Menu

Category Archives: All

Everything

Google: 2021 was a Banner Year for Exploited 0-Day Bugs
US warns North Korean Lazarus gang rises against cryptocurrency outfits
Google tracked record 58 exploited-in-the-wild zero-day security holes in 2021

security update

security update

security update

security update

Kaspersky cracks Yanluowang ransomware, offers free decryptor
GitHub repositories compromised by stolen OAuth tokens
Rethinking Cyber-Defense Strategies in the Public-Cloud Age
‘CatalanGate’ Spyware Infections Tied to NSO Group
Beanstalk cryptocurrency heist: scammer votes himself all the money
ESET uncovers vulnerabilities in Lenovo laptops
Funky Pigeon stalls orders after hackers breach its systems
For cutting-edge web application and API protection – Trust Indusface WAAP

The Migration Toolkit for Containers (MTC) 1.5.4 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Virtualization release 2.6.10 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the container-tools:2.0 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat Ceph Storage 3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Funky Pigeon pauses all orders after ‘security incident’
7 ways to avoid a cloud misconfiguration attack
When “secure” isn’t secure at all: High‑impact UEFI vulnerabilities discovered in Lenovo consumer laptops

ESET researchers discover multiple vulnerabilities in various Lenovo laptop models that allow an attacker with admin privileges to expose the user to firmware-level malware The post When “secure” isn’t secure at all: High‑impact UEFI vulnerabilities discovered in Lenovo consumer laptops appeared first on WeLiveSecurity

UK Prime Minister, Catalan groups ‘targeted by NSO Pegasus spyware’
Microsoft ups bug bounties 30% for cloud lines, pays more for ‘scenario-based’ exploits
How To Create a Transparent Proxy through the Tor Network to Protect Your Privacy Online with archtorify & kalitorify>

Security fix for CVE-2018-25032

Security fix for CVE-2021-25220 New version 4.4.3 Add keama migration utility

Cyberattackers Put the Pedal to the Medal: Podcast

Several security issues were fixed in klibc.

Title::newMainPage() goes into an infinite recursion loop if it points to a local interwiki (CVE-2022-28201). Messages widthheight/widthheightpage/nbytes not escaped when used in galleries or Special:RevisionDelete (CVE-2022-28202).

– Update to 1.2.20 Release notes: https://www.cacti.net/info/changelog/1.2.20

– Update to 1.2.20 Release notes: https://www.cacti.net/info/changelog/1.2.20

A security issue was discovered in Chromium, which could result in the execution of arbitrary code. For the stable distribution (bullseye), this problem has been fixed in

Multiple vulnerabilities have been discovered in abcm2ps: program which translates ABC music description files to PostScript. CVE-2018-10753

Yet another Chrome zero-day emergency update – patch now!
Feds offer $5m reward for info on North Korean cyber crooks
Star loses $500,000 NFT after crooks exploit Rarible market

Containers were incorrectly started with non-empty inheritable Linux process capabilities (CVE-2022-24769) References: – https://bugs.mageia.org/show_bug.cgi?id=30279

Double free in Regexp compilation (CVE-2022-28738). A buffer overrun was found in String-to-Float conversion (CVE-2022-28739). References: – https://bugs.mageia.org/show_bug.cgi?id=30278

7zip reader: fix PPMD read beyond boundary. ZIP reader: fix possible out of bounds read. ISO reader: fix possible heap buffer overflow in read_children(). RARv4 redaer: fix multiple issues in RARv4 filter code (introduced in libarchive 3.6.0): – fix heap use after free in archive_read_format_rar_read_data();

Containers were started incorrectly with non-empty inheritable Linux process capabilities. (CVE-2022-27650) References: – https://bugs.mageia.org/show_bug.cgi?id=30267

Karakurt Ensnares Conti, Diavol Ransomware Groups in Its Web
Cybercriminals are doing their homework in latest banking scam
Google issues third emergency fix for Chrome this year

An update that fixes two vulnerabilities is now available.

North Korea’s Lazarus cyber-gang caught ‘spying’ on chemical sector companies

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Cisco’s Webex app phoned home audio telemetry even when muted
Microsoft-led move takes down ZLoader botnet domains

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

US Government warns of new malware attacks on ICS/SCADA systems
ESET takes part in global operation to disrupt Zloader botnets

ESET researchers provided technical analysis, statistical information, and known command and control server domain names and IP addresses The post ESET takes part in global operation to disrupt Zloader botnets appeared first on WeLiveSecurity

Feds: APTs Have Tools That Can Take Over Critical Infrastructure
S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]
Threat group builds custom malware to attack industrial systems

Several issues have been found in fribidi, a free Implementation of the Unicode BiDi algorithm. The issues are related to stack-buffer-overflow, heap-buffer-overflow, and a SEGV.

Update to 91.8.0

Rebase on upstream version 42.2.25. This rebase fixes CVE-2022-21724.

Security fix for CVE-2022-21698

Security fix for CVE-2022-21698

An update that solves 21 vulnerabilities and has 7 fixes is now available.

OpenSSH SCP deprecation in RHEL 9: What you need to know
Smashing Security podcast #270: Bearded Barbie, EDR scams, and hobbyist crime detectives
Microsoft details how China-linked crew’s malware hides scheduled Windows tasks
Don’t let ransomware crooks spend months in your network – like this govt agency did
Apache says Struts 2 security bug wasn’t fully fixed in 2020
RaidForums hacking site shut down by police, alleged admin arrested
US cryptocurrency coder gets 5 years for North Korea sanctions busting
Taiwan, China square off over chip tech espionage laws
Feds Shut Down RaidForums Hacking Marketplace
Enemybot botnet uses Gafgyt source code with a sprinkling of Mirai
Git for Windows issues update to fix running-someone-else’s-code vuln
Security blind spots in the era of cloud communication & collaboration. Are you protected?

Gzip could be made to overwrite arbitrary files.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

A minor version update (from 7.10.1 to 7.10.2) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

Red Hat OpenShift Container Platform release 4.7.48 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

An update for rh-dotnet31-curl is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Updated images that include numerous enhancements, security, and bug fixes are now available for Red Hat OpenShift Data Foundation 4.10.0 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

Investment firm KKR buys Barracuda Networks
Huawei reportedly furloughs Russian staff and stops taking orders
Microsoft’s huge Patch Tuesday includes fix for bug under attack

security update

Stolen-data market RaidForums taken down in domain seizure
CitySprint confirms security breach, warns delivery drivers their personal data may be in the hands of hackers
Microsoft Zero-Days, Wormable Bugs Spark Concern
AWS fixes local file vuln on internal credential access for Relational Database Service
Hardware-assisted security poised for growth, says Intel
Menswear Brand Zegna Reveals Ransomware Attack
Can we solve the zero-day threat once and for all? No, but here’s what we can do
Five critical bugs fixed in hospital robot control system
Industrial cybersecurity group gathers lobbying force
OpenSSH takes aim at ‘capture now, decrypt later’ quantum attacks

Red Hat OpenShift Container Platform release 4.8.36 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for expat is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,