Menu

Category Archives: All

Everything

UK cops score legal win in EncroChat snooping op
India to send official whassup to WhatsApp after massive spamstorm
Let white-hat hackers stick a probe in those voting machines, say senators

security update

Millions of mobile phones come pre-infected with malware, say researchers
Turning on stealth mode: 5 simple strategies for staying under the radar online

Have your cake and eat it too – enjoy some of what the online world has to offer without always giving out your contact details The post Turning on stealth mode: 5 simple strategies for staying under the radar online appeared first on WeLiveSecurity

S3 Ep134: It’s a PRIVATE key – the hint is in the name!
Akira ransomware – what you need to know
ENISA leans into EU-based clouds with draft cybersecurity label

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container sles-15-sp4-chost-byos-v20230510-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230510-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230510-x86_64-gen2 was updated. The following patches have been included in this update:

Smashing Security podcast #321: Eurovision, acts of war, and Twitter circles
Sonatype axes 14 percent of staff, reminds them not to talk to the press
Twitter adds new DM features, and Musk says E2EE is here, starting today
ESET APT Activity Report Q4 2022­–Q1 2023

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2022 and Q1 2023 The post ESET APT Activity Report Q4 2022­–Q1 2023 appeared first on WeLiveSecurity

How the war in Ukraine has been a catalyst in private‑public collaborations

As the war shows no signs of ending and cyber-activity by states and criminal groups remains high, conversations around the cyber-resilience of critical infrastructure have never been more vital The post How the war in Ukraine has been a catalyst in private‑public collaborations appeared first on WeLiveSecurity

What should protection for your 365 data really look like?

SQL parse could be made to denial of service if it received a specially crafted regular expression.

Open vSwitch could be made to stop forwarding packets if it received specially crafted network traffic.

Several security issues were fixed in OpenStack Neutron.

OpenStack Heat could be made to expose sensitive information.

23-year-old Brit linked to 2020 Twitter attack and SIM-swap scheme pleads guilty

Several security issues were fixed in css-what.

New Red Hat Single Sign-On 7.6.3 packages are now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Bootkit zero-day fix – is this Microsoft’s most cautious patch ever?
Capita looking at a bill of £20M over breach clean-up costs
Japan’s ubiquitous convenience stores now serving up privacy breaches
Two Microsoft Windows bugs under attack, one in Secure Boot with a manual fix
FBI-led Op Medusa slays NATO-bothering Russian military malware network
Microsoft disarms push notification bombers with number matching in Authenticator
Low-level motherboard security keys leaked in MSI breach, claim researchers
EU proposes spyware Tech Lab to keep Big Brother governments in check

An update for openssh is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for mysql is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for krb5 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for curl is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for pcs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for lua is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Why Cloud Linux Is Beneficial for E-Commerce Stores
Beijing raids consultancy, State-sponsored media warns more to come
FYI: Intel BootGuard OEM private keys leak from MSI cyber heist
Western Digital: Customer info stolen in that IT attack
WordPress plugin hole puts ‘2 million websites’ at risk
Twitter admits ‘security incident’ made private Circles not so much
Modern Auth comes to on-prem Exchange Server gear

Several security issues were fixed in WebKitGTK.

Several security issues were fixed in MySQL.

Erlang could allow unintended access to network services.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

Uber’s ex-CSO avoids prison after data breach cover up
T-Mobile US suffers second data theft within months

– digiKam-8.0.0 – enabled MediaPlayer – Security fix for CVE-2023-1729 https://www.digikam.org/news/2023-04-16-8.0.0_release_announcement/

Attestation in confidential computing

The container suse/registry was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

The container ses/7.1/rook/ceph was updated. The following patches have been included in this update:

DEF CON to set thousands of hackers loose on LLMs
APTs target MSP access to customer networks – Week in security with Tony Anscombe

The recent compromise of the networks of several companies via the abuse of a remote access tool used by MSPs exemplifies why state-aligned threat actors should be on the radars of IT service providers The post APTs target MSP access to customer networks – Week in security with Tony Anscombe appeared first on WeLiveSecurity

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

Dump these insecure phone adapters because we’re not fixing them, says Cisco

security update

A right Royal pain in the Dallas: City IT systems crippled by ransomware
PHP Packagist supply chain poisoned by hacker “looking for a job”
WordPress plugin vulnerability puts two million websites at risk

Several vulnerabilities were discovered in odoo, a suite of web based open source business apps. CVE-2021-44775, CVE-2021-26947, CVE-2021-45071, CVE-2021-26263:

The system could be made to run programs as an administrator.

Several security issues were fixed in the Linux kernel.

The guest VM system could be made to crash or expose sensitive information.

Capita admits some pension data ‘likely’ to have been accessed in March breach

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Users complain over UK state-owned bank’s services as Atos eyes the exit

The container bci/openjdk-devel was updated. The following patches have been included in this update:

China labels USA ‘Empire of hacking’ based on old Wikileaks dumps

security update

Ex-Uber CSO gets probation for covering up theft of data on millions of people
PSA. Don’t share your password in your app’s release notes

An update is now available for Red Hat Satellite 6.13. The release contains a new version of Satellite and important security fixes for various components.

Red Hat Integration Camel for Spring Boot 3.20.1 release and security update is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Using Discord? Don’t play down its privacy and security risks

It’s all fun and games until someone gets hacked – here’s what to know about, and how to avoid, threats lurking on the social media juggernaut The post Using Discord? Don’t play down its privacy and security risks appeared first on WeLiveSecurity

APT groups muddying the waters for MSPs

A quick dive into the murky world of cyberespionage and other growing threats facing managed service providers – and their customers The post APT groups muddying the waters for MSPs appeared first on WeLiveSecurity

Strike three: FTC says Meta still failing to protect user privacy
Patch now! The Mirai IoT botnet is exploiting TP-Link routers
World Password Day: 2 + 2 = 4
Confidential computing primer
Creating strong, yet user‑friendly passwords: Tips for your business password policy

Don’t torture people with exceedingly complex password composition rules but do blacklist commonly used passwords, plus other ways to help people help themselves – and your entire organization The post Creating strong, yet user‑friendly passwords: Tips for your business password policy appeared first on WeLiveSecurity

Several security issues were fixed in Ruby.

A practical guide to React Native authentication