Menu

Monthly Archives: January 2023

Hackers disrupt 24 Hours of Le Mans Virtual esports event
Security Considerations for Azure Linux & Windows Subsystem for Linux Users
For password protection, dump LastPass for open source Bitwarden

An update for libxml2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for dpdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dpdk is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for dpdk is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dpdk is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for dpdk is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

China aims to grow local infosec industry by 30 percent a year, to $22 billion by 2025

menglong2234 discovered NULL pointer exceptions in net-snmp, a suite of Simple Network Management Protocol applications, which could could result in debian of service.

The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.

The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.

The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.

The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.

The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.

NSA asks Congress to let it get on with that warrantless data harvesting, again

security update

security update

security update

APT group trojanizes Telegram app – Week in security with Tony Anscombe

StrongPity’s backdoor is fitted with various spying features and can record phone calls, collect texts, and gather call logs and contact lists The post APT group trojanizes Telegram app – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Russians say they can grab software from Intel again

v1.5.1 – fix logging to stdout when –stdout is used *thanks to Eta – update –treshold option accept decimal numbers as parameter – fix crashes when processing certain broken JPEG images – fix memory leaks – fix (logging) output in parallel processing mode

Security fix for CVE-2022-45061: CPU denial of service via inefficient IDNA decoder

New netatalk packages are available for Slackware 14.1, 14.2, 15.0, and -current to fix a security issue.

Several security issues were fixed in the Linux kernel.

Two vulnerabilities were discovered in the LLPD implementation of Open vSwitch, software-based Ethernet virtual switch, which could result in denial of service.

Igor Ponomarev discovered that LAVA, a continuous integration system for deploying operating systems onto physical and virtual hardware for running tests, was suspectible to denial of service via recursive XML entity expansion.

Canadian owes bosses for ‘time theft’ after work-tracking app sinks tribunal bid
Introducing IPyIDA: A Python plugin for your reverse‑engineering toolkit

ESET Research announces IPyIDA 2.0, a Python plugin integrating IPython and Jupyter Notebook into IDA The post Introducing IPyIDA: A Python plugin for your reverse‑engineering toolkit appeared first on WeLiveSecurity

Microsoft Defender ASR rules remove icons and apps shortcuts from Taskbar
Call centres behind fake cryptocurrency scams shut down across Europe
Long data privacy notices aren’t foolproof, Euro watchdog tells Meta
A Brief History of Cryptography
OpenSSL: From FIPS 140-2 upstream to 140-3 downstream
This can’t be a real bomb threat: you’ve called a modem, not a phone

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Euro-cops shut down crypto scam that bilked millions from unwitting punters
Microsoft fumbles zero trust upgrade for some Asian customers

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

security update

security update

security update

Lawyers slam SEC for ‘blatant fishing expedition’ after Exchange mega-attack
S3 Ep117: The crypto crisis that wasn’t (and farewell forever to Win 7) [Audio + Text]
Now you can legally repair your tech – sort of

A new law portends a future where (we hope) it will be easier for us all to repair, fix, upgrade, and just tinker with things we already own The post Now you can legally repair your tech – sort of appeared first on WeLiveSecurity

Researchers warn AI-generated phishing attacks are becoming more convincing
Smashing Security podcast #304: Oxford’s dating disaster, cheap security robots, and faking a suicide

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for sqlite is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the postgresql:10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for systemd is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

VALL-E AI can mimic a person’s voice from a three-second snippet
US think tank says China would probably lose if it tries to invade Taiwan
Post-ransomware attack, The Guardian warns staff their personal data was accessed
Free decryptor for victims of MegaCortex ransomware released
Royal Mail, cops probe ‘cyber incident’ that’s knackered international mail
AI-generated phishing emails just got much more convincing
StrongPity espionage campaign targeting Android users

ESET researchers identified an active StrongPity campaign distributing a trojanized version of the Android Telegram app, presented as the Shagle app – a video-chat service that has no app version The post StrongPity espionage campaign targeting Android users appeared first on WeLiveSecurity

Microsoft fixes Windows database connections it broke in November
German cartel watchdog objects to the way Google processes user data

An update that fixes one vulnerability is now available.

Red Hat Insights malware detection service is now generally available

It was discovered that there were two issues in viewvc, a web-based interface for browsing Subversion and CVS repositories. The attack vectors involved files with unsafe names; names that, when embedded into an HTML stream, could cause the browser to run unwanted code.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

Swiss Army’s Threema messaging app was full of holes – at least seven

A vulnerability has been discovered in protobuf-java which could result in denial of service.

Multiple vulnerabilities have been found in Alpine, the worst of which could result in denial of service.

Health insurer Aflac blames US partner for leak of Japanese cancer policy info
Privacy on the line: Boffins break VoLTE phone security
Microsoft Patch Tuesday: One 0-day; Win 7 and 8.1 get last-ever patches
First Patch Tuesday of the year explodes with in-the-wild exploit fix

security update

security update

Russian meddling in 2016 US presidential election was weak sauce
Popular JWT cloud security library patches “remote” code execution hole
Cracked it! Highlights from KringleCon 5: Golden Rings

Learning meets fun at the 2022 SANS Holiday Hack Challenge – strap yourself in for a crackerjack ride at the North Pole as I foil Grinchum’s foul plan and recover the five golden rings The post Cracked it! Highlights from KringleCon 5: Golden Rings appeared first on WeLiveSecurity

Hybrid work: Turning business platforms into preferred social spaces

Hybrid work and hybrid play now merge into hybrid living, but where is the line between the two? Is there one? The post Hybrid work: Turning business platforms into preferred social spaces appeared first on WeLiveSecurity

California e-ink platemaker exploited to track equipped cars
Wiretap lawsuit accuses Apple of tracking iPhone users who opted out

Red Hat OpenShift Container Platform release 4.10.47 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

The container suse/registry was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

Pakistan’s government to agencies: Dark web is dangerous, please don’t go there
Homeland Security, CISA builds AI-based cybersecurity analytics sandbox
US Supremes deny Pegasus spyware maker’s immunity claim

security update

Does a hybrid model for vulnerability management make sense?
CircleCI – code-building service suffers total credential compromise

Libksba could be made to crash or run programs if it processed specially crafted data.