Menu

Category Archives: All

Everything

security update

security update

World Cup apps pose a data security and privacy nightmare
Dangerous SIM-swap lockscreen bypass – update Android now!
Toward the cutting edge: SMBs contemplating enterprise security

Survey finds SMBs, weary of security failures, curious about detection and response The post Toward the cutting edge: SMBs contemplating enterprise security appeared first on WeLiveSecurity

Alleged LockBit ransomware operator arrested in Canada
NSA urges orgs to use memory-safe programming languages
What observability means for cloud operations

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Europe calls for joint cyber defense to ward off Russia
Australia blames Russia for harboring health insurance hackers
Instagram star gets 11 years for $300m email scam plot
S3 Ep108: You hid THREE BILLION dollars in a popcorn tin?
Husband and wife nuclear warship ‘spy’ team get 20 years each
10 common security mistakes and how to avoid them

Do you make these security mistakes and put yourself at greater risk for successful attacks? The post 10 common security mistakes and how to avoid them appeared first on WeLiveSecurity

Twitter Chief Information Security Officer flies the coop
Update your Lenovo laptop’s firmware now! Flaws could help malware survive a hard disk wipe

A vulnerability has been found in lesspipe which could result in arbitrary code execution.

A vulnerability has been found in lesspipe which could result in arbitrary code execution.

This is the October 2022 monthly update for .NET 6. It updates the SDK to 6.0.110 and the Runtime to 6.0.10. This update includes a fix for CVE 2022-41032

This is the October 2022 monthly update for .NET 6. It updates the SDK to 6.0.110 and the Runtime to 6.0.10. This update includes a fix for CVE 2022-41032

– url: use IDN decoded names for HSTS checks (CVE-2022-42916) – http_proxy: restore the protocol pointer on error (CVE-2022-42915) – netrc: replace fgets with Curl_get_line (CVE-2022-35260) – fix POST following PUT confusion (CVE-2022-32221)

– url: use IDN decoded names for HSTS checks (CVE-2022-42916) – http_proxy: restore the protocol pointer on error (CVE-2022-42915) – netrc: replace fgets with Curl_get_line (CVE-2022-35260) – fix POST following PUT confusion (CVE-2022-32221)

A roadmap to better cyber security training
Windows breaks under upgraded IceXLoader malware
Emergency code execution patch from Apple – but not an 0-day
Smashing Security podcast #297: Mastodon 101, and the Hushpuppi saga
Wells Fargo, Zelle slammed by Liz Warren over rampant online banking fraud

security update

security update

Exchange 0-days fixed (at last) – plus 4 brand new Patch Tuesday 0-days!
Having refused to pay ransom, health insurer Medibank sees customer data posted online by hackers
Authoritative Guide on Linux Disk Encryption
OpenSSL: Email address buffer overflow security flaws

Several security issues were fixed in OpenJDK.

Zstandard could be made to expose sensitive information

Zstandard could be made to expose sensitive information

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for linux-firmware is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.

An update for linux-firmware is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.

VMware warns of three critical holes in remote-control tool
Microsoft squashes six security bugs already exploited in the wild
Swiss Re wants government bail out as cybercrime insurance costs spike
Silk Road drugs market hacker pleads guilty, faces 20 years inside
Robin Banks crooks back at the table with fresh phish from Russia
Experian, T-Mobile US settle data spills for mere $16m
Hacking baby monitors can be child’s play: Here’s how to stay safe

Make sure that the device that’s supposed to help you keep tabs on your little one isn’t itself a privacy and security risk The post Hacking baby monitors can be child’s play: Here’s how to stay safe appeared first on WeLiveSecurity

Mastodon: What you need to know for your security and privacy
Cloud architects are afraid of automation

For Debian 10 buster, these problems have been fixed in version 2:8.1.0875-5+deb10u3. We recommend that you upgrade your vim packages.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

FBI: Russian hacktivists achieve only ‘limited’ DDoS success
Feds find Silk Road thief’s $1b+ Bitcoin stash in popcorn tin, hidden safe
All the US midterm-related lies to expect when you’re electing

security update

Public URL scanning tools – when security leads to insecurity
Medibank refuses to pay ransom after 9.7 million health insurance customers have their data stolen
Microsoft hits the switch on password-free smartphone authentication

Small and medium-size business (SMB) leaders have a lot on their minds. The looming recession and inflation have created financial uncertainty. Meanwhile, the global rise in sophisticated ransomware threats and geo-political tensions are escalating cyber threats. With so many factors and pressures at play, how are SMBs navigating this challenging business landscape while fighting back […]

Oh, look: More malware in the Google Play store
Can confidential computing stop the next crypto heist?
Linux Database Security Tips
Japan officially joins NATO’s cyber defense center
Do all vulnerabilities really matter?

It was discovered that there was a potential out-of-bounds write vulnerability in pixman, a pixel-manipulation library used in many Linux graphical applications.

It was discovered that there was a potential out-of-bounds write vulnerability in pixman, a pixel-manipulation library used in many Linux graphical applications.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

It was discovered that there was a information disclosure utility in sudo, a tool used to provide limited superuser privileges to specific users.

China is likely stockpiling and deploying vulnerabilities, says Microsoft
Red Cross seeks digital equivalent of its emblems to mark some tech as off-limits in war
Breached health insurer won’t pay ransom to protect customers, warns of more attacks

security update

Several vulnerabilities were discovered in libxml2, a library providing support to read, modify and write XML and HTML files. CVE-2022-40303

Several vulnerabilities were discovered in libxml2, a library providing support to read, modify and write XML and HTML files. CVE-2022-40303

New sudo packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

security update

Ransomware rages on – Week in security with Tony Anscombe

This week’s news offered fresh reminders of the threat that ransomware poses for businesses and critical infrastructure worldwide The post Ransomware rages on – Week in security with Tony Anscombe appeared first on WeLiveSecurity

updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209

updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209

# New in release OpenJDK 19.0.1 (2022-10-18) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes-19.0.1.html) * This update depends on [FEDORA-2022- 10bb6f119e](https://bodhi.fedoraproject.org/updates/FEDORA-2022-10bb6f119e) ## CVEs Fixed – CVE-2022-21618 – CVE-2022-21619 – CVE-2022-21624 –

Security fix for CVE-2022-3705 2139842 – vim upgrade broke :! for displaying terminal output

Security fix for CVE-2022-3705 2139842 – vim upgrade broke :! for displaying terminal output

updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209

SolarWinds reaches $26m settlement with shareholders, expects SEC action
Qualys previews TotalCloud FlexScan for multicloud security management
Double-check demand payment emails from law firms: Convincing fakes surface
Twitter Blue Badge email scams – Don’t fall for them!