Menu

Category Archives: All

Everything

Criminal records office yanks web portal offline amid ‘cyber security incident’
Cops cuff teenage ‘Robin Hood hacker’ suspected of peddling stolen info
Smashing Security podcast #316: Of Musk and Afroman
Cops put the squeeze on Genesis crime souk denizens, not just the admins this time
US government warning! What if anyone could open your garage door?

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

A security issue was fixed in trim-newlines.

Microsoft tells admins to autoreview your Autopatch alerts or autolose the service
Why you should spring clean your home network and audit your backups

Do you know how many devices are connected to your home network? You don’t? This is precisely why it’s time for a network audit. The post Why you should spring clean your home network and audit your backups appeared first on WeLiveSecurity

Notorious stolen credential warehouse Genesis Market seized by FBI
Feds seize $112m in cryptocurrency linked to ‘pig-butchering’ finance scams
Can ChatGPT bash together some data-stealing code? With the right prompts, sure
Snyk bolsters developer security with fresh devsecop, cloud capabilities
Einstein tilings – the amazing “Hat” shape that never repeats!
UK data regulator issues warning over generative AI data protection concerns
UK data watchdog fines TikTok £12.7M for failing to protect kids
Best Browsers with a Built-in VPN
Spring into action and tidy up your digital life like a pro

Spring is in the air and as the leaves start growing again, why not breathe some new life into the devices you depend on so badly? The post Spring into action and tidy up your digital life like a pro appeared first on WeLiveSecurity

Bank rewrote ads for infosec jobs to stop scaring away women
Hey Siri, use this ultrasound attack to disarm a smart-home system
Uber driver info stolen yet again: This time from law firm
April brings tulips, taxes … and phisherfolk scammers
Researchers claim they can bypass Wi-Fi encryption (briefly, at least)
Keeping secrets safe
Western Digital confirms digital burglary, calls the cops
3CX thought supply chain attack was a false positive

Several security issues were fixed in amanda.

Vietnam threatens to cut off two million mobile subscribers
School principal resigns after writing $100,000 check to Elon Musk impersonator

Fixes CVE-2023-1393: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability

Update to ldb 2.7.2 and samba 4.18.1 Security fixes for CVE-2023-0225, CVE-2023-0922, CVE-2023-0614

Update to ldb 2.7.2 and samba 4.18.1 Security fixes for CVE-2023-0225, CVE-2023-0922, CVE-2023-0614

Fixes CVE-2023-1393: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability

xwayland 22.1.9 Security fix for CVE-2023-1393

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container bci/bci-busybox was updated. The following patches have been included in this update:

Avoiding data backup failures – Week in security with Tony Anscombe

Today is World Backup Day, but maybe we also need a “did you test your backups” day? The post Avoiding data backup failures – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Multiple potential security vulnerabilities in some Intel® Processors have been found which may allow information disclosure or may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerabilities.

Ukrainian cops nab suspects accused of stealing $4.3m from victims across Europe

The container bci/openjdk was updated. The following patches have been included in this update:

An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

go1.19.7 (released 2023-03-07) includes a security fix to the crypto/elliptic package, as well as bug fixes to the linker, the runtime, and the crypto/x509 and syscall packages. See the [Go 1.19.7 milestone on the upstream issue tracker](https://go.dev/doc/devel/release#go1.19.7) for details.

Maintenance release with fix for CVE-2023-28686 and bug fixes.

NYPD blues: Cops ignored 93 percent of surveillance law rules
ESET Research Podcast: A year of fighting rockets, soldiers, and wipers in Ukraine

ESET experts share their insights on the cyber-elements of the first year of the war in Ukraine and how a growing number of destructive malware variants tried to rip through critical Ukrainian systems The post ESET Research Podcast: A year of fighting rockets, soldiers, and wipers in Ukraine appeared first on WeLiveSecurity

Hack the Pentagon website promotes the benefits of bug bounties to US Military

Several security issues were fixed in the Linux kernel.

Psst! Infosec bigwigs: Wanna be head of security at HM Treasury for £50k?
Red Hat Shares – Security automation
NHS Highland ‘reprimanded’ by data watchdog for BCC blunder with HIV patients
World Backup Day: Avoiding a data disaster is a forever topic 

By failing to prepare you are preparing to fail. Make sure you’re able to bounce back if, or when, a data disaster strikes. The post World Backup Day: Avoiding a data disaster is a forever topic  appeared first on WeLiveSecurity

Multiple vulnerabilities were found in Json-smart library. Json-smart is a performance focused, JSON processor lib written in Java. CVE-2021-31684

Pro-Russia cyber gang Winter Vivern puts US, Euro lawmakers in line of fire

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Leaked IT contractor files detail Kremlin’s stockpile of cyber-weapons
World Backup Day is here again – 5 tips to keep your precious data safe
Azure blunder left Bing results editable, MS 365 accounts potentially exposed
AlienFox malware caught in the cloud hen house
Supply chain blunder puts 3CX telephone app users at risk
Pig butchering scams: The anatomy of a fast‑growing threat

How fraudsters groom their marks and move in for the kill using tricks from the playbooks of romance and investment scammers The post Pig butchering scams: The anatomy of a fast‑growing threat appeared first on WeLiveSecurity

Do you use comms software from 3CX? What to do next after biz hit in supply chain attack
Clipboard-injecting malware disguises itself as Tor browser, steals cryptocurrency
S3 Ep128: So you want to be a cyber­criminal? [Audio + Text]
Microsoft uses carrot and stick with Exchange Online admins

Several out of bounds memory access and buffer overflows were fixed in xrdp, an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP)

The most important email conversation you will ever have

The container bci/bci-init was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

Warning: Your wireless networks may leak data thanks to Wi-Fi spec ambiguity
US sends million-dollar scammer to prison for four years
Another year, another North Korean malware-spreading, crypto-stealing gang named
Smugglers busted sneaking tech into China
Malware disguised as Tor browser steals $400k in cryptocash
Smashing Security podcast #315: Crypto hacker hijinks, government spyware, and Utah social media shocker

security update

Microsoft Defender shoots down legit URLs as malicious
Staying safe on OnlyFans: The naked truth

How content creators and subscribers can embrace the social media platform without (overly) exposing themselves to the potentially toxic brew of NSFW content and privacy threats The post Staying safe on OnlyFans: The naked truth appeared first on WeLiveSecurity

EU mandated messaging platform love-in is easier said than done: Cambridge boffins

Jan-Niklas Sohn discovered that a user-after-free flaw in the Composite extension of the X.org X server may result in privilege escalation if the X server is running under the root user.

Several security vulnerabilities have been discovered in unbound, a validating, recursive, caching DNS resolver. CVE-2022-3204

FTX cryptovillain Sam Bankman-Fried charged with bribing Chinese officials
DDoS DNS attacks are old-school, unsophisticated … and they’re back

The container bci/rust was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update: