Menu

Monthly Archives: August 2023

High severity vuln in WinRAR could allow code to run when files are opened

An update that fixes 21 vulnerabilities is now available.

Last rites for the UK’s Online Safety Bill, an idea too stupid to notice it’s dead

Several security issues were fixed in Vim.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/nginx was updated. The following patches have been included in this update:

Microsoft DNS boo-boo breaks Hotmail for users around the globe

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Better securing the frontlines: Leveraging Ansible Automation Platform and AIDE for DoD file integrity
Interpol arrests 14 who allegedly scammed $40m from victims in ‘cyber surge’

The container bci/golang was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

security update

The container suse/sles12sp5 was updated. The following patches have been included in this update:

respin of security cpu due to uninstallable sources subpkg —- updatet to july security update 382.b05

respin of security cpu due to uninstallable sources subpkg —- updatet to july security update 382.b05

update to 115.0.5790.170. Fixes several security issues

update to 2.9.8

FYI: There’s another BlackCat ransomware variant on the prowl

security update

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes one vulnerability is now available.

Centralized cloud security is now a must-have

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/389-ds was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update:

Add ‘writing malware’ to the list of things generative AI is not very good at doing
Don’t just patch your Citrix gear, check for intrusion: Two bugs exploited in wild

security update

LinkedIn under attack, hackers seize accounts
S3 Ep148: Remembering crypto heroes

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

FBI warns cryptocurrency app beta-testers of malware menace
Smashing Security podcast #335: AI chat wars, and hacker passwords exposed
Man arrested in Northern Ireland police data leak as more incidents come to light
Japan’s digital minister surrenders salary to say sorry for data leaks
Vietnam admits it has just ten percent of the infosec pros it needs
Discord.io pulls the cord after crooks steal 760K users’ info
FBI warns about scams that lure you in as a mobile beta-tester

Red Hat OpenShift Virtualization release 4.13.3 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

OpenStack Heat could be made to expose sensitive information.

Ceph could be made to run programs as an administrator.

LockBit’s dirty little secret: ransomware gang is failing to publish victims’ data

GStreamer could be made to denial of service if it received a specially crafted datetime string.

Two vunerabilities were discovered in openssl, a Secure Sockets Layer toolkit: CVE-2023-3446, CVE-2023-3817

Clorox cleans up IT security breach that soaked its biz ops

security update

Cumbria Police accidentally publish officers’ names and salaries online
Ensure data security at the edge
You’re not seeing double – yet another UK copshop is confessing to a data leak
Tech CEO admits role in tricking Qualcomm into $150M takeover
Florida Man and associates indicted for conspiracy to steal data, software

An update for rust-toolset-1.66-rust is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Chinese media teases imminent exposé of seismic US spying scheme
Sextortion suspects on trial after teen victim dies from a self-inflicted gunshot wound
“Grab hold and give it a wiggle” – ATM card skimming is still a thing
Beware cool-looking beta crypto-apps. They may be money-stealing fakes
Ford SYNC 3 infotainment vulnerable to drive-by Wi-Fi hijacking

An update for the rust-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for .NET 6.0 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for .NET 6.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for .NET 7.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Multicluster Engine for Kubernetes 2.2.7 General Availability release images, which provide security updates and fix bugs. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score,

Preventing Linux DDoS Attacks with Minimal Cybersecurity Knowledge
Crimeware server used by NetWalker ransomware seized and shut down
How to hack casino card-shuffling machines

Two vulnerabilities have been fixed in poppler, a PDF rendering library. CVE-2020-36023

Pygments could be made to hang if it opened a specially crafted file.

Cumbrian cops accidentally publish all of its officers’ details online

Several security issues were patched in the Go yaml package.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

Hacktivists attack Japanese government over Fukushima wastewater release
US government to investigate China’s Microsoft email breach

PyPDF2 could be made to crash if it opened a specially crafted file.

security update

Persistent volume support with peer-pods: Solution overview

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

security update

security update

Multiple vulnerabilities were discovered in the RealMedia demuxers for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Google Chrome to shield encryption keys from promised quantum computers

The container trento/trento-web was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update: