Menu

Category Archives: All

Everything

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

China urges Apple to improve security and privacy

security update

Apple patches all the iThings, including iOS 15 hole under attack right now
Google again accused of willfully destroying evidence in Android antitrust battle
Apple patches everything, including a zero-day fix for iOS 15 users
Cops use fake DDoS services to take aim at wannabe cybercriminals

The container bci/bci-init was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

US president Biden kind of mostly bans commercial spyware
Lawyers cough up $200k after health data stolen in Microsoft Exchange pillaging
UK police reveal they are running fake DDoS-for-hire sites to collect details on cybercriminals
Microsoft assigns CVE to Snipping Tool bug, pushes patch to Store

The container ses/7.1/rook/ceph was updated. The following patches have been included in this update:

The container ses/7.1/ceph/ceph was updated. The following patches have been included in this update:

The container ses/7.1/ceph/grafana was updated. The following patches have been included in this update:

The container ses/7.1/cephcsi/cephcsi was updated. The following patches have been included in this update:

Can zero trust be saved?
Gone in 120 seconds: Tesla Model 3 child’s play for hackers
China crisis is a TikToking time bomb

An update for kernel is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

In Memoriam – Gordon Moore, who put the more in “Moore’s Law”

security update

Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in privilege escalation, denial of service or information leaks.

3 security issues (#2180425) x86 shadow plus log-dirty mode use-after-free [XSA-427, CVE-2022-42332] x86/HVM pinned cache attributes mis-handling [XSA-428, CVE-2022-42333, CVE-2022-42334] x86: speculative vulnerability in 32bit SYSCALL path [XSA-429, CVE-2022-42331]

3 security issues (#2180425) x86 shadow plus log-dirty mode use-after-free [XSA-427, CVE-2022-42332] x86/HVM pinned cache attributes mis-handling [XSA-428, CVE-2022-42333, CVE-2022-42334] x86: speculative vulnerability in 32bit SYSCALL path [XSA-429, CVE-2022-42331]

Fix for CVE-2022-48303

This update upgrades Thunderbird to version 102.9.0. * Mozilla: Incorrect code generation during JIT compilation (CVE-2023-25751) * Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 (CVE-2023-28176) * Mozilla: Potential out-of-bounds when accessing throttled streams (CVE-2023-25752) * Mozilla: Invalid downcast in Worklets (CVE-2023-28162) * Mozilla: URL being dragged fr [More…]

Highlights from TikTok CEO’s Congress grilling – Week in security with Tony Anscombe

Here are some of the key moments from the five hours of Shou Zi Chew’s testimony and other interesting news on the data privacy front The post Highlights from TikTok CEO’s Congress grilling – Week in security with Tony Anscombe appeared first on WeLiveSecurity

What TikTok knows about you – and what you should know about TikTok

As TikTok CEO attempts to placate U.S. lawmakers, it’s time for us all to think about the wealth of personal information that TikTok and other social media giants collect about us The post What TikTok knows about you – and what you should know about TikTok appeared first on WeLiveSecurity

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

update to 111.0.5563.110. Fixes the following security issues: CVE-2023-1528 CVE-2023-1529 CVE-2023-1530 CVE-2023-1531 CVE-2023-1532 CVE-2023-1533 CVE-2023-1534

Rebuild for CVE-20220-{3064,41717,41723}

security update

security update

New tar packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue.

CISA unleashes Untitled Goose Tool to honk at danger in Microsoft’s cloud
WooCommerce Payments plugin for WordPress has an admin-level hole – patch now!
GitHub publishes RSA SSH host keys by mistake, issues update

This update includes the changes in tzdata 2023b for the Perl bindings. For the list of changes, see DLA-3366-1. For Debian 10 buster, this problem has been fixed in version

This update includes the changes in tzdata 2023b. Notable changes are: – – Egypt uses DST again, starting on April.

French parliament says oui to AI surveillance for 2024 Paris Olympics

Incorrect code generation during JIT compilation. (CVE-2023-25751) Potential out-of-bounds when accessing throttled streams. (CVE-20223-25752) Invalid downcast in Worklets. (CVE-2023-28162) URL being dragged from a removed cross-origin iframe into the same tab triggered navigation. (CVE-2023-28164)

If a malicious Flatpak app is run on a Linux virtual console such as /dev/tty1, it can copy text from the virtual console and paste it back into the virtual console’s input buffer, from which the command might be run by the user’s shell after the Flatpak app has exited. This is similar to CVE-2017-5226, […]

In the MHD_PostProcessor, malformed inputs can be used to crash the server (for denial-of-service). References: – https://bugs.mageia.org/show_bug.cgi?id=31670

LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. (CVE-2022-4645) References:

Uncle Sam reveals it sent cyber-soldiers to Albania to hunt for Iranian threats
Critical infrastructure gear is full of flaws, but hey, at least it’s certified
S3 Ep127: When you chop someone out of a photo, but there they are anyway…
Danger USB! Journalists sent exploding flash drives
Europe’s transport sector terrorised by ransomware, data theft, and denial-of-service attacks
Fake GPT Chrome extension steals Facebook session cookies, breaks into accounts
Understanding Managed Detection and Response – and what to look for in an MDR solution

Why your organization should consider an MDR solution and five key things to look for in a service offering The post Understanding Managed Detection and Response – and what to look for in an MDR solution appeared first on WeLiveSecurity

Secure mail
Attackers hit Bitcoin ATMs to steal $1.5 million in crypto cash

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

Bogus ChatGPT extension steals Facebook cookies

Several security issues were fixed in amanda.

B-List celebs including Lindsay Lohan fined after crypto shill probe
South Korea fines McDonald’s for data leak from raw SMB share
Smashing Security podcast #314: Photo cropping bombshell, TikTok debates, and real estate scams
Cisco kindly reveals proof of concept attacks for flaws in rival Netgear’s kit
Journalist hurt by exploding USB bomb drive
The hidden danger to zero trust: Excessive cloud permissions
Splunk adds new security and observability features
Observability will transform cloud security
Windows 11 also vulnerable to “aCropalypse” image data leakage
aCropalypse now! Cropped and redacted images suffer privacy fail on Google Pixel smartphones

The container bci/golang was updated. The following patches have been included in this update:

The container suse/389-ds was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

German political parties accused of microtargeting voters on Facebook

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

Unknown actors deploy malware to steal data in occupied regions of Ukraine
India’s absurd infosec reporting rules get just 15 followers
Xi, Putin, declare intent to rule the world of AI, infosec

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

BreachForums shuts down … but the RaidForums cybercrime universe will likely spawn a trilogy
You just gonna take that AWS? Let Microsoft school your users on cloud security?
Google Pixel phones had a serious data leakage bug – here’s what to do!
Twitter ends free SMS 2FA: Here’s how you can protect your account now

Twitter’s ditching of free text-message authentication doesn’t mean that you should forgo using 2FA. Instead, switch to another – and, indeed, better – 2FA option. The post Twitter ends free SMS 2FA: Here’s how you can protect your account now appeared first on WeLiveSecurity

ManageEngine Vulnerability Manager Plus: How To Protect Your Enterprise from Security Vulnerabilities
High-Impact DoS, Arbitrary Code Execution, Spoofing Bugs Fixed in Thunderbird 102.9.0
Tails 5.11 Amnesic Incognito Live System Switches to ZRam and Linux Kernel 6.1 LTS
Researcher Creates Polymorphic Blackmamba Malware with ChatGPT
Bringing observability to cloud security
Ex-Meta security staffer accuses Greece of spying on her phone

USN-5904-1 caused a minor regression in SoX.