Menu

Monthly Archives: January 2023

Admins Receive Automated Linux Patch Management & Improved Security with ManageEngine Endpoint Central

Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in HTTP request smuggling, cache poisoning or denial of service.

No more holidays for US telcos, FCC is cracking down
Chinese researchers’ claimed quantum encryption crack looks unlikely

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container bci/bci-busybox was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Here’s how to remotely takeover a Ferrari…account, that is

The container bci/bci-micro was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Freedom for MegaCortex ransomware victims – the fix is out
RSA crypto cracked? Or perhaps not!
How to prioritize effectively with threat modeling
Ransomware target list – Week in security with Tony Anscombe

Why schools, hospitals, local governments and other public sector organizations are in a sweet spot for ransomware attacks The post Ransomware target list – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Dridex malware pops back up and turns its attention to macOS

Red Hat OpenShift Container Platform release 4.9.54 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

JP Morgan must face suit from Ray-Ban maker after crooks drained $272m from accounts

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

Rackspace blames ransomware woes on zero-day attack
Twitter data dump: 200m+ account database now free to download

It was discovered that there was a potential cross-site scripting vulnerability in smarty3, a widely-used PHP templating engine. For Debian 10 buster, this problem has been fixed in version

It was discovered that there was a potential null pointer dereference vulnerability in libetpan, an low-level library for handling email. For Debian 10 buster, this problem has been fixed in version

Several security issues were fixed in curl.

S3 Ep116: Last straw for LastPass? Is crypto doomed? [Audio + Text]
The doctor will see you now … virtually: Tips for a safe telehealth visit

Are your virtual doctor visits private and secure? Here’s what to know about, and how to prepare for, connecting with a doctor from the comfort of your home. The post The doctor will see you now … virtually: Tips for a safe telehealth visit appeared first on WeLiveSecurity

LockBit ransomware gang says sorry, gives free decryptor to SickKids hospital
Twitter whistleblower Peiter ‘Mudge’ Zatko lands new gig at Rapid7

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

New vim packages are available for Slackware 15.0 and -current to fix security issues.

Security fix for CVE-2021-4287

Security fix for CVE-2021-4287

Ex-GE engineer gets two years in prison after stealing turbine tech for China

Red Hat OpenShift Container Platform release 4.10.46 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The Guardian ransomware attack hits week two as staff told to work from home

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

An update that solves 13 vulnerabilities and has one errata is now available.

The welcoming of a new year also welcomes the return of one of the most overused sayings in our shared lexicon: “New Year, New Me!” While there are countless overused resolutions like starting a workout regimen, the new year does provide an opportunity for additional self-improvement that most people never consider – bolstering cybersecurity protections. […]

Serious Security: Vital cybersecurity lessons from the holiday season
Gaming: How much is too much for our children?

With many children spending a little too much time playing video games, learn to spot the signs things may be spinning out of control The post Gaming: How much is too much for our children? appeared first on WeLiveSecurity

Google Home smart speaker bug could have allowed hackers to spy on your conversations
Ireland fines Meta $414m for using personal data without asking
PyTorch dependency poisoned with malicious code

Red Hat OpenShift Container Platform release 4.11.21 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenShift Container Platform release 4.11.21 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

xwayland 22.1.7

LockBit: Sorry about the SickKids ransomware, not sorry about the rest
‘Multiple security breaches’ shut down trucker protest

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Data of over 200 million Deezer users stolen, leaks on hacking forum
Inside a scammers’ lair: Ukraine busts 40 in fake bank call-centre raid
The world’s most common passwords: What to do if yours is on the list

Do you use any of these extremely popular – and eminently hackable – passwords? If so, we have a New Year’s resolution for you. The post The world’s most common passwords: What to do if yours is on the list appeared first on WeLiveSecurity

LostPass: after the LastPass hack, here’s what you need to know
Google gets off easy in Indiana, DC location tracking lawsuits

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

It was discovered that node-xmldom, a standard XML DOM (Level2 CORE) implementation in pure javascript, processed ill-formed XML, which may result in bugs and security holes in downstream applications.

The w3m program is a pager (or text file viewer) that can also be used as a text-mode Web browser. W3m features include the following: when reading an HTML document, you can follow links and view images using an external image viewer; its internet message mode determines the type of document from the header; if […]

OpenImageIO is a library for reading and writing images, and a bunch of related classes, utilities, and applications. Main features include: – Extremely simple but powerful ImageInput and ImageOutput APIs for reading and writing 2D images that is format agnostic. – Format plugins for TIFF, JPEG/JFIF, OpenEXR, PNG, HDR/RGBE, Targa, JPEG-2000,

An update that contains security fixes can now be installed.

An update for bcel is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for bcel is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

PyTorch: Machine Learning toolkit pwned from Christmas to New Year