Menu

Monthly Archives: April 2023

update to 112.0.5615.121. Fixes the following security issues: CVE-2023-2004 CVE-2023-2133 CVE-2023-2134 CVE-2023-2135 CVE-2023-2136 CVE-2023-2137 CVE-2023-2033

Update to 4b3d078 (dr_wav 0.13.8): fix a possible null-pointer dereference and a crash when loading files with badly-formed metadata.

S3 Ep131: Can you really have fun with FORTRAN?
The EU’s Cyber Solidarity Act: Security Operations Centers to the rescue!

The legislation aims to bolster the Union’s cyber-resilience and enhance its capabilities to prepare for, detect and respond to incidents The post The EU’s Cyber Solidarity Act: Security Operations Centers to the rescue! appeared first on WeLiveSecurity

PC running slow? 10 ways you can speed it up

Before you rush to buy new hardware, try these simple tricks to get your machine up to speed again – and keep it that way. The post PC running slow? 10 ways you can speed it up appeared first on WeLiveSecurity

US charges three men with six million dollar business email compromise plot
LockBit ransomware for Mac – coming soon?

Dnsmasq could cause transmission reliability issues when sending large DNS messages.

Capita has ‘evidence’ customer data was stolen in digital burglary
An earlier supply chain attack led to the 3CX supply chain attack, Mandiant says
Ex-CEO of hacked therapy clinic sentenced for failing to protect patients’ session notes
FTC accuses payments firm of knowingly assisting tech support scammers

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

Designing user management for machine-to-machine interactions
AI defenders ready to foil AI-armed attackers
Protect the Industrial Control Systems (ICS)
Medusa ransomware crew brags about spreading Bing, Cortana source code
Smashing Security podcast #318: Tesla workers spy on drivers, and Operation Fox Hunt scams
Appeals court spares Google from $20m patent payout over Chrome
Spyware slinger QuaDream’s reported demise may be the canary in the coal mine
Discarded, not destroyed: Old routers reveal corporate secrets

When decommissioning their old hardware, many companies ‘throw the baby out with the bathwater’ The post Discarded, not destroyed: Old routers reveal corporate secrets appeared first on WeLiveSecurity

GitHub debuts pedigree check for npm packages via Actions

Several security issues were fixed in Vim.

The State of Kubernetes Security in 2023
Prioritize what matters most

The container bci/nodejs was updated. The following patches have been included in this update:

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Avoid possible self-DoS attack Resolves: CVE-2023-25136

Update to the latest 1.0.16: * Lots of updates, enhancements and fixes from 1.0.4 * CVEs: CVE-2020-27827, CVE-2021-43612

US citizens charged with pushing pro-Kremlin disinfo, election interference
Russian snoops just love invading unpatched Cisco gear, America and UK warn
Microsoft opens up Defender threat intel library with file hash, URL search
Payments firm accused of aiding ‘contact Microsoft about a virus’ scammers must cough $650k
Ex-CEO of breached pyschotherapy clinic gets prison sentence for bad data security
Army helicopter crash blamed on skipped software patch
Brit cops rapped over app that recorded 200k phone calls

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Wrong time to weaken encryption, UK IT chartered institute tells government
Several Distros Release Important Advisories for Actively Exploited Linux Kernel Use After Free Vuln
Capita IT breach gets worse as Black Basta claims it’s now selling off stolen data
US alleges China created troll army that tried to have dissidents booted from Zoom
Military helicopter crash blamed on failure to apply software patch
LockBit crew cooks up half-baked Mac ransomware

security update

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code. For the stable distribution (bullseye), this problem has been fixed in

FBI and FCC warn about “Juicejacking” – but just how useful is their advice?

Two ruby-rack issues have been addressed: CVE-2023-27530

Marketing biz sent 107 million spam emails… to just 437k people

LibreOffice could be made to run arbitrary code if an empty entry to the java class path is configured.

Several security issues were fixed in ImageMagick.

Deploying confidential containers on the public cloud
Firmware is on shaky ground – let’s see what it’s made of
Student requested access to research data. And waited. And waited. And then hacked to get root

config file permission change to increase security of polkitd

Update now: Google emits emergency fix for zero-day Chrome vulnerability

Update to ldb 2.5.3 and samba 4.16.10 Security fixes for CVE-2023-0922, CVE-2023-0614

Update to ldb 2.5.3 and samba 4.16.10 Security fixes for CVE-2023-0922, CVE-2023-0614

security update

Fullscreen notification obscured. (CVE-2023-29533) Double-free in libwebp. (MFSA-TMP-2023-0001) Potential Memory Corruption following Garbage Collector compaction. (CVE-2023-29535) Invalid free from JavaScript code. (CVE-2023-29536)

Updated firefox and libwebp packages fix security vulnerabilities: Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash (CVE-2023-1945).

DOS due to incorrect HTTP and MIME header parsing (CVE-2023-24534) DOS due to incorrect Multipart form parsing (CVE-2023-24536) Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow. (CVE-2023-24537)

Vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call. (CVE-2023-0996)

Hunting down BlackLotus – Week in security with Tony Anscombe

Microsoft releases guidance on how organizations can check their systems for the presence of BlackLotus, a powerful threat first analyzed by ESET researchers The post Hunting down BlackLotus – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Safety first: 5 cybersecurity tips for freelance bloggers

The much-dreaded writer’s block isn’t the only threat that may derail your progress. Are you doing enough to keep your blog (and your livelihood) safe from online dangers? The post Safety first: 5 cybersecurity tips for freelance bloggers appeared first on WeLiveSecurity

Learn about Confidential Containers

An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Russia-pushed UN Cybercrime Treaty may rewrite global law. It’s … not great
US extradites Nigerian charged in $6m email fraud scam

security update

security update

Compatibility mess breaks not one but two Windows password tools
As Tax Day approaches, Microsoft warns accounting firms of targeted attacks

Several security issues were fixed in the Linux kernel.

While Twitter wants to sell its verification, Microsoft will do it for free on LinkedIn

The container suse/sles/15.5/cdi-importer was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

Linux kernel logic allowed Spectre attack on ‘major cloud provider’
To improve security, consider how the aviation world stopped blaming pilots
Pentagon leak suspect Jack Teixeira arrested at gunpoint

security update

security update

Pentagon super-leak suspect cuffed: 21-year-old Air National Guardsman