Menu

Monthly Archives: April 2023

The future of Red Hat security data

An issue has been found in sniproxy, a transparent TLS and HTTP layer 4 proxy with SNI support. Due to bad handling of wildcard backend hosts, a crafted HTTP or TLS

Several vulnerabilities were discovered in libxml2, a library providing support to read, modify and write XML and HTML files.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Mac malware-for-hire steals passwords and cryptocoins, sends “crime logs” via Telegram
What was hot at RSA Conference 2023? – Week in security with Tony Anscombe

The importance of understanding – and prioritizing – the privacy and security implications of large language models like ChatGPT cannot be overstated The post What was hot at RSA Conference 2023? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

The container bci/bci-init was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container bci/php-fpm was updated. The following patches have been included in this update:

Google wins court order to force ISPs to filter botnet traffic
Minecraft clones stealthily load ads on millions of Android devices
Online Safety Bill age checks? We won’t do ’em, says Wikipedia

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container caasp/v4/helm-tiller was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

“Ashamed” LockBit ransomware gang apologises to hacked school, offers free decryption tool
Google sues CryptBot slingers, gets court order to shut down malware domains
Microsoft is busy rewriting core Windows code in memory-safe Rust
RSA Conference 2023 – How AI will infiltrate the world

As all things (wrongly called) AI take the world’s biggest security event by storm, we round up of some of their most-touted use cases and applications The post RSA Conference 2023 – How AI will infiltrate the world appeared first on WeLiveSecurity

S3 Ep132: Proof-of-concept lets anyone hack at will
Israel’s Prime Minister has his Facebook account hijacked, website knocked offline
Charming Kitten targets critical infrastructure in US and elsewhere with BellaCiao malware

The container bci/python was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

Smashing Security podcast #319: The CEO who also ran IT, Strava strife, and TikTok tall tales
Microsoft probes complaints of Edge leaking URLs to Bing
DoJ, Treasury accuses 3 men of laundering crypto for North Korea
Google leaking 2FA secrets – researchers advise against new “account sync” feature for now
Pro-Russia hackers attack European air traffic control website, but don’t panic! Flights continue as normal

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.11.7 on Red Hat Enterprise Linux 8 from Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact

Logging Subsystem 5.6.5 – Red Hat OpenShift Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Evasive Panda APT group delivers malware via updates for popular Chinese software

ESET Research uncovers a campaign by the APT group known as Evasive Panda targeting an international NGO in China with malware delivered through updates of popular Chinese software The post Evasive Panda APT group delivers malware via updates for popular Chinese software appeared first on WeLiveSecurity

The good, the bad and the generative AI

The container suse/pcp was updated. The following patches have been included in this update:

Red Hat OpenShift Container Platform release 4.10.58 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

USN-6010-2 caused some minor regressions in Firefox.

update to 112.0.5615.165. Fixes the following security issues: CVE-2023-2004 CVE-2023-2133 CVE-2023-2134 CVE-2023-2135 CVE-2023-2136 CVE-2023-2137 CVE-2023-2033 CVE-2023-2136

Apache Superset: A story of insecure default keys, thousands of vulnerable systems, few paying attention
Menaced by miscreants, critical infrastructure needs a good ETHOS. Ah, here’s one
How fiends abuse an out-of-date Microsoft Windows driver to infect victims
PaperCut security vulnerabilities under active attack – vendor urges customers to patch

Several security issues were fixed in the Linux kernel.

An update is now available for OpenJDK. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for OpenJDK. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for pcs is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

How To Secure Against WordPress Vulnerabilities with Predictive Analysis Detection & Automated Remediation
Double zero-day in Chrome and Edge – check your versions now!

An update that fixes 5 vulnerabilities is now available.

If you haven’t patched Microsoft Process Explorer, prepare to be pwned

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version

An update for emacs is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for emacs is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Multiple security issues were discovered in 389-ds-base: an open source LDAP server for Linux. CVE-2019-3883

That 3CX supply chain attack keeps getting worse: More victims found
Chinese scientists calculate the Milky Way’s mass as 805 billion times that of our Sun

Authenticated users can use the HINCRBYFLOAT command to create an invalid hash field that will crash Redis on access. (CVE-2023-28856) References: – https://bugs.mageia.org/show_bug.cgi?id=31809

security update

security update

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

Backport fix for CVE-2023-1972.

ceph 16.2.12 GA Security fix for CVE-2022-3650

Disable stringop-overflow warnings. Patch “bfd-CVE-2023-1972” fixes a security issue in bfd library.

Update to 4.10 for CVE-2023-23009

Did you mistakenly sell your network access? – Week in security with Tony Anscombe

Many routers that are offered for resale contain sensitive corporate information and allow third-party connections to corporate networks The post Did you mistakenly sell your network access? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Linux malware strengthens links between Lazarus and the 3CX supply‑chain attack

Similarities with newly discovered Linux malware used in Operation DreamJob corroborate the theory that the infamous North Korea-aligned group is behind the 3CX supply-chain attack The post Linux malware strengthens links between Lazarus and the 3CX supply‑chain attack appeared first on WeLiveSecurity

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.12.2 on Red Hat Enterprise Linux 8 from Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact

European air traffic control confirms website ‘under attack’ by pro-Russia hackers

The container bci/dotnet-aspnet was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

The container rancher/elemental-operator/5.3 was updated. The following patches have been included in this update:

The container rancher/elemental-teal/5.3 was updated. The following patches have been included in this update:

Microsoft pushes for more women in cybersecurity

security update

VMware patches break-and-enter hole in logging tools: update now!
US Facebook users can now claim their share of $725 million Cambridge Analytica settlement
MacStealer – newly-discovered malware steals passwords and exfiltrates data from infected Macs
International cops urge Meta not to implement secure encryption for all
Healthcare organisations urged to improve system security

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The container suse/postgres was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container suse/registry was updated. The following patches have been included in this update:

Thanks for fixing the computer lab. Now tell us why we shouldn’t expel you?