Menu

Category Archives: All

Everything

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Biden now wants to toughen up chemical sector’s cybersecurity

security update

New York Post was hacked from the inside, employee fired after offensive articles posted online
S3 Ep106: Facial recognition without consent – should it be banned?
Parcel delivery scams are on the rise: Do you know what to watch out for?

As package delivery scams that spoof DHL, USPS and other delivery companies soar, here’s how to stay safe not just this shopping season The post Parcel delivery scams are on the rise: Do you know what to watch out for? appeared first on WeLiveSecurity

LinkedIn’s new security features fight scammers, deepfakes, and hackers
The point solution IAM evolution under reform

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Cryptographic signatures for zip distributions

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Purpleurchin cryptocurrency miners spotted scouring free GitHub, Heroku accounts
Japan to citizens: Get a digital ID or health insurance gets harder
Pro-China crew ramps up disinfo ahead of US midterms. Not that anyone’s falling for it
Feds accuse Ukrainian of renting out PC-raiding Raccoon malware to fiends
Cisco AnyConnect Windows client under active attack
Microsoft realizes it hasn’t updated list of banned dodgy Windows 10 drivers in years
Online ticketing company “See” pwned for 2.5 years by attackers

This is the October 2022 release of .NET Core 3.1 This updates .NET Core 3.1 SDK to 3.1.424 and Runtime to 3.1.30. This includes fixes for CVE-2022-41032

added patches to fix CVE-2022-41751

– New version 4.4.3-P1 (rhbz#2132240) – Fix for CVE-2022-2928 (rhbz#2132429) – Fix for CVE-2022-2929 (rhbz#2132430)

Update to 1.12.24 * Fix CVE-2022-42010, CVE-2022-42011, CVE-2022-42012

This is the October 2022 release of .NET Core 3.1 This updates .NET Core 3.1 SDK to 3.1.424 and Runtime to 3.1.30. This includes fixes for CVE-2022-41032

added patches to fix CVE-2022-41751

Service Preview of Red Hat Advanced Cluster Security Cloud Service
New Year, new cyber security career
Ransomware down this year – but there’s a catch
If someone tries ransacking your Windows network, it’s a bit easier now to grok in Microsoft 365 Defender
Health insurer Medibank’s data breach diagnosis keeps getting worse
Clearview AI image-scraping face recognition service hit with €20m fine in France
FTC slaps down Drizly CEO after 2.4m user records stolen from ‘careless’ booze app biz
PayPal ditches passwords, at least on Apple devices
The safety of numbers
Cybersecurity event cancelled after scammers disrupt LinkedIn live chat

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

What Should Be on My Resume as a Linux Administrator?

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Why you’re getting cloud security wrong
Gone phishing: UK data watchdog fines construction biz £4.4m for poor infosec hygiene
Seven months after it found out, FamilySearch tells users their personal data has been breached
Uncle Sam says these Chinese nationals are Beijing agents breaking the law on US soil
Apple megaupdate: Ventura out, iOS and iPad kernel zero-day – act now!
Payment terminal malware steals $3.3m worth of credit card numbers – so far

security update

Car dealer group Pendragon refuses to pay $60 million to ransomware extortionists
DHL named most-spoofed brand in phishing
CISA, FBI warn healthcare organizations of Daixin ransomware
Serious Security: You can’t beat the house at Blackjack – or can you?
APT‑C‑50 updates FurBall Android malware – Week in security with Tony Anscombe

ESET Research spots a new version of Android malware known as FurBall that APT-C-50 is using in its wider Domestic Kitten campaign The post APT‑C‑50 updates FurBall Android malware – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Ex-cop abused police tool in Snapshot sextortion plot that stole sexually explicit photos and videos
Google says slap some GUAC on your software supply chain

An incomplete fix was discovered in Pillow.

Several security issues were fixed in MySQL.

An update that fixes four vulnerabilities is now available.

An update for pki-core is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for libksba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Update to maintenance release 3.0.8

Most reported CVEs for Docker Hub images are harmless
5 reasons to keep your software and devices up to date

Next time you’re tempted to hold off on installing software updates, remember why these updates are necessary in the first place The post 5 reasons to keep your software and devices up to date appeared first on WeLiveSecurity

A year of SANS security summits
Linux: Here, there and everywhere
Could you not? BlackByte ransomware slinger twists the knife with data stealer
Hacktivists say they stole 100,000 emails from Iran’s nuclear energy agency

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

Russia wages disinformation war. Ukraine’s cyber chief calls for global anti-fake news fight

An update that solves 7 vulnerabilities, contains one feature and has one errata is now available.

Security fix for CVE-2022-2476

– Update to 20.10.20. – Mitigates CVE-2022-39253

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

Domestic Kitten campaign spying on Iranian citizens with new FurBall malware

APT-C-50’s Domestic Kitten campaign continues, targeting Iranian citizens with a new version of the FurBall malware masquerading as an Android translation app The post Domestic Kitten campaign spying on Iranian citizens with new FurBall malware appeared first on WeLiveSecurity

When cops hack back: Dutch police fleece DEADBOLT criminals (legally!)

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) (CVE-2022-21626) * OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628) * OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) (CVE-2022-21619) * OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) (CVE-2022-21624 [More…]

This update upgrades Firefox to version 102.4.0 ESR. * Mozilla: Same-origin policy violation could have leaked cross-origin URLs (CVE-2022-42927) * Mozilla: Memory Corruption in JS Engine (CVE-2022-42928) * Mozilla: Denial of Service via window.print (CVE-2022-42929) * Mozilla: Memory safety bugs fixed in Firefox 106 and Firefox ESR 102.4 (CVE-2022-42932) For more details about the securit […]

OpenJDK: improper MultiByte conversion can lead to buffer overflow (JGSS, 8286077) (CVE-2022-21618) * OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) (CVE-2022-21626) * OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628) * OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) (CVE-202 [More…]

Good news, URSNIF no longer a banking trojan. Bad news, it’s now a backdoor
It’s time to prioritize SaaS security
Oops, web trackers may have leaked 3 million patients’ info

security update

Cloud migration and the cyber skills shortage
Don’t get scammed when buying tickets online

With hot-ticket events firmly back on the agenda, scammers selling fake tickets online have also come out in force The post Don’t get scammed when buying tickets online appeared first on WeLiveSecurity