Menu

Category Archives: All

Everything

Patch your iPhone now against mystery Mail crash bug

Several security issues were fixed in AdvanceCOMP.

A command injection vulnerability was found in Rexical, a lexical scanner generator for the Ruby programming language. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user

Multiple vulnerabilities were discovered in Nokogiri, an HTML/XML/SAX/Reader parser for the Ruby programming language, leading to command injection, XML external entity injection (XXE), and denial-of-service (DoS).

Red Hat AMQ Broker 7.10.1 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for expat is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

How Wi-Fi spy drones snooped on financial firm
Crypto exchange Bittrex coughs up $53m to end claims of US sanctions busting
“Stealing the crown jewels” – see me talk at UK Cyber Week
It’s Patch Tuesday and still no fix for ProxyNotShell Microsoft Exchange holes
Steam account stolen? Here’s how to get it back

Has your Steam account been hacked? Here are the signs to look for and what you can do to get your account back. The post Steam account stolen? Here’s how to get it back appeared first on WeLiveSecurity

Move over Patch Tuesday – it’s Ada Lovelace Day!
China could use Digital Yuan to swerve Russia-style sanctions
If you’re wondering why Google blew $5b on Mandiant, this may shed some light

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

The Most Important Things you Can do to Quickly Secure Ubuntu Linux

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Fortinet warns of critical flaw in its security appliance OSes, admin panels
Cloud security is the new battle zone
Kolide gives you real-time fleet visibility across Mac, Windows, and Linux, answering questions MDMs can’t
Can IAM help save on cyber insurance?
Optus data breach prompts pincer movement of twin regulatory probes
Toyota dev left key to customer info on public GitHub page for five years
Mystery iPhone update patches against iOS 16 mail crash-attack
Pro-Putin goons claim responsibility for blowing US airport websites offline
Intel Alder Lake BIOS code leak may contain vital secrets
Red Hat backs CNCF project, spills TEE support over Kubernetes
Endor Labs offers dependency management platform for open source software
Serious Security: OAuth 2 and why Microsoft is finally forcing you into it

Evgeny Vereshchagin discovered multiple vulnerabilities in D-Bus, a simple interprocess messaging system, which may result in denial of service by an authenticated user.

It’s 2022 and netizens are only now getting serious about cybersecurity

Several security vulnerabilities were discovered in WordPress, a popular content management framework. Server Side Request Forgery and cross-site scripting (XSS) attacks may facilitate the bypass of access controls or the injection of client-side scripts.

Singtel confirms digital burglary at Dialog subsidiary
Criminal multitool LilithBot arrives on malware-as-a-service scene
How do you protect your online systems? Cultivate an insider threat

A security issue was fixed in nginx’s lua module.

Mastercard moves to protect ‘risky and frisky’ crypto transactions

Security fix for CVE-2022-38784

That thing to help protect internet traffic from hijacking? It’s broken
When are we gonna stop calling it ransomware? It’s just data kidnapping now

There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the ‘err_msg’ of ‘sqlite3_exec’ is not releasing after use, while libxml2 emphasizes that the caller needs to release it. (CVE-2021-42523)

A syntactically invalid type signature with incorrectly nested parentheses and curly brackets would cause an assertion failure in debug builds. Similar messages could potentially result in a crash or incorrect message processing in a production build, although we are not aware of a practical example. (CVE-2022-42010)

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup. (CVE-2022-41322)

libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup(). (CVE-2020-29260) References: – https://bugs.mageia.org/show_bug.cgi?id=30917

Core Fixed bug GH-9323 (Crash in ZEND_RETURN/GC/zend_call_function) Fixed bug GH-9361 (Segmentation fault on script exit #9379). Fixed bug GH-9407 (LSP error in eval’d code refers to wrong class for static type).

Non-Responsive Delegation Attack. (CVE-2022-3204) Improves performance when under load, by cutting promiscuous queries for nameserver discovery and limiting the number of times a delegation point can look in the cache for missing records.

