Menu

Category Archives: All

Everything

Chinese-sponsored gang Gallium upgrades to sneaky PingPull RAT
New Syslogk Linux Rootkit Uses Magic Packets to Trigger Backdoor

security update

security update

security update

The transition to a digital-first world enables us to connect, work and live in a realm where information is available at our fingertips. The children of today will be working in an environment of tomorrow that is shaped by hyperconnectivity. Operating in this environment means our present and future generations need to understand the importance […]

HelloXD ransomware bulked up with better encryption, nastier payload
You’re invited! Join us for a live walkthrough of the “Follina” story…
A Getting-Started Guide to Improving Security with Open-Source Static & Dynamic Security Scanners

Several security issues were fixed in liblouis.

Bluetooth Signals Can Be Used to Track Smartphones, Say Researchers

Firefox could be made to crash or run programs as your login if it opened a malicious website.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Industroyer: A cyber‑weapon that brought down a power grid

Five years ago, ESET researchers released their analysis of the first ever malware that was designed specifically to attack power grids The post Industroyer: A cyber‑weapon that brought down a power grid appeared first on WeLiveSecurity

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Two vulnerabilities were discovered that the containerd container runtime, which could result in denial of service or incomplete restriction of capabilities.

– lockState: do not print `error:` when exit code is unaffected (#2090926) —- – fix potential DoS from unprivileged users via the state file (CVE-2022-1348)

security update

Several vulnerabilities were discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of these flaws for local root privilege escalation.

Multiple vulnerabilities were discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed media file is opened.

3 takeaways from RSA Conference 2022 – Week in security with Tony Anscombe

Here are three themes that stood out at the world’s largest gathering of cybersecurity professionals The post 3 takeaways from RSA Conference 2022 – Week in security with Tony Anscombe appeared first on WeLiveSecurity

RSA – APIs, your organization’s dedicated backdoors

API-based data transfer is so rapid, there’s but little time to stop very bad things happening quickly The post RSA – APIs, your organization’s dedicated backdoors appeared first on WeLiveSecurity

U.S. Water Utilities Prime Cyberattack Target, Experts
Potent Emotet Variant Spreads Via Stolen Email Credentials
Feds Forced Travel Firms to Share Surveillance Data on Hacker
Kubernetes Operators: good security practices

An update that fixes one vulnerability is now available.

OMIGOD: Cloud providers still using secret middleware

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The container suse-sles-15-sp3-chost-byos-v20220609-x86_64-gen2 was updated. The following patches have been included in this update:

bump to v1.23.4, security fix for CVE-2022-21698 —- Add missing container networking dependencies (#2081834)

World Economic Forum wants a global map of online crime

security update

Threat and risk specialists signal post-COVID conference season is back on
RSA – Digital healthcare meets security, but does it really want to?

Technology is understandably viewed as a nuisance to be managed in pursuit of the health organizations’ primary mission The post RSA – Digital healthcare meets security, but does it really want to? appeared first on WeLiveSecurity

Symbiote Linux malware spotted, and infections are ‘very hard to detect’
You can be tracked via your Bluetooth signal, researchers claim
DogWalk zero-day Windows bug receives patch – but not from Microsoft

An update that solves 6 vulnerabilities and has three fixes is now available.

An update that solves 6 vulnerabilities and has two fixes is now available.

An update that solves 6 vulnerabilities and has two fixes is now available.

An update that solves 6 vulnerabilities and has two fixes is now available.

An update that solves 7 vulnerabilities and has three fixes is now available.

“Legacy” cryptography in Fedora 36 and Red Hat Enterprise Linux 9

An update that solves 6 vulnerabilities and has three fixes is now available.

Apple M1 chip contains hardware vulnerability that bypasses memory defense
Emotet malware gang re-emerges with Chrome-based credit card heistware
Chinese ‘Aoqin Dragon’ gang runs undetected ten-year espionage spree
Hardware flaws give Bluetooth chipsets unique fingerprints that can be tracked
Russia, China, warn US its cyber support of Ukraine has consequences
What keeps Mandiant Intelligence EVP Sandra Joyce up at night? The coming storm
Cloud services proving handy for cybercriminals, SANS Institute warns
Google has more reasons why it doesn’t like antitrust law that affects Google
Smashing Security podcast #278: Tim Hortons, avoiding sanctions, and good faith security research
Facebook phishing campaign nets millions in IDs and cash
RSA – Creepy real‑world edition

Digital fiddling somehow got mixed up in a real war The post RSA – Creepy real‑world edition appeared first on WeLiveSecurity

S3 Ep86: The crooks were in our network for HOW long?! [Podcast + Transcript]
Microsoft disrupts Bohrium spear-phishing ring by seizing 41 domains
Symantec: More malware operators moving in to exploit Follina

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Containers vulnerability risk assessment

An update that fixes 6 vulnerabilities is now available.

Several vulnerabilities were discovered in Mailman, a web-based mailing list manager. An attacker could impersonate more privileged accounts through different vectors.

Several security issues were fixed in FFmpeg.

Five Eyes alliance’s top cop says techies are the future of law enforcement

Red Hat Advanced Cluster Management for Kubernetes 2.5.0 is now generally available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Supply chain attacks will get worse: Microsoft Security Response Center boss
Now Windows Follina zero-day exploited to infect PCs with Qbot

security update

SSNDOB Market domains seized, identity theft “brokerage” shut down
Feds raid dark web market selling data on 24 million Americans
Taming the Digital Asset Tsunami
Intel offers ‘server on a card’ reference design for network security
Paying Ransomware Paints Bigger Bullseye on Target’s Back
Getting a list of fixes for a Red Hat product between two dates is easy with daysofrisk.pl
Joomla Security in 2022 – Best Practices To Secure Your Website
Black Basta Ransomware Teams Up with Malware Stalwart Qbot

An update that solves one vulnerability and has four fixes is now available.

MongoDB: From jokes to juggernaut

python-twisted: possible http request smuggling (CVE-2022-24801) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 python-twisted-web-12.1.0-8.el7_9.x86_64.rpm – Scientific Linux Development Team

Beijing-backed baddies target unpatched networking kit to attack telcos
US cyber chiefs: Moving to Shields Down isn’t gonna happen

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

Ukraine’s secret cyber-defense that blunts Russian attacks: Excellent backups

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

GitHub adds supply chain security tools for Rust language
RSA – Spot the real fake

How erring on the side of privacy might ultimately save you from chasing down a virtual rendition of you doing the bidding of a scammer The post RSA – Spot the real fake appeared first on WeLiveSecurity

Know your enemy! Learn how cybercrime adversaries get in…
Cyber Risk Retainers: Not Another Insurance Policy
Conducting Modern Insider Risk Investigations
Follina Exploited by State-Sponsored Hackers
Complete Guide to Keylogging in Linux: Part 2
Attackers Use Public Exploits to Throttle Atlassian Confluence Flaw

An update for rh-postgresql13-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,