release. The updated versions are SDK 6.0.113 and Runtime 6.0.13 This include a fix for CVE-2023-21538

Patches for CVE-2023-23456 and CVE-2023-23457

Rebase to sudo-1.9.12p2 – security fix for CVE-2023-22809

libXpm 3.5.15, fixes CVE-2022-46285, CVE-2022-44617, CVE-2022-4883

This updates .NET 6 to the January 2023 security release. The updated versions are SDK 6.0.113 and Runtime 6.0.13 This include a fix for CVE-2023-21538

Ransomware payments down 40% in 2022 – Week in security with Tony Anscombe

Ransomware revenue plunges to $456 million in 2022 as more victims refuse to pay up. Here’s what to make of the trend. The post Ransomware payments down 40% in 2022 – Week in security with Tony Anscombe appeared first on WeLiveSecurity

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

security update

USN-5810-1 introduced a regression in Git.

T-Mobile admits to 37,000,000 customer records stolen by “bad actor”
Ireland’s data protection watchdog fines WhatsApp €5.5 million
Tech support scammers are still at it: Here’s what to look out for in 2023

Hello, is it me you’re looking for? Fraudsters still want to help you fix a computer problem you never had in the first place. The post Tech support scammers are still at it: Here’s what to look out for in 2023 appeared first on WeLiveSecurity

Ransomware attack hit KFC and Pizza Hut stores in the UK
T-Mobile has been hacked… again. 37 million customers’ data stolen
Miscreants sure do love ransacking cloud networks, more so than before
Crims steal data on 40 million T-Mobile US customers
PayPal says crooks poked around 35,000 accounts in credential stuffing attack

Igor Ponomarev discovered that LAVA, a continuous integration system for deploying operating systems onto physical and virtual hardware for running tests, was susceptible to denial of service via recursive XML entity expansion.

It was discovered that the CompareTool of iText, a Java PDF library which uses the external ghostscript software to compare PDFs at a pixel level, allowed command injection when parsing a specially crafted filename.

Finally, ransomware victims are refusing to pay up

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

security update

security update

LockBit ransomware – what you need to know
Mailchimp slips up again, suffers security breach after falling on social engineering banana skin
University of Texas latest US school to ban TikTok
S3 Ep118: Guess your password? No need if it’s stolen already! [Audio + Text]
Bitzlato cryptocurrency exchange shut down by authorities, accused of cybercriminal links
Mailchimp ‘fesses up to second digital burglary in five months

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.

New deep threat intelligence in Red Hat Insights: Helping to prioritize what matters the most with system vulnerabilities
Ransomware attack severs 1,000 ships from their on-shore servers

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-42852

– Update to 109.0

New sudo packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue.

Smashing Security podcast #305: Norton unlocked, and police leaks
Thousands of Sophos firewalls still vulnerable out there to hijacking

It was discovered that the CompareTool of iText, a Java PDF library which uses the external ghostscript software to compare PDFs at a pixel level, allowed command injection when parsing a specially crafted filename.

Sudo could be made to possibly edit arbitrary files if it received a specially crafted input.

Proposed Washington law puts period-tracking apps and search engines on notice
Top 10 Venmo scams – and how to stay safe

Don’t be the next victim – here’s what to know about some of the most common tricks that scammers use on the payment app The post Top 10 Venmo scams – and how to stay safe appeared first on WeLiveSecurity

Does your MFA solution secure access to your on-premise apps as well as those in the cloud?
Researchers warn of malicious Visual Studio Code extensions

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

New libXpm packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.

New httpd packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.

New git packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.

Been hit by BianLian ransomware? Here’s your get-out-of-jail-free card

Security fix for CVE-2022-46391

Security fix for CVE-2022-46391

Russian criminals can’t wait to hop over OpenAI’s fence, use ChatGPT for evil

security update

Nearly 300 MSI motherboards will run any old code in Secure Boot, no questions asked
Serious Security: Unravelling the LifeLock “hacked passwords” story
Hybrid commerce: Blurring the lines between business and pleasure

It is now acceptable to find a job on a dating app! The post Hybrid commerce: Blurring the lines between business and pleasure appeared first on WeLiveSecurity

Microsoft locks door to default guest authentication in Windows Pro

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/389-ds was updated. The following patches have been included in this update:

An update that contains security fixes can now be installed.

The container sles-15-sp4-chost-byos-v20230111-arm64 was updated. The following patches have been included in this update:

Crypto exchanges freeze accounts tied to North Korea’s notorious Lazarus Group
Tencent fired 100 people for corruption during 2022

A logic error was discovered in the implementation of the “SafeSocks” option of Tor, a connection-based low-latency anonymous communication system, which did result in allowing unsafe SOCKS4 traffic to pass.

Multi-million investment scammers busted in four-country Europol raid
Ugh! Norton LifeLock password manager accounts accessed by hackers