Menu

Monthly Archives: February 2023

US cybersecurity chief: Software makers shouldn’t lawyer their way out of security responsibilities
Dish: Someone snatched our data, if you’re wondering why our IT systems went down

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Container Platform release 4.11.29 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for vim is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for httpd is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for git is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kubeflow, dashboard, deployer is now available for Red Hat OpenShift Data Science 1.22. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

News Corp outfoxed by IT intruders for years
Russian hacktivists DDoS hospitals, with pathetic results
US Marshals Service leaks ‘law enforcement sensitive information’ in ransomware incident
LastPass: Keylogger on home PC led to cracked corporate password vault
Feeling VEXed by software supply chain security? You’re not alone
Dish multi-day outage rolls on as ransomware fears grow

security update

security update

security update

security update

Beware rogue 2FA apps in App Store and Google Play – don’t get hacked!
Dutch police arrest three cyberextortion suspects who allegedly earned millions
“Ethical hacker” amongst those arrested in Dutch ransomware investigation
China makes it even harder for data to leave its shores

Several security issues were fixed in ZoneMinder.

How to Build an Encryption Strategy to Protect Your Online Identity
Russian charged with smuggling US counterintel tech to Motherland

Several security issues were fixed in ClamAV.

It was discovered that there was a regression in the previous fix for python-cryptography, a Python library offering a number of encryption and cryptography primitives.

Several security issues were fixed in Intel Microcode.

An update for service-binding-operator-bundle-container and service-binding-operator-container is now available for OpenShift Developer Tools and Services for OCP 4.9. Red Hat Product Security has rated this update as having a security impact

APR could possibly be made to crash or run programs if it received specially crafted network traffic.

The cloud’s worst kept secret? Vulnerabilities
Microsoft: For better security, scan more Exchange server objects

Vulnerabilities have been found in Node.js, which could result in DNS rebinding or arbitrary code execution. CVE-2022-43548

One year on, how is the war playing out in cyberspace? – Week in security with Tony Anscombe

With the conflict in Ukraine passing the one-year mark, have its cyber-war elements turned out as expected? The post One year on, how is the war playing out in cyberspace? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

A year of wiper attacks in Ukraine

ESET Research has compiled a timeline of cyberattacks that used wiper malware and have occurred since Russia’s invasion of Ukraine in 2022 The post A year of wiper attacks in Ukraine appeared first on WeLiveSecurity

Triggering arbitrary code execution was possible due to .desktop files registered as application/x-ms-dos-executable MIME handlers in the open source .NET framework Mono.

‘Ethical hacker’ among ransomware suspects cuffed by Dutch cops

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

Security fix for CVE-2023-0778 —- remove quadlet package specification completely —- bump to v4.4.0

Security fix for CVE-2023-0056, CVE-2023-25725

Telus source code, staff info for sale on dark web forum
Bitcoin mining rig found stashed in school crawlspace
Google destroyed evidence for antitrust battle, Feds complain

security update

security update

security update

security update

WinorDLL64: A backdoor from the vast Lazarus arsenal?

The targeted region, and overlap in behavior and code, suggest the tool is used by the infamous North Korea-aligned APT group The post WinorDLL64: A backdoor from the vast Lazarus arsenal? appeared first on WeLiveSecurity

An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.

HTTP multi-header compression denial of service has been fixed in curl, a command line tool and library for transferring data with URLs. For Debian 10 buster, this problem has been fixed in version

Several flaws were found in tiffcrop, a program distributed by tiff, the Tag Image File Format (TIFF) library and tools. A specially crafted tiff file can lead to an out-of-bounds write or read resulting in a denial of service.

European Commission bans TikTok from staff gadgets
Microsoft grows automated assault disruption to cover BEC, ransomware campaigns
Ukraine invasion blew up Russian cybercrime alliances

Fix a possible DOS involving the Qt SQL ODBC driver plugin.

