Menu

Monthly Archives: April 2023

What are the cybersecurity concerns of SMBs by sector?

Some sectors have high confidence in their in-house cybersecurity expertise, while others prefer to enlist the support of an external provider to keep their systems and data secured The post What are the cybersecurity concerns of SMBs by sector? appeared first on WeLiveSecurity

S3 Ep130: Open the garage bay doors, HAL [Audio + Text]

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Demystifying risk using CVEs and CVSS
DISA releases the first Ansible STIG

An update for openvswitch3.1 is now available in Fast Datapath for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openvswitch3.1 is now available in Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openvswitch2.17 is now available in Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openvswitch2.17 is now available in Fast Datapath for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

How insecure is America’s FirstNet emergency response system? No one’s sure
Smashing Security podcast #317: Another Uber SNAFU, an AI chatbot quiz, and is juice-jacking genuine?
FBI: How fake Xi cops prey on Chinese nationals in the US
Remotely Exploitable Chromium DoS, Info Disclosure Vulns Fixed
Google launches dependency API and curated package repository with security metadata
10 things to look out for when buying a password manager

Here’s how to choose the right password vault for you and what exactly to consider when weighing your options The post 10 things to look out for when buying a password manager appeared first on WeLiveSecurity

Plenty of juice-jacking scare stories, but precious little juice-jacking

Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially allowing User Enumeration, Cross-Site-Scripting or Cross-Site Request Forgery.

Microsoft fixes a zero-day – and two curious bugs that take the Secure out of Secure Boot
OpenAI starts bug bounty program with cash rewards up to $20,000
Mission possible

Several security issues were fixed in Json-smart.

Several security issues were fixed in Firefox.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

3CX teases security-focused client update, plus password hashing
US cyber chiefs warn AI will help crooks, China develop nastier cyberattacks faster

Important: httpd and mod_http2 security update

Another zero-click Apple spyware maker just popped up on the radar again
April Patch Tuesday: Ransomware gangs already exploiting this Windows bug

security update

Attention gamers! Motherboard maker MSI admits to breach, issues “rogue firmware” alert

An update that contains security fixes can now be installed.

An update that fixes 12 vulnerabilities is now available.

Azure admins warned to disable shared key access as backdoor attack detailed

The container sles-15-sp4-chost-byos-v20230410-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230410-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230410-x86_64-gen2 was updated. The following patches have been included in this update:

Beyond Firewalls: What Else Is Required to Secure a Linux System?
GitGuardian’s honeytokens in codebase to fish out DevOps intrusion

Red Hat OpenShift Container Platform release 4.12.11 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

40% of IT security pros say they’ve been told not to report a data leak
3 overlooked cloud security attack vectors
How much to infect Android phones via Google Play store? How about $20k
Inside FTX: Jokes about misplaced funds, diabolical IT, poor oversight, and worse
Apple squashes iOS, macOS zero-day bugs already exploited by snoops
Apple zero-day spyware patches extended to cover older Macs, iPhones and iPads
Google to kill Dropcam, Nest Secure hardware next year
Microsoft, Fortra are this fed up with cyber-gangs abusing Cobalt Strike
When it comes to technology, securing your future means securing your present

Irssi could be made to crash in specific scenarios.

A regression was reported that the fix for CVE-2021-3802 broken mounting allow-listed mount option/value pairs, for example errors=remount-ro. For Debian 10 buster, this problem has been fixed in version

Multiple security vulnerabilities have been discovered in OpenImageIO, a library for reading and writing images. Buffer overflows and out-of-bounds read and write programming errors may lead to a denial of service (application crash) or the execution of arbitrary code if a malformed image

update to 112.0.5615.49. Fixes the following security issues: CVE-2023-1528 CVE-2023-1529 CVE-2023-1530 CVE-2023-1531 CVE-2023-1532 CVE-2023-1533 CVE-2023-1534

https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/message/6UQBHI5FWLATD7QO7DI4YS54U7XSSLAN/

Update to 2.53.16 Langpacks are now provided in the modern form of web extensions. This may take a bit longer at startup if all languages are enabled at the same time. To avoid this, just disable unneeded languages by Add-ons Manager. (Note, langpacks are related to the language of the application menus etc., and are […]

– fix SSH connection too eager reuse still (CVE-2023-27538) – fix GSS delegation too eager connection re-use (CVE-2023-27536) – fix FTP too eager connection reuse (CVE-2023-27535) – fix SFTP path ~ resolving discrepancy (CVE-2023-27534) – fix TELNET option IAC injection (CVE-2023-27533)

Popular server-side JavaScript security sandbox “vm2” patches remote execution hole

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

An update for httpd and mod_http2 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for tigervnc is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

The 6.2.9 stable kernel update contains a number of important fixes across the tree.

Apple issues emergency patches for spyware-style 0-day exploits – update now!
MSI hit in cyberattack, warns against installing knock-off firmware

Stefan Walter found that udisks2, a service to access and manipulate storage devices, could cause denial of service via system crash if a corrupted or specially crafted ext2/3/4 device or image was mounted, which could happen automatically on certain environments.

Welcome to open source, Elon. Your Twitter code just got a CVE for shadow ban bug
It’s this easy to seize control of someone’s Nexx ‘smart’ home plugs, garage doors
With ICMP magic, you can snoop on vulnerable HiSilicon, Qualcomm-powered Wi-Fi

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal. (CVE-2023-28371) References: – https://bugs.mageia.org/show_bug.cgi?id=31742

Buffer overrun in util.c (CVE-2022-4899) References: – https://bugs.mageia.org/show_bug.cgi?id=31740 – https://lists.suse.com/pipermail/sle-security-updates/2023-March/014246.html

security update

security update

security update

Ukrainian hackers spend $25,000 of pro-Russian blogger’s money on sex toys
A fireside chat with four CISOs about how they secure their cybersecurity firms from attack
Own a Nexx “smart” alarm or garage door opener? Get rid of it, or regret it
S3 Ep129: When spyware arrives from someone you trust
Steer clear of tax scams – Week in security with Tony Anscombe

In a rush to file your taxes? Watch out for cybercriminals preying on stressed taxpayers as Tax Day looms large on the horizon. The post Steer clear of tax scams – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Russia has a stash of scary malware? We’re shocked

It was discovered that there was a potential path-traversal vulnerability in GruntJS, a multipurpose task runner and build system tool. This could have been exploited via malicious symlinks.

Red Hat OpenShift sandboxed containers for debugging with elevated privileges
Eight Distros Release Important Advisories for Actively Exploited Linux Kernel Use After Free Vuln

Red Hat OpenShift Container Platform release 4.9.59 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

CAN do attitude: How thieves steal cars using network bus
Cleaning up your social media and passwords: What to trash and what to treasure

Give your social media presence a good spring scrubbing, audit your passwords and other easy ways to bring order to your digital chaos The post Cleaning up your social media and passwords: What to trash and what to treasure appeared first on WeLiveSecurity

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

Criminal records office yanks web portal offline amid ‘cyber security incident’
Cops cuff teenage ‘Robin Hood hacker’ suspected of peddling stolen info
Smashing Security podcast #316: Of Musk and Afroman
Cops put the squeeze on Genesis crime souk denizens, not just the admins this time
US government warning! What if anyone could open your garage door?

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: