Menu

Category Archives: All

Everything

Reducing the risk of cloud attack

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Crime in the metaverse – police face new challenges in a virtual world

– Updated to 106.0.3 —- – New upstream version (106.0.1)

– Updated to 106.0.3 —- – New upstream version (106.0.1)

French-speaking voleurs stole $30m in 15-country bank, telecoms cyber-heist spree
Multi-factor auth fatigue is real – and it’s why you may be in the headlines next

security update

S3 Ep107: Eight months to kick out the crooks and you think that’s GOOD? [Audio + Text]
International summit agrees crack down on crypto to combat ransomware
Verified users beware! Scammers are exploiting Twitter turmoil caused by Elon Musk’s takeover

**PHP version 8.1.12** (27 Oct 2022) **Core:** * Fixes segfault with Fiber on FreeBSD i386 architecture. (David Carlier) **Fileinfo:** * Fixed bug [GH-8805](https://github.com/php/php-src/issues/8805) (finfo returns wrong mime type for woff/woff2 files). (Anatol) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**)

**PHP version 8.1.12** (27 Oct 2022) **Core:** * Fixes segfault with Fiber on FreeBSD i386 architecture. (David Carlier) **Fileinfo:** * Fixed bug [GH-8805](https://github.com/php/php-src/issues/8805) (finfo returns wrong mime type for woff/woff2 files). (Anatol) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**)

# New in release OpenJDK 17.0.5 (2022-10-18) * [Release announcement](https://bit.ly/openjdk1705) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes-17.0.5.html) ## Security Fixes – JDK-8282252: Improve BigInteger/Decimal validation – JDK-8285662: Better permission resolution – JDK-8286077, CVE-2022-21618: Wider

# New in release OpenJDK 17.0.5 (2022-10-18) * [Release announcement](https://bit.ly/openjdk1705) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes-17.0.5.html) ## Security Fixes – JDK-8282252: Improve BigInteger/Decimal validation – JDK-8285662: Better permission resolution – JDK-8286077, CVE-2022-21618: Wider

# New in release OpenJDK 11.0.17 (2022-10-18) * [Release announcement](https://bit.ly/openjdk11017) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes-11.0.7.html) ## Security Fixes – JDK-8282252: Improve BigInteger/Decimal validation – JDK-8285662: Better permission resolution – JDK-8286077, CVE-2022-21618: Wider

# New in release OpenJDK 8u352 (2022-10-18) * [Release announcement](https://bit.ly/openjdk8u352) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes- openjdk8u352.html) ## Security Fixes * JDK-8282252: Improve BigInteger/Decimal validation * JDK-8285662: Better permission resolution * JDK-8286511: Improve

Using daysofrisk.pl with the Red Hat Security Data API
The future starts now: 10 major challenges facing cybersecurity

To mark Antimalware Day, we’ve rounded up some of the most pressing issues for cybersecurity now and in the future The post The future starts now: 10 major challenges facing cybersecurity appeared first on WeLiveSecurity

Royal Mail customer data leak shutters online Click and Drop
Smashing Security podcast #296: Twitter turmoil, AI animal chatters, and metaverse at work
The OpenSSL security update story – how can you tell what needs fixing?
US Treasury thwarts DDoS attack from Russian Killnet group

security update

security update

The spy who rented to me? Throwing the spotlight on hidden cameras in Airbnbs

Do you find reports of spy cams found in vacation rentals unsettling? Try these tips for spotting hidden cameras and put your worries to rest. The post The spy who rented to me? Throwing the spotlight on hidden cameras in Airbnbs appeared first on WeLiveSecurity

Ransomware cost US banks $1.2 billion last year

Upstream update including security & bug fixes as well as feature enhancements. From the upstream [release notes](https://github.com/git/git/raw/v2.38.1/Documen tation/RelNotes/2.30.6.txt): CVE-2022-39253 ————– When relying on the `–local` clone optimization, Git dereferences symbolic links in the source repository before creating hardlinks (or copies) of the dereferenced link in the

Azul detects Java vulnerabilities in production apps

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Ritz cracker giant settles bust-up with insurer over $100m+ NotPetya cleanup
Dropbox admits 130 of its private GitHub repos were copied after phishing attack
OpenSSL downgrades horror bug after week of panic, hype
3 primo cloud computing jobs in 2023
OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway!
Trick or treat? Stay so cyber‑safe it’s scary – not just on Halloween

Gather around, folks, to learn about some of the ghastliest tricks used by criminals online and how you can avoid security horrors this Halloween and beyond The post Trick or treat? Stay so cyber‑safe it’s scary – not just on Halloween appeared first on WeLiveSecurity

Government by Gmail catches up with UK minister… who is reappointed anyway
SHA-3 code execution bug patched in PHP – check your version!

Several security issues were fixed in OpenSSL.

Several security issues were fixed in OpenSSL.

**PHP version 8.0.25** (27 Oct 2022) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**) (cmb) **Hash:** * Fixed bug php#81738: buffer overflow in hash_update() on long parameter. (**CVE-2022-37454**) (nicky at mouha dot be) **Session:** * Fixed bug [GH-9583](https://github.com/php/php-src/issues/9583)

**PHP version 8.0.25** (27 Oct 2022) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**) (cmb) **Hash:** * Fixed bug php#81738: buffer overflow in hash_update() on long parameter. (**CVE-2022-37454**) (nicky at mouha dot be) **Session:** * Fixed bug [GH-9583](https://github.com/php/php-src/issues/9583)

New upstream release fixing CVE-2022-3515

New upstream release fixing CVE-2022-3515

Kioxia warns Uncle Sam: Be careful what you wish for with China sanctions
German cops arrest student suspected of running infamous dark-web souk
Unofficial fix emerges for Windows bug abused to infect home PCs with ransomware
India’s Home Ministry cracks down on predatory lending apps following suicides
Education tech giant gets an F for security after sensitive info on 40 million users stolen

security update

Extortion fears after hacker stole patient files from Dutch mental health clinics
Psychotherapy extortion suspect: arrest warrant issued
The White House’s global ransomware summit couldn’t come at a better time
Ordinary web access request or command to malware?

Libtasn1 could cause a crash when processing certain inputs.

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

Twilio reveals hackers compromised its systems a month earlier than previously thought
Apple patches actively exploited iPhone, iPad kernel vulns
Singapore hosts ICS/OT cybersecurity training extravaganza
Indian government creates body with power to order social media content takedowns

security update

security update

security update

Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine. CVE-2021-43980

It was discovered that Apache Batik, a SVG library for Java, allowed attackers to run arbitrary Java code by processing a malicious SVG file. For the stable distribution (bullseye), these problems have been fixed in

A security issue was discovered in Chromium, which could result in the execution of arbitrary code. For the stable distribution (bullseye), this problem has been fixed in

It was discovered that libxml2, the GNOME XML library, was vulnerable to integer overflows and memory corruption. CVE-2022-40303

A heap use-after-free vulnerability after overeager destruction of a shared DTD in the XML_ExternalEntityParserCreate function in Expat, an XML parsing C library, may result in denial of service or potentially the execution of arbitrary code.

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version

Courts vs. cybercrime – Week in security with Tony Anscombe

A look at a recent string of law enforcement actions directed against (in some cases suspected) perpetrators of various types of cybercrime The post Courts vs. cybercrime – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Chrome issues urgent zero-day fix – update now!

It was discovered that Apache Batik, a SVG library for Java, allowed attackers to run arbitrary Java code by processing a malicious SVG file. For Debian 10 buster, these problems have been fixed in version

Everything You Need To Know About Open Source Network Monitoring Tools

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

An issue has been found in openvswitch, a software-based, Ethernet virtual switch.

An issue has been found in ncurses, a collection of shared libraries for terminal handling. This issue is about an out-of-bounds read in convert_strings in the

This Windows worm evolved into slinging ransomware. Here’s how to detect it

security update

Federal bans aren’t stopping US states from buying forbidden Chinese kit
Why your phone is slow – and how to speed it up

You probably don’t have to ditch your phone just yet – try these simple tips and tricks to make any Android device or iPhone run faster The post Why your phone is slow – and how to speed it up appeared first on WeLiveSecurity

Multiple vulnerabilities were discovered in Django, a popular Python-based web development framework: * CVE-2020-24583: Fix incorrect permissions on intermediate-level

The top cloud cyber security threats unpacked
Updates to Apple’s zero-day update story – iPhone and iPad users read this!
Post-quantum cryptography: Hash-based signatures
3 primo cloud gigs in 2023

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update: