Menu

Monthly Archives: July 2023

An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the nodejs:16 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the nodejs:16 module is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

ESET Research Podcast: Finding the mythical BlackLotus bootkit

A story of how analysis of a supposed game cheat turned into the discovery of a powerful UEFI threat The post ESET Research Podcast: Finding the mythical BlackLotus bootkit appeared first on WeLiveSecurity

Miscreants exploit five Microsoft bugs as Windows giant addresses 130 flaws
Apple silently pulls its latest zero-day update – what now?

A Client Authentication Bypass vulnerability has been discovered in the concurrent, real-time, distributed functional language Erlang. Impacted are those who are running an ssl/tls/dtls server using the ssl application either directly or indirectly via other applications. Note that the

Linux VPN Myths Exposed: Separating Fact from Fiction for Enhanced Online Security

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.

Several security issues were fixed in dwarves.

Barts NHS hack leaves folks on tenterhooks over extortion
Urgent! Apple fixes critical zero-day hole in iPhones, iPads and Macs
Serious Security: Rowhammer returns to gaslight your computer

security update

An update for the python39:3.9 and python39-devel:3.9 modules is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.

Liberté, Égalité, Spyware: France okays cops snooping on phones

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the oldstable distribution (bullseye), this problem has been fixed

A potential Cross Site Scripting (XSS) vulnerablity (CVE-2022-36180) and session handling vulnerability (CVE-2022-36179 )have been found in fusiondirectory, a Web Based LDAP Administration Program.

The source package ocsinventory-server, a Hardware and software inventory tool has been updated to address the API change in php-cas due to CVE-2022-39369, see DLA 3485-1 for details.

A vulnerability has been found in phpCAS, a Central Authentication Service client library in php, which may allow an attacker to gain access to a victim’s account on a vulnerable CASified service without victim’s knowledge, when the victim visits attacker’s website while

Update to 2023.07.06. Mitigates CVE-2023-35934 / GHSA-v8mc-9377-rwjj

Security fix for CVE-2023-31484 CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. CPAN 2.35 – Add verify_SSL=>1 to HTTP::Tiny to verify https server identity

Security fix for CVE-2023-31484 CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. CPAN 2.35 – Add verify_SSL=>1 to HTTP::Tiny to verify https server identity

security update

security update

Emotet: sold or on vacation? – Week in security with Tony Anscombe

Originally a banking trojan, Emotet later evolved into a full-blown botnet and went on to become one of the most dangerous cyberthreats worldwide The post Emotet: sold or on vacation? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

The container sles-15-sp5-chost-byos-v20230704-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp5-chost-byos-v20230704-x86_64-gen2 was updated. The following patches have been included in this update:

The container sles-15-sp4-chost-byos-v20230704-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230704-x86_64-gen2 was updated. The following patches have been included in this update:

Low: open-vm-tools security update

Critical: go-toolset and golang security update

It was discovered that the Nullsoft Scriptable Install System (NSIS) before version 3.09 mishandles access control for the uninstaller directory.

Capita staffers told attackers stole data from its own pension fund

Gerbv could be made to crash or run programs as your login if it opened a specially crafted file.

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2023-32439

debian-archive-keyring is a package containing GnuPG archive keys of the Debian archive. New GPG-keys are being constantly added with every new Debian release. For Debian 10 buster, GPG-keys for 12/bullseye Debian release are added

Details not available at this time. (CVE-2022-48503) Memory corruption issue may lead to arbitrary code execution (CVE-2023-32435) Type confusion issue may lead to arbitrary code execution (CVE-2023-32439)

Denial of service due to integer overflow (CVE-2022-28041) References: – https://bugs.mageia.org/show_bug.cgi?id=32055 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/SEQGDVH43YW7AG7TRU2CTU5TMIYP27WP/

Nickelodeon probes claims of massive data leak as SpongeBob fans rejoice
Microsoft puts out Outlook fire, says everything’s fine with Teams malware flaw

security update

security update

S3 Ep142: Putting the X in X-Ops
Free Akira ransomware decryptor released for victims who wish to recover their data without paying extortionists
What’s up with Emotet?

A brief summary of what happened with Emotet since its comeback in November 2021 The post What’s up with Emotet? appeared first on WeLiveSecurity

The rising risk of eavesdropping

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

Red Hat OpenShift Container Platform release 4.11.44 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11.

Red Hat OpenShift Container Platform release 4.11.44 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11.

Red Hat OpenShift Container Platform release 4.10.63 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

LockBit louts unload ransomware at Japan’s most prolific cargo port
North Korean satellite had no military utility for spying, says South Korea
Former boss who stole $10M from Amazon using fake vendor invoices is jailed for 16 years
Smashing Security podcast #329: Pornhub, Barbie dolls, and can you trust a free TV?
RAM-ramming Rowhammer is back – to uniquely fingerprint devices
Suspected bank-infecting OPERA1ER crime boss cuffed
Firefox 115 is out, says farewell to older Windows and Mac users

Django could be made to consume resources if it received specially crafted network traffic.

Several security issues were fixed in containerd.

Several security issues were fixed in Firefox.

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Singapore tells crypto operators: act like grown up financial institutions

security update

Ghostscript bug could allow rogue documents to run system commands
How Open Source Can Help Protect Your Organization Against Email Threats

Several security issues were fixed in ImageMagick.

Deepfaking it: What to know about deepfake‑driven sextortion schemes

Criminals increasingly create deepfake nudes from people’s benign public photos in order to extort money from them, the FBI warns The post Deepfaking it: What to know about deepfake‑driven sextortion schemes appeared first on WeLiveSecurity

Undiplomatic Chinese threat actor attacks embassies and foreign affairs departments

Update to 114.0.5735.198. Fixes the following security issues: CVE-2023-3420 CVE-2023-3421 CVE-2023-3422 CVE-2023-36191

Update to 2.40.3: * Make memory pressure monitor honor memory.memsw.usage_in_bytes if exists. * Include key modifiers in wheel events. * Apply cookie blocking policy to WebSocket handshakes. * Fix several crashes and rendering issues. * Security fixes: CVE-2023-32439

croc 9.6.4

croc 9.6.4

**Changelog** “` * Sun Jun 25 2023 Didik Supriadi – 2.5.1-3 – Build with ivy instead of maven “`

You’ve patched right? ‘340K+ Fortinet firewalls’ wide open to critical security bug
TSA wants to expand facial recognition to hundreds of airports within next decade
Dublin Airport staff pay details stolen by hackers after MOVEit attack at third-party provider Aon
WordPress plugin lets users become admins – Patch early, patch often!
Dublin Airport staff pay data ‘compromised’ by criminals

GNU Screen could be made to crash applications if it received specially crafted input.

OpenLDAP could be made to crash if it received specially crafted input.

ReportLab could be made to crash or run programs as your login if it opened a specially crafted file.

Verizon 2023 DBIR: What’s new this year and top takeaways for SMBs

Here are some of the key insights on the evolving data breach landscape as revealed by Verizon’s analysis of more than 16,000 incidents The post Verizon 2023 DBIR: What’s new this year and top takeaways for SMBs appeared first on WeLiveSecurity

The container suse-sles-15-sp4-chost-byos-v20230606-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

US authorities warn on China’s new counter-espionage law

Several security issues were fixed in Vim.

Japan rebukes Fujitsu for cloud security fails

Update to 114.0.5735.198. Fixes the following security issues: CVE-2023-3420 CVE-2023-3421 CVE-2023-3422 CVE-2023-36191

A memory leak has been found in yajl, a JSON parser / small validating JSON generator written in ANSI C, which might allow an attacker to cause an out of memory situation and potentially causing a crash.

Multiple multiple vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Multiple multiple vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

security update

security update