Menu

Category Archives: All

Everything

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

BreachForums shuts down … but the RaidForums cybercrime universe will likely spawn a trilogy
You just gonna take that AWS? Let Microsoft school your users on cloud security?
Google Pixel phones had a serious data leakage bug – here’s what to do!
Twitter ends free SMS 2FA: Here’s how you can protect your account now

Twitter’s ditching of free text-message authentication doesn’t mean that you should forgo using 2FA. Instead, switch to another – and, indeed, better – 2FA option. The post Twitter ends free SMS 2FA: Here’s how you can protect your account now appeared first on WeLiveSecurity

ManageEngine Vulnerability Manager Plus: How To Protect Your Enterprise from Security Vulnerabilities
High-Impact DoS, Arbitrary Code Execution, Spoofing Bugs Fixed in Thunderbird 102.9.0
Tails 5.11 Amnesic Incognito Live System Switches to ZRam and Linux Kernel 6.1 LTS
Researcher Creates Polymorphic Blackmamba Malware with ChatGPT
Bringing observability to cloud security
Ex-Meta security staffer accuses Greece of spying on her phone

USN-5904-1 caused a minor regression in SoX.

The container bci/nodejs was updated. The following patches have been included in this update:

Putin to staffers: Throw out your iPhones, or ‘give it to the kids’
Google suspends top Chinese shopping app Pinduoduo
Australian FinTech takes itself offline to deal with cyber incident that caused data leak

TigerVNC could be made to expose sensitive information over the network.

Ferrari in a spin as crims steal a car-load of customer data

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Privacy fail: Pictures cropped, redacted by Google Pixel phones can be recovered
ForgeRock, Secret Double Octopus offer passwordless authentication for enterprises
Bitcoin ATM customers hacked by video upload that was actually an app

Several security issues were fixed in Vim.

BBC to staff: Uninstall TikTok from our corporate kit unless you can ‘justify’ having it

Python could be made to bypass blocklisting methods if a specially crafted URL was provided.

One of the security fixes released as DLA 3315 introduced a regression in the processing WAV files with variable bitrate encoding. Updated sox packages are available to correct this issue.

Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or spoofing.

Vessels claiming to be Chinese warships are messing with passenger planes
Police pounce on ‘pompompurin’ – alleged mastermind of BreachForums

The newest upstream commit Security fixes for CVE-2023-1175, CVE-2023-1170, CVE-2023-1264.

Update to 1.15.4 * Fix CVE-2023-28100 and CVE-2023-28101

TikTok cannot be considered a private company, says Australian report
BianLian ransomware crew goes 100% extortion after free decryptor lands

Update to 102.9.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2023-11/ ; https://www.thunderbird.net/en- US/thunderbird/102.9.0/releasenotes/

Denial of service using crafted input. (CVE-2022-40152) References: – https://bugs.mageia.org/show_bug.cgi?id=31665 – https://lists.suse.com/pipermail/sle-security-updates/2023-March/013995.html

Remote code execution on feed enrichment. If “Extract full content from HTML5 and Google AMP” has been enabled for one or more feed subscriptions it is possible for a an attacker to inject a script command that runs with user priveleges. (CVE-2023-1350)

An out-of-bounds write vulnerability exists in TPM2.0’s Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in

A potential buffer overflow exists in the file src/w_help.c at line 55. Specifically, the length of the string returned by getenv(“LANG”) may become very long and cause a buffer overflow while executing the sprintf() function. This vulnerability could potentially allow an attacker to execute arbitrary code or cause a denial-of-service condition.

Some mod_proxy configurations on Apache HTTP Server allow a HTTP request smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied

Banking turmoil opens opportunities for fraud – Week in security with Tony Anscombe

Scammers are looking to cash in on the chaos that has set in following the startling meltdowns of Silicon Valley Bank and Signature Bank and the crisis at Credit Suisse The post Banking turmoil opens opportunities for fraud – Week in security with Tony Anscombe appeared first on WeLiveSecurity

You’ve been pwned, how much will each stolen customer SSN cost you? How about $7.5k?

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225

CVE-2022-37454: Fix buffer overflows in _sha3 module

Update to OWSLib-0.28.1, fixes CVE-2023-27476.

