Menu

Monthly Archives: May 2023

Extra! Extra! Don’t quite read all about it: Cyber attack hits Philadelphia Inquirer

security update

Some potential: How bad software updates could over-volt, brick remote servers
Zut alors! Raclage crapuleux! Clearview AI in 20% more trouble in France
No more macros? No problem, say miscreants, we’ll adapt

Several security issues were fixed in Thunderbird.

Two security issues were found in PostgreSQL, which may result in privilege escalation or incorrect policy enforcement. For Debian 10 buster, these problems have been fixed in version

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version

Sigstore: Roots of trust for software artifacts
An important system on project [REDACTED] was all [REDACTED] up
Ransomware corrupts data, so backups can be faster and cheaper than paying up
Arm acknowledges side-channel attack but denies Cortex-M is crocked

Several security issues were fixed in Firefox.

Toyota’s bungling of customer privacy is becoming a pattern

Patch CVE-2023-27783 – CVE-2023-27789 – CVE-2023-27783 – CVE-2023-27784 – CVE-2023-27785 – CVE-2023-27786 – CVE-2023-27787 – CVE-2023-27788 – CVE-2023-27789

Patch CVE-2023-27783 – CVE-2023-27789 – CVE-2023-27783 – CVE-2023-27784 – CVE-2023-27785 – CVE-2023-27786 – CVE-2023-27787 – CVE-2023-27788 – CVE-2023-27789

security update

The 6.2.15 stable kernel update contains a number of important fixes across the tree.

Update to 102.11.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2023-18/ ; https://www.thunderbird.net/en- US/thunderbird/102.11.0/releasenotes/

The 6.2.15 stable kernel update contains a number of important fixes across the tree.

Update to 0.10.5 (CVE-2023-1667 CVE-2023-2283)

The 6.2.15 stable kernel update contains a number of important fixes across the tree.

An integer overflow vulnerability exists in golang-websocket, a Go package implementing the WebSocket protocol connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.

security update

Key findings from ESET’s new APT Activity Report – Week in security with Tony Anscombe

What have some of the world’s most infamous advanced threat actors been up to and what might be the implications of their activities for your business? The post Key findings from ESET’s new APT Activity Report – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Why you need parental control software – and 5 features to look for

Strike a balance between making the internet a safer place for your children and giving them the freedom to explore, learn and socialize The post Why you need parental control software – and 5 features to look for appeared first on WeLiveSecurity

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

‘Top three Balkans drug kingpins’ arrested after cops crack their Sky ECC chats

The container bci/python was updated. The following patches have been included in this update:

– Updated to latest upstream (113.0)

Update to 4.11 for CVE-2023-30570

Update to 4.11 for CVE-2023-30570

Update to 4.11 for CVE-2023-30570

Why Microsoft just patched a patch that squashed an under-attack Outlook bug
Ex-Ubiquiti dev jailed for 6 years after stealing internal corp data, extorting bosses
Britain’s largest private pension scheme reveals scale of Capita break-in
Whodunnit? Cybercrook gets 6 years for ransoming his own employer
Atomic malware steals Mac passwords, crypto wallets, and more

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container rancher/seedimage-builder/5.3 was updated. The following patches have been included in this update:

The container rancher/elemental-operator/5.3 was updated. The following patches have been included in this update:

Six years prison for ex-Ubiquiti staffer who stole data and attempted to extort millions of dollars
Activists gatecrash Capita’s AGM to protest GPS tracking contract
UK cops score legal win in EncroChat snooping op
India to send official whassup to WhatsApp after massive spamstorm
Let white-hat hackers stick a probe in those voting machines, say senators

security update

Millions of mobile phones come pre-infected with malware, say researchers
Turning on stealth mode: 5 simple strategies for staying under the radar online

Have your cake and eat it too – enjoy some of what the online world has to offer without always giving out your contact details The post Turning on stealth mode: 5 simple strategies for staying under the radar online appeared first on WeLiveSecurity

S3 Ep134: It’s a PRIVATE key – the hint is in the name!
Akira ransomware – what you need to know
ENISA leans into EU-based clouds with draft cybersecurity label

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container sles-15-sp4-chost-byos-v20230510-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230510-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230510-x86_64-gen2 was updated. The following patches have been included in this update:

Smashing Security podcast #321: Eurovision, acts of war, and Twitter circles
Sonatype axes 14 percent of staff, reminds them not to talk to the press
Twitter adds new DM features, and Musk says E2EE is here, starting today
ESET APT Activity Report Q4 2022­–Q1 2023

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2022 and Q1 2023 The post ESET APT Activity Report Q4 2022­–Q1 2023 appeared first on WeLiveSecurity

How the war in Ukraine has been a catalyst in private‑public collaborations

As the war shows no signs of ending and cyber-activity by states and criminal groups remains high, conversations around the cyber-resilience of critical infrastructure have never been more vital The post How the war in Ukraine has been a catalyst in private‑public collaborations appeared first on WeLiveSecurity

What should protection for your 365 data really look like?

SQL parse could be made to denial of service if it received a specially crafted regular expression.

Open vSwitch could be made to stop forwarding packets if it received specially crafted network traffic.

Several security issues were fixed in OpenStack Neutron.

OpenStack Heat could be made to expose sensitive information.

23-year-old Brit linked to 2020 Twitter attack and SIM-swap scheme pleads guilty

Several security issues were fixed in css-what.

New Red Hat Single Sign-On 7.6.3 packages are now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Bootkit zero-day fix – is this Microsoft’s most cautious patch ever?
Capita looking at a bill of £20M over breach clean-up costs
Japan’s ubiquitous convenience stores now serving up privacy breaches
Two Microsoft Windows bugs under attack, one in Secure Boot with a manual fix
FBI-led Op Medusa slays NATO-bothering Russian military malware network
Microsoft disarms push notification bombers with number matching in Authenticator
Low-level motherboard security keys leaked in MSI breach, claim researchers
EU proposes spyware Tech Lab to keep Big Brother governments in check

An update for openssh is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for mysql is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for krb5 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for curl is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for pcs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for lua is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Why Cloud Linux Is Beneficial for E-Commerce Stores
Beijing raids consultancy, State-sponsored media warns more to come
FYI: Intel BootGuard OEM private keys leak from MSI cyber heist
Western Digital: Customer info stolen in that IT attack
WordPress plugin hole puts ‘2 million websites’ at risk
Twitter admits ‘security incident’ made private Circles not so much
Modern Auth comes to on-prem Exchange Server gear

Several security issues were fixed in WebKitGTK.

Several security issues were fixed in MySQL.

Erlang could allow unintended access to network services.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update: