Menu

Monthly Archives: May 2023

Uber’s ex-CSO avoids prison after data breach cover up
T-Mobile US suffers second data theft within months

– digiKam-8.0.0 – enabled MediaPlayer – Security fix for CVE-2023-1729 https://www.digikam.org/news/2023-04-16-8.0.0_release_announcement/

Attestation in confidential computing

The container suse/registry was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

The container ses/7.1/rook/ceph was updated. The following patches have been included in this update:

DEF CON to set thousands of hackers loose on LLMs
APTs target MSP access to customer networks – Week in security with Tony Anscombe

The recent compromise of the networks of several companies via the abuse of a remote access tool used by MSPs exemplifies why state-aligned threat actors should be on the radars of IT service providers The post APTs target MSP access to customer networks – Week in security with Tony Anscombe appeared first on WeLiveSecurity

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

Dump these insecure phone adapters because we’re not fixing them, says Cisco

security update

A right Royal pain in the Dallas: City IT systems crippled by ransomware
PHP Packagist supply chain poisoned by hacker “looking for a job”
WordPress plugin vulnerability puts two million websites at risk

Several vulnerabilities were discovered in odoo, a suite of web based open source business apps. CVE-2021-44775, CVE-2021-26947, CVE-2021-45071, CVE-2021-26263:

The system could be made to run programs as an administrator.

Several security issues were fixed in the Linux kernel.

The guest VM system could be made to crash or expose sensitive information.

Capita admits some pension data ‘likely’ to have been accessed in March breach

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Users complain over UK state-owned bank’s services as Atos eyes the exit

The container bci/openjdk-devel was updated. The following patches have been included in this update:

China labels USA ‘Empire of hacking’ based on old Wikileaks dumps

security update

Ex-Uber CSO gets probation for covering up theft of data on millions of people
PSA. Don’t share your password in your app’s release notes

An update is now available for Red Hat Satellite 6.13. The release contains a new version of Satellite and important security fixes for various components.

Red Hat Integration Camel for Spring Boot 3.20.1 release and security update is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Using Discord? Don’t play down its privacy and security risks

It’s all fun and games until someone gets hacked – here’s what to know about, and how to avoid, threats lurking on the social media juggernaut The post Using Discord? Don’t play down its privacy and security risks appeared first on WeLiveSecurity

APT groups muddying the waters for MSPs

A quick dive into the murky world of cyberespionage and other growing threats facing managed service providers – and their customers The post APT groups muddying the waters for MSPs appeared first on WeLiveSecurity

Strike three: FTC says Meta still failing to protect user privacy
Patch now! The Mirai IoT botnet is exploiting TP-Link routers
World Password Day: 2 + 2 = 4
Confidential computing primer
Creating strong, yet user‑friendly passwords: Tips for your business password policy

Don’t torture people with exceedingly complex password composition rules but do blacklist commonly used passwords, plus other ways to help people help themselves – and your entire organization The post Creating strong, yet user‑friendly passwords: Tips for your business password policy appeared first on WeLiveSecurity

Several security issues were fixed in Ruby.

A practical guide to React Native authentication
Apple and Google join forces to combat AirTag stalking

The Migration Toolkit for Containers (MTC) 1.7.9 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Update to 1.21.1 (resolve rhbz#2182365)

Go ahead, forget that password. Use a passkey instead, says Google
Meta does the ‘We found baddies and crushed them’ thing again – this time for AI

Red Hat Advanced Cluster Management for Kubernetes 2.5.8 General Availability release images, which fix bugs and security updates container images. Red Hat Product Security has rated this update as having a security impact

Smashing Security podcast #320: City Jerks, AI animals, and is the BBC hacking again?
Tracked by hidden tags? Apple and Google unite to propose safety and security standards…
Give NotPetya-hit Merck that $1.4B, appeals court tells insurers

security update

Chrome’s HTTPS padlock heads to Google Graveyard

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service, or information leak.

Multiple vulnerabilities have been discovered in Lua, the worst of which could result in arbitrary code execution.

Fortify your Mac with Intego – the award-winning Mac antivirus

Multiple vulnerabilities have been discovered in ISC DHCP, the worst of which could result in denial of service.

A buffer overflow vulnerability has been discovered in libapreq2 which could result in denial of service.

A vulnerability has been discovered in Firejail which could result in local root privilege escalation.

Multiple vulnerabilities have been found in libsdl2, the worst of which could result in arbitrary code execution.

The importance of being certified

security update

security update

Apple pushes first-ever ‘rapid’ patch – and rapidly screws up
Mirai botnet loves exploiting your unpatched TP-Link routers, CISA warns
Apple, Google propose anti-stalking spec for Bluetooth tracker tags
288 arrested in multinational Monopoly Market takedown
In the face of data disaster

An untrusted search path vulnerability was discovered in Node.js, which could result in unexpected searching or loading ICU data when running with elevated privileges.

An update that fixes one vulnerability is now available.

This update includes the changes in tzdata 2023c for the Perl bindings. For the list of changes, see DLA-3412-1. For Debian 10 buster, this problem has been fixed in version

This update includes the changes in tzdata 2023c. Notable changes are: – – Revert Lebanon DST changes.

An update for libwebp is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libwebp is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

Protect Your Organization Against Linux Malware Attacks with Comprehensive, Automated Patch Management
Data loss costs are going up – and not just for those who choose to pay thieves
Medusa ransomware gang leaks students’ psychological reports and abuse allegations
Russia’s APT28 targets Ukraine government with bogus Windows updates
Feds rethink warrantless search stats and – oh look, a huge drop in numbers
Apple delivers first-ever Rapid Security Response “cyberattack” patch – leaves some users confused

security update

IT giant Bitmarck shuts down customer, internal systems after cyberattack
Centralized secrets management picks up pace

The system could be made to run programs as an administrator.

Several security issues were fixed in the Linux kernel.

ZenLib could be made to crash if it received specially crafted input.

Several security issues were fixed in Git.

Google adds account sync for Authenticator, without E2EE
Your security failure was so bad we have to close the company … NOT!
China has 50 hackers for every FBI cyber agent, says Bureau boss

This is a routine update of the distro-info-data database for Debian LTS users. It includes the expected release date for Debian 12, adds Debian 14,

update to 2.40.1 (CVE-2023-25652, CVE-2023-25815, CVE-2023-29007) Refer to the release notes for 2.30.9 for details of each CVE as well as the following security advisories from the git project: https://github.com/git/git/security/advisories/GHSA-2hvf-7c8p-28fx (CVE-2023-25652)