Security fix for CVE-2022-41717

Google: Turn off Wi-Fi calling, VoLTE to protect your Android from Samsung hijack bugs
Eufy security cams ‘ignore cloud opt-out, store unique IDs’ of anyone who walks by
Dangerous Android phone 0-day bugs revealed – patch or work around them now!
Free decryptor released for Conti-based ransomware following data leak
Android phones can be hacked just by someone knowing your phone number

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or spoofing.

SVB collapse is a scammer’s dream: Don’t get caught out

How cybercriminals can exploit Silicon Valley Bank’s downfall for their own ends and at your expense The post SVB collapse is a scammer’s dream: Don’t get caught out appeared first on WeLiveSecurity

One of the security fixes released as DSA 5356 introduced a regression in the processing of specific WAV files. Updated sox packages are available to correct this issue.

Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or spoofing.

The container bci/python was updated. The following patches have been included in this update:

Feds arrest and charge exiled Chinese billionaire over massive crypto fraud
Here’s how Chinese cyber spies exploited a critical Fortinet bug

security update

FTX inner circle helped itself to $3.2B, liquidators say

security update

security update

Got Conti? Here’s the ransomware cure to avoid paying up
S3 Ep 126: The price of fast fashion (and feature creep) [Audio + Text]
UK.gov bans TikTok from its devices as a ‘precaution’ over spying fears
Not‑so‑private messaging: Trojanized WhatsApp and Telegram apps go after cryptocurrency wallets

ESET researchers analyzed Android and Windows clippers that can tamper with instant messages and use OCR to steal cryptocurrency funds The post Not‑so‑private messaging: Trojanized WhatsApp and Telegram apps go after cryptocurrency wallets appeared first on WeLiveSecurity

The container suse/sles/15.5/virt-operator was updated. The following patches have been included in this update:

The container suse/sles/15.5/libguestfs-tools was updated. The following patches have been included in this update:

The container suse/sles/15.5/virt-launcher was updated. The following patches have been included in this update:

The container suse/sles/15.5/virt-handler was updated. The following patches have been included in this update:

The container suse/sles/15.5/virt-exportserver was updated. The following patches have been included in this update:

The container suse/sles/15.5/virt-exportproxy was updated. The following patches have been included in this update:

Smashing Security podcast #313: Tesla twins and deepfake dramas
Hands up who DIDN’T exploit this years-old flaw to ransack a US govt web server…
Microsoft has another go at closing security hole exploited by Magniber ransomware
Cancer patient sues hospital after ransomware gang leaks her nude medical photos

Several buffer overflows were found which allow an attacker to make tcpdump crash.

Sebastian Krahmer found a problem in the modprobe utility that could beexploited by local users to run arbitrary commands as root if themachine is running a kernel with kmod enabled.

Proton reported on bugtraq that tcsh did not handle in-here documentscorrectly. The version of tcsh that is distributed with Debian GNU/Linux2.2r0 also suffered from this problem.

The version of gnupg that was distributed in Debian GNU/Linux 2.2 hada logic error in the code that checks for valid signatures which couldcause false positive results:

The slow Tick‑ing time bomb: Tick APT group compromise of a DLP software developer in East Asia

ESET Research uncovered a campaign by APT group Tick against a data-loss prevention company in East Asia and found a previously unreported tool used by the group The post The slow Tick‑ing time bomb: Tick APT group compromise of a DLP software developer in East Asia appeared first on WeLiveSecurity

Emacs could be made to crash or run programs as your login if it opened a specially crafted file.

Pair accused of breaking into US law enforcement database, posing as cops

Several security issues were fixed in OpenJPEG.

Tailscale: Fast and easy VPNs for developers
SVB collapse’s mix of money, urgency and uncertainty makes it irresistible to scammers
China sought control of submarine cables to spy, says Micronesia

No matter how old you are, it is important to learn how to stay safe online! According to a study conducted by Learning Innovation, more than 93% of students have access to smartphones and laptops. Cyber threats show no sign of slowing down, which is why it is important to stay up to date on […]

Microsoft fixes two 0-days on Patch Tuesday – update now!
Crims exploit Microsoft, Fortinet flaws before any patches exist

security update

Microsoft squashes Windows bug exploited to inflict ransomware misery
Firefox 111 patches 11 holes, but not 1 zero-day among them…
5 signs you’ve fallen for a scam – and what to do next

Here’s how to know you have fallen victim to a scam – and what to do in order to undo or mitigate the damage. The post 5 signs you’ve fallen for a scam – and what to do next appeared first on WeLiveSecurity