Key takeaways from ESET Threat Report T2 2022 – Week in security with Tony Anscombe

A look back on the key trends and developments that shaped the cyberthreat landscape from May to August of this year The post Key takeaways from ESET Threat Report T2 2022 – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Update to the September 2022 update release of .NET Core 3.1 Release Notes: https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.29/3.1.29.md This includes a fix for CVE-2022-38013

Security fix for CVE-2022-21797

Update to the September 2022 update release of .NET Core 3.1 Release Notes: https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.29/3.1.29.md This includes a fix for CVE-2022-38013

Open source incident response solutions
What is the Confidential Containers project?
Biden’s Privacy Shield 2.0 order may not satisfy Europe
Make your neighbor think their house is haunted by blinking their Ikea smart bulbs

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

security update

security update

security update

Binance robbed of $600 million in crypto-tokens
The need to change cybersecurity for the next generation

Healthy habits that are instilled and nurtured at an early age bring lifelong benefits – the same applies to good cybersecurity habits The post The need to change cybersecurity for the next generation appeared first on WeLiveSecurity

ESET Threat Report T2 2022

A view of the T2 2022 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T2 2022 appeared first on WeLiveSecurity

WhatsApp goes after Chinese password scammers via US court
Utility security is so bad, US DoE offers rate cuts to improve it

Security fix for CVE-2022-38784

Some stability fixes. —- Update to 2.53.14 Note that besides the ordinary builds for the current Fedora and EPEL branches, there is an additional distro- independed build available at https://buc.fedorapeople.org/seamonkey . So if you have friends who use other Linux distro, but that distro does not provide SeaMonkey yet, you can recommend it for them.

Rebase to 2.4.9

**Version 3.4.3** (2022-09-28) * Fix a security issue on filesystem loader (possibility to load a template outside a configured directory)

**Version 2.15.3** (2022-09-28) * Fix a security issue on filesystem loader (possibility to load a template outside a configured directory)

Updated to version 0.10.2 with CVE fix.

Loads of PostgreSQL systems are sitting on the internet without SSL encryption
Hardening data security in the cloud
Top of the Pops: US authorities list the 20 hottest vulns that China’s hackers love to hit
Lloyd’s of London reboots after dodgy network activity detected
Huge nonprofit hospital network suffers IT meltdown after ‘security incident’
NetWalker ransomware affiliate sentenced to 20 years by Florida court
Papa John’s sued for ‘wiretap’ spying on website mouse clicks, keystrokes
Foreign spies hijacking US mid-terms? FBI, CISA are cool as cucumbers about it
S3 Ep103: Scammers in the Slammer (and other stories) [Audio + Text]

expat: a use-after-free in the doContent function in xmlparse.c (CVE-2022-40674) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 expat-2.1.0-15.el7_9.i686.rpm expat-2.1.0-15.el7_9.x86_64.rpm expat-debuginfo-2.1.0-15.el7_9.i686.rpm expat-debuginfo-2.1.0-15.el7_9.x86_ [More…]

squid: buffer-over-read in SSPI and SMB authentication (CVE-2022-41318) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 squid-3.5.20-17.el7_9.8.x86_64.rpm squid-debuginfo-3.5.20-17.el7_9.8.x86_64.rpm squid-migration-script-3.5.20-17.el7_9.8.x86_64.rpm squid-sysvinit [More…]

Australian Federal Police arrest man suspected of exploiting Optus cyberattack

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Smashing Security podcast #292: Trussterflucks and eBay stalking
Learning from real life situations
Former Uber CSO convicted of covering up megabreach back in 2016
Former Uber CSO convicted for covering up massive 2016 data theft
NetWalker ransomware scumbag jailed for 20 years

security update

security update

security update

Cyber-snoops broke into US military contractor, stole data, hid for months