Suspected Russian NLBrute malware boss extradited to US

Xi Lu discovered that missing input sanitising in Emacs (in etags, the Ruby mode and htmlfontify) could result in the execution of arbitrary shell commands.

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Dole production plants crippled by ransomware, stores run short

security update

FTX fiasco founder SBF faces further fraud charges
At least one open source vulnerability found in 84% of code bases: Report
Sensitive DoD emails exposed by unsecured Azure server
S3 Ep123: Crypto company compromise kerfuffle [Audio + Text]
That ticking noise is your end users’ laptops
Writing like a boss with ChatGPT and how to get better at spotting phishing scams

It’s never been easier to write a convincing message that can trick you into handing over your money or personal data The post Writing like a boss with ChatGPT and how to get better at spotting phishing scams appeared first on WeLiveSecurity

Fake ChatGPT apps spread Windows and Android malware
Food giant Dole hit by ransomware, halts North American production temporarily
Security by design: Security principles and threat modeling

Several security issues were fixed in DCMTK.

Multiple security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. Buffer overflows and other programming errors could be exploited for launching a denial of service attack or the execution of arbitrary code.

A new MariaDB minor maintenance release 10.3.38 has been released. It includes fix for a major performance/memory consumption issue (MDEV-29988). For further details, see the MariaDB 10.3 release notes:

Brief introduction CVE-2023-22490

Russian authorities claim Ukraine hackers are behind fake missile strike alerts

Red Hat OpenShift Container Platform release 4.9.56 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.9.

Red Hat OpenShift Container Platform release 4.9.56 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.9.

Datacenters in China, Singapore cracked by crims who then targeted tenants
Lawyers join forces to fight common enemy: The SEC and its probes into cyber-victims
Smashing Security podcast #310: Verified blue ticks and horny AI chatbots
Hackers blamed after Russian radio stations play warnings of missile strikes and air raids
NPM JavaScript packages abused to create scambait links in bulk
ESET SMB Digital Security Sentiment Report: The damaging effects of a breach

SMBs need to not only reduce their odds of being hit by an attack, but also implement processes that they can follow if their defenses are breached The post ESET SMB Digital Security Sentiment Report: The damaging effects of a breach appeared first on WeLiveSecurity

Open source software has its perks, but supply chain risks can’t be ignored
HardBit ransomware tells corporate victims to share their cyber insurance details

* Fix large memory allocation when uploading content. * Fix scrolling after a history navigation with PSON enabled. * Always update the active uri of WebKitFrame. * Fix several crashes and rendering issues. * Security fixes: CVE-2023-23529 —- * Improve GStreamer multimedia playback across the board with improved codec selection logic, better handling of latency, […]

Update to upstream 1.1.6

Update to 2.39.2 (CVE-2023-22490, CVE-2023-23946) Refer to the [upstream release notes](https://github.com/git/git/raw/v2.39.2/Documentation/RelNotes/2.30.8.txt) and the security advisories ([CVE-2023-22490](https://github.com/git/git/security/advisories/GHSA-

Rebase to upstream version 3.0.8 Resolves: CVE-2022-4203 Resolves: CVE-2022-4304 Resolves: CVE-2022-4450 Resolves: CVE-2023-0215 Resolves: CVE-2023-0216 Resolves: CVE-2023-0217 Resolves: CVE-2023-0286 Resolves: CVE-2023-0401

CVE-2023-0494: potential use-after-free in DeepCopyPointerClasses

xwayland 22.1.8 – Security fix for CVE-2023-0494

Global threats fuel cyber defence training
Coinbase breached by social engineers, employee data stolen
Will ChatGPT start writing killer malware?

AI-pocalypse soon? As stunning as ChatGPT’s output can be, should we also expect the chatbot to spit out sophisticated malware? The post Will ChatGPT start writing killer malware? appeared first on WeLiveSecurity

An update for tar is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. An update for redhat-release-virtualization-host,

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for the php:8.0 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which