Menu

Monthly Archives: September 2023

security update

security update

security update

Microsoft Bing Chat pushes malware via bad ads

security update

security update

PhD student guilty of 3D-printing ‘kamikaze’ drone for Islamic State terrorists
Three men found guilty of laundering $2.5 million in Target gift card tech support scam
Norway wants Facebook behavioral advertising banned across Europe
ZeroFont trick makes users think that message has been scanned for threats
Chinese snoops stole 60K State Department emails in that Microsoft email heist
Feds’ privacy panel backs renewing Feds’ S. 702 spying powers — but with limits
DARPA takes its long-duration Manta undersea drone for a test-dip
Ransomware group demands $51 million from Johnson Controls after cyber attack
After failing at privacy, again, Google is working to keep Bard chats out of Search
China’s national security minister rates fake news among most pressing cyber threats
Smashing Security podcast #341: Another T-Mobile breach, ThemeBleed, and farewell Naked Security
British charities warn supporters their personal data has been breached
NYC rights groups say no to grocery store spycams and snooping landlords

security update

ROBOT crypto attack on RSA is back as Marvin arrives
Exiled Russian journalist claims “European state” hacked her iPhone with Pegasus spyware
MOVEit breach delivers bundle of 3.4 million baby records
LinuxSecurity.com Migrates to Joomla 4 and PHP 8: Our Experience & Key Takeaways
Update on Naked Security
Ukraine accuses Russian spies of hunting for war-crime info on its servers
Mixin suspends deposits and withdrawals after $200m cryptocurrency heist
“The good and the bad that comes with the growth of AI” – watch this series of webinars with Abnormal, OpenAI, and others
iOS 17 update secretly changed your privacy settings; here’s how to set them back
How generative AI changes cybersecurity
T-Mobile US exposes some customer data – but don’t call it a breach
ESET’s cutting-edge threat research at LABScon – Week in security with Tony Anscombe

Two ESET malware researchers took to the LABScon stage this year to deconstruct sophisticated attacks conducted by two well-known APT groups

security update

Accelerated Encryption with 4th Gen Intel® Xeon® Scalable Processors
Apple squashes security bugs after iPhone flaws exploited by Predator spyware
ESA gets the job of building Europe’s secure satcomms network
US govt IT help desk techie ‘leaked top secrets’ to foreign nation

security update

TransUnion reckons big dump of stolen customer data came from someone else
Snatch ransomware – what you need to know
Cisco spends $28B on data cruncher Splunk in cybersecurity push
Donald Trump Jr’s hacked Twitter account announces his father has died
Smashing Security podcast #340: Heated seats, car privacy, and Graham’s porn video
Menacing marketeers fined by ICO for 1.9M cold calls
India’s biggest tech centers named as cyber crime hotspots
Data breach reveals distressing info: People who order pineapple on pizza
Feds raise alarm over Snatch ransomware as extortion crew brags of Veterans Affairs hit
Signal adopts new alphabet jumble to protect chats from quantum computers
International Criminal Court hit in cyber-attack amid Russia war crimes probe
Pot calls the kettle hack as China claims Uncle Sam did digital sneak peek first
Robocall scammers sentenced in US after netting $1.2M via India-based call centers
Sysadmin and spouse admit to part in ‘massive’ pirated Avaya licenses scam
Broaden your cyber security knowhow at CyberThreat 2023
What a mess! Clorox warns of “material impact” to its financial results following cyberattack
The Expel Quarterly Threat Report distills the threats and trends the Expel SOC saw in Q2. Download it now.
Marvell disputes claim Cavium backdoored chips for Uncle Sam

security update

security update

security update

security update

Yikes! My sex video has been uploaded to YouPorn, apparently
Russian allegedly smuggled US weapons electronics to Moscow

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container suse/helm was updated. The following patches have been included in this update:

The Clorox Company admits cyberattack causing ‘widescale disruption’
Australia to build six ‘cyber shields’ to defend its shores
Thousands of Juniper Junos firewalls still open to hijacks, exploit code available to all
Former CIO accuses Penn State of faking cybersecurity compliance
Microsoft worker accidentally exposes 38TB of sensitive data in GitHub blunder
California passes bill to set up one-stop data deletion shop

A buffer overflow in parsing WebP images may result in the execution of arbitrary code. For Debian 10 buster, this problem has been fixed in version

Cryptojackers spread their nets to capture more than just EC2

An update for busybox is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

What ChatGPT doesn’t say about Kubernetes in production

The container sles-15-sp5-chost-byos-v20230915-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp5-chost-byos-v20230915-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

Update matrix-synapse to v1.80.0 to fix CVE-2022-39374, CVE-2023-32323

Update matrix-synapse to v1.80.0 to fix CVE-2022-39374, CVE-2023-32323

security update

A buffer overflow in parsing WebP images may result in the execution of arbitrary code. For Debian 10 buster, this problem has been fixed in version

A vulnerability has been discovered in Requests which could result in the disclosure of plaintext secrets.

Multiple vulnerabilities have been discovered in Binwalk, the worst of which could result in remote code execution.

Multiple vulnerabilities have been discovered in Samba, the worst of which could result in root remote code execution.

An arbitrary file overwrite vulnerability has been discovered in RAR and UnRAR, potentially resulting in arbitrary code execution.

Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which could result in remote code execution.

Probe reveals previously secret Israeli spyware that infects targets via ads

A buffer overflow in parsing WebP images may result in the execution of arbitrary code. For Debian 10 buster, this problem has been fixed in version

The container bci/dotnet-aspnet was updated. The following patches have been included in this update:

Backport fix for CVE-2023-4863.

**Redis 7.0.13** Released Wed 06 Sep 2023 15:00:00 IDT Upgrade urgency SECURITY: See security fixes below. Security Fixes * (**CVE-2023-41053**) Redis does not correctly identify keys accessed by SORT_RO and as a result may grant users executing this command access to keys that are not explicitly authorized by the ACL configuration. Bug Fixes * Cluster: […]